Why high performance doesn't have to mean high anxiety
Learn how Jameeka Green Aaron (CISO at Headspace) approaches leadership, resilience, burnout, and sustainable success in cybersecurity.
Read More
Ask most people what a security leader’s job is, and they’ll probably talk about protecting data or infrastructure. Jameeka Green Aaron (CISO at Headspace) sees it differently.
During a recent conversation on the Black Hat MEA podcast, she explained that cybersecurity and mental health share a common purpose: protecting people.
“Cybersecurity professionals are at the heart of our job. We are here to protect people. Most of what people say about what we're doing is that we are protecting technology, but what we're really doing is protecting people. Mental health is the same way – mental health is a space about protecting people. So it was easy for me to find that thread and find that commonality between the two jobs.”
It's a powerful way to frame the profession. Every firewall, identity platform and incident response plan ultimately exists to safeguard customers, employees and communities. And yet one group often receives far less attention than the technology itself: the security professionals carrying that responsibility every day.
We’ve written about burnout on the blog before. In one earlier interview, Dr. Leila Taghizadeh (CISO for IberoLatAm and Global Head of Cyber Risk at Allianz) told us:
“Without a doubt, burnout and stress are massive issues in the cybersecurity space. Cybersecurity professionals are the frontline defense, and that responsibility is heavy. The demands only seem to grow as threats evolve.”
Since then, the industry has continued to operate under relentless pressure – with new vulnerabilities emerging daily, and attackers constantly evolving their tactics.
Those conditions create technical challenges, but they also create human ones; something Green Aaron knows from experience.
“I burned out in my previous role. I thought I was physically tired but I was mentally exhausted. When you're giving so much of yourself to your work, to your family, to all the competing priorities that we have, you don't realise what a toll that takes on you.”
We know many security professionals will recognise that feeling. The industry often rewards long hours, and applauds those who carry the weight of every incident. Over time, those habits become part of the culture.
The problem is that exhausted people rarely produce their best work.
As Green Aaron puts it:
“If security people are overworked and burned out, they're going to miss things.”
It's a simple observation with significant implications. Security leaders devote enormous effort to reducing operational risk, but fatigue can undermine even the strongest technical controls. The human element becomes another point of vulnerability.
Organisations have become much better at talking about resilience. Business resilience, cyber resilience and operational resilience have all become board-level priorities. But in the middle of it all, personal resilience is still often treated as an individual responsibility rather than something leaders actively cultivate.
Green Aaron believes that mindset needs to change.
“CISOs have a very hard job and burnout is real in our community. And I think that while we're all ambitious and we're all very focused on protecting people, the first person that we need to protect is ourselves.”
That message extends beyond the CISO. Security culture is driven by the behaviour that leaders encourage every day. Teams notice whether taking annual leave is genuinely supported, for example, or whether switching off after hours is respected.
Those choices influence more than morale. They shape how well teams perform over months and years (not just through the next crisis).
The conversation around mental health in cybersecurity has become more visible in recent years, but it still tends to focus on individual coping strategies. Green Aaron's perspective moves the conversation towards leadership and organisational culture.
Because if the purpose of cybersecurity is protecting people, then protecting security professionals is part of the mission itself.
That doesn't mean lowering expectations or accepting poorer performance. It means recognising that sustainable performance depends on people having the capacity to think clearly, make sound decisions and respond effectively when pressure inevitably arrives.
Technology will continue to evolve and threat actors will continue to innovate. Security leaders will always face difficult decisions.
As Green Aaron reminds us, cybersecurity has always been about protecting people. The industry should apply that principle just as consistently to the professionals defending the front line as it does to the organisations they serve.
Join the newsletter to receive the latest updates in your inbox.
Learn how Jameeka Green Aaron (CISO at Headspace) approaches leadership, resilience, burnout, and sustainable success in cybersecurity.
Read More
Executive impersonation tactics now include fake social profiles, video impersonation, lookalike domains and AI-enabled fraud. Here’s how organisations can respond.
Read More
Data extortion is gaining ground as cybercriminals look beyond file encryption. Explore the latest ransomware trends, AI-powered extortion tactics and what organisations should do to reduce risk.
Read More