CYBR.Minded

The Human Side of Cybersecurity with Bill Brenner

CYBR.SEC.Media Season 1 Episode 1

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 27:19

In the first episode of CYBR.Minded, Dr. Dustin Sachs speaks with Bill Brenner about the human side of cybersecurity: stress, burnout, alert fatigue, mental health, responsibility overload, and why security leaders need to look beyond controls to understand how people actually experience cyber work.

Things mentioned:

Do you have a question for the hosts? Reach out to us at media@cscgroupllc.com 

In this episode:

 Created in partnership with PsyberCog Labs

Keep up with Our Events:


Keep up with CYBR.SEC.Media:

Check out our other shows:

Check out our Conferences and Events:

Support CYBR.SEC.Careers Non-Profit Efforts

Subscribe to the podcast: 

SPEAKER_00

Welcome to Cyberminded, where cybersecurity, behavior, and leadership meet. I'm Dr. Dustin Sachs, and this podcast, co-sponsored by CyberCog Labs and Cybersec Media, asks a simple question. What if the biggest risks in cybersecurity start with how we think, decide, and respond? Each episode is a chance to pause, reflect, and see security through a more human lens. Let's take some time and look beyond the controls to the human side of cybersecurity. Welcome, welcome, welcome to the first episode of Cyberminded. For this first episode, I want to just start with a question that I'm going to pose for everybody that I think sits underneath a lot of cybersecurity conversations. When was the last time a security issue in your organization was truly just a technology failure? Most of the time, there's something else underneath it, a decision that was made under pressure, a process someone worked around, a warning that was missed or ignored, a team that was exhausted, a leader who believed the risk was understood because it was documented. And that's the space this podcast is built to explore. So today we're having our first cyberminded discussion to ask: what are we missing when we focus only on controls and not enough on the people making the decisions around them? My guest today, I'm really excited that our first guest on Cyberminded is none other than the man, the myth, the legend, Bill Brenner, VP and editor-in-chief at Cybersec Media. It is not at all coincidental that Cybersec Media is a partner and the key distributor for this for us, that Bill is our first guest. Bill brings a deeply relevant perspective on cybersecurity media, practitioner storytelling, security culture, and the human side of cyber defense. His work is consistently focused on the realities, security professionals face every day, including cognitive overload, burnout, alert fatigue, resilience, and the pressure of making good decisions in complex environments. What makes this conversation most important is that it sits right at the center of what this show is about and what we want this show to be about: the intersection of cybersecurity behavior and leadership. Because if we want stronger security outcomes, we must understand not only what controls exist, but how people experience them, interpret them, and work around them, or rely on them under pressure. And in Bill's world, that pressure is not abstract. He's seen it show up in discussions with SOC analysts and SOC leaders, in incident response, in security communities, in leadership decisions, and in stories that he has heard and he has experienced, where we talk about what cybersecurity work demands of people. Bill, welcome to Cyberlighted. Thank you, my friend.

SPEAKER_01

Great to kick this off.

SPEAKER_00

Yeah. Anything else that would be helpful for the audience to know about you?

SPEAKER_01

I mean, that was a heck of an introduction. I think I'm gonna redo my LinkedIn bio and just plop that in there.

SPEAKER_00

You know, Bill, we've known each other and had some really good conversations, so I'm really looking forward to this. So before we get into the deeper parts of this conversation, I want to I want to start with your perspective. When you hear the phrase the human side of cybersecurity, what does that mean to you?

SPEAKER_01

The human side of cybersecurity are the people in the trenches, the threat hunters, the security architects and engineers, the governance, risk, and compliance practitioners, everybody who's responsible for a business's security. And we often talk when we're talking about cybersecurity, as you pointed out at the beginning, we talk a lot about the technology. And we don't talk nearly enough about the environmental conditions for the people who are working the technology. But over the last year, it's really become a front burner topic, which I've been glad to see. But what it means to me is everything to do with making sure that the human behind the technologies and behind the policies have the can the conditions and environment that they need to do their work consistently. And you can't do your work consistently if you're in a stressful environment, if your basic needs for how one should take care of themselves aren't being met.

