Cybersecurity preparedness depends not only on robust technology and incident response plans, but also on whether security professionals can maintain effective judgement and decision-making under sustained pressure. In an exclusive interview, Rebecca McKeown, Founder and Principal Psychologist with Mind Science, tells Intelligent CISO Editor Mark Bowen why cognitive readiness must become a core component of cyber-resilience and how organisations can better prepare their people to perform effectively when a major cyberincident occurs.

Are your people as prepared as your playbooks?
Cybersecurity teams rarely enter a major incident fresh – they arrive carrying the pressure of the job they were already doing. That pressure comes from competing priorities, persistent threat, regulatory scrutiny, technical complexity, resource constraints and the knowledge that something important could happen at any time. Then the incident arrives, and all of that existing demand continues while a new and much more intense layer is added – and that distinction matters.
We tend to think about cyberincidents as discrete events, and much of our preparation reflects that model. Playbooks, tabletop exercises, escalation procedures and technical training are designed to help people know what to do when an incident occurs.
Research with experienced cybersecurity practitioners suggests a different picture. The incident itself may not be the biggest human performance risk. The bigger risk may lie in the sustained pressure of business as usual and what that pressure progressively does to people’s capacity to perform.
Performance can remain stable while capacity is disappearing
One of the most important findings from the research was also one of the least visible. When demand increases, experienced professionals do not suddenly become bad at their jobs, they compensate. They concentrate harder. They work longer. They invest more effort. They prioritise the most important tasks and defer those that can wait. From the outside, their performance continues to look perfectly acceptable.
Psychologist Robert Hockey described this through his theory of compensatory control: under high workload and stress, people can protect primary task performance by investing additional effort. Performance is maintained, but at a cost.
This creates a problem for organisations because we tend to use visible performance as evidence of whether or not someone still has the capacity to meet additional demands. If the work is still getting done, we assume the person is coping, but that may not be the case. Performance capacity can be consumed long before performance visibly deteriorates.
In cybersecurity, that compensatory period may be substantial and the early warning signs may not be dramatic. They can appear in the margins of performance. Recovery between demanding periods becomes poorer and maintaining concentration requires more effort. People may fall back on familiar ways of working, while communication becomes more effortful and tolerance for ambiguity or challenge reduces. At the same time, it becomes progressively harder to keep sight of the bigger picture. By the time obvious mistakes appear, much of the reserve may already have gone. That is why the apparent sudden failure of performance can be misleading. The failure may be sudden but the depletion that produced it was not.
The incident is the exposure point, not the cause
The practitioners I interviewed did not generally describe pressure as something that arrived with an incident and disappeared when it was contained. They described it as a standing condition of the work and a serious incident simply adds to it.
As the incident unfolds, executive scrutiny increases and customers need answers, while regulators and legal teams may become involved. The demand for communication grows at the same time as business continuity begins to compete with containment, leaving people to make difficult decisions with incomplete information and potentially significant consequences. After containment, recovery, investigation, reporting, scrutiny and organisational learning may continue for weeks or months.
One practitioner described the acute phase of an incident as ‘a week-long fist fight with Russian organised crime’, but the acute phase was only part of the experience. Others described incidents and their consequences continuing far beyond the period we would conventionally think of as incident response. This changes the question organisations need to ask. It is no longer simply: Are our people prepared for an incident? It is: How much performance capacity will they have available when it happens? The major incident is often where the problem becomes visible. It is not necessarily where the problem began.
What sustained pressure does to operational performance
This matters because sustained pressure affects exactly the capabilities that incident response depends upon. Communication is one of the first places the strain becomes apparent, although not because people stop communicating – quite often the opposite happens and the volume of communication increases dramatically.
Meetings, briefings and updates multiply, with different stakeholders requiring different versions of the same information. Technical teams need one level of detail, executives another, while legal advisers, regulators, customers and communications teams may need something different again. Communication stops simply being the mechanism through which the work happens and becomes another substantial piece of work in its own right.
