Horizontal mobbing among peers and what happens when cybersecurity teams turn on each other
Some teams talk endlessly about hostile actors, insider threats, and operational resilience, then tolerate a colleague being quietly frozen out of decisions, mocked in post-incident reviews, or turned into the designated idiot in the team chat. That contradiction would be funny if it were not so expensive. In cybersecurity, the system can be technically sound and still fail because the people running it have been trained to distrust each other.

A useful starting point is The silent threats in our workplaces: understanding Mobbing and straining, which outlines how repeated hostile conduct at work differs from ordinary conflict and how these patterns often become visible only after real damage has already been done. Here, the same logic applies, but with an unpleasant twist: when peer-to-peer abuse settles in, it does not just hurt the target; it degrades the team’s ability to detect, decide, and respond.
In brief
- Horizontal mobbing in cybersecurity is repeated hostile behavior between colleagues of similar rank, not just a bad week or an abrasive personality.
- Exclusion and technical gatekeeping among peers can become operational risks because knowledge sharing is part of the job, not a nice extra.
- Burnout in cybersecurity is already a documented problem, and toxic peer dynamics make it worse, faster, and harder to reverse.
- Standards such as ISO 45003:2021 give organizations a practical framework for managing psychosocial risks, including bullying, social exclusion, and poor organizational support.
- Italy’s ratification of ILO Convention No. 190 matters because it reinforces the principle that work should be free from violence and harassment, including forms that do not leave bruises, only attrition.
It rarely looks dramatic at first
The popular image of workplace abuse still revolves around the tyrannical boss, the public tirade, the caricature of the manager who mistakes cruelty for leadership. Horizontal mobbing is less theatrical. It moves sideways, among peers, often in teams that claim to be flat, agile, meritocratic, and other fashionable things people say before wrecking each other’s nervous systems.
In practice, horizontal mobbing can look deceptively mundane: exclusion from critical calls, selective omission from distribution lists, mockery disguised as technical rigor, repeated undermining during incident reviews, or systematic denial of credit for analytical work. The University of Milan’s overview of mobbing notes that mobbing can occur horizontally, between colleagues of the same level, and that what matters is not a single dispute but a sustained pattern of hostile conduct. That distinction matters because many technical environments romanticize aggression as evidence of competence, as if being insufferable were listed among the required certifications.
This is where the distinction from ordinary workplace friction becomes essential. Teams under pressure will have disagreements, blunt conversations, and the occasional ugly meeting. That is not automatically mobbing. The problem starts when behavior becomes repetitive, targeted, and structurally tolerated, when one person is routinely isolated, delegitimized, or set up to fail, and when the organization responds with the usual masterpiece of cowardice, “that’s just how the team works.” The earlier article on mobbing and straining is useful here because it separates persistent abuse from generic stress and from the kind of low-grade strain that organizations often prefer to mislabel as resilience.
Why this field is fertile ground for it
Cybersecurity likes to imagine itself as hyper-rational, but the reality is a profession built around asymmetric pressure, opaque success, chronic urgency, and a work culture that still too often confuses endurance with professionalism. That combination creates ideal conditions for horizontal mobbing because scarce recognition and constant exposure to failure make teams prone to status games.
The burnout problem is not speculative. The BBC’s report Why burnout is a growing problem in cyber-security describes a field where stress, constant alertness, and high emotional load are pushing practitioners out of the workforce. The pressure does not come only from threat actors or long hours. It also comes from environments where every mistake is memorable, every success is invisible, and support tends to arrive after the damage, if at all. Once that climate sets in, peer hostility stops being an interpersonal issue and becomes part of the operating model.
Some functions are especially exposed. SOC teams live inside queues, false positives, fatigue, and the unglamorous reality of triage. DFIR teams deal with crisis tempo, high-stakes interpretation, and sometimes deeply disturbing content, a theme explored in When digital evidence follows you home in DFIR teams. Incident response adds sleep disruption, blame risk, and executive visibility. In those conditions, the colleague who withholds context, ridicules uncertainty, or weaponizes hindsight damages more than morale. He makes the team slower, more brittle, and more likely to miss something important.
There is also the matter of informal hierarchy. Plenty of teams claim to have little hierarchy while operating under a rigid caste system built on experience, niche expertise, and personality. One engineer becomes the keeper of arcane firewall history, another monopolizes cloud logging knowledge, a third controls the relationship with management, and suddenly the team depends on a few people who can turn access to information into a social weapon. The result is classic gatekeeping, except now it comes wrapped in technical jargon and sold as quality control.
From toxic culture to operational weakness
Teams like ours depend on trust in a very literal way. People need to be able to say “I’m not sure,” “I may have missed this,” or “someone check my assumptions” without inviting ritual humiliation. When that safety disappears, analysts start hiding uncertainty, minimizing escalation, and avoiding visibility. The environment does not become stronger, only quieter about its mistakes.
