We use a lot of combat terminology for security. Maybe that’s not such a good idea. According to a study by Dynatrace, a ‘war-room’ style approach to incident management, blame culture, and disconnected IT teams are causing burnout among IT staff. The study found that 91% of organizations still play the blame game with IT service providers after serious incidents, leading to fractured relationships and hampering the ability to respond to emerging threats. This reliance on war-room-style meetings has left 49% of IT teams feeling burnt out, with 46% admitting to missing personal time. The increasing stress has led 21% of professionals to consider switching job roles or even careers. Dynatrace suggests that this approach not only fails to remediate issues but also damages office culture and exacerbates skills shortages.
KnowBe4 has released its 2024 Security Culture Report, which examines the impact of cybersecurity measures on organizations and their employees. The report reveals that the overall security culture score globally remains at a low-moderate level, with smaller organizations performing better than larger ones. Industries such as insurance, financial services, and banking lead in security culture, while government, manufacturing, and education sectors struggle.
And from Axios, Many health care providers affected by the hack of a UnitedHealth Group subsidiary are uncertain if their cyberattack insurance will cover their losses. Cyber insurance plans may not provide adequate protection when providers are affected by attacks on third-party vendors. Some providers may have been underinsured or unable to afford coverage due to rising cyber insurance rates. Surveys show that only about 15% of companies have standalone insurance plans for cyberattacks. Large health systems estimated losses of over $100 million per day, while smaller providers may have limited coverage that falls short of the actual damage.
The “war-room” approach, characterized by high-stress, blame-oriented tactics, is not only ineffective but actively harmful. The significant percentage of IT staff feeling burnt out and considering career changes highlights an urgent need for a shift towards more constructive and empathetic incident management strategies. An organization that masters this approach will have more long term viability.
Cyber insurance is undergoing a reckoning. The uncertainty faced by providers about their coverage highlights a gap in the current cyber insurance market, where policies may not fully account for the complexities of digital supply chains and the interconnected nature of cyber risks. This gap, compounded by rising insurance rates and the under-preparedness of some organizations, points to a critical area for reform in how cyber risks are assessed, insured, and managed. Gaps are opportunities, of course.

