Back to news and press releases

8 in 10 cyber security leaders say job has harmed their physical or mental health

Over 40% also admit that stress significantly impairs their performance

News
July 21, 2026
Man with insomnia sitting on a bed, with clock showing 2am

Cardiff, UK, 21 July 2026 Socura, a cyber security services provider that protects many of the nation’s biggest NHS trusts, councils, and private companies, has published a new report: ‘Sleepless in security’. The report, based on a survey of over 500 security leaders in the UK, paints a stark picture of a dedicated senior workforce going above and beyond to maintain organisational resilience, often at a high cost to their work-life balance and overall wellbeing.

Eight in ten security leaders surveyed, including CISOs and Heads of Information Security, said working in cyber security has negatively impacted their mental or physical health. Their jobs are a regular cause of sleeplessness and nightmares, and have even contributed to burnout and depression. Despite the high-stakes nature of the role and its challenges, 94% of security leaders would still recommend a career in the industry.

Other key findings
  • Systemic overtime: On average, security leaders work an extra 38 days a year in overtime, with over three-quarters feeling a ‘very large’ or ‘large’ obligation to always be contactable.
  • Symptoms of stress: The most common impacts of stress include burnout, a lack of sleep, and social withdrawal. 13% of security leaders have experienced depression because of work.
  • Impact on performance: 42% of security leaders admit that stress significantly affects their performance, impairing their judgement and making them more prone to making mistakes.
  • Nightmares about work: Half of security leaders experience a nightmare or stressful work-related dream at least once a month.
  • Job insecurity: 86% of security leaders worry they could be fired in the event of a serious security incident, and a third have taken a pay cut in exchange for a role with less stress or a better work-life balance.
  • Strategic and operational challenges: Keeping pace with new threats and technical complexity are cited as the greatest overall challenges of being a cyber security professional. Leaders specifically highlight AI governance as a major strategic difficulty, while identifying threat intelligence analysis and 24/7 posture monitoring as their primary operational stressors.
“Cyber security has always been challenging, but the burden on leaders in the AI era is heavier than ever,” said Andrew Kays, CEO at Socura. “Intense pressure to avoid breaches is creating an unsustainable workload that is severely damaging leaders’ health and threatening their long-term future in the industry.
"To restore a healthier work-life balance, organisations must support leaders in stepping back from daily firefighting. This gives them the space to focus on strategy and drive improvements that benefit not only themselves and their teams, but the wider business. No single leader should be expected to shoulder the full operational burden of maintaining a 24/7 defence.”

In addition to the impact of stress on human wellbeing, Sleepless in security also highlights a hidden business cost that is less frequently spoken about—the drop in a security leader’s performance and the direct risk this poses to an organisation's resilience.

“While the industry loves the myth of a tireless cyber hero, pressure sharpens focus only up to a point,” said Rebecca McKeown, Founder and Principal Psychologist at Mind Science. “This means that cyber teams rarely enter crises with a full tank. When such a large number of security leaders admit stress impairs their decision-making, a fatigued lapse during a live breach could mean the difference between containment and catastrophe.”
"As cyber security professionals, we are expertly trained to spot anomalies and vulnerabilities in our tech stacks,” said Nasser Arif, Cyber Security Manager, London North West Healthcare NHS Trust. “But when it comes to our own mental and physical health? We’re not nearly as sharp. I personally love this industry and the work I do. Yes, it can be stressful—but with the right support and awareness, the challenges we face are definitely solvable.”
Methodology

In April 2026, Socura commissioned an online survey of 502 UK-based cyber security leaders, including Chief Information Security Officers and Heads of Information Security. Atomik Research, an independent research firm, conducted the survey in accordance with the Market Research Society Code of Conduct.

Resources
  • Read summary blog
  • Read full report
  • View infographic
About Socura

Socura is a Managed Detection and Response provider bringing the power of calm to organisations across the UK. In an ever-changing landscape, we empower teams with the clarity, control, and confidence to minimise cyber security risk and thrive.

Trusted by businesses and critical infrastructure, we deliver a precise, measured, and personal service that shuts down threats swiftly and effectively. We’re proud to be ranked among the top 100 managed security service providers globally.

Contact

Mike Marquiss

Decoded Comms

[email protected]