SPEAKER_00

Yeah, that that makes a lot of sense. So what I hear you saying is that the human side is not separate from cybersecurity, it's embedded in how we actually work. Is that fair? Very much. Before we go further, this episode is supported by Cybercog Labs. At CyberCog Labs, we help cybersecurity and risk leaders look beyond control design to understand where human behavior is shaping cyber risk. Because the issue is not that a control does not exist, it's that the control breaks down when real people encounter pressure, ambiguity, competing priorities, unclear incentives, or decision fatigue. Cybercog Labs helps leaders identify those breakdowns and turn behavioral cyber risk into practical, board-relevant insight. Visit us at cybercog.com. That's P-S Y B-E-R-C-O-G.com. Now, with that in mind, let's get into the problem beneath the problem. Bill, one of the reasons I wanted you as the opening guest is that you've been willing to talk very publicly about the human side of cybersecurity in a way that is still really rare in this field. We often talk about burnout, stress, alert, fatigue, and mental health as abstract industry issues. We know that they're there, but no one really talks about them. They become the eloquent in the word. But those words land very differently when someone connects them to a real story. So I want to start there. Can you share a bit, as much as you're comfortable with, obviously, but can you share a bit about your own mental health journey and how it shaped the way you see cybersecurity practitioners?

SPEAKER_01

Yeah. So right around the time, 23 years ago now, where I started really focusing my journalism on what was information security back then. In fact, cybersecurity as a term was frowned upon back then. But I was in the throes of starting to do a lot of work to get to the bottom of why I was the way I was. And so what I mean by that is I had a lot of obsessive, compulsive tendencies. I let addictive behavior get the better of me on a regular basis. And all of that at the root of that was just a history of depression and anxiety that I didn't have the self-awareness to do anything about. And so I was just beginning the work of sorting that out right around the time I started focusing on cybersecurity as a writer. And so a couple of years in, I started blogging about my experience. The blog was called the OCD Diaries. It's still out there. I just I haven't written anything in it for five or six years now.

SPEAKER_00

And part of that's because it sounds like it's kind of like your MySpace page. It's out there somewhere, but you haven't touched it in a while. Yeah, I think that's fair.

SPEAKER_01

You know, somebody needs it from one time or another, and so they press play, but it's just out there for people to find. I don't do any advertising of it. I don't do any public. I used to, but I reached a point where I understood myself well enough and had the mental the tools for better mental resilience. I I had to sort through the medication part and I did the diet and exercise part, which I did. All of these basic things for a human dysfunction, period. But I stopped the OCD diaries because I told my story and I didn't want to keep repeating it. And instead, I wanted to put my energy towards taking care of the mental health problem in my chosen industry.

SPEAKER_00

Yeah. And that that brings up my really my next question, which is when you look at your own experience, where do you see it mirrored in the cybersecurity community?

SPEAKER_01

That's an interesting question. I'm pausing because there are a few ways to go at that. So I'll have to talk about the OCD diaries again because here's something that happened when I started that blog. A lot of people in the security industry latched onto it. Turns out everybody was waiting for somebody to talk about the stuff that they were going through themselves. And that was really where I saw it. Did two things. The first thing was it confirmed for me that I am indeed not a special snowflake, that this is just part of the human condition. We all have our struggles. And people who are in the people who are in the hacking profession are, you know, no exception. But cybersecurity is a very high stress line of work. You're constantly getting deluged with alerts, and you have to figure out which ones are worth following up and which ones are not. Every company has its politics that can weigh on people in ways that make it hard for them to be as effective at their job as they can be. If you're a CISO, my goodness, you're the person who, if something goes wrong, you know, if everything's under control and there's never a breach, you're not getting the credit for that from your organization. But if there's a breach, now you're the fall guy or the fall gal.

SPEAKER_00

There's obviously the trend of, I'll say jokingly, you know, the the statement that CISA stands for chief information scapegoat officer.

SPEAKER_01

But what that does, what I've seen over the years, people who are under that kind of stress, they drink a lot more than they might otherwise. I had an exercise, forget about it. You know, I say that I don't want to paint too broad a brush because I I have a lot of friends in the industry who are at the top of their game when it comes to diet and exercise. I think of somebody like Dave Kennedy of Trusted Sec, who is one of the most disciplined guys I know, and he's in the gym all the time. You know, but there are also a lot of other folks who I've met over the last 23 years that struggle a lot more with those things. And it's usually because they don't have the kind of tools and procedures that you might have if you're, say, a first responder or if you're active military, where there are things for dealing with PTSD. The quality of that stuff is another conversation entirely. But if you are a CISO or you're working on a security team, usually you're working without those resources. And so as attacks get more aggressive, as they increasingly target critical infrastructure and the stakes just get higher and higher, it becomes harder and harder for security professionals to maintain the mental equilibrium that they need to stay steady and on target. And so part of my life's work is remedying that.

