Your Next Vulnerability May Be an Exhausted Employee

That is not an HR talking point. It is a business risk.

Businessman selecting a female leader icon with crown from row of employee profile icons in digital recruitment scene
istock.com/LeoWolfert

We keep treating artificial intelligence (AI) as if it will carry cybersecurity. It will help. It will also help the other side. What it will not do is replace the people who still have to decide, under pressure, whether an alert is noise or a breach.

Those people are exhausted. That is not an HR talking point. It is a business risk.

Employees flooded with too much information, too many false alarms to assess, and too much data to protect can fall victim to decision fatigue, which can leave them drained physically, mentally, and emotionally. Once that happens, they are more likely to display poor judgment or miss threats that should have been caught. 

Poor judgment in that environment is not a character flaw. It is the predictable outcome of piling more data, more tools, and more alerts onto the same finite human attention. 

How grave is this problem of exhausted cybersecurity professionals? A recent survey showed that 68 percent of cybersecurity professionals say their work has become harder over the past two years, even as AI adoption has accelerated. 

The survey, by the Information Systems Security Association and Omdia, had additional bad news for those who worry about the future of their cybersecurity teams. Close to half of respondents said they have thought about leaving their role in the past 18 months, and among those, 57 percent have considered leaving cybersecurity entirely.

Those unwelcome numbers help illustrate why cybersecurity burnout should be considered a business risk and not just an HR problem. If your security team is that close to the exit, you do not have a staffing inconvenience. You have a major vulnerability.

The Risk Goes Beyond Your Business

Data breaches can destroy customer trust and loyalty. Research published by Industrial Marketing Management shows that this is just as true, maybe even more so, in business-to-business relationships as it is in business-to-consumer relationships. 

The research says one reason for this is that if a consumer loses trust in a brand because their data was compromised, it’s fairly simple for them to switch to another brand. But if an organization’s data is breached because of one of its main suppliers, it takes time to build a new trusted business partnership. 

Also, B2B breaches involve more than the loss of buyer or customer data. Intellectual property is at risk, which can prove to be exponentially harmful to businesses that fall victim to breaches.

Part of the problem with cybersecurity overload is the very existence of much of that data. Businesses constantly collect data about customers, clients, and employees, information that must be stored and constantly protected from identity thieves and other bad actors. Much of that information may be unnecessary, presenting a liability for the business and a tantalizing lure for criminals without serving the business in any practical way.

Although AI has become a helpful tool in cybersecurity, it’s not the ultimate solution, in part because AI contributes to the problem. Just as businesses can use AI to help keep data secure, cybercriminals use the technology to thwart those defenses.

Meanwhile, inside the companies, employees can inadvertently leak sensitive data when they plug it into the AI tools they are using. That, of course, gives those already fatigued cybersecurity employees even more to be anxious about. 

One of the first steps in solving this onerous problem is for businesses to re-evaluate how much data they collect and store. The less data to protect, the fewer worries for the cybersecurity teams that already are reporting their jobs have gotten harder, not easier, over the last two years. 

The first question is not which new dashboard to buy. It is a harder one: why do we have this data at all?

Data triage may be in order. Instead of collecting everything, focus on what is essential, and avoid storing raw personal information. Instead, use tokenized, privacy-first verification methods.

For example, does a business really need a person’s Social Security number to verify background information? Also, businesses should consider whether much of the data they have stored currently is out of date and serving no purpose other than to fall victim to a breach. Companies should revisit their data-retention policies and consider discarding old data that is no longer of use.

There is a better design than copying the same identifiers into every vendor, platform, and HR system. Verify once. Turn the result into a reusable, privacy-preserving credential the individual controls. 

Share only the claim that is required (identity, a license, a clear screening result) without handing over the underlying Social Security number, date of birth, or home address. Organizations get the assurance they need. People keep ownership of their information. Security teams stop guarding copies of data that never needed to live in another database. 

By stockpiling all this sensitive information, businesses unintentionally created massive liability for themselves with treasure troves that attract hackers. They collect all this personal data supposedly to better secure and serve their customers, but in doing so, they’ve created the very vulnerability that now plagues us.

Policy leaders and boards can play a critical role in all of this. Before approving any new data practice, they should ask a pertinent question: Will this increase or decrease the number of places where sensitive information is stored? If the answer is “increase,” then it’s time to pause and consider a design that reduces risk rather than adds to it. 

After all, the safest data is the data that never has to be collected at all. 

Raj Ananthanpillai is the founder and CEO of Trua.

More in Safety