Welcome to the KuppingerCole Analyst Chat. I'm your host. My name is Matthias Reinwarth. I'm an analyst and advisor at KuppingerCole Analysts. Today we have a very special episode of the KuppingerCole Analysts Chat. We are joined by somebody who has been our guest late last year in episode 435. I want to welcome Kashyap Timaraju and he will introduce himself. He's not an analyst, but he has a lot of interesting things to tell.
Thanks, Matthias. It's a pleasure to be here again. Thank you again for this opportunity. As you mentioned, my name is Kashyap Timaraju. I'm the founder of Flowguard Institute, a research and training company dedicated to advancing human performance in cybersecurity. I'm also the postdoctoral researcher at TU Berlin. I'm really excited to be here, Matthias, and talk about some interesting things that we have lined up today. Right. We want to continue a discussion that we started, as I said, last year.
There we had an episode, which was already a kind of alien episode for us because this is an interesting topic, but we usually talk about analyst stuff, tech stuff. But we did not do that way back then. We talked about burnout, about work-life imbalance when it comes to those who bear responsibility in cybersecurity. So that was an interesting episode. You continued the discussion also with webinars and presentations at our conferences. And you've made some significant progress here.
But if we look back at this episode, what were the key takeaways for you from this episode where we can build upon for today? I think in the last episode, what we discussed was some of the factors or the reasons why many people in cybersecurity are experiencing mental health conditions like stress, burnout, anxiety, and so on. So we talked about how the evolution of technology, the digital transformation, how regulation and laws are actually impacting and adding to the stress.
We talked also about some of the socio-technical factors like workload and time pressure and changing priorities and so on. I cited some research as well. And then I think Saurabh also mentioned, who was also on the podcast last time, who talked about trust, how that's important, and what the Mental Health and Cybersecurity Foundation is also doing. And we also encourage people to sign up to the charter, join the community of practice, and sort of trying to get the word out and spread awareness on this important issue.
Because there's a lot of vendors out there who have a lot of solutions and so on, say that these solutions can potentially reduce burnout and so on. But it's not just about adding technology, but it's actually about the people behind the cybersecurity solutions and the teams. And I think that's why we spoke about their conditions last time. As I'm also an advisor, and of course we are dealing a lot with technology, but making things right, leveraging technology on the one hand while having proper processes and mechanisms in place is also something that is very close to me.
So to make sure that the soft factors of people are really also taken into account. And when it comes to health, when it comes to well-being, I think that's even more important. So it's really something that absolutely rings a bell for me, because this is really an important factor.
Always, I say, 30% technology and 70% doing things right, processes, policies, mechanisms, and people really making sure that leadership understands what this all means to their teams, to their employees, to their colleagues. Absolutely. Yeah. So when we continue that discussion, and I think you also continued your research work, it has a long title, but there's a lot of stuff packed into there. Yeah. Without human performance in security operations, the survey on burnout, well-being and flow state among practitioners, objectives and significance. That was the long title that I had.
It's a really interesting study that I did read, and I really read it wise to make sure that I fully get the point. It's a survey to start with. It's really based on information that you gathered from practitioners. Yeah. So the title is indeed long, and I think it's sort of two parts to it. So the first part is about, we're talking about human performance in cybersecurity. And then the second part is, how do we sort of measure this? And that's what the paper was about. It's about a survey that we conducted among practitioners to measure the current state of mental health in some sense.
I think the paper is, in addition to the survey, it's also about putting our vision out there and what we want to do, because what we believe is that we can transform security operations and outcomes and the performance of the team by actually focusing on the well-being and engagement of the team.
Because there's a research in software engineering, I think there's also something I mentioned in the last episode called the developer experience, where they identified that developer productivity actually depends on the well-being of the developers and them being able to get into the so-called flow state, which is the state where we're completely immersed. We lose sense of time. It feels effortless. We're not worried about what others are thinking about us. We have the sense of control. It's challenging, but not too challenging.
