• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Texas businessman gets 13 years in federal prison as feds seize his Lamborghinis, Ferraris, Firebird, and dozens more cars to pay back fraud victims

2

$3 menu items, a $4 breakfast, and fewer visits: McDonald's barrage of deals isn't winning over enough customers

3

Current price of oil as of October 7, 2026

1

Texas businessman gets 13 years in federal prison as feds seize his Lamborghinis, Ferraris, Firebird, and dozens more cars to pay back fraud victims

2

$3 menu items, a $4 breakfast, and fewer visits: McDonald's barrage of deals isn't winning over enough customers

3

Current price of oil as of October 7, 2026
Commentarycyber

IBM cyber response chief: After 26 years in incident response, I’m more concerned about burnout than AI

By
Tony Kirtley
Tony Kirtley
Down Arrow Button Icon
By
Tony Kirtley
Tony Kirtley
Down Arrow Button Icon
October 8, 2026, 7:30 AM ET
cyber
Soldiers and IT experts sit in front of screens during the "Locked Shields" exercise. Soldiers and experts have come together for the NATO cyber defense exercise "Locked Shields". Oliver Berg/picture alliance via Getty Images
Google source logo
Add Fortune on Google for similar content.

I’ve spent two and a half decades responding to cyber incidents or leading teams of people who do. Over that time, I’ve watched the threat landscape evolve from opportunistic attacks and early internet worms to organized cybercrime, ransomware syndicates, and nation-state campaigns. Each major shift brought new technology, new tactics, and new challenges for defenders.

Recommended Video

But one consistent part of the job is the people. The analysts who spent nights and weekends investigating suspicious activity, the incident responders making high-stakes decisions with incomplete information and working around the clock to restore critical systems.

Incident response has always been a human profession disguised as a technical one. Which is why I believe we’re approaching a challenge that isn’t getting enough attention: the human impact of machine-speed threats. Most discussions about AI in cybersecurity focus on capability. What will attackers be able to automate? How sophisticated will AI-enabled attacks become? Those are important questions. But from where I sit, they’re not the most urgent ones.

Recent global research found that AI-enabled attacks increased 56% over the past year. The question isn’t just what AI enables attackers to do, it’s what that acceleration means for the people expected to defend against it every day. The industry often talks about cyberattacks in financial terms—costs, losses, downtime, recovery expenses. What gets discussed less frequently is the human cost.

For years, incident response teams have operated under intense pressure. I’ve seen relationships strained by weeks of around-the-clock work. I’ve seen people step away to recover after particularly difficult incidents. I’ve missed sporting events, birthday parties and holiday celebrations because hackers like to ramp things up on weekends and holidays. Those life-disrupting incidents are about to become much more frequent and stressful.

Sustainability of the workforce has been something we’ve been battling for years. Global research found that 68% of incident responders regularly defend against two or more attacks simultaneously, while 67% reported experiencing daily stress or anxiety associated with responding to cyber incidents. If we don’t change how we support defenders, AI won’t just expose gaps in our technology. It will expose the limits of the people we’ve been asking to carry the burden for years.

That’s why we need to shift the conversation from whether we have enough people to whether we’re enabling the people we already have to operate more effectively. Even as organizations apply frontier AI to defense at scale, our success will ultimately depend on the skills, judgment, and expertise of the people manning the digital front lines.

The first priority should be preparing the workforce for the transition ahead. Security teams need more time to experiment with new technology, to understand it, and to integrate it into their daily workflows. Too often, organizations wait until a crisis forces change. The companies that will navigate this transition most successfully are the ones investing in their people now, giving them the training, resources, and confidence to evolve alongside the technology.

The responsibility of leadership is to create an environment where that sense of purpose can endure. As AI reshapes cybersecurity operations, leaders must ensure technology amplifies human expertise rather than adds to the burden. The best organizations will create environments where security professionals can focus their energy on the decisions that truly require human judgment. That means reducing unnecessary cognitive load. It means eliminating repetitive tasks. It means providing better context so responders spend less time gathering information and more time acting on it.

Most importantly, we need to recognize that resilience starts with people. Retention, wellbeing, and sustainable workload management are more important than ever. That means helping teams’ recharge between incidents, encouraging continuous learning, and ensuring people feel like they are contributing to something meaningful rather than simply moving from one crisis to the next. For my team, I have noticed that allowing them to experiment with technology and research areas that they’re passionate about helps. Not only does it help them, but it helps the team. We’ve been able to put some of what they built into our own workflows.

As AI continues to transform cybersecurity, I think leaders need to broaden the conversation. Yes, we should be discussing adversarial AI, autonomous agents, and machine-speed attacks. But we should also be talking about workforce resilience, burnout, operational design, and the conditions that enable defenders to perform at their best.

The organizations that do the best job supporting the holding of the digital front lines will be the most resilient. After decades in incident response, that’s the lesson I keep coming back to. Technology changes constantly, human limits don’t. And as cybersecurity enters the age of machine-speed threats, taking care of our people may become one of the most important security investments we can make.

The opinions expressed in Fortune.com commentary pieces are solely the views of their authors and do not necessarily reflect the opinions and beliefs of Fortune.

Fortune Daily breaks the traditional barrier between audience and newsroom. The show transforms Fortune’s trusted reporting into actionable, conversational, and entertaining insights for an emerging class of business leaders. Watch here.
About the Author
By Tony Kirtley
See full bioRight Arrow Button Icon
Google source logo
Add Fortune on Google for similar content.

Latest in Commentary


Most Popular

Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • TikTok icon
  • YouTube icon
    Tony Kirtley is Head of Incident Response for IBM X-Force, leading a team that specializes in responding to cyber breaches as well as proactive incident response preparation and threat hunting assessments. X-Force IR’s team of veteran incident responders helps clients recover from cyber breaches and improve their cyber resiliency. 

    Tony is a retired US Army Lieutenant Colonel, who served 22 years in the Missouri National Guard. Tony founded and led the Missouri Cyber Team known in military cyber circles.

    Latest in Commentary


    Most Popular

    © 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
    FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.