Burnout is an operational-readiness signal

An exhausted security analyst creates a security-operations problem because detecting, investigating and containing threats requires sustained human attention. Security teams continuously monitor digital environments and respond to incidents while facing attackers who need to succeed only once. Staffing constraints, budget pressure, rapidly changing technology and AI-fueled threats add to that demand, so burnout can signal that the operating model consumes human capacity faster than the team can restore it.

That operational framing differs from a common response to employee burnout in other industries, where organizations may focus on work-life balance or individual stress-management skills. Cybersecurity experts argued that their field may be different, and perhaps unique, because system and operational design can directly contribute to the strain. When people repeatedly receive work that technology creates but cannot complete, individual coping skills leave the operating problem unchanged.

Debbie Sallis, executive director of The Cyber Guild Foundation, put that connection at the center of the “Burnout and Resilience in Cyber Operations” panel she moderated at the 17th annual Billington Cybersecurity Summit in Washington, D.C., this September. “We believe that burnout isn’t simply a wellness issue … Burnout is really about operational readiness and resilience, and therefore, it’s a mission-critical subject.” For CISOs and SOC leaders, that connection puts analyst exhaustion inside operational planning because it affects whether the security function can perform when needed.

The workload data points to a capacity problem

The reported workload supports this view of burnout as a readiness issue. The 2025 ISC2 Cybersecurity Workforce Study found that 48% of cybersecurity professionals surveyed were exhausted from trying to keep pace with current threats and emerging technologies, while 47% said their workloads often overwhelmed them. The findings show substantial strain among those surveyed, although they do not establish that every security organization faces the same problem.

That strain can reach capabilities organizations depend on during an incident. Burnout can make it harder to retain good people and preserve institutional knowledge, while overloaded and exhausted staff can struggle to identify and respond to threats. Experienced attention matters especially when an investigation requires knowledge of an organization’s environment, previous incidents and established response practices.

Those consequences create a distinction between capability and capacity. An organization can have the products, procedures and skills that constitute a security capability on paper while lacking enough experienced human attention to exercise it reliably. Under staffing and budget constraints, appropriate security products can therefore coexist with an operational weakness because the team may have too little capacity to process what those products generate and act on it effectively.

Okoone experts
LET'S TALK!

A project in mind?
Schedule a 30-minute meeting with us.

Senior experts helping you move faster across product, engineering, cloud & AI.

Please enter a valid business email address.

Tool-rich SOCs can still consume scarce analyst capacity

That capacity problem becomes clearer inside the SOC, where tools intended to improve security can also create work that analysts must absorb. David Grundy, public sector CTO at workflow automation platform Tines, describes burnout as “an issue of system design” within a threat environment whose demands continue to compound. Tines sells workflow automation, so the company benefits when security teams see automation and workflow design as ways to address that burden. Grundy’s diagnosis focuses on how security operations distribute work, helping explain why workload can remain high even in a tool-rich environment.

Rapid technology introduction is one part of the design problem Grundy identifies. According to Grundy, new tools reach staff and analysts quickly while those people are also pulled into false-positive investigations, audit logging and reporting. “That is not what I would call fulfilling work,” he said. Each activity consumes analyst time, including time from people hired for their security judgment and experience.

False positives show that allocation problem clearly because an automated signal can still require human research before anyone knows whether a real threat exists. When analysts spend large amounts of attention on signals that prove harmless, that attention is unavailable for harder investigations, security improvements or emerging risks. The cost is measured in the experienced judgment consumed by triage.

Audit logging and reporting place a different demand on the same constrained group. These tasks may be necessary, but repeated processing takes time that cannot also go to investigation or proactive security design. Adding tools without redesigning those flows can increase the information and processes humans must handle, even when every product has a valid security purpose.

The same pattern appears when organizations try to bring new people into security work. Patrica Titus, field CISO at cybersecurity software company Abnormal AI, recalled attempts to train help desk employees as security analysts, only to find that the resulting role did not match what those employees wanted from security work. “They don’t want to be ticket takers and today, that’s what’s happening.” Abnormal AI sells cybersecurity software and benefits commercially when buyers see AI-driven technology as a way to reduce repetitive analyst work, so Titus’s diagnosis also comes from a vendor with a stake in that direction.

The SOC shows why owning security products alone cannot resolve the human bottleneck. A security information and event management system, or SIEM, and endpoint detection and response, or EDR, can generate alerts around the clock, but human investigation is still required. Continuous detection can therefore expose a shortage of analyst attention even when an organization has deployed appropriate products.

That shortage matters more during incident response. A well-designed response plan establishes what the organization should do, yet execution still depends on people with enough capacity and experience to carry it out. When those people are already occupied by investigations, logging, reporting and other transactions, the plan can exist while the team struggles to execute it under pressure.

The resulting management question is how much experienced attention the operating system around the tools consumes and where that attention goes. SOC leaders also need to know whether routine work crowds out activities that depend most on human judgment. Framed this way, workload provides a test for any additional technology: how it changes the allocation of human work, including when that technology is AI.

The same logic sets a higher bar for AI

AI enters security operations with its own tension because it contributes to the threat environment while also offering ways to reduce analyst workload. Titus said, “We have a growing threat landscape that AI is introducing and making worse,” and pointed to harmful applications including creating “cyberweapons of mass destruction” and attacks against companies and water plants. Security teams are therefore evaluating AI while simultaneously dealing with threats it can help create.

