Mounting workplace issues prompt infosec burnout scare The Register

The proportion of cybersecurity professionals reporting low "Happiness ratings" has risen sharply over the last 12 months, raising concerns about increasing burnout rates in the industry. According to 14,865 global infosec workers surveyed by ISC2, the largest portion fall into the "Low employee experience" bracket, indicating low levels of happiness at work. By contrast, the proportion of workers that fell into the medium and high employee experience brackets was recorded at 31.8 percent and 31.3 percent respectively. The data indicated overall workplace happiness is falling across the board, with both medium and high-satisfaction ratings dropping and "Low satisfaction" ratings the only bracket that grew, increasing by more than five percent. Issues such as departmental cutbacks, the ever-looming threat of layoffs, and lack of managerial support were cited as the main reasons contributing to a reduction in overall happiness. "Having a strong culture within cybersecurity is critical for organizational success. Happy workers are more motivated, more focused, and are less likely to make mistakes," ISC2 said in its report. The data suggests that the threat of layoffs may have a more profound impact on a cybersecurity pro's job happiness than the layoffs that have already happened and the ongoing skills shortages. Those who expect job losses to come in the next 12 months reported a happiness score of just 38.9 compared to those who don't expect any layoffs, with the latter group scoring 59.5. "68 percent of those who experienced layoffs said those layoffs significantly hurt team morale, and 62 percent reported that cybersecurity cutbacks have a negative effect on productivity," ISC2 said. The majority of pros reported a heavier workload in the past year, with the most commonly cited pain points being excessive emails and tasks, and lack of resources to do the job effectively, as well as staffing and skills-related issues. Both the overabundance of emails and tasks, and the general feeling of being overworked, were reported in significant numbers by staff at organizations that were suffering from personnel and skill shortages, as well as those at organizations that suffered from neither of these issues. A much larger gap in reporting was observed when looking at the adequacy of resources available to workers at organizations struggling with staff numbers and skills. Nearly half of respondents said resources were an issue compared to just 13 percent at well-staffed and sufficiently skilled organizations. Such issues weren't as common across the board as heavy workloads, but those with managers who either didn't support or respect their workers most often reported the lowest levels of workplace satisfaction. "Those at organizations with staffing shortages and skills gaps are considerably more likely to report a lack of support from managers/executives, a feeling that their employers don't value - or even listen to - their input, and more." This year's estimated total number of security pros has risen 8.7 percent to 5.4 million, with growth particularly evident in North America and Japan with respective rates of 11.3 and 24 percent year-on-year. The Middle East and Africa also both reported growth of more than 11 percent, but this year's study considered responses from Saudi Arabia, the United Arab Emirates, Nigeria, and South Africa for the first time, so the year-on-year results are based on estimates for these four and therefore may not be entirely reflective of the entire regions. Only a handful of countries reported a decline in hiring growth: Mexico and Germany saw slight reductions with -1.2 and -1.9 percent respectively. Singapore's growth shrank a tiny -0.6 percent, while Australia's slowed the most at -3.4 percent. Although hiring is up almost everywhere, that industry skills gap has grown wider again - as it seems to every year - this year by 12.6 percent, according to ISC2's estimates.

This Cyber News was published on www.theregister.com. Publication date: Thu, 30 Nov 2023 23:19:27 +0000


Cyber News related to Mounting workplace issues prompt infosec burnout scare The Register