And we have some feedback where we know what we're doing is actually going in the right direction or not. And this paper also measures the capability of practitioners to be able to get into the flow state. So that's a brief introduction into the paper, I would say. And the motivation also for this work came about because there's a lot of reports out there by the various market research companies and so on. And they've conducted surveys asking people if they experience burnout, if they're stressed out, and so on. And to some degree, this is true.
People answer these questions, and these are valid in some sense. But our motivation was to actually collect scientific data. So we actually used questionnaires developed by psychologists and have validated that these questionnaires are actual indicators of certain conditions, such as burnout, well-being, and flow state. And I think this is also one of the major contributions of the paper is that we collected data using these questionnaires and actually identified the conditions people are experiencing in cybersecurity.
So we actually had 25 participants, but only 19 of them were really involved in security operations. And the reason we focused on security operations is because we noticed that this is actually a really high-pressure, high-demand, highly stressful environment based on the articles that we found online. And that was one of the other reasons why we decided to focus specifically on security operations compared to some other activities in security. Right. So we have this questionnaire, which is scientifically accurate, and it really lays a good foundation.
On the other hand, you have a, as of now, not really limited, but a smaller number of participants. So 19 out of 25 is already a good basis, but it's not representative in any way. Nevertheless, we will talk about the results later anyway, but if you summarize that, how do your results differ from these out-there market research company-produced results? Where are the deltas where you add value to it?
Yeah, so that's actually a really good question because there's a lot of research that talks about burnout. What we did identify is that is indeed a phenomenon that we observed. There were many people who, there were at least six out of the 19 who fell under the high burnout category.
Of course, there could be more, but what we also observed is the number of participants who answered the burnout questions were actually considerably less compared to the questions on wellbeing and flow state. So when it comes to stress and burnout, we observed the same thing that some of the market research and the other surveys that are there are.
On the other hand, what we also, I think what we really added was to look at wellbeing and flow because most of the research out there is focusing on the negative aspects, but they've not really looked at what their current state of wellbeing is and are they really engaged? And this is where we added real value to the research and we identified which dimensions of wellbeing people are faring well in and not. They also correlated with the burnout. So when it comes to burnout, people feel exhausted.
Whereas with the wellbeing, we noticed that their mental and physical health are also not so good, but they actually score higher on some other aspects like financial and material stability. So people are actually quite happy with the compensation they receive. And then the flow state, I think, is something really value-add over here where we see people are really engaged and they have certain aspects that let them get into the flow state, but there are also certain aspects that might need to be improved on or worked upon or changed in some sense.
I really love that term flow state and everybody actually knows what you mean. So the moment when you're really immersed in the work and that you don't really care about time and food and drink and everything else. And in my spare time, I'm a musician. I know that mainly from there with creating music, composing music and doing that, that usually leads to the situation of where did the time go and what happened in the meantime.
If we look at that from the perspective that you have covered, so really having this flow state during day-to-day work and really leveraging that flow state for improvement of the results and the wellbeing of the people, what are the obstacles or how can you help people or give them guidance to get into that flow state, at least for a limited amount of time per day? Is there a recipe? Are there known obstacles? It would be nice if we had a manual that said, you know, step one, step two, step three, and then you're in flow state.
Of course, in a nice lab setting that might be possible and certain activities are more conducive to flow than others. But there are certain concepts that we can sort of base our thoughts on or our actions on to be able to get into the flow states. I think the most important aspect to be able to get into the flow state is what's known as the flow channel. And this is choosing or whatever activity we have, that activity has a particular challenge level to it, a challenge, and we have certain skills to that particular activity.
To be able to get into the flow state, what's really important is the activity is not too challenging. So it should slightly exceed our skill level. Because if the task or the activity is too challenging, it makes us feel anxious or frustrated. And if it's not challenging enough, it feels boring. And so it's all about finding this sort of this sweet spot that's going to actually help us get into the flow channel. And once we know that, then we can sort of leverage that, you know, if a task is, for example, really challenging, what can we do to bring the challenge level down?
Or if it's kind of boring, what can we do to bump up the challenge level? And this is actually an aspect I'm really interested in, because I think LLMs are a very interesting technology that could perhaps help us.
