Skip to content
Software Supply Chain Security

Passion as the Antidote to CISO Burnout

antidotum tegen burnout

Burnout in security leadership is a real risk, especially for CISOs who sit at the intersection of business pressure, fast-moving threats, and constant decision-making. In a conversation, Russ Kirby—Global CISO for enterprise security, product security, GRC and privacy—argues that the strongest protection against CISO burnout isn’t a single policy or program. It’s passion for the job, reinforced by leadership habits and a supportive network.

Kirby’s path into cybersecurity wasn’t a straight line. Yet, over time, his focus on order, improvement, and an honest love for the details helped him build a long tenure—without succumbing to burnout. Here’s what he says matters most, from career “signposts” to handling the stress that modern technology creates.

Why CISO burnout is not just a workload problem

Burnout is widely recognized as complex and can be driven by overwork and stress. Kirby doesn’t treat it as something that affects everyone equally. For him, the key question is whether there is an escape route or relief from the pressure. If stress has no outlet, it compounds over time—no matter how capable a leader is.

He also frames “relief” in practical terms. CISOs can’t always remove the external pressures that keep coming, but they can build conditions that prevent stress from becoming constant and inescapable. In his view, the role of a CISO includes protecting the people doing the work, not just making risk decisions.

Kirby’s own pattern is telling: he describes himself as a “very long tenured CISO,” contrasting his experience with the short tenures often seen in the market. His explanation is straightforward—he enjoys the work. If he had freedom to do anything, he says he would still choose cybersecurity.

How passion becomes a practical anti-burnout strategy

Passion isn’t a motivational slogan for Kirby. It affects how teams recruit, how leaders communicate, and how people keep going when the pressure is relentless. He looks for enthusiasm when building security teams, not just credentials.

He makes a distinction between qualifying for a role and wanting to do the work. For a more junior position, for example, he would rather see someone who is genuinely interested—someone who can show their curiosity through personal experiments—than someone who seems bored even if their résumé looks strong.

This mindset supports two outcomes at once: it improves day-to-day performance and it reduces the emotional drain that can lead to CISO burnout. For Kirby, enjoyment helps teams stay efficient without constantly burning out.

Luck, opportunity, and the courage to step forward

Kirby uses the word “luck,” but he immediately clarifies that it’s not just chance. In his interpretation, luck is a combination of opportunity and response. The real differentiator is whether you have the conviction and courage to take an opportunity when it becomes clear.

He says he has often been willing to be bold rather than wait. That willingness is also part of why cybersecurity appealed to him: change happens quickly, details matter, and there’s always something new to learn.

His background also shaped his fit. He’s worked with technology for a long time, describing himself as part of the Gen X generation that grew up as computers became normal. Over the years, the appeal was not only the machinery, but technology’s potential for humanity—an idea that made the work feel meaningful.

From technology to cybersecurity—by necessity

Kirby’s move into cybersecurity wasn’t originally planned as a career script. Instead, it happened because the organization needed someone to take responsibility for the role, and he decided to lean into the challenge.

Once he accepted the assignment, it matched his interests and strengths. He then continued with similar responsibilities in larger global environments, eventually positioning himself for CISO roles across multiple organizations.

He is currently Global CISO at Ping Identity (starting in the summer of 2023). His scope includes enterprise security, product security, GRC, and privacy—showing how the work demands both technical judgment and broader governance thinking.

Career signposts: “Don’t let perfect be the enemy of good”

Good careers tend to include good advice along the way, and Kirby cites a memorable signpost: Don’t let perfect be the enemy of good. The idea resonates because striving for flawless outcomes can delay action that would prevent real harm.

He offers a concrete example using incident disruption. The “perfect” target, he notes, is zero disruption. But sometimes the best move is bold and immediate—like shutting things down to stop damage quickly. That requires the discipline to choose “good enough” solutions when perfect is not realistic.

This philosophy also reduces burnout risk indirectly. When leaders accept that reality sometimes requires decisive trade-offs, they avoid the exhaustion of aiming for unattainable outcomes.

