Ransomware Is Driving Cyber Security Professionals To Consider Quitting

Persistent ransomware threats and looming, large-scale attacks are pushing some security professionals towards leaving their chosen career. Cyber security has become a hot button issue for businesses around the world, particularly ransomware. The cyber threat has become common threat for every type of business.

Now, a report by cyber security company Deep Instinct has found that 46% of senior and executive-level cybersecurity professionals have considered quitting the industry due to stress. 

Ransomware is a type of malware that prevents you from accessing your computer, or the data that is stored on it. The computer itself may become locked, or the data on it might be stolen, deleted or encrypted. Typically, victims asked to contact the attacker via an anonymous email address or follow instructions on an anonymous web page, to make payment. The payment is usually demanded in a crypto currency, most often Bitcoin, in order to unlock your computer, or access your data. 

The cyber security industry is stretched thin. Ransomware attacks are now so prolific that some companies simply cannot help every newly hacked victim get back online and the chronic shortage of skilled workers means no immediate prospect of relief.

According to Deep Instinct, “More than 90% of cyber security professionals are stressed in their role   Nearly half of the respondents (46%) have thought about quitting the industry and stress levels are increasing across all sectors,” says the Report.  

Deep Instinct's Report is based on the responses of 1,000 senior cybersecurity professionals from companies in the US, UK, Germany and France. All interviewees worked for businesses with 1,000 employees or more, and for businesses with annual revenues of at least US $500m across financial services, retail and eCommerce, healthcare, manufacturing, public sector, critical infrastructure, and technology. 

The more senior the cyber security role, the more stressful the job   A significant proportion of professionals concede that stress is negatively   impacting their ability to do their job.   

“There appears to be a widespread adoption of completely counter-productive   measures, such as switching off alerts because cyber security teams find them to be overwhelming   Paying off the ransomware criminals is in the aftermath of an attack results in  trouble-free consequences in just 16% of cases... We’ve identified that more cyber security professionals than ever are seriously considering leaving the industry permanently because of these pressures, with potentially catastrophic consequences for the organisations that rely on their vigilance." says the Report.

This is being driven by an "unrelenting threat from ransomware", as well as supply chain attacks on a scale similar to the 2020 SolarWinds attack and the 2021 Kaseya ransomware attack and both have had severe consequences for organisations attacked, Deep Instinct found.

 The burden of preventing such attacks weighs heavily on those tasked with keeping networks and wider organisational systems secure

More than 90% of cyber security professionals are stressed in their roles, with a "significant proportion" of professionals conceding that this is negatively impacting their ability to do their jobs. Those in leadership positions are likely to be feeling pressures of the industry more acutely, the report found: one in three C-Suite executives, including CISOs, CTOs, ITOs and IT strategy directors, said they were 'highly stressed'. 

Cyber security problems have been exacerbated by the move to remote working, which has made network security more challenging for organisations. "Senior cybersecurity executives acknowledge that their stress levels are impacting decision-making and can have implications for the security posture of companies," the report added. 
"The stress we're seeing across the cyber industry appears to be accelerating the exodus of talented people from the industry: a particular challenge when many cybersecurity defences and mitigation processes are human-dependent, requiring constant monitoring and intervention."

"Without a singular focus on one type of attack, resources are stretched thin and its obvious to see how a SecOps team may feel deflated against the challenges they face." While organisations are typically advised not to pay hackers in exchange for encrypted data, cyber security professionals are doing so in order to avoid downtime and the associated reputational damage should the attack become public.

More than a third (38%) of survey respondents admitted to both experiencing a ransomware attack and paying the ransom in exchange for the decryption key, compared to 62% that didn't pay. A big problem is that paying hackers off does not guarantee the safe return of company data:

  • 46% of those who paid said records or sensitive information was exposed regardless.
  • 45% were unable to restore all their data
  • 23% of respondents were hit by a subsequent extortion demand after paying the ransom.

Working in cyber security is a hard job, exacerbated by the long, stressful hours that cyber security incident responders have to spend putting out the fires that ransomware cause to ignite 

Worse, the cyber security field is very short-staffed with  74% of organisations reporting that a lack of cyber security skills has had an effect their organisation, while only 9% of millennials have reportedly expressed interested in the industry.

Deep Instinct:       NCSC:     CheckPoint:       Proofpoint:       NBC:       ZDNet:    Tech.co

You Might Also Read: 

Overcoming The Obstacles Caused By The Great Resignation:
 

« What To Look For In A Cyber Essentials Assessment Partner
Iranian Hackers Try Intercepting Israeli & US Government Emails »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Quotium

Quotium

Quotium provides automated testing technologies to make business software applications secure and robust.

Horangi

Horangi

Horangi provides security products and services that enable the rapid delivery of Incident Response and threat detection for our customers who lack the scale, expertise, or time to do it themselves.

NGS (UK)

NGS (UK)

NGS (UK) Ltd are independent, vendor agnostic, next generation security trusted advisors, providing all-encompassing solutions from the perimeter to the endpoint.

Dathena

Dathena

Dathena is a company developing data governance software based on machine learning algorithms.

CybernetIQ

CybernetIQ

CLAW by CybernetIQ is the industry's most advanced SOAR platform helping unify all cybersecurity tools under one umbrella and providing organizations faster, better and more accurate cybersecurity.

Utility Cyber Security Forum

Utility Cyber Security Forum

The Utility Cyber Security Forum offers a focused venue in which utility executives can network one-on-one with colleagues facing issues in protecting against cyber attacks.

Global EPIC

Global EPIC

Global EPIC is an international cybersecurity initiative designed to combat growing world challenges by facilitating global collaboration in the field of cyber security.

EuraTechnologies

EuraTechnologies

EuraTechnologies, the French incubator and accelerator, is a centre of excellence and innovation for startups and entrepreneurs with a focus on Digital, Data, Cybersecurity and IoT.

AmWINS Group

AmWINS Group

AmWINS are a global specialty insurance distributor with expertise in property, casualty and professional lines including cyber liability.

CyberScotland

CyberScotland

The CyberScotland Partnership is a collaboration of key strategic stakeholders, brought together to focus efforts on improving cyber resilience across Scotland in a coordinated and coherent way.

ANSSI Burkina Faso

ANSSI Burkina Faso

ANSSI is responsible for managing the security of information systems and cyberspace in Burkina Faso.

Verinext

Verinext

Verinext delivers transformative business technology, from intelligently automating time-consuming tasks and protecting data assets to securing infrastructure and improving customer experiences.

CloudCoCo

CloudCoCo

CloudCoCo help UK businesses of all sizes and industries succeed by providing enterprise-grade technology at small-business prices.

Corinium Global Intelligence

Corinium Global Intelligence

At Corinium, we have been bringing together the brightest minds in data, AI and info sec since 2013, to innovate at the intersection of technological advancements and critical thinking.

PayPal Ventures

PayPal Ventures

PayPal Ventures invests in companies at the forefront of innovation in fintech, payments, commerce enablement, artificial intelligence, blockchain and cryptocurrency, regulatory and cyber technology.

MIND

MIND

MIND is the first-ever data security platform that puts data loss prevention and insider risk management programs on autopilot, so you can automatically identify, detect and prevent data leaks.