Cyber Exodus: Burnout Symptoms, Exit Intention, and Peer Response in Online Cybersecurity Communities Nadia Mehjabin1 , Ji Hyun Kim1 , Laura Barnes2 , Koustuv Saha3 , Henry Kautz1 , Subigya Nepal1 1
Department of Computer Science, University of Virginia Department of Systems and Information Engineering, University of Virginia 3 Siebel School of Computing and Data Science, University of Illinois Urbana-Champaign [email protected], [email protected], [email protected], [email protected], [email protected], [email protected]
arXiv:2609.19556v1 [cs.HC] 17 Sep 2026
2
Abstract Security practitioners burn out at high rates, and the resulting attrition is itself a security problem. This workforce is hard to study: security operations centers are closed to outside researchers, studies that reach practitioners recruit through employers, and those who have disengaged most may have the least reason to answer an employer’s survey. The same practitioners discuss their working conditions openly in online communities. We adapt the Burnout Assessment Tool, a validated clinical instrument, into a text annotation scheme and apply it to 354,861 posts and 296,442 replies from five online communities of cybersecurity practitioners. Checked against two trained coders on 100 posts, the annotation reaches a macro F1 of 0.75 across the four symptoms and 0.98 for detecting any burnout signal. We find that the four symptoms point to different problems at work, not to the same problem at different levels of severity. Exhaustion appears in almost any complaint about staffing or workload. Mental distance, a loss of belief that the work is worthwhile, is the only symptom unrelated to operational problems, and among posts with a single symptom it is accompanied by a stated intention to leave roughly twice as often as any other. Peer responses show the opposite pattern. When a poster says they are considering leaving, the mix of replies shifts toward career advice, but this shift is smallest for mental distance. The symptom most strongly associated with leaving is thus the one peers adjust to least, and a single burnout score obscures both patterns.
1
Introduction
The cybersecurity workforce is under strain, and that strain is itself a security problem. In the 2025 ISC2 workforce survey, 48% of practitioners reported exhaustion from keeping up with new threats and technologies, 47% reported being overwhelmed by their workload, and a third said their organization lacked the resources to staff its team (ISC2 2025). More than half of organizations report difficulty retaining qualified security staff (ISACA 2024). The consequences are operational. Sustained alert volume desensitizes analysts and degrades their effectiveness, which recent work identifies as an open challenge for the field (Tariq et al. 2025), and organizations with severe security staffing shortages incur breach costs averaging 1.76 million US dollars more than Copyright © 2026, Association for the Advancement of Artificial Intelligence (www.aaai.org). All rights reserved.
those with little or no shortage (IBM Security 2024). When experienced analysts leave, those who remain absorb the work, which can raise fatigue, let detection slip and prompt further departures. Despite this, the human side of security is harder to study than the technical side, and the obstacle is access. Security operations centers are closed environments, and empirical work inside them is routinely blocked by non-disclosure agreements, liability concerns and operational security requirements. Research that does reach this workforce recruits through employers, professional networks or targeted outreach (Hollis 2023; Arora and Hastings 2024; Nepal et al. 2024). That work establishes that the problem exists, but it does not scale, and it misses a particular group. Security work carries clearance requirements and strong norms around anonymity, and admitting to burnout can read as admitting to reduced reliability. In one survey, 60% of practitioners said they were unlikely to report work-related stress or burnout to management (Arora and Hastings 2024), and workers more generally fear that wellbeing data will be used to evaluate them (Kawakami et al. 2023). The people furthest along, who have stopped caring and are preparing to leave, may have the least reason to answer. Online communities of practitioners offer a way around that barrier. They work as informal break rooms in which practitioners discuss conditions they cannot raise at work. The disclosure is unsolicited rather than prompted by a researcher, and every reply is preserved beside it. Prior work has established this kind of text as a source for studying distress and the support that follows it (De Choudhury and De 2014; Saha and Sharma 2020; Alghamdi et al. 2025), mostly in general mental health communities rather than in a single occupation. Two questions remain open for this workforce. The first concerns the composition of its burnout. The Maslach Burnout Inventory and the Burnout Assessment Tool both separate burnout into distinct symptoms (Maslach and Jackson 1981; Schaufeli, Desart, and De Witte 2020). Studies of security practitioners, however, mostly report burnout as a single figure or describe it qualitatively (Arora and Hastings 2024; Pham, Brennan, and Furnell 2019; Hollis 2023), and where the symptoms have been measured separately in a recruited sample (Nepal et al. 2024) they have not been tied to the working situations practitioners describe or to
their intention to leave. So for this workforce it is not known whether a practitioner reporting exhaustion and one reporting cynicism are describing the same conditions or carry the same risk of departure. If they are not, a workforcelevel burnout figure would conceal which practitioners are close to leaving. The second question is what happens after someone discloses. A survey can record that a practitioner is burned out. It cannot record what their peers said in reply, and for many practitioners peers are the main support available. We therefore ask: How do the four burnout symptoms relate to the work situations and intentions to leave that cybersecurity practitioners express in online posts, and how do peer responses vary across these symptoms? To address this question, our contributions are as follows: 1. The symptom closest to leaving is the one peers answer least. Among posts carrying a single symptom, mental distance co-occurs with a stated intention to leave roughly twice as often as any other symptom. It is also the symptom whose replies shift least when that intention is stated, and the ordering holds for every reply type we can compare (Sections 4.3 and 4.4). Neither community membership nor voting behavior accounts for this. 2. The four symptoms describe different situations, not one condition at four strengths. Rather than relying on the symptom definitions, we let a concept induction method read the posts and report what they are about (Section 3.6). Exhaustion accompanies almost any complaint about staffing and workload. Mental distance is the only symptom with no detected association with operational content, appearing instead with technical disillusionment and mismatched values. 3. Construct-level burnout measurement in unsolicited text. We adapt the Burnout Assessment Tool into an annotation scheme and apply it to 354,861 posts spanning 2018 to 2026 (Sections 3.1–3.3). We validate the symptom and exit labels against two trained coders, and the symptoms against a model that estimates how much each rater catches without treating any rater as ground truth (Section 3.4).
2 2.1
Related Work
Burnout in Security Work
Studies of security practitioners converge on the same picture from several directions. Hollis (2023) ties stress and burnout among incident responders to multifaceted job demands, improvisation and emotional labour. Arora and Hastings (2024) find that 44% of 50 practitioners report severe work-related stress and burnout, and most often attribute it to the nature of the work, unsupportive cultures and unrealistic expectations. Nepal et al. (2024) link burnout among incident responders to job demands and poor sleep, and identify the unpredictable timing of incidents as a leading stressor. An ethnography of a corporate security operations center describes analyst burnout as the product of human, technical and managerial factors interacting over time (Sundaramurthy et al. 2015). Related work on employees outside the
security function ties burnout to the demands of complying with security policy (Pham, Brennan, and Furnell 2019) and shows that work overload raises job stress, which in turn degrades security behavior (Hong, Kim, and Roh 2023). These studies span several roles and countries. Each recruits through channels that require institutional access, so none can scale, and none observes what follows a disclosure. Where they establish how much burnout exists in recruited samples, we ask what its components look like in text practitioners wrote for their peers, and what those peers wrote back.