SPEAKER_00

Yeah, and you said something at the very beginning that I I wanted I want to double-click on, which was that talking about it and putting a lens to it actually caused people to come out of the woodwork. You and I have talked very candidly about my mental health journey and my journey into really reckoning with my mental health challenges. And I think I had a very similar experience, which is when I posted very much about my personal connections and my personal vulnerabilities around finding out as an adult that I was on the autism spectrum. It was very reassuring to see other people who I had known for years who I never would have put into that book and go, me too. And, you know, hey, if you ever need anything, I'm here for you. You know, there are people out there that I now have a common bond with, not only because we're both in the, we're all in the same industry, but we're all grappling with the same challenges. And I think what that brings out is this idea that many practitioners don't realize in the moment that they're either experiencing distress or that it's normal to feel that sense of distress. Oftentimes we look at people and we say in a business setting, oh, they're just really dedicated, or they're just driven to whatever the mission is, or they'll always do what the job requires. But what we don't realize is the score that's being kept behind the scenes by their mind or their body. Before we kind of transition a little bit, in your view, what are some of the warning signs that a cybersecurity professional, especially an analyst or an incident responder, leader, somebody who maybe doesn't may struggle more with identifying the signs of burnout or the signs of issues? What are those warning signs that they should be paying attention to that show, hey, you know what? Maybe I am carrying more weight than I realize.

SPEAKER_01

So I think danger signs, and this is something that I still struggle with every day. I'll give you an example or two. There are some folks who can just let texts, text messages pile up on their phone, or, you know, maybe they only check their email once a day. I'm always watching the texts. I'm always watching the emails, I'm always watching the Slack channels because, and I'm better at this than I used to be, but you know, this is a common struggle where you can't turn it off. And some of that is a deep-seated fear that when you turn it off, that's when the shit's gonna hit the fan. Pardon my French.

SPEAKER_00

I think we're good because because as the editor-in-chief for Cybersec Media, I think you're gonna you're gonna let that one slip through and we're not gonna get an FCC violation or anything.

SPEAKER_01

I also don't consider it a real swear word in the year 2026.

SPEAKER_00

Fair, fair, fair point.

SPEAKER_01

Yeah, so that's a struggle that affects a person's sleep, affects a person's ability to live in the moment. And so if you're trying a vacation with your family, you're not doing such a good job. You're not fully present. And I've fought this battle a trillion times where you're on vacation, you're supposed to not be looking at anything. And because you're somebody who can't not look, you start letting that you start trying to deal with things. And it's taking away from what you where you should be and what you should be doing in the moment. So we hear a lot of that described among the security vendors who talk about it as alert fatigue, and they talk about it because they see themselves as being a solution to something like that. And so you have alert fatigue. We had we recently had on our cyber hack cast podcast, Wynne Schwartau, a legend in this industry.

SPEAKER_00

Yeah, Bill, Win is definitely a legend in the industry. Uh, if you've not seen that episode, please check out the Cybersec Media website and go find that episode. I was fortunate to get to spend some time with Wynne in Florida earlier this year, and it was one of my favorite conversations so far this year. So, yeah.

SPEAKER_01

Yeah. So one of his big things right now is, and all the speaking that he's doing right now is really centering on this topic, which is the, you know, when is the guy who initially started talking about a cyber Pearl Harbor? This was in the early 90s before a lot of people realized the internet was what it was going to be, what it was to become, what it is now. And he's now talking about a cognitive Pearl Harbor, where you have the complete breakdown of a person's ability to focus on the most important things because they're just constantly under a storm of information, alerts, emails, social media, YouTube, just all of these things. And so he's starting to talk about.

SPEAKER_00

Yeah, that's the ability to ignore the, I would say it even further is the ability to say no. And so many of us, I myself struggle with that ability to say no. One thing I want to be careful about, we don't want to turn mental health into a slogan and cybersecurity. We often reduce complex human realities into shingle phrases like burnout, stress, resilience. But those, I think what I've what I'm taking away from our conversation is those words can hide what people are really experiencing. They may be exhausted because of constant escalations, as you mentioned. They may be afraid of missing something. They may feel responsible for outcomes that they fully can't control. They may be working in environments where every mistake is visible, but many of the pressures that lead to the mistakes are invisible. So this topic is really important, and it's more than just a cliche kind of conversation. It's definitely something important that we need to keep in mind.

SPEAKER_01

Cybersecurity, and you can look at other industries, healthcare is another great example, but healthcare, cybersecurity, you have the largest population of responsibility hoarders, people who feel a responsibility for all the problems out there. And so they have trouble triaging and focusing on where they can actually do the most good or focus on what their job most requires at the time.