You know, I think we're seeing a lot of this already with how people are able to code so much better. I mean, I've been using this and coding is like so much faster. It's kind of like just debugging it, as long as we know what we want to do, right? So this makes something challenging, less challenging, and the barrier to entry increases. And so people can actually start engaging. And I think that could also be done to make something boring, also more interesting. So many people don't like writing or reading and summarizing stuff, right?
So again, LLMs over here can make something very boring, more interesting by summarizing text for them, so that they can actually then think of how this could be used, for example, in cyber threat intelligence, or actually connecting the dots between different threat reports and so on. So I think these are at least a couple of concepts that one can use to be able to get in the flow state. I think other aspects of being able to get in the flow state are looking at what enables one to get into the flow state. So do we have enough feedback? Do we have a sense of control?
I think the sense of control, autonomy, agency is very important. This is also something I mentioned last time. So reframing is one way of doing that. Speaking with our team, our managers, our supervisors, or whoever it is, leadership, to be able to have a sense of autonomy in the work that we do helps us get into the flow state. There's also what's another really important aspect of being able to get in the flow state is the so-called autotelic experience, which is doing it for the joy of doing something rather than doing it for the outcome.
And that might be a slightly harder thing for people to maybe apply in their work, but I think if people are really aligned with their values, their meaning, their purpose, and the goals that they have, why they're doing this, and if this is going in the right direction, that gives them the sense of reward. For example, when I do my research, of course, it's painful. It's hard. There are things that I don't like, but there is this sort of rewarding feeling that we get by actually doing the research or going through logs or finding a true positive from a bunch of false positives, for example.
So I think this is sort of like having that so-called what one of the founders of flow, Mihaly Csikszentmihalyi, said is to have this so-called autotelic personality where we just do things because it feels rewarding and joyful to us. If I think of other aspects, I mentioned goals. I think clear goals are also really important that we know what we're doing and why we're doing it. I think there's another really important aspect to it, which is concentration, to be able to completely focus on what we're doing.
And what we noticed, at least in the survey that we conducted, is that the participants scored quite high when it came to the challenge to skill ratio, the feedback, and the autotelic personality. So the feeling of the activity being highly rewarding. But when it came to concentration and autonomy and feelings of self-consciousness, that is worrying about what others might be thinking of them. These were aspects of flow that the participants actually scored low on. And I was actually speaking with a psychologist, a researcher who did her PhD on psychological safety.
And it seems like feelings of self-consciousness and worry about what others might be thinking or sense of insecurity, self-doubt, and so on are quite linked with psychological safety. And so what we mentioned in the paper is to be able to get in the flow state, especially with work activities, psychological safety is actually really important. So people should be able to feel comfortable saying things that's on their mind, being able to make mistakes and not be punished for that. And to have this so-called just culture is also, I think, really important to be able to get in the flow state.
I think that's a long answer I gave. I said many things. Hopefully that answers your question to some degree.
Yeah, absolutely. And I think the more you explained that, the more it became clear to me that this is also a real important aspect for leadership, for culture within an organization. This is only partially something that somebody can do for themselves, but they really need the support within the organization, within their leadership, within their colleague, with their team to allow for everything that you just described, for this culture of being allowed to fail and identify mistakes and correct them and get better and get into the flow. The leadership involvement is really important, right?
Yeah, absolutely. I think also if we think of it in the survey that we did, we were measuring individual flow, but there's group flow and team flow as well. And these are also aspects that we're really interested in, because at work or as a security team, it's not just one person working on something. It's a whole team that actually works towards defending an organization or creating detection logic or going through reports and so on. And so there needs to be this sense, collective purpose and shared goals, a collective shared goal that everyone works towards.
And I think this is also something we're really interested in looking at. And so what are the conditions required or necessary to put in place so that the entire team, the security team, can get into flow? And like you mentioned, it's leadership. Not only it's about making them aware of this, but also taking action to be able to sort of provide a conducive environment for this. And I think that can be a huge opportunity, because if a company or a team or an organization is able to adopt this perspective and this philosophy, they're not buying any technology.
