> ## Content Index
> Fetch the complete content index at: https://www.cybrsecmedia.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# You Can’t Patch Cybersecurity Burnout: Joe Marshall’s Human Incident Response Framework
- URL: https://www.cybrsecmedia.com/you-cant-patch-cybersecurity-burnout-joe-marshalls-human-incident-response-framework/
- Published: 2026-09-17T04:13:21.000Z
- Updated: 2026-09-17T04:14:37.000Z
- Description: In his CYBR.SEC.CON. 2026 keynote, Joe Marshall introduces the Human Incident Response Framework, a practical playbook for recognizing cybersecurity burnout, secondary traumatic stress, vicarious trauma and moral injury — and responding before the human incident becomes a crisis.
- Author: Bill Brenner
- Tags: Burnout, CYBR.SEC.CON, Article

In 2018, Joe Marshall helped fight one of the most consequential botnets the cybersecurity industry had seen.

VPNFilter had compromised at least 500,000 routers and network-attached storage devices across at least 54 countries. Cisco Talos warned that the malware could steal credentials, monitor industrial protocols and potentially render infected devices unusable. The FBI seized part of its command-and-control infrastructure, disrupting the operation before its destructive potential could be fully realized.

The industry got its success story.

Marshall carried something else away from it.

For seven years, he says, he didn't talk publicly about what working that operation had taken from him: the secrecy, pressure and accumulated stress of helping defend against a state-sponsored campaign while carrying on as though the people doing that work were simply another component of the security stack.

At CYBR.SEC.CON. 2026, Marshall turned that experience into his keynote, “You Can't Patch Burnout: VPNFilter, the Defender's Toll, and the Playbook Nobody Writes.” But the talk wasn't simply a personal account of burnout.

It was an argument that cybersecurity has spent decades building incident-response procedures for compromised machines while largely failing to build an equivalent response system for the people defending them.

Marshall is trying to change that with his **Human Incident Response Framework**, a practitioner wellbeing framework designed specifically for cybersecurity operations. The entire program is available here:

[GitHub - SoShinySoChrome/human-incident-response-framework: A practitioner wellbeing framework for cybersecurity operations. Four injuries, four zones, and what to do about them.A practitioner wellbeing framework for cybersecurity operations. Four injuries, four zones, and what to do about them. - SoShinySoChrome/human-incident-response-framework![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/favicon-6a11cad4-ea56-4b1d-8757-7fc677b20e63.png)GitHubSoShinySoChrome![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/human-incident-response-framework-06d2ee94-fd50-4a2d-a996-f585954efe2b.png)](https://github.com/SoShinySoChrome/human-incident-response-framework?ref=cybrsecmedia.com)

One of its first challenges to the industry is uncomfortable:We call too many different kinds of human injury “burnout.”

[Subscribe to the CYBR.SEC.Media newsletter](#/portal/signup/free)

## VPNFilter was stopped. The human incident continued.

The scale of VPNFilter helps explain the pressure behind Marshall's story.

When Talos disclosed the malware in May 2018, researchers estimated it had infected at least half a million devices. Talos had observed sharp increases in infections in Ukraine and feared an attack could be imminent, prompting the team to disclose its findings before completing all of its research.

The response involved coordination among researchers, vendors, law enforcement and international partners. The FBI seized command-and-control infrastructure while security companies deployed detections and mitigation measures. A year later, Talos described VPNFilter as a potential catastrophe that had been averted.

Cybersecurity knows how to tell that part of the story.

Find the threat. Analyze it. Contain it. Eradicate it. Recover. Document what happened.

Marshall's keynote asked what happens to the people who do those things.

Who checks whether the analyst is recovering? Who recognizes when secrecy prevents a researcher from talking about what they've experienced? What happens when an incident ends technically but continues inside the people who worked it?

Marshall's answer is to borrow something cybersecurity already understands extremely well: Incident response.

**Full CYBR.SEC.CON. Coverage:**

[CYBR.SEC.CON 2026: News, Speakers, Agenda & CoverageFollow CYBR.SEC.CON. 2026 in Houston with the latest news, speakers, keynotes, agenda, cybersecurity tracks, AI.SEC.CON. highlights, interviews and event coverage.![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-f29fb523-62b2-4996-a97d-5973f0ae8e7c.jpg)CYBR.SEC.MediaBill Brenner![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/42601a79-4e56-4e1b-8342-c02f537cefcd-11fc85a0-3a12-4803-84ac-0b607da76510.png)](https://www.cybrsecmedia.com/cybr-sec-con-2026-news-speakers-agenda-and-coverage/)

## Not everything is burnout

The Human Incident Response Framework begins by challenging the industry's vocabulary.

