Always connected, never really on break: the invisible cost of being always-on in cybersecurity
We’re in the summer vacation period and now I want to tell you a story that I imagine you’ll know well.
The long-awaited vacation has started. You’ve been dreaming of it for months, you desperately need it to recharge your energy, because you’re exhausted. The computer is turned off, in theory… but the company phone is still on. A notification arrives "do I read it or not?". It could be a trivial communication or an important alert. "I’ll just take a quick look" you say to yourself "just to be calm".
Do you recognize yourself in this story?
Even if the notification is actually trivial, often it doesn’t end there. Maybe you don’t need to intervene, maybe there’s no urgency, but by now it’s happened: in a flash, your mind is already back at work. You find yourself mentally going over the activities you left pending, evaluating the possible consequences, waiting for a second message. Your well-deserved break has been interrupted and, with it, also the precious process of recovery that you desperately need.
For those who work in IT and cybersecurity, this scenario is far from rare. We know that incidents and threats don’t respect office hours, indeed, vacations are a great time to launch attacks. Availability, when organized through shifts and agreed-upon responsibilities, is part of the job. The most insidious part is that implicit availability that pushes us to check emails, chats, and alerts even when we’re not at work.
Scientific literature talks about Technology-Assisted Supplemental Work, or TASW, to indicate work activities performed outside of regular hours through smartphones, computers, emails, and digital platforms. This is not about traditional overtime: TASW is that message read during dinner, that ticket checked on the weekend, or accessing your email during your vacation.
Researchers Fenner and Renn observed that this type of supplemental work is favored by company expectations. It’s not necessary for someone to order you to be always available: often it’s a matter of tacit habits, behaviors that we see our colleagues and superiors exhibit, it’s what we imagine is really expected of us to be up to the task, in a sector where making mistakes is not tolerated. The same study demonstrated that TASW increases the conflict between work and family life. One problem that calls another…
In a study I conducted with the University of Padua on psychosocial risks in IT and cybersecurity professionals, technology-mediated supplemental work, techno-overload, and techno-invasion were found to be higher than in the sample of workers from other sectors. The particularity of these professions lies not only in the amount of stress experienced but also in the ease with which work crosses the company walls and continues to occupy our mental space even in our private time.
Tarafdar and colleagues define techno-invasion as the ability of technologies to invade personal life, making workers reachable anywhere and at any time. The professional day thus extends to evenings, weekends, and even vacations. Sometimes not checking your phone produces further unease: "what if something happened?" or "who will take care of it if not me?".
To recover energy, it’s not enough to be physically away from the office, you also need a certain psychological detachment: the possibility of temporarily interrupting work-related thoughts and concerns.
Here, an apparently innocuous notification can have a greater weight, even if reading it takes only a few seconds. That simple notification reactivates the professional role, brings attention back to problems, and interrupts that gradual reduction of activation that was allowing the mind to recover.
In the cyber sector, the problem is amplified by the high cognitive demand. Those who work in information security must analyze large amounts of information, distinguish relevant signals from false alarms, make quick decisions in conditions of uncertainty, and maintain a high level of vigilance for a long time. Alerts fragment work and can quickly turn into priorities.
In a study where 37 CISOs were interviewed, several participants described their work as "guided by interruptions" and characterized by continuous monitoring, numerous emails, high responsibility, and expectations of constant availability. If we add to these demands the chronic lack of staff and the always insufficient resources, the "always-on" risks becoming the norm.
Breaks, therefore, are not a luxury and not a reward to be given when everything is under control (in the cyber sector, that moment may never arrive). Real breaks are an indispensable condition for continuing to maintain attention, clarity, and decision-making ability.
From a few minutes of break to vacations.
Recovery happens on multiple levels. There are short breaks during the day (breaks, coffee breaks, lunch breaks), evening free time, weekends, and finally vacations. Each of these spaces has a different function, but all can be compromised by continuous connection.
A break, to be such, should not be spent reading mail or checking a dashboard. If that were the case, the screen would change, but not the mental state. And if during a vacation you’re constantly waiting for a call, you know you won’t have physical rest without real mental detachment.
In a small study conducted on 50 cybersecurity professionals, 70% stated they had received work calls during scheduled vacations. The data is not representative of the entire sector, but it’s food for thought. In the same study, vacations and days off were indicated among the strategies adopted by workers to deal with stress and burnout… a paradox, if work continues to penetrate precisely the time destined for recovery.
However, I will continue to repeat that the responsibility cannot fall on the individual worker. Turning off the phone is of little use if the company considers it normal to contact someone on vacation or if an emergency can be handled by one person. However, some practical choices can make the boundaries less permeable:
There is no individual strategy that can compensate for unsustainable shifts, lack of staff, or unrealistic expectations from the company. Breaks really work when they are also protected by the organization, through procedures that don’t leave all the weight on the workers’ shoulders.
Information security requires constant attention, but human attention is not infinite. It needs to be periodically recharged, disconnected, and breathe.
A resilient cyber team is not one that never stops. It’s one that knows how to organize so that people can really stop, recover, and return to work with the mental and physical resources needed to protect the organization.