Accountability without any real authority is driving CISO burnout, and organizations need to take notice.

August 3, 2026

Only 2% of cybersecurity professionals report feeling no stress about their job, according to Omdia and ISSA's eighth annual Life and Times of Cybersecurity Professionals study. In addition, 68% say the work has become measurably harder over the past two years. The difference between those two figures is screaming that stress in this profession has moved from an occupational hazard to the default condition, and that shift changes what conclusions security leaders should draw from the gap.

The common response to numbers like these is a workforce argument: too much pressure on too few people, addressed by hiring more of them or paying them more. Both responses are already underway across the industry, and neither has closed the gap. In fact, 47% of respondents say they have thought about leaving their current job or the profession entirely within the past year. Eight years of the same survey producing the same findings points to a design flaw in the cybersecurity profession itself, one that security leaders experience most directly because that is where an organization's structural problems tend to surface first.