Marshall identifies **four distinct forms of injury** that cybersecurity tends to collapse under the word “burnout”: burnout itself, secondary traumatic stress, vicarious trauma and moral injury.

That distinction matters because they don't have the same causes — and therefore don't have the same remedies.

In Marshall's framework, burnout is a workload injury. Secondary traumatic stress can result from exposure to what happened to other people. Vicarious trauma develops through cumulative exposure that gradually changes how someone sees the world. Moral injury can arise from participating in something a person believes was wrong or being prevented from doing what they believed was right.

Only one of those, the framework argues, is primarily addressed by rest.

That's a significant distinction for an industry accustomed to responding to chronic stress with some version of: Take some PTO.

If someone is experiencing secondary traumatic stress, vicarious trauma or moral injury, a vacation may not address what is actually happening.

And if the industry calls all four conditions burnout, Marshall argues, people can receive the wrong response, find that it doesn't help and conclude that nothing will.

## Different cybersecurity jobs carry different exposure

Marshall's framework also rejects the idea that cybersecurity stress is simply about working too many hours.

It identifies six factors that can influence the human cost of a security role: **content type, decision weight, institutional friction, cumulative dose, adversarial engagement and secrecy.**

That helps explain why two practitioners working similar hours can experience their jobs very differently.

A threat intelligence analyst investigating abuse material or human targeting isn't exposed to the same content as someone reviewing routine vulnerability scans. An incident responder making decisions during an active intrusion carries a different decision weight. A researcher locked behind confidentiality restrictions may be unable to discuss what they've seen. Someone repeatedly engaging adversaries accumulates a different kind of exposure.

And then there is cumulative dose. One incident may end. Years of incidents don't necessarily disappear with it.

That makes the framework particularly relevant to threat intelligence, incident response, digital forensics, SOC operations, vulnerability research and trust-and-safety roles — groups Marshall explicitly identifies among its intended audiences.

**Related:**

[Cybersecurity Burnout Is a Measurable Security RiskVeteran CISO Kayla Williams tells CYBR.Minded that overloaded security teams create measurable cyber risk through slower escalation, weaker judgment and missed signals — and CISOs should start tracking the warning signs.![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-5dee44a2-aa4e-4dcf-9e30-e25f47ddcdf9.jpg)CYBR.SEC.MediaBill Brenner![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/8720d0e7-d43b-4f7a-aec0-5e25b1b465d9-5bc6b78b-6eb9-41c7-ac5d-76f7cea0545c.png)](https://www.cybrsecmedia.com/cybersecurity-burnout-is-a-risk-signal-pizza-parties-wont-fix-it/)

[Deidre Diamond: Burnout Is Cybersecurity’s Bigger CrisisDeidre Diamond says burnout, not hiring, is cybersecurity’s biggest workforce challenge. Learn what leaders should do next.![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-9b076447-9e87-403d-b342-d9618518e102.jpg)CYBR.SEC.MediaBill Brenner![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/f1a22dc4-30ba-4699-81c6-0205660c5f19-eb157582-12c8-4786-bde7-7d72c239dd35.png)](https://www.cybrsecmedia.com/cybersecurity-keeps-talking-about-hiring-deidre-diamond-says-burnout-is-the-bigger-crisis/)

## Ready. Reacting. Injured. Crisis.

To make those problems operational, Marshall adapts concepts from professions that have spent much longer dealing explicitly with occupational stress and trauma, including the military, social work, emergency medicine and child welfare.

The framework establishes four zones for recognizing changes in a practitioner: **Ready, Reacting, Injured and Crisis.**

The goal is to give teams a common vocabulary.

Cybersecurity already does this technically. Analysts don't describe every event as “the system is having a bad day.” They classify severity, establish baselines, watch for indicators, escalate when thresholds are crossed and route incidents to people qualified to handle them.

Marshall applies similar thinking to humans. That begins with knowing what normal looks like for the person beside you.

## The open-door policy isn't enough

One of the more consequential ideas in the framework concerns how teams check on one another.