2.2
Distress and Support in Online Communities
A large body of work uses public online text to study how people disclose difficult experiences and what support they receive (De Choudhury and De 2014; Andalibi et al. 2018). The language of replies predicts later outcomes for the person who posted (Saha and Sharma 2020), supporters differ in whether they offer information or emotional care (Kim et al. 2023), and reciprocal exchanges keep people in a community (Sharma et al. 2020). Alghamdi et al. (2025) go further and ask whether a supportive reply is effective rather than merely present, using community signals such as votes alongside the text and grounding their labels in social science theories of support. Chancellor and De Choudhury (2020) reviewed methods for predicting mental health status from social media and found recurring problems with how constructs are defined and how validity is established. Ernala et al. (2019) showed that classifiers trained on social media proxies for a diagnosis performed poorly on patients with clinically verified diagnoses. We take two lessons from that work. We do not predict a diagnosis, only the presence of symptom criteria in a piece of text, and we report what our labels are worth against human coders rather than treating model output as ground truth. Further, our framing is occupational rather than clinical: our posters describe a job, and the risk they take in disclosing is a career risk rather than a social one. And we condition support on the symptom profile of the post being replied to, rather than treating support as a property of the community in general. That lets us ask whether the help offered matches the difficulty disclosed, which is the question optimal matching theory poses for support more broadly (Cutrona and Russell 1990).
2.3
Measuring Burnout and Intention to Leave
Burnout is commonly measured through self-report instruments such as the Maslach Burnout Inventory (Maslach and Jackson 1981) and the Burnout Assessment Tool (BAT) (Schaufeli, Desart, and De Witte 2020). The BAT has been validated across occupations and countries (Schaufeli, Desart, and De Witte 2020; Angelini et al. 2021), and its 12-item short form converges with the Maslach instrument (De Beer, Schaufeli, and Bakker 2022). Social media research has also operationalized distinct facets of job satisfaction from posts about work (Saha et al. 2021). Intentions to leave are associated with subsequent departure (Hom et al. 2017), and fit Hirschman’s account of exit
as one response to a deteriorating organization (Hirschman 1970). Studies of online communities have similarly examined self-disclosed accounts of disengagement from social and ideological groups (Phadke 2025). Research on occupational turnover identifies working conditions, workplace relationships, recognition, and health among the reasons employees give for leaving (Hörberg et al. 2023). Person– organization fit research also links alignment between individual and organizational values to work attitudes and withdrawal (Kristof-Brown, Zimmerman, and Johnson 2005; Cable and Judge 1996). Applying these constructs to online text requires explicit definitions and evidence about what the resulting measures capture (Chancellor and De Choudhury 2020; Ernala et al. 2019). Studies of language models demonstrate their potential for text annotation (Gilardi, Alizadeh, and Kubli 2023; Törnberg 2023), with performance varying across tasks and constructs (Ziems et al. 2024). We build on this work by adapting BAT criteria and turnover categories to identify burnout symptoms, intentions to leave, and reasons for departure in practitioner posts. We evaluate the burnout labels against human coding and assess agreement across models for the remaining annotations.
3
Data and Methods
Our analysis proceeded in five stages. After constructing the corpus, we screened posts for work-related distress, annotated burnout symptoms and intentions to leave, characterized the content of posts and replies, and examined temporal associations between vulnerability disclosures and burnoutrelated posting.
3.1
Corpus
We collect posts from r/sysadmin, r/cybersecurity, r/asknetsec, r/SecurityCareerAdvice and r/ciso using Arctic Shift (Heitmann 2024), an archival service that provides bulk access to historical Reddit data. We removed duplicate submissions, kept only self-posts containing user-written text, restricted the window to January 2018 through April 2026, dropped posts whose body had been deleted, stripped URLs and markdown, and excluded posts under 20 words. Minimum-length thresholds in this literature vary by task; Hengle et al. (2024), for example, drop Reddit posts under 75 words. This yielded 354,861 posts. Table 1 gives the breakdown by community, and Figure 1 shows how the corpus narrows at each step of the pipeline described below. We treat all five as security practitioner communities. r/sysadmin is the largest, and we include it because the security function in most organizations is not staffed separately from infrastructure operations. Outside large enterprises, the same people run patching, identity, logging, and incident response, and the conditions most tied to burnout in this work fall on that same group. Excluding them would define the profession by job title rather than by the work performed. We report r/sysadmin as its own stratum throughout and test explicitly whether it behaves differently from the four communities that name security in their titles.
Table 1: The corpus by community. Symptomatic posts show at least one BAT symptom. Rate is the share of that community’s posts that are symptomatic, which orders the communities differently from the raw counts. Community
3.2
Posts Sympt.
Rate
r/sysadmin 269,343 r/cybersecurity 61,586 r/asknetsec 15,832 r/SecurityCareerAdvice 7,674 r/ciso 426
9,871 1,626 199 529 12
Total
12,237 3.4%
354,861
3.7% 2.6% 1.3% 6.9% 2.8%
Step 1: Identifying Work-Related Distress
We developed a screening scheme covering workload, worklife balance, imposter syndrome, job search difficulties, and motivation. The scheme included descriptions of distress that did not explicitly mention burnout. We manually labeled 410 posts using these criteria; Table 5 and Appendix A provide the annotation scheme. We evaluated three screening approaches on the same 82post holdout set. A few-shot Kimi K2.5 prompt achieved 87.8% accuracy, a linear support vector machine (SVM) using word-frequency features achieved 84.2%, and a zeroshot Kimi K2.5 prompt achieved 82.9%. We selected the SVM because its accuracy was within 3.6 percentage points of the best-performing approach and it could screen the full corpus without a language-model call for each post. The SVM identified 144,652 posts (40.8%) as expressing workrelated distress. These posts proceeded to the symptom and exit-intention annotation stages.
3.3
Step 2: Annotating Burnout Symptoms
We operationalized burnout expressions using the four core symptoms of the Burnout Assessment Tool (BAT) (Schaufeli, Desart, and De Witte 2020). Exhaustion concerns physical or mental depletion. Emotional impairment concerns intense or persistent work-related emotional reactions. Cognitive impairment concerns difficulties with memory, attention, or decision-making at work. Mental distance concerns persistent psychological withdrawal from work, including indifference, cynicism, or working on autopilot. We adapted items from the validated BAT short form into textual inclusion and exclusion criteria for each symptom (De Beer, Schaufeli, and Bakker 2022). Kimi K2.5 assessed each screened post separately for each symptom and returned a supporting text span for every positive label. Posts could receive multiple labels. We summed the four binary labels to obtain a symptom count ranging from 0 to 4. Appendix B provides the annotation prompt.