So you're not spending hundreds or millions of euros or dollars to do this. You're actually changing the way you work and actually getting the benefits and improving our security without actually adding new technology. And this is also something that we really believe in. So transforming productivity and well-being and outcomes through non-technological approaches. I fully understand that.
And I think it makes perfect sense because there are usually enough tools around, but leveraging those apart from the first 20 percent that you typically use and getting better in deploying those tools and making teams work much more efficiently, I think that's the way to move forward here as well. Usually enough money is spent on tooling. But before we go into more details of the results of the survey, a question of data availability for you. So more data would be helpful. And that could be the time for you to also maybe call for participation for the survey, right? Absolutely.
Yeah, I think firstly, we were really grateful that we got 19 to 25 participants. But as you mentioned earlier, that's not statistically significant. And so if we can actually get more people to participate in this, this actually provides us with a better understanding of what the current state is in the industry among practitioners. And it will also help us and participants understand what we can do about it and start thinking of ways to improve well-being, improve flow state. But also what can we do to prevent people from entering stressful environments?
What can we do to change our environments and the conditions that we work in to reduce stress? Could be like reducing workload and so on. But I think this is really critical. If I can make a request to the listeners today, please participate in our survey. All your data is absolutely private. We don't share it with anybody. We have a data protection policy and so on. And we are dedicated to privacy and protection of your personal PII. So I think I've shared the QR code with you, Matthias, so we can put that up in a link to the survey as well.
And we'd be really grateful if we could get more people to take part in our survey. I think the QR code, it's just showing right now. So please just use it and get in touch with them. I know this is a step to take, but maybe you really want to support the work of CACHE to really improve the overall databases for the survey and to, in the end, consolidate, substantiate the results of the survey. So first of all, thank you to all of those who will contribute to that. It's really a stretch, I know, but it will really be helpful.
Going back to the results, when it comes to what we've discussed as of now, it's really just the nice side of the results of getting into the flow, getting to better results, better interaction, and focusing on what people can really do well and skip the boring stuff. If you look at the other side of things, the burnout part, do you learn in understanding burnout and security operations from the survey? So in the survey, we measured burnout using what's called the Copenhagen burnout inventory. And so this particular questionnaire measures a burnout in terms of exhaustion.
And they've categorized burnout into three parts. So personal burnout, work burnout, and client-related burnout. And what we noticed is participants experienced, most of the participants firstly answered most of the work and personal-related burnout questions. There were rather fewer people who took part in the client-related burnout because not many people work with clients. And what we observed is that this feeling of tiredness and exhaustion is quite prevalent. And this is either from work-related activities or in their personal life as well.
The reasons for why they feel this, that was not measured in the survey, that would require further research. However, there have been a couple of papers published that have tried to understand what are the factors that lead to burnout. I think I mentioned this last time where they looked at incident responders and identified some of the factors over there.
However, in our paper, we were purely focused on a quantitative approach, which is using the survey. I think what we want to do as sort of our future work is to take this forward and answer the question that you have exactly posed to us is to, what are the reasons or what are the socio-technical factors that are leading to burnout? And this is, to answer this question is not easy because it depends on the individual, it depends on the organization, it depends on various aspects like the workload they face. And what we want to do over here is to apply a sort of like a mixed method.
So can we combine surveys with interviews, speak to people and identify what are their reasons or what are the factors that are actually leading to burnout for them? And to do this across different, let's say security operation centers, but also between different roles because incident responders might have a different workload and stress levels compared to say someone working in threat hunting versus someone in red teaming and so on. And so this is actually an aspect that we're really, really interested in looking at as part of future work.
But what we can say from the survey is that exhaustion is definitely what they're feeling, but why they're feeling it is not really answered through our research. Right, and if you look at your future research directions that you're working on, do you think that the methodological and also the theoretical foundation for this specific area of burnout and flow in cyber security is there already a good enough basis or is this also some groundwork that needs to still be approved?
Yeah, so there has been to date one paper that actually came up with the theory for burnout in security operation centers and this was done about 12 to 15 years back. And I actually met with one of the professors who was part of that work and recently when I presented our paper last month. I believe it's actually time to actually revise that and also look at it more broadly. There is actually really, apart from that one theory, there is no real work out there that describes, provides a theory or an explanation for why this is happening.
