By John Hollenberger (Lead Consultant, Fortinet and FIRSTCON26 Speaker) & Jennifer Hollenberger (PhD, LCSW)
August 13, 2026
It’s 3:16 a.m. A failed login alert triggers alongside a suspicious PowerShell command alert. The overnight analyst tags it for investigation and moves on.
By 8:21 a.m., the security team realizes they are no longer dealing with isolated alerts.
An active intrusion is spreading in real time.
Slack messages flood the infosec team. Executives request updates every 15 minutes. Legal wants to know whether customer data has been stolen. IT asks whether operations should cease. Employees complain about access issues.
Then comes the message nobody wants to hear:
“We think they have domain admin.”
For the next several days, nobody truly rests. The CISO stays awake so long his hands shake while typing. The overnight analyst quietly cries in the bathroom after realizing the attacker had been inside the environment for weeks. Another responder misses his daughter’s birthday dinner.
Eventually, the incident ends. Leadership congratulates the team on handling the response well.
But nobody asks how the responders themselves are doing.
The cybersecurity industry is often marketed as exciting, rewarding, fast-paced, and deeply technical, filled with elite professionals conducting threat hunting, defending against nation-state actors, and responding to major attacks.
And while that image is not wrong, there is another side to the work that people do not talk about enough.
Cybersecurity incident response is an intense, high-pressure job. According to Microsoft Security Research, nearly two-thirds of SOC professionals have considered leaving the field because of stress and burnout.
During a major cyber incident, responders are not just solving technical problems. They are managing fear, uncertainty, exhaustion, executive pressure, communication breakdowns, and the reality that their decisions may directly affect businesses, hospitals, schools, governments, and people’s lives.
In preparation for our talk, “Mind Over Malware: Reducing Decision Fatigue in Incident Response Teams", for the 38th Annual FIRST Conference, we spoke with current and former incident responders across the globe about how this work has affected them personally andprofessionally.
While every experience was different, common themes emerged again and again.
Responders described:
One responder described sleeping with his phone beside him for years because of constant on-call expectations. Another shared that even when physically present with family, he often felt mentally absent because of ongoing incidents and anticipation of future ones.
Several responders reflected on the cumulative impact of prolonged crisis work. One described incident response as “a crisis-management job that also happens to be technical.”
Another stated plainly:
“IR is cool, but like hard drugs, don’t do it for long.”
Cybersecurity responders operate under prolonged stress, sleep deprivation, and intense emotional pressure all while trying to make rapid decisions.
In many emergency response professions (eg. fire and police), support systems exist specifically to address the emotional and psychological toll of crisis work. In fact, throughout the United States, Critical Incident Stress Management (CISM) programs provide peer support, counseling, structured debriefings, and psychological first aid for emergency responders after traumatic events.
According to the Occupational Safety and Health Administration (OSHA) Critical Incident Stress Guide, organizations should take proactive steps to reduce the risks associated with critical incident stress among responders and workers exposed to crisis situations.
Yet despite the increasing intensity and frequency of cyber incidents, similar post-incident support structures rarely exist for cybersecurity professionals.
Incident response demands constant high-stakes decision-making under pressure. Teams must analyze incomplete information, coordinate remediation efforts, communicate with leadership, respond to customer concerns, anticipate attacker behavior, and maintain composure.
Over time, this creates decision fatigue: the gradual decline in decision-making quality after prolonged mental strain.
The effects can include:
Organizations cannot eliminate the stress that comes with crisis response, but they can reduce unnecessary harm by recognizing the human limitations of responders.
Practical strategies include:
Small interventions matter too. Taking walks, stepping away from the computer for a few minutes, spending time with people or pets you enjoy, or simply pausing for a snack or meal can help responders reset during long, stressful engagements.
These small interventions are often called distress tolerance techniques. They are simple strategies that help calm the body and mind during high-stress moments. Research in psychology and trauma-informed care shows that techniques like deep breathing, movement, grounding exercises, and stepping away from screens can help reduce the body’s stress response and lower mental overload during a crisis.
The goal is not to eliminate stress completely. In incident response, that simply is not realistic. Instead, these techniques help responders regulate their nervous system enough to stay focused and think clearly during high-pressure situations.
Cybersecurity incidents will continue to happen. Threat actors are not slowing down, and neither are the demands placed on security teams. Organizations need to be prepared to support the people carrying the weight of those crises.
If you or someone on your team is struggling after a major incident, support resources are available:
Many organizations also offer Employee Assistance Programs (EAPs), peer support resources, and counseling services that may help responders process stress and burnout related to incident response work.