3.4
Validation of Burnout Labels
Two trained coders annotated 100 posts: 40 selected at random and 60 sampled to provide roughly equal coverage of the four symptoms. We measured coder agreement using Gwet’s AC1, a chance-corrected coefficient that addresses
A. Building the corpus Step 1
Step 2
Screen for work distress
Label four BAT symptoms
Label intent to leave and post content
posts
144,652
12,237
12,237
posts
posts
posts
five security subreddits 2018 to 2026
SVM classifier 84% accuracy
Kimi K2.5, one judgment per symptom
Kimi K2.5 and GPT-5.6
Corpus
354,861
Steps 3 & 4
296,442 replies to those posts 53,283 scored for response type
B. One post through the pipeline “Running patching for 40,000 endpoints with two other people, three years now. I used to care about getting it right. Now I close the ticket and go home. Started looking at what else is out there.” paraphrased composite, not a quotation
Symptoms Exhaustion, mental distance Intent to leave Contemplating Resource inadequacy, Post content technical disillusionment Replies received 14, mostly career advice
Figure 1: Panel A: how many posts remain after each stage, and what was used to get there. The 296,442 replies we analyze are the replies to the 12,237 posts that carry at least one symptom. Panel B: a single post, and everything the pipeline records about it. the prevalence-related agreement paradox associated with Cohen’s κ (Gwet 2008). Coder agreement was 0.93 for the presence of any burnout signal and 0.63 across the four symptom labels (Table 2). Agreement varied by symptom: 0.84 for exhaustion, 0.73 for cognitive impairment, 0.52 for emotional impairment, and 0.54 for mental distance. These differences indicate greater consistency in identifying exhaustion and cognitive impairment than in distinguishing emotional impairment and mental distance. We evaluated model performance on the cases where the two coders agreed. For any burnout signal, the model achieved an F1 of 0.98 and 97% agreement with the shared coder label. Across the four symptoms, macro F1 was 0.75. F1 ranged from 0.81 to 0.84 for exhaustion, emotional impairment, and mental distance. For mental distance, the model achieved an F1 of 0.83 and balanced accuracy of 0.87 on the 76 coder-agreed posts. Cognitive impairment had a lower F1 of 0.52. Among the 81 coder-agreed posts, eight were positive; the model identified six of these and labeled nine coder-negative posts as positive. Its balanced accuracy was 0.81. We report F1 alongside balanced accuracy to show performance on posi-
Table 2: Coder agreement and model performance, on 100 validation posts for the symptoms and a separate 100 for exit intention. n is the number of posts where both coders agreed and %Y the share of those that were positive. The model is scored against the coder-agreed label. Symptom
n %Y AC1
F1 Bal.
Exhaustion Emotional impairment Cognitive impairment Mental distance
91 76 81 76
67 50 10 38
0.84 0.81 0.52 0.83
Exit intention, three classes Any exit intention
85 88
53 0.78 0.96 0.97 55 0.76 0.98 0.98
All four symptoms Any burnout signal
324 95
42 0.63 0.75 0.83 81 0.93 0.98 n/a
0.84 0.52 0.73 0.54
0.82 0.80 0.81 0.87
tive cases and across both classes. We also fitted a latent class model to the three raters’ annotations on all 100 posts, including the cases where the coders disagreed. The model jointly estimated latent symptom status and each rater’s sensitivity and specificity from
their annotation patterns (Table 6). The model is the weakest of the three raters on exhaustion. It over-reports emotional impairment, passing over fewer non-cases than either coder. It is the strongest rater on cognitive impairment, the symptom the coders found hardest to agree on. On mental distance the two coders applied divergent thresholds, one conservative and one liberal, and the model fell between them on both measures, so the low coder agreement for that symptom reflects a difference in coder threshold rather than a symptom the model cannot detect. These model-based estimates complement the performance measures calculated on coderagreed cases.
3.5
Step 3: Annotating Intention to Leave
We classified each screened post into one of three categories. Explicit indicated a stated intention to leave a job or the profession, such as giving notice. Contemplating indicated consideration of leaving, including tentative plans to explore other opportunities. No exit indicated no expressed intention to leave. Kimi K2.5 assigned these labels in a separate annotation pass and returned a confidence score, supporting text span, and short justification. The criteria concerned language about leaving and did not refer to burnout symptoms. Appendix C provides the prompt. The same two coders evaluated a separate set of 100 posts sampled to include roughly equal numbers of the three categories. Coder agreement was 0.78 for the three-class annotation, and the model achieved a macro F1 of 0.96 on the 85 coder-agreed posts. When explicit and contemplating labels were combined into a binary exit-intention measure, coder agreement was 0.76. On the 88 posts where coders agreed on this binary label, the model achieved an F1 of 0.98, identified all coder-positive cases, and labeled two coder-negative cases as positive. Figure 3 uses this binary measure.
3.6
Step 4: Characterizing Posts and Replies
We used LLooM (Lam et al. 2024) with gpt-5.6-luna-pro to generate candidate concepts from sampled documents. LLooM distills documents into short descriptions, groups related descriptions, and generates concept names and inclusion criteria. This process allowed us to identify recurring content without supplying a predefined list of content categories. Categories from prior research. For posts, we adapted the turnover categories discussed in Section 2.3. For replies, we used five categories of social support (Cutrona and Suhr 1992) and a category for unsupportive responses (Ingram et al. 2001). These categories connected the analysis to established accounts of turnover and social support. We finalized the induced concepts before writing the criteria for categories drawn from prior work. Post content. We ran concept induction on 2,000 of the 12,237 symptomatic posts, sampling roughly equal numbers from each observed symptom combination to represent less common combinations. Although we initially targeted approximately 20 concepts, four induced concepts were retained after review. Together with six categories adapted
from prior work, these formed the final set of ten postcontent labels. Table 7 in Appendix D lists the labels and their definitions. Reply content. The reply corpus contained 296,442 toplevel comments on symptomatic posts. Approximately 90% came from r/sysadmin. We annotated all comments from the four smaller communities and a random sample of 25,000 from r/sysadmin, yielding 53,283 comments. For corpuslevel estimates, we weighted the sampled r/sysadmin comments to recover that community’s share of the full reply corpus. We directed reply induction toward the functions of responses, such as offering guidance or sharing an experience. We selected a steering phrase by comparing how many concepts generated by candidate phrases described response functions. Eight induced concepts were retained after review: career planning advice, workplace problem guidance, practical advice, emotional support, personal relating, support connections, critical pushback, and discussion direction. Appendix D provides their criteria. Label agreement and stability. We assessed agreement across three models from different providers: gpt-5.6-luna-pro, claude-sonnet-4.5, and gemini-2.5-pro. Each model annotated the same 300 documents, and we calculated Gwet’s AC1 for each label. Ten of the twelve candidate post labels exceeded the 0.60 agreement threshold, with AC1 values ranging from 0.70 to 0.94. We retained these ten labels and excluded personal limits (0.52) and systemic futility (0.55). We also assessed label stability by rewording the criteria and reversing document order. These changes altered an average of 6.3% of labels. Personal limits and systemic futility were the least stable, with changes of 15.4% and 9.4%, respectively. Using the retained criteria, gpt-5.6-luna-pro annotated all 12,237 symptomatic posts and the 53,283 sampled comments. For analyses of replies, we clustered standard errors by post to account for dependence among comments responding to the same post.
