The threats posed by rapidly intensifying AI security technologies are increasing burnout among already stressed cybersecurity professionals, according to a new survey that also found employers are relaxing hiring standards and now favour adaptability over hard credentials.
Fully 35 per cent of respondents to peak industry body ISACA’s latest annual State of Cybersecurity survey – which included nearly 100 Australian cybersecurity professionals in a cohort of 1,800 global respondents – said they had seen an increase in cyberattacks compared with last year.
Some 68 per cent of respondents said their jobs have become more stressful over the past five years while 71 per cent blamed this stress on the increasingly complex cybersecurity landscape they’re working in, up from 63 per cent last year.
And 52 per cent said they faced unrealistic expectations or too much work while the proportion saying cybersecurity professionals are leaving their jobs because of high work stress levels jumped from 47 per cent last year to 52 per cent this year.
Those and other key signals confirm that the ICT and, particularly, the cybersecurity burnout crisis – long identified as an issue for outgunned and outflanked cyber defenders – is continuing to get worse, fed by lingering funding shortfalls and the growing intensity of AI-enhanced cyberattacks.
“Burnout is such a real thing, particularly in the more senior ranks, but it’s increasingly flowing down to the teams in general,” ISACA vice chair Jamie Norton told Information Age, “and within the growing threat environment, that stress is not going to abate any time soon.”
There were some small wins, with the proportion blaming their stress on poor work-life balance, inadequately skilled staff, compliance reporting or hiring and retention challenges all dropping slightly – suggesting that organisational culture was slowly improving.
Yet recognition of staff wellbeing isn’t always translating into change: 39 per cent of respondents said their company’s cybersecurity organisation remains somewhat underfunded while 16 per cent are significantly underfunded – up marginally from 14 per cent last year.
“Aside from the threat environment, there's this massive innovation push that I see across most organisations I talk to,” Norton said, because “they just want to go faster – and there's a real perceived risk that if they don't innovate quickly, they're going to fall behind.”
Employers turning to soft skills
With innovation pressures on one side and a growing climate of cybersecurity on the other, managers have been fighting to keep the right balance of staff to both defend against increasingly AI-driven cyberattacks, and to maintain governance and other relevant capabilities.
That struggle is shaping managerial staffing and spending priorities, with a recent Barracuda survey finding around half of senior IT leaders named AI security and governance among their top capability gaps – with AI-powered phishing and social engineering attacks topping the list.
Responding to this ever-changing mix of threats requires more than simply adding more technical expertise – and the ISACA results showed that employers are already rethinking their hiring strategies.
Asked what factors they use in assessing a candidate’s suitability for cybersecurity roles, only 62 per cent named prior cybersecurity work experience – well down from 73 per cent in 2024 – while just 34 per cent said formal credentials are a key factor, down from 38 per cent in 2024.
Many recent university graduates lacked needed skills, with incident response named as the largest skills gap by 47 per cent of respondents and threat detection, data security, vulnerability management, identity and access management, and LLM SecOps skills also hard to find.
Recognising that responding to AI requires flexible thinking, they were more likely to look for attributes like adaptability – up from 61 per cent last year to 67 per cent – and organisational and cultural fit, up from 56 per cent last year to 61 per cent this year.
Indeed, survey respondents most valued critical thinking, communication, problem solving, teamwork, and adaptability – skills that many cybersecurity executives gained in other industries, with 54 per cent saying they worked in a different field before transitioning to cybersecurity.
Still catching up to the AI threat
Whereas a year ago AI-based security tools were seen as a radical improvement on conventional defences, cybercriminals’ use of AI – and cybercriminal activity by AI platforms themselves – have quickly put cybersecurity professionals in a very different situation.
AI agents have proven surprisingly capable at attacking companies unprompted, with revelations that AI agents from Anthropic, OpenAI, and most recently Google have outmanoeuvred guardrails to target and manipulate victim networks.
Malicious automated bot traffic grew nine times faster than human traffic between July 2025 and June this year, according to a new DataDome analysis that found bad bot traffic grew by 124 per cent during that period – even though 65.3 per cent of tested websites stopped none of the bots.
ISACA respondents have similarly seen AI-based attacks quickly dominate their threat profile, with social engineering and business email compromise flagged by 45 per cent of respondents as the cause of a recent cyber attack.
Yet for all the pressure AI is creating, just 8 per cent of organisations said they run regular AI-specific response exercises – with only 20 per cent having AI-specific runbooks in place and 64 per cent admitting they haven’t conducted any AI-related incident response exercises at all.