The Breach Was Contained. The Team Wasn't.
- CyberSpeak Labs

- Aug 16
- 4 min read
Author:
Stephen Engler
Owner, Ctrl-Alt-GenX | Cybersecurity Speaker
@PHtheAdmin
Last time I wrote about burnout in the abstract. Turnover stats, survey numbers, the general shape of the problem. It's easy to nod along to numbers like that and go back to your day, because a percentage doesn't land in your gut the way a specific story does. So this time I want to talk about one story instead of another pile of stats, because I read something a couple months ago that I haven't been able to shake.
Infosecurity Magazine covered a new report out of Cybermindz that's trying to do something I think is overdue: treat burnout as a measurable security risk. Not a wellness perk you bolt on with a meditation app subscription and call it a day. Buried in that report is a case that should be required reading for anyone who runs a security team.
A CSO in Luxembourg had his team handle a major insider attack. I don't know the details of the attack itself, and honestly it doesn't matter for the point here. What matters is what happened after. In the aftermath, he lost 6 of his 10 team members. Not to layoffs, not to a competitor poaching them with better pay. To trauma. The incident ended, the postmortem got written, the technical damage got contained, and then, over the following months, the team quietly came apart.
Six out of ten. Sit with that for a second. That kind of number doesn't come from routine turnover, and it happened after the crisis was supposedly over, after everyone assumed the hard part was behind them.
I keep coming back to the phrase "trauma-driven attrition" because it's such a clinical way to describe something genuinely brutal. These weren't people who wore down from the usual grind. They went through something awful together, professionally, and couldn't stay in the job afterward. There was an incident response plan for the breach itself. Nobody, as far as I can tell, had written down so much as a page for what happens to the six people left standing in the wreckage of handling it.
Who plans for that?
Almost nobody, it turns out.
That's the part that connects back to what I've been saying all along. We build incident response plans assuming the technical system is the thing that breaks. Servers, networks, data. We rehearse failover. We document recovery time objectives down to the minute. And then the actual outage, the one that takes out 60 percent of a team's capacity, happens to the humans who responded to the first one, and it gets treated like a personnel matter instead of the second incident it actually was.
I've sat in rooms during a bad incident, nothing as dramatic as Luxembourg but bad enough, and I remember the adrenaline afterward. Everybody's high on having pulled it off, high-fiving, ordering pizza at 3am. That part gets talked about plenty. What gets talked about way less is the three months after, when the adrenaline's gone and what's left is tired people replaying the worst night of their career on a loop. Most leadership doesn't even know to look for that. It doesn't show up on a dashboard. It shows up as a two-week notice that seems to come out of nowhere, and by then it's too late to do much besides backfill the role.
This isn't an isolated Luxembourg thing either. The same research found that roughly half of cybersecurity professionals report burnout symptoms on a weekly or even daily basis. Half. Not a rough patch for a handful of unlucky teams. Just how the job is for a lot of this industry, incident or no incident, and I'll admit that number bothered me more than almost anything else in the report.
I keep asking myself the same question. If we're willing to spend money on redundant infrastructure so one server failing doesn't take down the business, why don't we treat the people who respond to our worst days with anything close to that same rigor? Where's the monitoring for a team sliding toward this kind of collapse? Where's the documented recovery plan for after a major incident that isn't just "great job everyone, see you Monday"? Most places don't have one. Most places have never had to think about their own staff as infrastructure that can fail.
This is exactly why I built the SpiceWorld 2026 talk the way I did. It's not an HR session dressed up as a security talk. The argument is that a story like the Luxembourg case isn't a wellness anecdote, it's an outage report, and we ought to read it the same way we'd read a postmortem on a failed cutover, which sounds obvious written out like that and yet almost nobody actually does it. If you've ever watched a team come out the other side of a real incident and then quietly dissolve over the next few months, you already know this isn't theoretical.
Come find me at SpiceWorld 2026 and I'll walk through what an actual recovery plan for this looks like, not just the case for why we need one.
Follow @PHtheAdmin for updates before the talk.
Stephen Engler
Owner, Ctrl-Alt-GenX | Cybersecurity Speaker
@PHtheAdmin
Sources referenced:
Infosecurity Magazine: Why Burnout Is a Cybersecurity Risk




Comments