3.7
Step 5: Temporal Associations with Vulnerability Disclosures
Security work has obvious external shocks. A serious software vulnerability becomes public, and for the following weeks practitioners patch systems under time pressure. If burnout in these communities is driven by those events, then posting about burnout should increase in the weeks after a spike in serious vulnerabilities. If, instead, it accumulates gradually, no such link should appear. We tested this against the National Vulnerability Database (NVD), maintained by the US National Institute of Standards and Technology (National Institute of Standards and Technology 2026). We constructed weekly counts of disclosed vulnerabilities with severity scores above 9.5 on the 0–10 scale and compared them with weekly counts of symptomatic posts. We applied Granger causality tests to assess whether past vulnerability counts improved prediction of symptomatic posting beyond the posting series’ own his-
tory (Granger 1969). We adjusted for comparisons across multiple time lags using Holm’s correction (Holm 1979).
4 4.1
Results
Burnout Expressions Across Communities
Of the 144,652 posts retained by the screening stage, 12,237 (8.5%) received at least one burnout symptom label. The number of posts decreased with symptom count, from 7,232 with one symptom to 389 with all four. Emotional impairment was the most common label, appearing in 5.3% of screened posts, followed by exhaustion (4.3%), mental distance (2.3%), and cognitive impairment (1.6%). Community-level rates, calculated using all retained posts in each community, are reported in Table 1. r/sysadmin contributed the largest number of symptomatic posts. The proportion of posts labeled symptomatic was highest in r/SecurityCareerAdvice (6.9%) and lowest in r/asknetsec (1.3%). We report r/ciso descriptively, given its 12 symptomatic posts.
4.2
Work Situations Associated with Burnout Symptoms
Within the symptomatic corpus, we compared the prevalence of each content label in posts with and without a given symptom. Figure 2 summarizes the content profiles. Exhaustion. Nine of the ten content labels were significantly associated with exhaustion, although the associations were modest. These included compensation, resource inadequacy, and workplace career strain. Exhaustion thus appeared across several forms of work strain. Emotional impairment. Toxic culture appeared in approximately a quarter of posts expressing emotional impairment, compared with 8.3% of posts without this symptom. Management failure and security governance resistance were also associated with emotional impairment. Workload and compensation showed no statistically significant association. Cognitive impairment. Learning confidence struggles were the most common content label, appearing in 78.2% of posts expressing cognitive impairment and 32.6% of posts without it. Value misalignment, toxic culture, and compensation were significantly less common in posts expressing cognitive impairment. Mental distance. Technical disillusionment appeared in 42.7% of posts expressing mental distance, compared with 9.5% of posts without it. Value misalignment appeared in 45.6% and 14.5%, respectively. Resource inadequacy and IT operations dysfunction showed no statistically significant association with mental distance; both were associated with exhaustion. Concept rankings were broadly similar across symptomcount groups (Spearman’s ρ = 0.867). Technical disillusionment was present in 13.2% of posts with one symptom and 44.7% of posts with all four, indicating a higher prevalence in posts expressing multiple burnout symptoms.
Table 3: Illustrative examples of the exit-intention categories, presented as paraphrased composites. Categories are defined by language about leaving. Class
Representative post
No exit
“Three of us cover ten thousand servers and I am on call every other weekend.” Contemplating “I have started looking at what else is out there, though I am not sure I want to leave the field.” Explicit “I put my notice in last week. Six years of this was enough.”
4.3
Burnout Symptoms and Intention to Leave
Across the screened corpus, 3.70% of posts were labeled as contemplating leaving, and 1.05% expressed an explicit intention to leave. The proportion expressing either form of exit intention increased with symptom count, from 2.7% of posts with no symptoms to 51.3% of posts with all four. Table 3 illustrates the three exit-intention categories. Exit intention also varied by symptom. Approximately half of posts expressing mental distance contained an intention to leave, compared with roughly a fifth of posts expressing cognitive impairment. To examine this pattern without symptom co-occurrence, we restricted the comparison to posts expressing exactly one symptom. Exit intention appeared in 40.7% of posts expressing mental distance, compared with 20.8% for exhaustion, 11.7% for emotional impairment, and 7.9% for cognitive impairment. The rate for mental distance was nearly twice that for exhaustion and higher still relative to the other two symptoms. Post content differed between contemplating and explicit exit intentions. Toxic culture appeared in 25.6% of posts contemplating departure and 42.5% of posts expressing an explicit intention to leave. Compensation, management failure, and resource inadequacy were also more common in the explicit category. Learning confidence struggles showed the opposite pattern, appearing in 46.1% of contemplating posts and 25.2% of explicit posts. Temporal associations with vulnerability disclosures. Most tests relating severe vulnerability disclosures to subsequent burnout-related posting or exit intention were not statistically significant after Holm correction. One association remained significant: higher counts of severe vulnerability disclosures preceded an increase in posts expressing at least two burnout symptoms at a four-week lag (p = .004, pHolm = .043). We do not read this as a relationship. It is a single pairing of one severity cutoff with one symptom threshold at one lag, it sits just inside the corrected boundary, and it is roughly what testing this many combinations would produce by chance. The test also compares one week against the next, so it cannot detect a process that accumulates over months, which is both what burnout is by definition and what our severity results point toward.
Symptom
Representative post (paraphrased)
Distinctive concepts
Share
Lift
Exhaustion
“Three of us cover ten thousand servers, on call every other weekend.”
Resource inadequacy
58%
Compensation
25%
1.26 1.32
Emotional impairment
“I snapped at a colleague over a ticket. Everything here angers me now.”
Toxic culture
26%
Management failure
32%
1.34 1.18
Cognitive impairment
“Six months in and I cannot keep up with the alerts. I second-guess calls.”
Learning confidence
78%
1.89
Mental distance
“I stopped caring a while ago. I close tickets, go home, none of it matters.”
Technical disillusionment
43%
Value misalignment
46%
2.28 1.97
Figure 2: Work situations associated with each burnout symptom. Share indicates the percentage of posts expressing a given symptom that also contain the content label. Lift is how many times more often it appears there than in posts without it, so a lift of 2 means twice as common. Exhaustion sits close to 1 on everything, while mental distance reaches 2.28. Examples are paraphrased composites. Table 4: Common reply types, their corresponding socialsupport categories, and paraphrased composite examples.
response type.
4.5 Career planning advice informational “Move into GRC and you are off the pager.” Workplace problem guidance informational “Get every override in writing and copy your manager.” Personal relating network “I did four years in a SOC and felt exactly this.” Emotional support emotional, esteem “That sounds exhausting, and none of it is your fault.” Critical pushback unsupportive “This is just what the job is.”