“Come talk to me if you need anything” sounds supportive. But it requires the person already under strain to recognize what is happening, decide they need help, overcome whatever stigma or organizational risk they perceive and initiate the conversation.

Marshall instead emphasizes **structured, recurring contact** that allows peers and leaders to establish a baseline over time. Importantly, the framework says that baseline should be something a person holds rather than something an organization automatically files — a distinction intended to preserve trust and protect sensitive personal information.

The framework then provides a peer check-in protocol built around the **seven C's: Check, Coordinate, Cover, Calm, Connect, Competence and Confidence.** It includes guidance on what to say, what not to say and when the situation has moved beyond what a peer should attempt to handle.

## Know when the incident is beyond you

Marshall draws a deliberate boundary around the framework.

It is a **detection aid, not a safety system**. Someone can appear fine, meet deadlines and participate normally while still experiencing serious problems. People also retain the right not to disclose what they're going through.

Peer support doesn't replace clinical care or crisis services.

The framework therefore includes escalation thresholds and guidance for routing people toward appropriate help without turning the process into surveillance or a disciplinary mechanism.

That distinction may be especially important in cybersecurity, where monitoring is almost instinctive.

Human incident response can't become another telemetry system. Trust has to remain part of the architecture.

## The playbook is built for practitioners, not just CISOs

Marshall didn't publish a single 50-page document and expect everyone to consume it. The repository includes three primary versions:

- The complete **Human Incident Response Framework** covers the four injuries, four severity zones, six exposure drivers, role-to-injury mapping, check-in protocol, escalation procedures and an organizational layer.
- A 43-page **Field Guide** removes much of the organizational material and is designed for an individual practitioner, peer or team leader who wants something usable without waiting for a formal corporate program.
- And a two-page **Human IR Playbook** reduces the model to an operational reference containing the zones, injuries, seven C's, escalation triggers and routing guidance.

That design reflects an important part of Marshall's approach: helping a colleague shouldn't require first getting budget approval or launching an enterprise wellbeing initiative.

A practitioner can start with the field guide. A CISO can use the larger framework to examine how different roles are exposed. And organizations can build more formal programs around the model.

## Cybersecurity borrowed the technology. Marshall borrowed the response model.

The framework isn't presented as a new clinical theory. Marshall explicitly describes it as a synthesis of work from other disciplines, drawing on research into burnout, secondary traumatic stress, vicarious trauma and moral injury, along with the U.S. military's four-zone stress continuum and Stress First Aid model.

It also directs practitioners toward established training such as Stress First Aid and Mental Health First Aid rather than suggesting that reading the framework makes someone qualified to handle a mental health crisis.

Cybersecurity doesn't need to reinvent psychology any more than it needs to reinvent cryptography.

The opportunity is to translate existing knowledge into a language practitioners recognize and can actually use.

Marshall has done that through the vocabulary of incident response: recognize the indicators, understand the exposure, establish a baseline, check in, know the escalation threshold and route appropriately.

## We need an incident-response plan for the incident responders

That brings Marshall's keynote back to VPNFilter.

The technical operation ended successfully. Talos and its partners helped prevent an attacker from using hundreds of thousands of compromised devices to carry out what could have been a destructive campaign.

But technical recovery isn't necessarily human recovery.

Security organizations routinely conduct postmortems after major incidents. They examine what failed, what worked, which controls need changing and what they should do differently next time.

Marshall's argument is that the people who carried the incident deserve an after-action process too.

Not another resilience slogan. Not an open-door policy nobody uses. Not pizza after an all-nighter. And not automatically prescribing vacation for every form of distress.

The industry needs enough vocabulary to recognize that workload exhaustion, traumatic exposure, accumulated changes in worldview and moral injury aren't interchangeable problems.

Because **you can't patch burnout — and you can't recover from the wrong incident.**

Over the coming weeks, **CYBR.SEC.Media will dig deeper into the Human Incident Response Framework in a series of articles examining its individual pieces** — the four injuries, four severity zones, six exposure drivers, seven-C check-in protocol, escalation model and the organizational responsibilities surrounding them.

Marshall's keynote gives us the starting point.

[ ![HOU.SEC.CON CTA](https://s3.us-east-1.amazonaws.com/assets.cybersecmedia.com/HSC+CTA.jpg) ](https://houstonseccon.com/?ref=cybrsecmedia.com)