SPEAKER_00

Yeah. And I think the other point is this just reinforces the need to have a strong support system, to have a community that you can reach out to. And it's it's such an important thing to have places that you can go to commiserate, to celebrate, to do all of the things that you want to do. And that's where community comes in and really sets up a nice segue because this episode is brought to you in part by Cybersec Media, a cybersecurity media and community platform built for practitioners, leaders, and innovators who want sharper conversations about the human, technical, and operational realities of security. And if you want to be part of that community in person, get your tickets now for CybersecCon, happening September 15th and 16th, 2026 in Houston, Texas. Join cybersecurity leaders, practitioners, researchers, and innovators for two days of insight, connection, and actionable strategies. Secure your spot today at cybersetcon.com. That's cyberwithout the e at sec.com. So this is exactly why I wanted this conversation that you and I've had to open cybermind. We're gonna have a lot of amazing minds, people who have been part of the human factors and behavioral science cybersecurity world for many years. But this show exists because we in cybersecurity need a deeper diagnostic lens. We can't only ask what controls failed. We have to ask what pressure, what fatigue, what fear, what incentives, confusion, or overload made those failures more likely. We cannot only ask whether people follow. The process. We have to ask whether the process was designed for real human beings. It's a question that we talk about at CyberCog Labs every day. Are they operating? You know, have we designed for when for real human beings operating under real constraints or have we created this utopian ideal? And we can't only ask security practitioners to be resilient. We have to ask whether the systems around them create that sense of resilience. So, Bill, as someone who has lived part of this story personally, who's also spent years listening to the cybersecurity community, what do you think the field most needs to confront about mental health right now?

SPEAKER_01

The fact that it's not this separate thing. You know, here's your job, here's your mental health, because the pressures that we talked about that come with being in this industry, they're just going to keep getting worse. You have the AI effect, the Volume Pocalypse, or whatever we're calling it these days. You have the geopolitical tensions with Russia, with China, with North Korea, with Iran. And a lot of these people who are working doing security for private organizations, they are going to end up on the front lines of warfare because cyber, I think, especially if you're if you study what China's been doing, it's the conventional wisdom is that when they decide to move on Taiwan, they're going to start by setting loose all of this malware that they have sitting all over U.S. critical infrastructure to throw us off base and to throw our response off base.

SPEAKER_00

Yeah, I think that's that I couldn't say it better myself. I want to close with a question that I'll be asking every guest on Cyberminded. It's meant to slow the conversation down. We want to leave all listeners with something to reflect on after this episode ends. So the question that I've got for you, this will be the for our listeners who will hopefully keep coming back, you'll hear this from every one of our guests. What is one place where the cybersecurity field needs to slow down and think more carefully?

SPEAKER_01

AI. There's a lot of hysteria right now. There's a lot of noise, there's a lot of, you know, oh, mythos. You know, anthropic won't make it publicly available because it's so damn good at finding vulnerabilities that it's gonna just overload and destroy the system. And I think for things like that, people need to stop and take a breath. And we're going through a huge period of disruption as a society. And there will be opportunities at the other end of it, but we can't really get a clear visual on what those are yet, because we're a couple of years into this. And so I think when people are reading about the abilities of AI and whose job it's going to eliminate, I think people need to stop and do more research, but also remember that for anything to work, there are still humans behind it making decisions and doing the prompting. And I don't think that ever fully goes away.

SPEAKER_00

Yeah, I think you've encapsulated everything really well. So, you know, today's conversation reminds us that cybersecurity is not only about systems tools and controls. It's about the people operating inside those systems, often under pressure and competing priorities. If we want better security, we have to understand the behaviors behind the outcomes. Bill, I want to thank you so much for being our inaugural guest, for joining this conversation, for sharing your story, for being very open and vulnerable to share your story. I want to thank CyberCOG Labs and Cybersec Media for supporting this show, for supporting this crazy idea that we hope you all will start tuning in for on a regular basis. Until next time, look beyond the controls and pay attention to the human side of cybersecurity. Thanks, everyone. We'll see you again on the next episode.

SPEAKER_01

This has been a Cybersec Community production, recorded in partnership with CyberCog Labs. Cyberminded is hosted by Dr. Dustin Sachs. It's produced by Bill Brenner, edited by Ivan Basconcillo, and our music is by Staple Audio. Views and opinions expressed in this show are those of the speakers and do not necessarily reflect the views or positions of any entities they represent. The show is for informational purposes only and does not render or offer to render personalized advice. Subscribe now so you never miss an episode. You can find all our podcasts, articles, blogs, and conference talks on cybersecmedia.com. That's cyberwithout the e. And follow Cybersec Media on LinkedIn, X, Instagram, and Facebook at Cybersec Media. You can keep up with our conferences by following us on LinkedIn, X, Instagram, and Facebook at Cybersec.com. And you can learn more about our events or buy tickets at cybersecon.com.