That tension puts work allocation at the center of Titus’s proposed response. She argues for technology that removes analysts’ “low-risk, churn work” so they can become more efficient and effective at work they actually want to perform. Because Abnormal AI has a commercial interest in organizations adopting AI-based cybersecurity technology, leaders can treat that prescription as a vendor claim while examining the mechanism it proposes: fewer low-risk tasks requiring human time.

The mechanism also sets a limit on what deployment alone can establish. AI deployment needs evidence of changed work before leaders can infer lower burnout, while Grundy’s system-design diagnosis gives them a reason to examine how the technology changes work. Rapid technology introduction is already one of the pressures he identifies, so a poorly integrated AI product can become another system to operate, monitor or respond to while leaving work allocation unchanged.

For that reason, the adoption test should focus on the human queue before and after deployment. A useful AI deployment removes suitable repetitive and low-risk tasks from that queue and releases experienced attention for work where judgment, responsibility and creativity matter. Features have little operational value when analysts remain responsible for essentially the same recurring burden afterward.

Useful AI removes transactional work

Applying that test makes the proposed AI uses more specific. AI can take on alert triage and routine analysis, assist investigations and summarize information, reducing the repetitive processing analysts perform themselves. For an overloaded SOC, the material change comes when those uses remove recurring low-risk work and free the people who handled it to spend their time elsewhere.

From Tines’ commercially interested perspective as a workflow-automation vendor, Grundy says more mature organizations are already applying AI to transactional and rudimentary “muck work” while broadening analyst roles toward a more end-to-end model. His claim describes a direction among those organizations and is not a quantified industry trend. The operating-model claim is specific: automation absorbs suitable transactions while analysts gain wider responsibility for work across security processes.

That wider responsibility separates recovered capacity from higher transaction throughput. An analyst who closes more routine items per hour may still spend the day processing routine items. When automation reduces the underlying routine workload, the analyst can use the recovered time to make decisions across investigations, improve operations and address problems that require technical context and judgment.

Recovered time can support the more proactive role Grundy describes. He sees analysts “designing new processes, new operations and new models” for their teams, becoming more creative, developing new methods of support and working ahead of the threat landscape. In practice, the benefit he attributes to AI appears when analysts gain enough room to change security operations themselves.

That change gives leaders a concrete before-and-after test for automation. In the capacity-constrained SOC, products generate alerts and transactions that analysts must continuously absorb, leaving proactive work to compete for the attention that remains. In the redesigned model Grundy advocates, automation handles appropriate repetitive work while people gain time for end-to-end responsibility, creative problem solving and forward-looking security design.

Measure AI by the human capacity it gives back

The before-and-after test also defines what CISOs and SOC leaders can measure after an AI investment. Productivity matters, but transaction counts alone cannot show whether experienced people gained room to exercise judgment, own work end to end, develop new processes and move security activity toward emerging threats. Leaders can instead examine whether automation changed how scarce human attention is used.

Titus describes the intended role for AI amid the pressure surrounding security teams: “There’s so much stress around us. We have to turn AI into the helpful companion in our operations centers.” For Abnormal AI, that framing supports a market in which AI becomes part of security operations, giving the company a commercial stake in the claim. For a buyer, the relevant test is observable human work: whether low-value transactional effort falls and experienced attention becomes available for decisions and proactive operations.

That test makes deployment the point at which measurement begins. A team that implements AI and continues spending essentially the same human time on triage, routine analysis and other recurring work has not demonstrated recovered analyst capacity. A team that removes suitable work from human queues can identify where the released time goes, including investigations, process design, broader responsibility and work on emerging threats.

Key takeaways for leaders

  • Treat burnout as an operational-readiness signal: CISOs and SOC leaders can track analyst exhaustion as a capacity risk because sustained overload can weaken threat detection, incident response and retention of institutional knowledge.
  • Manage security capacity alongside capability: Security products and skilled staff do not guarantee reliable operations when experienced attention is overwhelmed. Security leaders can assess whether staffing and workload leave enough capacity to exercise existing capabilities during incidents.
  • Measure the analyst workload created by security tools: Alerts, false positives, reporting and other transactions consume scarce human attention even when the underlying tools serve a valid purpose. SOC leaders can identify where routine work crowds out investigations and proactive security work.
  • Judge AI by how it changes human work: AI deployment demonstrates operational value when it removes suitable repetitive tasks from analyst queues and releases experienced staff for work requiring judgment, responsibility and creativity.
  • Use AI to remove transactional work: Alert triage, routine analysis, investigation support and summarization are practical targets for automation. SOC leaders can redirect recovered time toward end-to-end ownership, process improvement and emerging threats.
  • Measure the capacity AI gives back: Post-deployment metrics can track reductions in recurring human effort and where released analyst time goes. Productivity gains are more meaningful when experienced staff gain measurable capacity for investigations, process design and proactive operations.

Alexander Procter

October 2, 2026

10 Min

Okoone experts
LET'S TALK!

A project in mind?
Schedule a 30-minute meeting with us.

Senior experts helping you move faster across product, engineering, cloud & AI.

Please enter a valid business email address.