4.4
How Peers Respond
Advice was prominent in the replies, with career planning advice the most common reply type. Table 4 illustrates five frequently occurring types, including workplace guidance, shared experiences, emotional support, and critical pushback. Reply patterns varied across exit-intention categories, with the strongest association for career planning advice and the weakest for critical pushback. We quantified the association between exit intention and reply type within each burnout symptom group using Cramér’s V . Figure 3 presents this comparison for career planning advice alongside the single-symptom exit-intention rates. The association was strongest for emotional impairment and exhaustion, followed by cognitive impairment, and weakest for mental distance. This pattern held for all three reply types observed across the four symptoms. The association for mental distance was V = 0.21. We repeated the analysis on posts expressing exactly one symptom, and the same pattern held. Mental distance therefore combined the highest frequency of stated exit intention with the weakest association between exit intention and peer
Community Differences and Voting Patterns
We considered two explanations for this pattern that have nothing to do with the symptom itself. The first is that different communities might simply reply in different ways, and mental distance posts might be concentrated in a community with an unusual reply style. Comparing r/sysadmin against the four security-focused subreddits, only 4 of 14 reply types differ meaningfully between them, and all four are kinds of advice. That is a difference in what people ask about, not in how they support each other. The second is that these communities might already be correcting the pattern through voting, rewarding better replies over time. They are not. Whether a comment is upvoted, and how highly, has essentially no relationship to what kind of reply it is. No style of response is rewarded or penalized, so nothing here would push these communities toward responding differently.
5
Discussion
We asked what could be learned from what security practitioners already write in public, and found that the answer is not simply a larger version of what surveys report. Burnout symptoms and working conditions. The content associated with each symptom helps identify what practitioners find difficult about their work. Exhaustion appeared across several forms of work strain, consistent with the Job Demands–Resources account of demands and exhaustion (Demerouti et al. 2001). Emotional impairment cooccurred with toxic culture and management failure, cognitive impairment with learning confidence struggles, and mental distance with technical disillusionment and value misalignment. These patterns extend research on burnout among incident responders (Nepal et al. 2024) by connecting
Which symptom comes with leaving
Which symptom changes the replies 0.4
40.7
30
20.8 20
11.7 10
7.9
0
How much replies change when leaving is stated
Posts stating intent to leave (%)
40
0.30
0.3
0.32 0.26
0.21 0.2
small effect
0.1
0.0 Mental distance
Exhaustion
Emotional Cognitive impairment impairment
Mental distance
Exhaustion
Emotional Cognitive impairment impairment
Figure 3: Exit intention and peer responses by burnout symptom. Left: the percentage of posts expressing a single symptom that also express an intention to leave. Right: the strength of association between exit intention and career planning advice within each symptom group. Larger values indicate a stronger association. Mental distance has the highest exit-intention rate and the weakest association between exit intention and reply type. This ordering also holds for the two other reply types observed across all four symptoms. burnout symptoms to the situations practitioners describe in peer discussions. The differences also matter for interpreting departure intentions. Among posts expressing a single symptom, 40.7% of those expressing mental distance mentioned leaving, compared with 20.8% for exhaustion. Reporting individual symptoms alongside an overall burnout score would make these differences visible. In workplace assessments, this could guide questions about workload, management relationships, confidence in meeting job demands, and alignment with organizational values. Public text reaches what a survey cannot. There is a reason the symptom closest to leaving is also the one least likely to appear on a form. Telling an employer you are exhausted reads as someone working hard under strain, and it invites help. Telling an employer you no longer care about the work can raise concerns about your commitment and reliability. Practitioners who are considering leaving therefore have stronger reasons to stay quiet. Public communities reduce this cost. The disclosure is unsolicited rather than prompted by a researcher, it is made to peers rather than to anyone with authority over the writer, and it is made under a pseudonym. We cannot show that practitioners answer surveys differently, because we did not measure that. We offer it as the most plausible reason that these two sources would see different things. Peer support and the difficulty disclosed. Optimal matching theory proposes that the usefulness of support depends on its fit with the stressor (Cutrona and Russell 1990). Research in online mental health communities has similarly connected the language and adaptability of peer responses to psychosocial outcomes (Saha and Sharma 2020), and ex-
amined how supporters differ in the informational and emotional resources they provide (Kim et al. 2023). Our findings bring the form of occupational distress into this account: the association between exit intention and reply type varied across burnout symptoms. One possible explanation concerns how readily a post lends itself to advice. Staffing problems or career transitions may provide familiar openings for practical suggestions. Disillusionment and value conflicts may require more information about what the practitioner wants from the exchange. This interpretation motivates examining the fit among the difficulty disclosed, the response offered, and the recipient’s assessment of its usefulness. Learning from occupational disclosures. Online communities make it possible to examine accounts of work alongside the interactions that follow them. Prior research has linked anonymity with disclosure and support seeking (De Choudhury and De 2014), while studies of workplace well-being technologies document concerns about how employers might interpret and use well-being information (Kawakami et al. 2023). Pseudonymous communities may provide opportunities to discuss disengagement outside formal workplace communication. Our approach also extends research that operationalizes workplace experiences through social media (Saha et al. 2021). Adapting BAT items into explicit annotation criteria allowed us to examine specific burnout expressions and connect them to peer responses. Applying this approach to other occupational communities would require attention to how the relevant constructs are expressed and validated in each setting (Chancellor and De Choudhury 2020; Ernala et al. 2019).
Implications for community support. The prominence of advice suggests opportunities to help practitioners communicate what they want from a response. Optional posting prompts could invite requests for practical guidance, shared experiences, or emotional support. Guidance for responders could include acknowledging disillusionment, asking what kind of help would be useful, and sharing relevant experiences. These approaches could be developed with community members and evaluated through recipients’ judgments of helpfulness and supporters’ experiences of responding.
Content and response categories. We assessed content and reply labels through agreement across three models, which may share training data or interpretive assumptions. Rewording criteria and changing document order altered an average of 6.3% of labels. The four retained induced post concepts also reflect the sampling and concept-generation process. Future work could combine human annotation with inductive qualitative analysis across symptom groups to identify shared model errors and experiences missing from the current categories.
Preserving practitioner control. Research and practical applications should preserve practitioners’ control over how their disclosures are used. Studies of workplace well-being technologies show how organizational power can complicate consent and create conflicting expectations about data use (Kawakami et al. 2023; Chowdhary et al. 2023). Applications should support voluntary participation, confidentiality, and reporting at the community level. Linking pseudonymous disclosures to individual employment decisions would undermine this control. Community members should also have a role in defining useful research questions and how findings are communicated.
Peer responses and their usefulness. Our analysis covers top-level replies; support developed in nested conversations, private messages, or offline interactions falls outside this view. The reply categories and association measures describe response patterns, and we did not measure recipients’ assessments of helpfulness. Extending the analysis to complete threads and voluntary recipient feedback could clarify how support develops over an exchange, building on research on reciprocal interaction and community participation (Sharma et al. 2020). Comparisons of posts describing similar work situations, together with vignette studies that vary symptom and exit language, could also help distinguish how each contributes to the responses offered.
What we are not proposing. We do not suggest that employers run this measurement on their staff or that these communities be monitored. Practitioners write in them because they sit outside the employment relationship, and detection by an employer would remove the condition that makes the writing possible. The value of this corpus for research depends on it not being used that way.