Sophos: Cyber Security Professional Burnout Is Widespread, Creating Risk for APAC Organisations - Many cybersecurity professionals with burnout in APAC have suffered in silence for years. The Sophos report, The Future of Cybersecurity in Asia-Pacific and Japan, found burnout and fatigue are widespread, with nine out of 10 employees impacted on ...
9 months ago Techrepublic.com
Forget Deepfakes or Phishing: Prompt Injection is GenAI's Biggest Problem - Cybersecurity professionals and technology innovators need to be thinking less about the threats from GenAI and more about the threats to GenAI from attackers who know how to pick apart the design weaknesses and flaws in these systems. Chief among ...
10 months ago Darkreading.com
Mounting workplace issues prompt infosec burnout scare The Register - The proportion of cybersecurity professionals reporting low "Happiness ratings" has risen sharply over the last 12 months, raising concerns about increasing burnout rates in the industry. According to 14,865 global infosec workers surveyed by ISC2, ...
1 year ago Theregister.com
How AI can be hacked with prompt injection: NIST report - As AI proliferates, so does the discovery and exploitation of AI cybersecurity vulnerabilities. Prompt injection is one such vulnerability that specifically attacks generative AI. In Adversarial Machine Learning: A Taxonomy and Terminology of Attacks ...
9 months ago Securityintelligence.com
AuditBoard enhances InfoSec Solutions to reduce compliance fatigue across the organization - AuditBoard announced powerful enhancements for its InfoSec Solutions to help organizations meet their IT compliance, cyber risk, and vendor risk management needs in the face of rising risks and increased regulatory requirements. With these new ...
7 months ago Helpnetsecurity.com
CVE-2013-0135 - Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) addressbook/register/delete_user.php, (2) addressbook/register/edit_user.php, or (3) ...
7 years ago
CVE-2017-17713 - Trape before 2017-11-05 has SQL injection via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, the /register country parameter, the /register countryCode parameter, the /register cpu parameter, the /register isp ...
6 years ago
CVE-2017-17714 - Trape before 2017-11-05 has XSS via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, the /register country parameter, the /register countryCode parameter, the /register cpu parameter, the /register isp parameter, ...
6 years ago
CVE-2023-52780 - In the Linux kernel, the following vulnerability has been resolved: net: mvneta: fix calls to page_pool_get_stats Calling page_pool_get_stats in the mvneta driver without checks leads to kernel crashes. First the page pool is only available if the bm ...
7 months ago Tenable.com
CVE-2024-47716 - In the Linux kernel, the following vulnerability has been resolved: ARM: 9410/1: vfp: Use asm volatile in fmrx/fmxr macros Floating point instructions in userspace can crash some arm kernels built with clang/LLD 17.0.6: BUG: unsupported FP ...
2 months ago Tenable.com
Infosec pros sound off on usefulness of higher education The Register - Half of infosec professionals polled by Kaspersky said any cybersecurity knowledge they picked up from their higher education is at best somewhat useful for doing their day jobs. On the other hand, half said the know-how was at least very useful. The ...
10 months ago Go.theregister.com
Infosec pros sound off on usefulness of higher education The Register - Half of infosec professionals polled by Kaspersky said any cybersecurity knowledge they picked up from their higher education is at best somewhat useful for doing their day jobs. On the other hand, half said the know-how was at least very useful. The ...
10 months ago Theregister.com
CVE-2015-2351 - Multiple cross-site scripting (XSS) vulnerabilities in Alkacon OpenCms 9.5.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) homelink parameter to ...
6 years ago
What is Certified information Security Manager? Definition from SearchSecurity - Certified Information Security Manager is an advanced certification that indicates that an individual possesses the knowledge and experience required to develop and manage an enterprise information security program. CISM is offered by ISACA, a ...
9 months ago Techtarget.com
OWASP Top 10 for LLM Applications: A Quick Guide - Even still, the expertise and insights provided, including prevention and mitigation techniques, are highly valuable to anyone building or interfacing with LLM applications. Prompt injections are maliciously crafted inputs that lead to an LLM ...
8 months ago Securityboulevard.com
CVE-2023-30549 - Apptainer is an open source container platform for Linux. There is an ext4 use-after-free flaw that is exploitable through versions of Apptainer < 1.1.0 and installations that include apptainer-suid < 1.1.8 on older operating systems where that ...
1 year ago
3 ways to reduce stress on the DevSecOps team - My session focused on the stresses and burnout experienced by security teams, including recent data showing that 94% of chief information security officers suffer from work-related stress, and 65% admit their stress levels compromise their ability to ...
1 year ago Infoworld.com
CVE-2023-22499 - Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Multi-threaded programs were able to spoof interactive permission prompt by rewriting the prompt to suggest that program is waiting on user confirmation to unrelated ...
1 year ago
UAC Bypass: 3 Methods Used Malware In Windows 11 in 2024 - User Account Control is one of the security measures introduced by Microsoft to prevent malicious software from executing without the user's knowledge. Modern malware has found effective ways to bypass this barrier and ensure silent deployment on the ...
6 months ago Cybersecuritynews.com
The Cyber Risk Nightmare and Financial Risk Disaster of Using Personal Messaging Apps in The Workplace - This practice, which is unfortunately still widespread in an environment of relentless cyberattacks, is fraught with major cyber and financial risk. Unsecure messaging apps are a gateway for cybercriminals to access, expose and exploit an ...
11 months ago Cyberdefensemagazine.com
New Relic warns customers it's experienced a cyber incident The Register - Web tracking and analytics outfit New Relic has issued a scanty security advisory warning customers it has experienced a scary cyber something. "We value our New Relic community and want to make our customers aware of a recent cyber security incident ...
1 year ago Theregister.com
CVE-2024-26706 - In the Linux kernel, the following vulnerability has been resolved: parisc: Fix random data corruption from exception handler The current exception handler implementation, which assists when accessing user space memory, may exhibit random data ...
8 months ago Tenable.com
British Library confirms IT outage caused by infosec issue The Register - The British Library has confirmed to The Register that a "Cyber incident" is the cause of a "Major" multi-day IT outage. The social media mouthpiece for the Library began reporting issues on the morning of October 28, saying its website and services ...
1 year ago Theregister.com
Cisco intros AI to find firewall flaws, but it'll cost you The Register - Cisco's executive veep for security Jeetu Patel has predicted that AI will change the infosec landscape, but that end users will eventually pay for the privilege of having a binary brainbox by their side when they go into battle. Speaking at the Asia ...
1 year ago Go.theregister.com
3 Ways to Close the Cybersecurity Skills Gap - Cybersecurity jobs continue to be the most in demand, as the industry cannot keep up with the number of openings, which currently sit at more than 700,000. 66% of professionals in cybersecurity roles report feeling significantly stressed at work, due ...
1 year ago Darkreading.com

Latest Cyber News


Cyber Trends (last 7 days)


Trending Cyber News (last 7 days)