This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Burnout – The Threat to Security Teams

Download resources

About this session

Chloé Messdaghi, co-founder of We Open Tech and Hacking Is Not a Crime, argues that burnout is a security risk, not a wellness footnote, and that it is produced by how the industry is organised rather than by individuals who fail at self-care. An exhausted analyst clicks the spoofed email from 'the manager' the way a tipsy one would. She walks through the progression from slower replies and lost creativity to insomnia, resentment and physical illness, then the pre-pandemic CISO figures: about a fifth had taken stress leave, nearly half reported damage to mental health, most work well beyond contracted hours and executives openly expect security teams to. She ties this to Ponemon data showing most incident response plans are ad hoc or never reviewed, and to the habit of buying tools instead of planning. Her four investments for managers: listen and act with the team, plan and revisit response plans together, encourage real time off (a recovery week, a monthly day, a no-meeting day) and be kind while respecting boundaries, backed by a 15-minute weekly one-on-one.

Did you notice a shift in your mental health and/or your colleagues? Burnout was at an all time last year due to the surreal 2020. As we approach the end of the pandemic, we recognize how critical mental health plays when accomplishing goals and productivity output. This talk dives into the factors that lead toburnout among security professionals, the clear line between burnout and failure to retain team members, and how to invest in your team to make sure your team is able to thrive during stressful times.   

Key takeaways

  • Treat burnout as a security control failure: exhausted staff click phishing links and miss patches, so watch for slower replies, missed deadlines and withdrawal on the team.
  • Hold a 15-minute weekly one-on-one with each team member to agree priorities and deadlines, and stop micromanaging remote staff between them.
  • Revisit the incident response plan every time a tool, team member or environment changes and name an owner for keeping it current.
  • Make time off real: a full week to recover from burnout, one personal day a month staggered across the team, and one no-meeting day a week.
  • Set communication boundaries: no chat or calls after hours, email means not urgent, and a defined channel for genuine emergencies.

Speakers

Chloé Messdaghi
Chloé Messdaghi
Tech Changemaker & Cofounder HINAC;WOT · Stand Out In Tech
Chloé Messdaghi is the Vice-President of Strategy at Point3 Security. She is an ethical hacker advocate who strongly believes that information security is a humanitarian issue. Besides her passion to keep people safe and empower online & offline… Read moreRead less

Chloé Messdaghi is the Vice-President of Strategy at Point3 Security. She is an ethical hacker advocate who strongly believes that information security is a humanitarian issue. Besides her passion to keep people safe and empower online & offline, she is driven to fight for hacker rights. She is the founder of WeAreHackerz (formerly known as WomenHackerz), president and co-founder of Women of Security (WoSEC), podcaster for ITSP Magazine's The Uncommon Journey, and runs the Hacker Book Club. She will be presenting her latest talk titled “Ethical Hackers and the Amygdala”.

Resources

Tags

More from GoSec 2021

Also from Chloé Messdaghi

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.