6
Limitations and Future Directions
Our study has limitations that suggest several directions for future research. Sampling and disclosure. The corpus reflects selfselected participation in five Reddit communities, with r/sysadmin contributing most posts and replies. Our estimates describe expressions within this corpus and depend on what practitioners choose to disclose. Future studies could examine additional communities and use voluntary recruitment to compare online accounts with confidential surveys and interviews. Such comparisons could clarify which experiences are disclosed in different settings and how the observed patterns vary across occupational roles. Measurement and classification. Errors in screening and symptom annotation can affect subsequent comparisons. Coder agreement was lower for emotional impairment and mental distance, and model F1 was lowest for cognitive impairment. The latent class analysis also estimated lower model sensitivity for exhaustion than for either human coder. Larger validation samples stratified by symptom, community, and year, including posts excluded by screening, could better characterize these errors and assess how they affect the findings. Pairing text annotations with consenting practitioners’ BAT responses could further examine the relationship between expressed symptoms and self-reported burnout.
Temporal patterns and departure. Our main comparisons are at the post level, and the temporal analysis uses weekly vulnerability disclosures and aggregate posting counts. These measures provide limited information about individual exposure to security incidents or changes in working conditions. Longitudinal studies with consenting practitioners could connect repeated burnout measures with work demands, incident exposure, and employment changes. This would help distinguish co-occurring symptoms from changes over time and examine how stated intentions to leave relate to subsequent departure.
7
Conclusion
This study examines burnout expressions, departure intentions, and peer responses in cybersecurity communities. The four burnout symptoms were associated with different work concerns. Mental distance co-occurred most frequently with intentions to leave and showed the weakest association between exit intention and reply type. These findings show the value of examining specific burnout expressions together with the interactions that follow their disclosure. They also motivate research on the forms of support practitioners find useful when describing psychological withdrawal from work.
Acknowledgements Generative AI tools were used to support the development of code and figures and the editing of prose. Their use as research instruments, performing the annotation described in Steps 1 to 4, is reported in the Methods and validated in Sections 3.4 and 3.6. The authors designed the study, performed all analyses, interpreted results and prepared the final text.
References Alghamdi, Z.; Kumarage, T.; Agrawal, G.; Karami, M.; Almuteb, I.; and Liu, H. 2025. RedditESS: A Mental Health Social Support Interaction Dataset–Understanding Effective Social Support to Refine AI-Driven Support Tools. arXiv preprint arXiv:2503.21888. Andalibi, N.; Haimson, O. L.; Choudhury, M. D.; and Forte, A. 2018. Social support, reciprocity, and anonymity in responses to sexual abuse disclosures on social media. ACM Transactions on Computer-Human Interaction (TOCHI), 25(5): 1–35. Angelini, G.; Buonomo, I.; Benevene, P.; Consiglio, P.; Romano, L.; and Fiorilli, C. 2021. The Burnout Assessment Tool (BAT): A contribution to Italian validation with teachers’. Arora, S.; and Hastings, J. D. 2024. A survey-based quantitative analysis of stress factors and their impacts among cybersecurity professionals. arXiv preprint arXiv:2409.12047. Cable, D. M.; and Judge, T. A. 1996. Person–organization fit, job choice decisions, and organizational entry. Organizational behavior and human decision processes, 67(3): 294–311. Chancellor, S.; and De Choudhury, M. 2020. Methods in predictive techniques for mental health status on social media: a critical review. NPJ digital medicine, 3(1): 43. Chowdhary, S.; Kawakami, A.; Gray, M. L.; Suh, J.; Olteanu, A.; and Saha, K. 2023. Can workers meaningfully consent to workplace wellbeing technologies? In Proceedings of the 2023 ACM conference on fairness, accountability, and transparency, 569–582. Cutrona, C. E.; and Russell, D. W. 1990. Type of social support and specific stress: Toward a theory of optimal matching. Cutrona, C. E.; and Suhr, J. A. 1992. Controllability of stressful events and satisfaction with spouse support behaviors. Communication research, 19(2): 154–174. De Beer, L. T.; Schaufeli, W. B.; and Bakker, A. B. 2022. Investigating the validity of the short form Burnout Assessment Tool: A job demands-resources approach. African Journal of Psychological Assessment, 4: 9. De Choudhury, M.; and De, S. 2014. Mental health discourse on reddit: Self-disclosure, social support, and anonymity. In Proceedings of the international AAAI conference on web and social media, volume 8, 71–80. Demerouti, E.; Bakker, A. B.; Nachreiner, F.; and Schaufeli, W. B. 2001. The job demands-resources model of burnout. Journal of Applied psychology, 86(3): 499. Ernala, S. K.; Birnbaum, M. L.; Candan, K. A.; Rizvi, A. F.; Sterling, W. A.; Kane, J. M.; and De Choudhury, M. 2019. Methodological gaps in predicting mental health states from social media: Triangulating diagnostic signals. In Proceedings of the 2019 chi conference on human factors in computing systems, 1–16. Gilardi, F.; Alizadeh, M.; and Kubli, M. 2023. ChatGPT outperforms crowd workers for text-annotation tasks. Proceedings of the National Academy of Sciences, 120(30): e2305016120.
Granger, C. W. 1969. Investigating causal relations by econometric models and cross-spectral methods. Econometrica: journal of the Econometric Society, 424–438. Gwet, K. L. 2008. Computing inter-rater reliability and its variance in the presence of high agreement. British Journal of Mathematical and Statistical Psychology, 61(1): 29–48. Heitmann, A. 2024. Arctic Shift: Bulk Access to Historical Reddit Data. https://github.com/ArthurHeitmann/ arctic shift. Accessed: 2026-09-08. Hengle, A.; Kulkarni, A.; Patankar, S. D.; Chandrasekaran, M.; D’silva, S.; Jacob, J. S.; and Gupta, R. 2024. Still not quite there! evaluating large language models for comorbid mental health diagnosis. In Proceedings of the 2024 Conference on Empirical Methods in Natural Language Processing, 16698–16721. Hirschman, A. O. 1970. Exit, Voice, and Loyalty: Responses to Decline in Firms, Organizations, and States. Cambridge, MA: Harvard University Press. Hollis, T. R. 2023. All Quiet on The Digital Front: The Unseen Psychological Impacts on Cybersecurity First Responders. University of South Florida. Holm, S. 1979. A simple sequentially rejective multiple test procedure. Scandinavian journal of statistics, 65–70. Hom, P. W.; Lee, T. W.; Shaw, J. D.; and Hausknecht, J. P. 2017. One hundred years of employee turnover theory and research. Journal of applied psychology, 102(3): 530. Hong, Y.; Kim, M.-J.; and Roh, T. 2023. Mitigating the impact of work overload on Cybersecurity Behavior: The moderating influence of corporate Ethics—A mediated moderation analysis. Sustainability, 15(19): 14327. Hörberg, A.; Gadolin, C.; Skyvell Nilsson, M.; Gustavsson, P.; and Rudman, A. 2023. Experienced nurses’ motivation, intention to leave, and reasons for turnover: a qualitative survey study. Journal of Nursing Management, 2023(1): 2780839. IBM Security. 2024. Cost of a Data Breach Report 2024. https://www.ibm.com/reports/data-breach. Accessed: 202609-09. Ingram, K. M.; Betz, N. E.; Mindes, E. J.; Schmitt, M. M.; and Smith, N. G. 2001. Unsupportive responses from others concerning a stressful life event: Development of the Unsupportive Social Interactions Inventory. Journal of Social and Clinical Psychology, 20(2): 173–207. ISACA. 2024. State of Cybersecurity 2024. https://www.isaca.org/about-us/newsroom/pressreleases/2024/nearly-two-thirds-of-cybersecurity-pros-sayjob-stress-is-growing-according-to-new-isaca-research. Accessed: 2026-09-14. ISC2. 2025. 2025 ISC2 Cybersecurity Workforce Study. https://www.isc2.org/Insights/2025/12/2025-ISC2Cybersecurity-Workforce-Study. Accessed: 2026-09-09. Kawakami, A.; Chowdhary, S.; Iqbal, S. T.; Liao, Q. V.; Olteanu, A.; Suh, J.; and Saha, K. 2023. Sensing wellbeing in the workplace, why and for whom? envisioning impacts with organizational stakeholders. Proceedings of the ACM on Human-Computer Interaction, 7(CSCW2): 1–33.
