Security pros are being hospitalized by after-effects of ransomware hacks

Stressed worker
(Image credit: Shutterstock)

New research from the Royal United Services Institute (RUSI) has laid bare the mental and physical toll that cybersecurity workers face as a result of their work.

In a number of interviews with individuals who had been at the forefront of ransomware attacks and their aftermath, RUSI found that individuals were suffering from stress related illnesses, alongside financial, reputational and social harm as a result of ransomware attacks.

Ransomware attacks involve bypassing an organizations network security, and then encrypting or exfiltrating their data before submitting a ransom that must be paid for the safe return of the data.

 Personal insight from victims

A significant number of those RUSI spoke to experienced sleep deprivation, resulting in them developing extreme fatigue and falling asleep at work. Various levels of stress were experienced by security workers, with one interviewee citing the stress of a ransomware attack as a potential cause for a heart attack that required surgery.

In another case, the interviewee required hospital checkups after the stress of a ransomware attack resulted in severe dehydration after the individual drank excessive amounts of coffee that exacerbated a pre-existing heart condition.

Some of those RUSI spoke to felt challenged and inadequate after their employer brought in an external IT company to assist in recovery, but poor communication and integration led to inefficiencies post-attack. Moreover, many security professionals take ransomware attacks as an opportunity to retire or resign, particularly those with several years experience in a single position.

Many of these people felt a sense of bereavement after the data and information they had been collecting and protecting for years was stolen, with one interviewee describing a sense of ‘love’ for their archives. These psychological issues extend beyond the professional environment, and often have a very real impact on the personal lives of security professionals.

A number of victims provided anecdotes about the excessive working hours resulting in a poor work/life balance, with many reporting that they had missed out on their personal and family life. In one case, an individual had to provide childcare for a senior member of their team so that they could work extended hours.

The physical impacts also extend far beyond cybersecurity teams, with ransomware attacks on hospitals resulting in above average excess deaths due to rescheduled appointments and lost data. Furthermore, the aftermath of a ransomware attack on the Hackney Council impacted its ability to provide access and repairs to social housing, resulting in some residents living in moldy and damp properties for extended periods of time.

Via TheRegister

More from TechRadar Pro

Benedict Collins
Staff Writer (Security)

Benedict has been writing about security issues for close to 5 years, at first covering geopolitics and international relations while at the University of Buckingham. During this time he studied BA Politics with Journalism, for which he received a second-class honours (upper division). Benedict then continued his studies at a postgraduate level and achieved a distinction in MA Security, Intelligence and Diplomacy. Benedict transitioned his security interests towards cybersecurity upon joining TechRadar Pro as a Staff Writer, focussing on state-sponsored threat actors, malware, social engineering, and national security. Benedict is also an expert on B2B security products, including firewalls, antivirus, endpoint security, and password management.