IBM cyber response chief: After 26 years in incident response, I’m more concerned about burnout than AI
Machine-speed cyberattacks demand more than better tools. They demand better support for defenders.
For the past 26 years, the author has dedicated their career to responding to cyber incidents or leading teams responsible for such tasks. Throughout this period, the threat landscape has transformed from simple opportunistic attacks and early internet worms to organized cybercrime, ransomware syndicates, and even nation-state campaigns. Despite these changes, the core of the job remains human, with analysts and incident responders working tirelessly to investigate, respond, and restore critical systems.
The author believes that the industry is overlooking a significant challenge that has not received enough attention: the human impact of machine-speed threats. While discussions about AI in cybersecurity often focus on the potential capabilities attackers may develop, the author argues that this isn't the most pressing issue. Recent research indicates that AI-enabled attacks have surged by 56% in the past year. The real concern is how this acceleration affects the people expected to defend against these threats daily.
The industry typically discusses cyberattacks in financial terms, such as costs, losses, downtime, and recovery expenses. However, less attention is given to the human cost. Over the years, incident response teams have endured immense pressure, with relationships strained by weeks of continuous work and people taking time off to recover from particularly challenging incidents.
These incidents often occur on weekends and holidays, further disrupting the lives of those involved. The author has personally missed significant events due to the unpredictable nature of cyberattacks.
The sustainability of the workforce has been a long-standing concern, with 68% of incident responders regularly defending against two or more attacks simultaneously, and 67% experiencing daily stress or anxiety related to cyber incidents. If the industry does not address the well-being of defenders, AI will not only expose gaps in technology but also reveal the limits of the people who have shouldered this burden for years.
Therefore, the conversation must shift from whether there are enough people to whether existing resources enable defenders to operate more effectively.
As organizations increasingly apply frontier AI to defense at scale, the author emphasizes that the success of these efforts ultimately depends on the skills, judgment, and expertise of the people working on the digital front lines. The first priority should be preparing the workforce for the transition ahead by providing more time for experimentation, understanding, and integration of new technologies into daily workflows.
Organizations that invest in their people now, offering training, resources, and confidence to adapt alongside the technology, are more likely to navigate this transition successfully.
Leaders must create an environment where AI enhances human expertise rather than adds to the burden. This involves reducing unnecessary cognitive load, eliminating repetitive tasks, and providing better context so responders can focus their energy on decisions that truly require human judgment. Most importantly, resilience starts with people. Retention, wellbeing, and sustainable workload management are crucial considerations, surpassing financial metrics in importance.
The author shares personal insights into how their team has benefited from allowing members to experiment with technology and research areas of interest. This approach not only benefits individual team members but also contributes to the team's overall capabilities. As AI continues to reshape cybersecurity, the author urges leaders to broaden the conversation to include workforce resilience, burnout, operational design, and the conditions that enable defenders to perform at their best.
The organizations that excel in supporting the digital front lines will ultimately be the most resilient. After decades in incident response, the author firmly believes that taking care of people may become one of the most critical security investments.
Written by urgent.news from Fortune's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.