Security1 publisher2 min readPublished
Talos splits security burnout into four injuries with four different fixes
The Threat Source newsletter's author spent the summer in trauma literature from medicine, first response and the military, and came back with four separate conditions that cybersecurity's one word merges into a single problem with a single fix.
The Watch · Security desk
What happened
- Cisco Talos's Threat Source newsletter argues that burnout, the industry's default answer for what the work does to the people doing it, is the wrong word most of the time.
- It separates four conditions, burnout, secondary traumatic stress, vicarious trauma and moral injury, and says each of the four has a different fix.
- The author spent the summer reviewing trauma case studies and clinical literature from first response, medicine, social work and the military, fields with decades of research on the subject.
- Talos says the research and a peer-deployable framework arrive next week, with a longer version in a talk at CYBR.SEC.CON in Houston.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision A manager who reads every case of distress as workload will buy headcount and rotation for a problem the newsletter locates in who gets to make the call.
- exposure Threat intel analysts working through dark web material sit under secondary traumatic stress in this taxonomy, and cutting their workload does not help them.
- constraint With no prevalence figures for security work, nobody can size any of the four conditions in their own team from this material.
The distinction is between workload and decision rights. Burnout, in the newsletter's definition, is "exhaustion from chronic workload, and it eases when the load eases" [2]. That fits the levers a manager already holds. Moral injury is defined as the damage from being made to act against your own values, or from being stopped from doing what you knew was right, and the newsletter puts it where someone owns an outcome but not the decision [5].
Only one of the four is defined by its response to load [19]; the other three are not. Vicarious trauma changes beliefs, not mood [4]; secondary traumatic stress is what absorbing somebody else's trauma does to you, and it looks like trauma [3]. "One word, four injuries, and four different fixes," the author wrote [6].
The basis is one career. The author was a manager during VPNFilter and described that run-in with burnout in an interview with Hazel Burton [9]. Nobody was refusing help afterwards, the newsletter says: "we just didn't have the words" [10]. "I'm writing it all down because I was bad at it in a way that cost me something," the author wrote [14].
The newsletter does not measure how often each of the four turns up in security work [20]. Its evidence is decades of trauma research in first response, medicine, social work and the military, imported wholesale [7]. The author's explanation for the gap: "We're just a young industry" [11].
The same edition carries the casework. Talos disclosed a WebDAV infection chain found while investigating an incident at a Ukrainian government organization, attributed to a Russian threat actor tracked as UAT-10820, delivering the Amatera stealer alongside ZigCryptoStealer and NetSupport Manager [15]. The secondary payloads include a vulnerable driver used to terminate EDR software [17]. Talos assesses with moderate confidence that the operation is opportunistic, broad-based cryptocurrency and credential theft [16].
What to watch
- Whether the peer-deployable framework pairs a distinct intervention with each of the four conditions when it lands.
- Whether Talos publishes any measurement of how common secondary traumatic stress and moral injury are in security teams.
- Whether the Houston talk names the decision-rights changes that moral injury implies for incident command.