Leadership style: bringing order, mentoring, and coordination

Kirby describes himself as someone who likes to bring order to chaos. He values rules, discipline, and structured teams. Importantly, he connects this personal preference to leadership execution: he enjoys coordinating work, working with people, and mentoring team members to bring out the best in individuals.

He ties part of this to personality traits he associates with the Enneagram, specifically a principled, improvement-driven approach. But he doesn’t treat personality as destiny. He also frames leadership as something built through seizing opportunities and learning how to lead where the need exists.

In other words, leadership isn’t a single moment where greatness arrives fully formed. For him, it’s an evolution driven by practice—especially when projects require action and others hesitate.

What he looks for in a CISO (and in the team)

When hiring or shaping a security function, Kirby highlights practical fundamentals: knowledge of technology, familiarity with different cybersecurity topics, and a real understanding of the subject matter. Yet, enthusiasm remains the differentiator.

He also advises that leaders in high-level roles must keep listening—especially when others challenge their beliefs. A common failure mode is assuming one organization’s approach should be copied directly into another. Kirby emphasizes that every company and team is different.

That flexibility supports better leadership decisions and helps reduce organizational friction, which can otherwise become a source of chronic stress for security teams.

Reactive security, proactive intent

Security work often involves reaction—incident response, for example. Still, Kirby argues that the role of a CISO should be as proactive as possible in intent.

Even activities like hardening systems, running penetration tests, and performing vulnerability scanning fit this proactive framing. Scanning may be technically reactive in the sense that it identifies what’s already wrong. But the purpose is to close gaps before attackers exploit them.

He also references the “agility gap”—a concept describing how adversaries adopt new technology faster than defenders. The defense challenge is to keep up, which reinforces his central point: cybersecurity should aim to get ahead, not merely catch up.

The burnout relief CISOs must provide to their teams

Kirby believes CISOs need to protect their teams because unreasonable demands tend to come from the world at large, not only from boards. Some of these demands are obvious and operational—such as the speed at which attackers use new technology. Others can be personal pressures outside work that trap people in roles they no longer enjoy.

To address this, he describes having direct conversations with team members when needed. On occasion, he tells them to go home and spend time with family and loved ones. If they don’t, he jokes that he would switch their computer off so they can’t keep working.

This may sound informal, but it reflects a serious belief: the environment around people matters. If a leader helps create real relief, stress decreases and the risk of CISO burnout drops.

What keeps him up at night: AI adoption

When asked what keeps him up at night, Kirby’s answer centers on AI—not because it’s inherently new, but because of how quickly it’s being adopted. The worry is whether organizations fully understand the capabilities and consequences of what they’re unleashing.

Rather than treating AI as an unstoppable external force, he focuses on education and planning. His approach is to inform and prepare: use AI responsibly, prevent misuse, and respond to bad uses when they occur.

At the same time, he places AI stress into perspective by comparing it to previous technology cycles. People worried about data theft when floppy disks were invented. Concerns about losing information over networks emerged when the internet arrived. In other words, cybersecurity has always involved chasing new risks created by new tools.

Embracing change without burning out

Cybersecurity is inherently iterative. Attackers bring new methods and defenders must adapt quickly—like a whack-a-mole game where the ball keeps popping up again. Kirby says progress and technology create both challenge and risk, and the cycle returns with each wave.

He expects that “AI” may even become just one label among many future computing realities. Eventually, the term will fade, and new challenges will take its place. The key is to keep learning, stay proactive in intent, and continue treating cybersecurity as an engaging field rather than a permanent grind.

For Kirby, this is where passion becomes a lasting advantage. It makes the hard parts tolerable, and it helps leaders build teams that can handle the next change without losing momentum—or themselves—to CISO burnout.

Conclusion

Russ Kirby’s perspective on CISO burnout boils down to a simple formula: enjoy the work, support your team, and lead with a proactive mindset. He connects burnout prevention to real enthusiasm, honest leadership habits, and a willingness to act without chasing perfection.

In a world where threats evolve and technology keeps accelerating, his message is clear—success as a CISO isn’t only about managing risk. It’s also about sustaining energy and building relief into the job so the pressure doesn’t become permanent.

Source: https://www.securityweek.com/ciso-conversation-russ-kirby-passion-is-the-antidote-to-burnout/