Kim, M.; Saha, K.; De Choudhury, M.; and Choi, D. 2023. Supporters first: understanding online social support on mental health from a supporter perspective. Proceedings of the ACM on Human-Computer Interaction, 7(CSCW1): 1–28. Kristof-Brown, A. L.; Zimmerman, R. D.; and Johnson, E. C. 2005. Consequences OF INDIVIDUALS’FIT at work: A meta-analysis OF person–job, person–organization, person–group, and person–supervisor fit. Personnel psychology, 58(2): 281–342. Lam, M. S.; Teoh, J.; Landay, J. A.; Heer, J.; and Bernstein, M. S. 2024. Concept induction: Analyzing unstructured text with high-level concepts using lloom. In Proceedings of the 2024 CHI Conference on Human Factors in Computing Systems, 1–28. Maslach, C.; and Jackson, S. E. 1981. The measurement of experienced burnout. Journal of Organizational Behavior, 2(2): 99–113. National Institute of Standards and Technology. 2026. National Vulnerability Database. https://nvd.nist.gov. Accessed: 2026-09-08. Nepal, S.; Hernandez, J.; Lewis, R.; Chaudhry, A.; Houck, B.; Knudsen, E.; Rojas, R.; Tankus, B.; Prafullchandra, H.; and Czerwinski, M. 2024. Burnout in cybersecurity incident responders: exploring the factors that light the fire. Proceedings of the ACM on Human-Computer Interaction, 8(CSCW1): 1–35. Phadke, S. 2025. Exit Stories: Using Reddit SelfDisclosures to Understand Disengagement from Problematic Communities. Proceedings of the ACM on HumanComputer Interaction, 9(7): 1–27. Pham, H. C.; Brennan, L.; and Furnell, S. 2019. Information security burnout: Identification of sources and mitigating factors from security demands and resources. Journal of Information Security and Applications, 46: 96–107. Saha, K.; and Sharma, A. 2020. Causal factors of effective psychosocial outcomes in online mental health communities. In Proceedings of the international AAAI conference on web and social media, volume 14, 590–601. Saha, K.; Yousuf, A.; Hickman, L.; Gupta, P.; Tay, L.; and De Choudhury, M. 2021. A social media study on demographic differences in perceived job satisfaction. Proceedings of the ACM on human-computer interaction, 5(CSCW1): 1–29. Schaufeli, W. B.; Desart, S.; and De Witte, H. 2020. Burnout Assessment Tool (BAT)—development, validity, and reliability. International journal of environmental research and public health, 17(24): 9495. Sharma, A.; Choudhury, M.; Althoff, T.; and Sharma, A. 2020. Engagement patterns of peer-to-peer interactions on mental health platforms. In Proceedings of the international AAAI conference on web and social media, volume 14, 614– 625. Sundaramurthy, S. C.; Bardas, A. G.; Case, J.; Ou, X.; Wesch, M.; McHugh, J.; and Rajagopalan, S. R. 2015. A human capital model for mitigating security analyst burnout. In
Eleventh symposium on usable privacy and security (SOUPS 2015), 347–359. Tariq, S.; Baruwal Chhetri, M.; Nepal, S.; and Paris, C. 2025. Alert fatigue in security operations centres: Research challenges and opportunities. ACM Computing Surveys, 57(9): 1–38. Törnberg, P. 2023. Chatgpt-4 outperforms experts and crowd workers in annotating political twitter messages with zero-shot learning. arXiv preprint arXiv:2304.06588. Ziems, C.; Held, W.; Shaikh, O.; Chen, J.; Zhang, Z.; and Yang, D. 2024. Can large language models transform computational social science? Computational linguistics, 50(1): 237–291.
Paper Checklist Ethical Statement All data analyzed in this study comes from Reddit’s publicly accessible submissions and comments, retrieved through an archival service in accordance with the platform’s terms. We report analyses exclusively at the aggregate level. No usernames or user identifiers are released, and usernames were hashed after being used to filter bot accounts. We construct no user-level profiles and track no individual across posts. Every post excerpt in this paper is a paraphrased composite written from the flagged material rather than a quotation, because verbatim Reddit text can be searched back to the account that produced it. Post identifiers are sequential rather than real. We excluded r/ciso from all group comparisons, because with 12 symptomatic posts an individual could plausibly be identified from a reported cell. This work infers a mental health construct about people who did not consent to be studied. We therefore report population-level patterns only. This work is not intended to support identification of individuals, and we do not recommend its use inside an employment relationship, where it would remove the conditions under which the disclosures we study occur. This study was not subject to IRB review as it involves secondary analysis of publicly available data with no interaction with human subjects.
A
Screening Annotation Guideline
Posts were annotated against a fine-grained scheme capturing distinct forms of work-related distress, then collapsed to a binary label for the screening classifier in Section 3.1. Any post assigned one of categories 1 through 10 was labeled in scope. Category 0 captures posts unrelated to work stress entirely, such as pure technical questions, news and memes. The breadth is deliberate. It establishes a high-recall screening stage so that posts expressing burnout indirectly are not excluded before the narrower BAT annotation is applied.
B
BAT Construct Annotation Prompt
The prompt below was given to Kimi K2.5 for every screened post. The model returned one judgment per symptom, and for a positive judgment the exact phrase that triggered it.