There are, like I mentioned earlier, there are different reports out here that say, you know, I'm feeling stressed because of this, because of that, but there's no fundamental theory or a foundation on which this is based upon. And this is something we strongly believe needs to be looked at, especially using some kind of scientific methods.
If we, for the final part, look into operationalizing your findings. So what I think many of the audience out there, they are really just thinking about what can I do to help my team? How can I maybe even identify signals that things are not going wrong or people are subject to too much stress and that should be improved? What are some, I don't know if this is possible, some hints, some guidelines, some recommendations that the individual or some team leads, management, culture-shaping people would like to take from you? Is there anything you can share?
Yeah, so I want to say a few things here. I want to also just continue my answer from before and then sort of get into the interventions part, because I think it's sort of, it's all connected. So what I was mentioning earlier was about coming up with the theory that explains the socio-technical factors that lead to burnout and security operations. I think that's a really important foundation to start with. And then how this is actually going to bring about change is by showing what impact that has on the security, on security outcomes.
So how does people actually being stressed out and burnt out impacting, let's say, security KPIs? There is really no work out there that describes this or has shown this relationship. Like I mentioned, there was a theory that described burnout, but its impact was not described. So this is also something we're really interested in working on. Then once we know this, we can then start to come up with interventions on what we can do to reduce stress, prevent burnout, and improve our well-being and flow stage.
So that would be like a really targeted and methodical way of approaching this, because I think what's important is to choose the right factors to address, because if we don't know this, then we're sort of just guessing and sort of trying to address something that might not actually be the root cause for these issues. Nonetheless, I think people have a pretty good idea sort of intuitively based on their experience in an organization and what they're working on that might be impacting them. So I think workload is pretty huge. This is what some research has already pointed at.
A lot of people in some of the market research that we've seen talks about, so this is definitely a way or something to focus on. How can organizations, leadership, so on, handle not only changing workload, but high workload as well. This is very tricky. So we also have low human resources. So people are low, budgets are low, so what can we do? LLMs seem to be a potential over here of automation.
Like one of the projects we're working on is on cyber threat intelligence, and many times it's a manual effort to go through a lot of these threat reports and then convert them into some kind of structured information. So can we use new technologies like LLMs to be able to do that for us? So it makes their life easier, it reduces the boring, mundane, frustrating work, it speeds things up, it reduces the workload also, because now you can actually process so many more threat reports, and people might feel more motivated and interested in doing things like this.
So I think that's something one can do. I mentioned psychological safety. I think that's also really important because we want to create an environment in which people feel safe and are able to express their current state of being. And so it might be difficult if people are not even aware of this concept or not even open to this concept, but a lot of research shows that psychological safety is a really good trigger for performance and well-being and reducing stress and burnout. So I think that's another really important aspect to follow. Apart from that, I think resilience is really important.
There's been a lot of research on resilience. There's a book that I read recently, it's called Tomorrow Mind. It's by Martin Seligman and Gabrielle, I forgot her last name. I think that's really important because they talk about this concept of VUCA, which is volatility, uncertainty, complexity, and ambiguity. And these are some of the reasons why it's also so stressful. And this applies to knowledge work in general, but it applies to cybersecurity as well. And so what can we do to improve resilience?
Because if we encounter a stressful situation, it's also our mindset to that stressful situation. Are we going to think of this as something very stressful and then get stressed out, feel anxious and not be able to accept the challenge? Or do we think of the particular situation at hand as something that's going to make us feel excited or we're curious about and we're going to be able to solve? This is actually a really important concept to keep in mind when we come up with a stressor, for example. That's known as the appraisal process.
So do we appraise something as a stressor or as a challenge or a hindrance? Resilience training, coming back to resilience training, I think this is super huge. If we can have some training for leaders and individuals to become more resilient, that's super important. There's also anti-fragility and so on. Whatever challenges that we encounter, if we can make ourselves stronger, that make us stronger, that's actually really good. Thank you very much.