At the same time, fatigue can alter how people interpret each other. As tolerance reduces, a message that might ordinarily be read as neutral can feel critical or challenging, making small misunderstandings harder to resolve. Over time, this can make it more difficult to sustain the trust and candour needed for people to challenge assumptions.
During a complex incident, nobody has the complete picture. SOC teams, executives, communications, legal advisers and external partners may each hold different pieces of it. As information changes, different parts of the organisation can develop a different understanding of what is happening. The decisions they make may be perfectly reasonable based on the information they have, but those decisions are being made from different pictures.
The operational consequence is significant. More effort has to be diverted into rebuilding alignment and making sure people are working from a common understanding of what is happening. Even then, that shared understanding may begin to degrade again almost immediately.
All of this is happening while the hardest decisions still have to be made. Contain now or understand more first? Maintain the security control or keep the business operating? Escalate now or wait for more evidence?
Expertise does not remove these tensions – it enables people to manage them. The problem is that sustained pressure progressively consumes the cognitive capacity on which that judgement depends.
Building cognitive readiness
This is where I believe cybersecurity needs to broaden its concept of preparedness. Knowing what to do is essential, but it is not the same as having the capacity to do it effectively after days, weeks or even months of sustained pressure.
Cognitive readiness is the trained capacity to maintain operational effectiveness under those conditions: to think clearly when information is incomplete, make sound decisions as situations evolve, co-ordinate effectively when priorities compete and learn from experience in ways that improve future performance.
In practice, cognitive readiness can be considered through four interconnected areas:
- Regulating our response to pressure and maintaining effectiveness under sustained load.
- Thinking effectively and exercising sound judgement under uncertainty.
- Connecting and co-ordinating with others through trust and effective communication.
- Adapting through experience and turning that experience into learning that improves future performance.
At Mind Science, these four areas provide the structure we use to understand cognitive readiness in practice.
Crucially, these capabilities can be developed, but doing so requires more than another one-off training course. People need opportunities to practise under realistic pressure, with repeated opportunities to apply, reflect and refine. Development should be informed by behavioural assessment and remain close enough to operational reality for learning to transfer back into the job.
Behavioural assessment can also tell us more than whether someone makes the ‘right’ decision. Situational judgement approaches use realistic operational scenarios to examine the quality of people’s judgements. Looking at confidence alongside those judgements can reveal something equally important: whether someone’s level of confidence matches the quality of the decisions they make.
Developing individual capability is only part of the picture. Organisations also need to consider the working conditions that create or amplify sustained pressure in the first place. Cognitive readiness and good organisational design have to work together.
AI makes human judgement more important, not less
AI, automation and increasingly capable decision-support systems are taking on more technical workload within cybersecurity. It is tempting to assume this reduces the importance of human capability. I don’t think it does – I think it changes what we need people to be good at.
Increasingly, that means knowing when and how to exercise human judgement. As machines become better at detection, analysis and information processing, people still need to judge whether an automated recommendation makes sense in context. Decisions still have to be made about whether to act, what the wider consequences might be and when an output needs to be challenged. Effective response also depends on being able to explain those decisions and co-ordinate people when there is no obviously correct answer. These are precisely the capabilities most vulnerable to sustained pressure.
There is a potential problem, though. Increasing reliance on AI and automation may reduce the opportunities people have to exercise that judgement independently. Research on automation has long shown that over-reliance on technology can weaken independent judgement. More recent research into Generative AI raises a similar concern: when technology repeatedly does part of the cognitive work for us, the underlying human capability may not develop or may gradually erode.
This creates an uncomfortable paradox. Sustained pressure threatens the same capabilities that increasing reliance on automation may weaken. These two effects overlap at exactly the point where human contribution is becoming most valuable – judgement under uncertainty.
The question for cybersecurity leaders therefore isn’t whether humans or AI will be better at particular tasks. It is whether organisations are deliberately developing the human capabilities they will still depend upon when automation has done everything it can.
Cybersecurity has become very good at preparing for incidents. The next step is to become equally deliberate about preparing the people who will have to manage them. Cognitive readiness is part of that preparation, and it cannot be developed once a major incident is already underway. The window to build it is every week that isn’t one.