Table 5: Screening categories. Categories 1 to 10 collapse to in scope. #
Description
0 1
Not about work stress or burnout Work-related burnout, chronic stress, workload, job demands 2 Ambiguous work stress; frustration, mental exhaustion or depressive affect 3 Imposter syndrome at work; not knowing something work-related 4 PTSD, mental health disorder or illness 5 De-stressing, stress relief, avoiding overwhelm 6 Work-life balance, work-health balance, workload balance 7 Job search or interview difficulty, job change, ethical or trust issues, toxic environment 8 Anxiety 9 Staying motivated, learning new things 10 Sleep disturbance, emotional numbness
General instructions You are a researcher applying the Burnout Assessment Tool (BAT) to Reddit text. Decide YES or NO for each of four symptoms. Count a burnout or stress signal written in any tense, including anticipated stress, past stress, or present difficulty with sleep or work-life balance. - Read the text cold. Assume nothing about whether burnout is present. - This is a sensitivity-first task. When in doubt, lean YES. Missing a real signal is worse than flagging a stress-adjacent one. - A post asking others about their experience is not the same as expressing it yourself. - Reddit language rarely uses clinical terms. Look for the meaning, not the exact words. - The word "burnout" alone with no other signal is NO. Any supporting signal alongside it is YES.
Exhaustion Energy loss from work, physical or mental, including sustained overload that implies depletion even without the word "drained". YES if: explicit depletion ("drained", "nothing
left", "running on empty"); sustained overload described over weeks or months; physical or health deterioration attributed to work; persistent misery tied to the job; no energy to begin work. NO if: a single bad day with no sustained element; asking others about exhaustion rather than expressing it; boredom or dissatisfaction with no energy or health cost described.
Emotional Impairment Intense, persistent or disproportionate emotional reactions tied to work. Does not require explicit loss of control. Strong sustained negative emotion qualifies. YES if: strong aversion toward the work situation; repeated or stacked emotional signals in the same post; snapping, unexpected crying or overreacting at work; persistent irritability beyond a single incident; feeling unable to control emotions at work. NO if: a single proportionate frustration mentioned once, calmly; mild annoyance without intensity or repetition; asking others about frustration rather than expressing it.
Cognitive Impairment Difficulty with memory, focus or decisions at work, including feeling cognitively overwhelmed by the volume, complexity or pace of the job. YES if: overwhelmed by cognitive demands such as alert volume or task complexity, beyond normal new-role adjustment; brain fog, forgetting procedures, trouble concentrating; indecision on normally easy decisions; difficulty keeping up with job demands. NO if: a new hire describing normal learning difficulty
with no distress; asking others about cognitive difficulty rather than expressing it; general confusion with no work-specific symptom.
language about leaving. Do not infer intention from how difficult the situation sounds. Return exactly one of three labels.
Mental Distance Persistent psychological withdrawal: indifference, cynicism, aversion, or working on autopilot. YES if: explicit loss of meaning or interest ("what is the point", "I do not care anymore"); going through the motions or autopilot, described personally; active avoidance of work tasks or colleagues; persistent cynical or resentful tone; persistent dread of work. NO if: asking others about engagement rather than expressing own detachment; a single bad day or one-off complaint; considering a career change out of ambition or curiosity rather than withdrawal; mild boredom mentioned once without sustained withdrawal; a stated plan to leave with no accompanying indifference, cynicism or withdrawal.
Output format Respond in JSON only, with no markdown fences and no text outside the object. For each symptom return a binary judgment and a reasoning field. For YES, the reasoning field is the exact phrase from the post that triggered the judgment. For NO, it is a one-sentence explanation of why the text did not meet the threshold.
C
Exit Intention Prompt
This pass reads only for directional language about leaving. It makes no reference to the burnout symptoms, so the two annotations stay independent of one another. Exit intention classification You are labelling Reddit posts written by security practitioners. Decide whether the author expresses an intention to leave their job or the field. Read only for
exit_explicit A decision stated or an action already taken. Examples of the form: "I put my notice in", "I start somewhere new in March", "I am done with this field". exit_contemplating Weighing leaving, without having decided. Examples: "I have started looking", "thinking about getting out", "not sure how much longer I can do this". no_exit Difficulty, frustration or exhaustion with no directional language about leaving. Venting alone is not exit intention. Asking how others cope is not exit intention. Rules - Wanting a different role at the same employer counts as exit_contemplating only if framed as leaving the current job, not as ordinary internal movement. - A hypothetical about the field in general is not exit intention unless applied to the author. - Past departures from previous jobs are not current exit intention. Return JSON only: {"label": ..., "confidence": 0.0 to 1.0, "evidence": "<exact phrase from the post>", "reasoning": "<one sentence>"}
Table 6: Latent class estimates of each rater’s sensitivity and specificity (%), fitted to all 100 validation posts including those where the coders disagreed. Coder 1
Coder 2
Kimi K2.5
Symptom
Sens Spec Sens Spec Sens Spec
Exhaustion Emotional impairment Cognitive impairment Mental distance
95 69 67 75
94 89 97 98
98 94 40 100
92 100 98 78
77 85 75 87
87 78 93 88
D
Concept Label Criteria
Table 7 gives the ten labels used to describe what symptomatic posts are about, and Table 8 the fourteen used to describe what replies do. Every label was scored independently on each document, as a binary judgment with no rationale requested. The induced labels were written by the concept induction step and left unedited. The labels drawn from prior work were written by us only after the induced set was frozen, so that induction was not steered toward categories we already had.
Table 7: The ten content labels used to describe what symptomatic posts are about. The first four were induced from the posts themselves, with no categories supplied in advance. The remaining six come from prior turnover research and were written only after the induced set was frozen. Label
What it marks
Induced from the corpus Workplace career strain IT operations dysfunction Security governance resistance Learning confidence struggles From prior turnover research Management failure Resource inadequacy Technical disillusionment Toxic culture Compensation Value misalignment
Unsustainable demands, declining wellbeing, or thoughts of changing job or field Understaffing, excessive technical responsibility, weak processes, or unclear priorities Management ignoring, delaying or overriding controls, compliance or risk findings Feeling unqualified or overwhelmed while developing skills or handling unfamiliar work Poor decisions, or absent support, from management Too little budget, tooling or headcount for the work being asked Loss of belief in the value or effectiveness of the work itself Hostile or corrosive relationships at work Pay judged inadequate for the responsibility carried Mismatch between the practitioner’s professional values and the employer’s priorities
Table 8: The fourteen labels used to describe what replies do. The eight on the left were induced from the replies themselves. The six on the right are established categories of social support. Label
What it marks
Induced from the replies Career planning advice Advice on changing role, employer, specialism or career direction Workplace problem guidance Advice on handling the specific situation the poster described Practical advice Concrete technical or procedural steps to take Emotional support Care, sympathy, reassurance or encouragement toward the poster Personal relating A comparable experience of the replier’s own, rather than a solution Support connections Pointing the poster toward another person, community or resource Critical pushback Challenging, minimising or dismissing the poster’s account Discussion direction Redirecting the thread, asking for clarification, or reframing the question From the social support literature Informational support Advice, guidance, instruction or factual help Emotional support Care, sympathy, reassurance or encouragement Esteem support Affirming the poster’s worth, competence or judgment Tangible support A concrete offer of help, resources or action Network support Signalling shared experience or belonging Unsupportive response Dismissal, minimisation, criticism or hostility