Future of Cybersecurity in APJ 2024: The Cybersecurity Kids Aren’t All Right
Cybersecurity Professionals Are Feeling the Heat of a Threat-Filled Landscape
The impacts of cyber threats are becoming more and more understood. Individuals are aware of the reputational, operational, and financial consequences of a cyberattack; however, there is one more risk flying under the radar. Sophos recently published the Future of Cybersecurity in APJ 2024 report, which uncovered worrying truths about the mental health of cybersecurity professionals.
According to Sophos’s Future of Cybersecurity in APJ 2024 report, burnout, fatigue, and disconnection to board directors dominated headspaces—and with cyber threats becoming increasingly prevalent, the industry must find a way to address this detrimental sentiment.
A Deteriorating Disposition: The State of Cybersecurity Professionals’ Headspace
The Future of Cybersecurity in APJ 2024 report found that, in Malaysia, 91 percent of respondents declared their employees had suffered, or were currently suffering from, fatigue and burnout. The two leading reasons cited for these overwhelming levels aren’t surprising: 58 percent said their burnout and fatigue were caused by a lack of resources, while 44 percent cited their burnout is due to increased pressure from executive or board management.
Both of these contributing factors could be put down to poor hiring practices. It is now quite common to hear of candidates looking to break into “cyber” and then find out that the position they are filling isn’t what they expected it to be. But were they consulted, prescriptively, on what their roles would be?
Mishiring cyber specialists into roles that do not match their skill sets or career goals is a sure way to put employees on the back foot. Furthermore, a lack of support and resourcing breeds more friction, preventing smooth operational defences against threats—to the point where 19 percent of respondents to the Future of Cybersecurity in APJ 2024 report stated that such issues contributed to a breach.
To help improve cybersecurity professionals’ mental health, organisations should support cyber-defenders to do more of what they do like to do best, guiding them towards acquiring greater skills and knowledge.
Future of Cybersecurity in APJ 2024: Addressing Culture from the Top Down
This industry desperately needs a better attitude toward fostering a healthier cyberculture, and it must begin from the top of the food chain. Overall, 49 percent of respondents said their company’s board members didn’t fully understand requirements around cyber resiliency; 46 percent believing the same thing about their C-suite. This is disturbing, as leaders of organisations play a vital role in improving cyberculture. They have the power to listen and address the problem, either using current staff skills and budgets or, if necessary, choosing to reallocate resources to make the necessary changes.
However, this change must stem further than only talking the talk. Survey respondents to the Future of Cybersecurity in APJ 2024 report reported that lip-service and non-committal indicators are the norm—and that leadership’s lack of understanding of their accountability leads to an incorrect expectation of how overall secure the business is.
This personnel crisis is, frankly, an issue of proper risk management. It may be that making that case at executive committee and board levels will bring the issue into focus: stress causes fatigue and burnout, fatigue and burnout cause staff turnover, or something potentially worse. Everyone is aware of how small and large businesses have fallen to cyber breaches due to employee error. These lived experiences should be used as a starting point to help educate and bootstrap a change in attitude towards cyber resilience.
It is also useful to highlight the legal and regulatory impact of cyberattacks on boards—phrasing it in a way that resets leadership’s expected level of accountability and drives change. Sophos’ report found that, in Malaysia, 98 percent of respondents believe legislation and regulatory changes mandating cybersecurity board-level responsibilities and liabilities increase the focus on cybersecurity at a company board or director level.
Finding a Path Forward for the Future of Cybersecurity in APJ 2024
There isn’t a quick fix to reducing pervasive workplace stress. Attitudes toward better stress management and improving other problematic cultural issues in cybersecurity have traditionally moved at a glacial pace. But at least they are moving, and tech leaders can move the needle in individual organisations even if they are not at the top of the corporate food chain. This can take place by:
- Considering the most basic building blocks of their day-to-day work. If employees are equipped with the right technology to help minimise noise and repetitive tasks and empowered with processes that guide them through risk identification and communication, they’ll have a great foundation to build on.
- Keeping a regular cadence of communication. It can be hard for managers to see those small stressors individually, but the cumulative effects of stress are a genuine vulnerability. Learn to recognise the signs of stress in yourself and your peers as well.
Ultimately, the findings of the Future of Cybersecurity in APJ 2024 report highlight how acknowledging stress and taking corrective action to minimise or mitigate constitute a solid base for building a great cybersecurity culture. It is our hope that the simple fact of asking how our colleagues are doing—and of normalising conversations around a topic that is often avoided – can help organisations to better drive positive outcomes around cyber resiliency.
Learn more about the Future of Cybersecurity in APJ 2024 report here.