In the boardroom, cybersecurity is almost universally treated as a technical problem. When a breach occurs, the immediate reflex of corporate leadership is to audit firewalls, update endpoint protection software or blame a sophisticated external threat actor. Millions of rand are channelled into technology stacks, yet the perimeter remains stubbornly vulnerable.
The missing link in this strategy is not digital; it is human. As South African companies navigate persistent macroeconomic pressure, inflation and shrinking operational teams, an invisible and highly dangerous vulnerability has emerged: chronic employee burnout.
Modern cybercriminals no longer focus primarily on breaking through technical defences. Instead, they exploit predictable human behaviour, making employee wellbeing and organisational culture central components of cyber resilience.
To understand why burnout has become such a significant security risk, executives must first understand how modern cybercriminals gain access to corporate networks. They rarely “hack” their way in. Instead, they simply log in using compromised user credentials.
Global research highlights just how heavily today’s security landscape depends on human behaviour.
According to Mimecast’s State of Human Risk Report, user-driven errors, credential misuse and social engineering now account for the vast majority of modern security incidents. The scale is equally alarming. Mimecast estimates that the average cost of each insider-driven incident is US$13.1 million, with surveyed organisations experiencing an average of six incidents every month.
The sheer frequency of these incidents should concern every executive team.
The Verizon Data Breach Investigations Report further confirms that approximately 60% of all data breaches involve the human element, including simple mistakes and unintentional human error. In its 2026 report, Verizon found that organisations took an average of 43 days to recover fully from a cyber incident.
The consequences extend well beyond financial losses. These incidents carry a significant operational and human cost.
Other industry research suggests that between 45% and 55% of risk and security professionals are experiencing moderate to acute burnout. When extended across the broader corporate workforce, the data paints a picture of an exhausted and distracted workforce. In South Africa, where economic uncertainty and workplace pressure further amplify stress, the risks become even more pronounced.
Imagine a high-pressure workplace characterised by unrealistic workloads and excessive micro-management. An employee receives a highly sophisticated, AI-generated phishing email that appears to come from the CEO requesting urgent action. A rested and focused employee might notice the subtly altered domain name or unusual wording. A burnt-out, anxious employee, rushing to meet deadlines and worried about performance, simply clicks the link to complete the task as quickly as possible.
In less than four seconds, the organisation’s entire multi-million-rand security perimeter has been bypassed.
The security risks associated with burnout extend far beyond accidental clicks. Fatigued and overworked employees actively look for shortcuts simply to survive their workloads, often bypassing established security protocols out of necessity rather than malicious intent.
This risk is being accelerated by the rapid adoption of Artificial Intelligence (AI). Recent research shows that 81% of corporate employees admit to using generative AI tools that have not been vetted or approved by their IT or security teams.
When employees are overwhelmed, they often copy proprietary company information, financial spreadsheets or sensitive customer data into public, unsecured AI platforms to draft reports, analyse information or accelerate routine tasks. Their intention is not to compromise the organisation. They are simply trying to achieve business objectives under immense time pressure.
Research also shows that 74% of employees are willing to bypass cybersecurity guidance if doing so helps their team achieve its targets. Burnout turns security shortcuts into survival mechanisms.
Disconnected departments will fail
The primary reason organisations fail to close this psychological loophole is institutional fragmentation. Traditional corporate structures separate these issues into disconnected silos.
Technology departments analyse network logs and deploy additional software.
Human Resources monitors staff turnover and rolls out generic wellness programmes.
Finance focuses on reducing costs while demanding greater output from increasingly lean teams.
None of these functions, in isolation, can solve the problem.
You cannot solve a human risk challenge with purely technical solutions, nor can you solve a complex data leakage problem with a basic employee wellness survey.
A unified approach to risk
To secure the modern enterprise, South African leadership teams must adopt a holistic approach that treats human capital and technological infrastructure as a single, interconnected ecosystem.
Boardrooms should recognise workplace stress as a genuine operational risk. This means equipping line managers to identify the early warning signs of burnout, including declining engagement, presenteeism and sustained fatigue, before those vulnerabilities result in a successful phishing attack or another avoidable security incident.
Traditional tick-box cybersecurity training is no longer sufficient against increasingly sophisticated threats. Organisations should transition towards continuous Human Risk Management programmes that combine behavioural insights with real-time technical controls, allowing security controls to adapt to user behaviour and organisational risk.
Finally, organisations should look to unify their business operations wherever possible. When accounting, human capital advisory and technology transformation strategies are aligned through an integrated operating model, businesses reduce the blind spots where human error, operational pressure and data exposure intersect.
Cyber resilience is not achieved by building higher digital walls. It is achieved by creating sustainable, compliant and supportive workplaces where employees have the cognitive capacity to become the organisation’s strongest line of defence.
- Suran Moodley, Ariston Global


