Work-life balance is one of those phrases cybersecurity organizations like to talk about. Sam Van Ryder is less interested in the phrase than what happens when a security professional closes the laptop, walks away and tries to actually stop working.
That turns out to be harder than it sounds.
Van Ryder, co-founder of CYBR.SEC.Community and Director of Strategic Accounts at Dragos, recently recorded an episode of CYBR.Signal while mountain biking in Switzerland, where he grew up and returns regularly. He described the trip as something of a "workcation": still thinking about work and doing some work, but deliberately carving out time for himself.
Full episode:

That attempt to disconnect prompted a broader message for cybersecurity practitioners and the organizations employing them.
"When I go through this process of trying to turn myself off a little bit, that's not easy," Van Ryder said. "We have a tough job inside where there's a lot going on all the time."
For an industry increasingly worried about burnout, staffing shortages and the sustainability of its workforce, that difficulty is more than a personal wellness problem.
It can become a security problem.
Work-life balance isn't something an employer can simply promise
Van Ryder is skeptical of the way organizations sometimes talk about work-life balance as an employee benefit.
For some people, he said, the term itself has become a "misnomer" because employers can talk endlessly about balance without creating conditions that allow people to disconnect.
Ultimately, practitioners also have to make the decision to step away.
"At the end of the day, it lies on you to do what you need to do to shut down," Van Ryder said.
Cybersecurity makes that unusually difficult.
Threats don't respect weekends. Vulnerabilities don't wait for vacations to end. Incidents happen overnight. Security professionals operate in an environment where there is almost always another alert, headline or potential crisis demanding attention.
Van Ryder admitted that even while trying to disconnect in Switzerland, he still kept "one eye kind of on the news" to see what was happening in cyber.
For people sitting even closer to the operational front lines, the pressure can be considerably greater.
SOC analysts and incident responders are being "taxed more than ever," Van Ryder said. The problem becomes particularly acute in operational technology security, where an already limited practitioner pool is responsible for protecting industrial systems and critical infrastructure.
Van Ryder has spent more than two decades working across cybersecurity and industrial environments, including energy, oil and gas and other critical sectors. His career has put him alongside security leaders and operators responsible for environments where availability and resilience are fundamental requirements.
The staffing equation he sees in OT is brutally simple.
"We just don't have enough practitioners," he said. "So what do you do? You load more work onto them so you can get the workload done."
That may solve today's staffing problem.
It risks making tomorrow's worse.
Related:



Leaders must protect people's downtime
Van Ryder's message isn't directed only at practitioners. Security leaders have a responsibility to make downtime real.
"If you've got teammates that are on the front lines of cyber, make sure that they get some downtime," he said. "Make sure that they can actually turn off."
That means more than approving a vacation request while allowing Slack messages, email, alerts and emergency calls to follow the employee out the door.
Van Ryder's prescription is considerably simpler. Leave them alone.
And if someone who is supposed to be taking time off tries to log back in, tell them to go back to whatever they were doing — swimming, biking or lying on a beach. There is a workforce argument behind that advice.
Cybersecurity already struggles to develop and retain experienced defenders. Burning through the people the industry already has only compounds the problem.
"It's really important that we keep as many people in this practice as we possibly can," Van Ryder said.
Exhaustion gives attackers an advantage
There is also a defensive argument for rest. Cybersecurity depends heavily on human judgment. Analysts must notice anomalies, investigate ambiguous signals, make decisions under pressure and respond correctly when something goes wrong.
Those demands don't disappear because someone is exhausted. Attackers don't disappear either.
"As defenders, there's a lot on our shoulders," Van Ryder said. "The bad guys aren't giving up. They're counting on us to quit. They're counting on us to get weak because that's when they have the opportunity to pop that box or do whatever they need to do to create chaos and make our lives worse."
Seen that way, protecting cybersecurity workers from chronic exhaustion isn't separate from protecting the enterprise. It is part of the defensive mission.
Organizations routinely invest in redundancy for infrastructure because they understand that systems operating continuously without sufficient resilience eventually fail. Security teams deserve some of the same thinking.
A workforce running permanently at maximum capacity has no reserve when the real crisis arrives.
A vacation once a year isn't enough
Van Ryder also cautioned against treating recovery as something accomplished with one annual vacation. Downtime has to become routine.
"Take a moment, take some downtime," he said. "As much as you can take that downtime throughout the year, it's not just a one-time thing, not just one, two week vacation or whatever."
That includes weekends, time with friends and family, exercise or simply doing something that has nothing to do with cybersecurity.
Van Ryder has made that philosophy visible before. At the beginning of 2026, he wrote about slowing down, reflecting and doing much of that reflection on a mountain bike. His advice then was similarly straightforward: take care of yourself throughout the year rather than waiting for some arbitrary moment to do it.
Months later, riding through the Swiss mountains, the message hasn't changed. Cybersecurity needs its defenders for the long haul.
Keeping them there requires organizations to stop treating work-life balance as a slogan, leaders to protect genuine downtime and practitioners to give themselves permission to disconnect.
Sometimes the best thing a defender can do for security is turn everything off and go ride the bike.