Now, just as you explained that, I was wondering if this VUCA aspect that you mentioned, when you try to make or to formulate some goals that are easier to follow, to avoid parts of that, you usually use something like KPIs, KRIs. Are they doing good or are they more dangerous when it comes to having things immediately measurable? Does that help or is this an obstacle?
Yeah, so being able to measure something gives us some insight on what's happening. Of course, what we measure is also really important. So if we are measuring the wrong thing or wrong metric, that's going to give us false information that could maybe make us more stressful. I think I want to cast light on the work that we've done again because I think the surveys are a way to measure what the current state of mental health is. So if we can plug these metrics into a dashboard that also has the KPIs of the security team, for example, we can then start to correlate what the metrics are.
And this gives us a sense of what the current state is and where we want to go and how these two play out with each other. So if people are experiencing their scores on burnout are actually increasing, is that actually impacting your, let's say, mean time to detection or the number of tickets you're processing and so on? Different teams have different metrics. So that's actually also, I think, a really important aspect to consider. I think quantifying something, putting a number, just makes it a little more tangible.
But of course, there is the other side to it that then we start to sort of play the game of increasing numbers rather than, let's say, considering our team, our colleagues and actually choosing the right work. Because then we might fall into the risk of choosing tasks that actually increase metrics versus actually choosing the tough ones that might not actually bump up metrics but are actually really critical and, let's say, difficult and need to be done but might not actually drive up metrics. So there is a double-edged, it is sort of double-edged over there and needs to be taken.
There needs to be a balance. So whoever is monitoring that and making decisions based on that should also be aware of these aspects of incentivizing metrics, if that's a good thing or if people are actually working towards that or not. Thank you. Really interesting. First of all, I want to encourage our audience to participate in the survey. The QR code should be somewhere around here and really support Cache in improving the databases to work upon. That would be a good starting point. Second is the question to the audience. And this is an unusual episode. This is an unusual topic for me.
I'm a layman here and you can hear that from my questions. Is this interesting to you? Please let us know in the comments to this episode on YouTube or wherever you are. Please do leave a comment. I'm really interested in your feedback. If you also want to hear these a bit outside topics of what we usually do and to have such interesting guests like Cache joining us again, this would be really helpful for us. Thank you for that as well. And as I said, I'm the layman. Before we close down Cache, are there any questions that I did not ask that you would like to have mentioned here?
Anything you want to close down this episode that you want to be considered by the audience? Thank you. I really like that question. What's the question I didn't ask? I asked that too. Let me see. I think we touched upon the survey that we did, what we're looking to do with our future work, what we can currently do, what people can also do on their own, what organizations can do. We also touched upon asking people to participate. So I think that's also really helpful. Thank you again. Dear listeners, if you've heard that and you've actually taken action on that, we're really grateful for that.
Anything else that you didn't ask that I'd like to have? I think, apart from that, it would be nice if you've been listening and you're interested in participating in our research, not just the survey, but if you think your organization would be interested in sort of taking these concepts further, like trying out the survey and putting it together, putting it alongside your dashboard and correlating the metrics, that would be super useful because what we've noticed from the research and our own experience is being able to get into a SOC and to be able to try this out.
And if you are interested in sort of taking this study further and sort of want to try a new approach to improving the effectiveness of your SOC, please do get in touch with me. I'd be really grateful to speak to you about it and to be able to take this research and this concept further and actually make an impact in a real SOC or in real SOCs.
So, yeah, I think that's the one thing I would like to add. Thank you. And that would be the latest point when we have results from that, that we can talk again.
So, I think that would be something where that correlates on the one hand, improving health and well-being and the flow state, and on the other hand, really getting to better results in the SOC. That would be really interesting to see. But I think we will talk about it again soon.
So, thank you very much, Cash, for being my guest today, for sharing your knowledge, for your expertise in this specific area. This is really helpful and interesting for me as well.
So, I love to do these episodes. I hope the audience as well. Looking forward to having you soon again.
And again, thank you for joining me today. Thanks, Cash.
Thank you, Matthias. Thank you. Bye-bye. Bye.