This is where the article can move beyond workplace commentary and into security practice. Horizontal mobbing damages detection quality because people stop sharing weak signals they are afraid will be mocked. It damages response quality because handovers become incomplete or politically filtered. It damages retention because skilled practitioners eventually decide that another employer, or another profession, might be preferable to being slowly flayed alive by colleagues who call it standards. Burnout literature repeatedly points to chronic stress, weak support, and poor culture as major drivers of attrition, and those factors are entirely compatible with persistent peer-to-peer abuse.
The organizational cost is easy to underestimate because it does not always appear as a single catastrophic failure. Instead, it shows up as delayed escalations, missing context, defensive documentation, people refusing ownership, endless second-guessing, and a slow migration of competent staff toward quieter corners of the industry. A team in that state can still produce dashboards, hold standups, and even pass audits. It is also one serious incident away from discovering that mutual contempt is not a substitute for collaboration.
A practical way to frame this is through psychosocial risk management. ISO 45003:2021 provides guidance for managing psychological health and safety at work within an occupational health and safety system. The standard’s logic is useful precisely because it treats factors such as poor communication, lack of role clarity, social isolation, bullying, harassment, and weak organizational support as risks to be identified and managed, not as vague matters of personality or softness. In other words, it drags the conversation out of the swamp of office folklore and into governance.
This matters because the field is still unusually tolerant of self-inflicted damage. Teams invest heavily in endpoint telemetry, attack surface management, threat intelligence, and ever more ornate acronyms, then ignore the fact that one bullying clique can reduce information flow more effectively than many external adversaries. There is nothing sophisticated about any of this; it is simply neglected.
What prevention looks like in the real world
The first mistake organizations make is assuming that a generic anti-harassment policy is enough. It is not. A policy that exists only to satisfy compliance paperwork will be ignored by the people causing the problem and distrusted by the people living through it. Prevention starts when leaders accept that horizontal mobbing can exist in high-performing technical teams and that technical excellence does not neutralize abusive behavior.
Italy’s ratification of ILO Convention No. 190 strengthened the broader framework around violence and harassment in the world of work. Legislation alone will not fix workplace culture any more than a patch management system fixes architecture, but the convention reinforces a principle security organizations should have grasped on their own: harm at work is not limited to spectacular misconduct, and repeated psychological aggression deserves preventive controls before it turns into damage control.
Preventive measures need to be embarrassingly concrete. Reporting channels must be credible, confidential, and separate from the social orbit of the dominant clique. Incident reviews need facilitation rules so they do not degenerate into public blame theatre. Knowledge must be documented and shared in ways that reduce dependency on individual gatekeepers. Workload and on-call patterns should be reviewed because exhausted teams become crueler, not wiser. Managers also need to be evaluated on team health, turnover, and trust, not only on service levels or the number of slide-friendly metrics they can stuff into a quarterly update.
ISO 45003 helps here because it frames psychosocial risks as manageable organizational issues rather than personality defects. That means looking at workload, autonomy, communication, support, role clarity, fairness, and exposure to distressing material. In this context, these are not abstract variables; they affect whether people escalate quickly, admit uncertainty, ask for peer review, or retreat into silence. If the team culture punishes vulnerability, the incident will collect its payment later.
There is also a cultural point that many security leaders would prefer to avoid. Some of the behavior celebrated as “high standards” is simply licensed humiliation. Ruthless code review, performative skepticism, sarcastic debriefs, territorial ownership of tooling, and the ritual destruction of junior staff are often mistaken for rigor. In reality, they show that a team has confused emotional abrasion with quality assurance. That confusion persists because some organizations still admire the difficult genius archetype, despite decades of evidence that difficult geniuses are often just difficult.
Why this deserves more attention now
The timing is not accidental. Teams are being asked to do more with tighter budgets, broader attack surfaces, and a permanently elevated sense of crisis. At the same time, the human cost of the profession is becoming harder to ignore. Burnout is receiving more public attention, including in mainstream coverage such as the BBC piece on cyber burnout, and practitioners are more willing to describe the psychological drag of the work than they were a few years ago. That makes this a good moment to talk about horizontal mobbing without pretending it is separate from resilience.
There is also a strategic reason to write about it now. Many organizations still treat workforce risk as a staffing problem, a hiring pipeline problem, or a skills shortage problem. Those issues are real, but they are not the whole story. Teams also lose people because some environments are internally corrosive, because skilled practitioners tire of informal punishment systems, and because no salary premium can permanently compensate for daily contempt. A field that prides itself on threat modeling should be able to recognize a pattern when the hostile behavior is already occurring inside the perimeter.
The uncomfortable truth is that cybersecurity has spent years refining its language for external threats while remaining embarrassingly primitive in how it describes internal damage between colleagues. Mobbing, straining, burnout, secondary trauma, social exclusion — these are not imported concerns from some distant HR planet but part of the reality of this work. Ignoring them will not make a team tougher, only slower to recognise its own fragility.
FAQ
What is horizontal mobbing among peers?
It is a pattern of hostile, repeated behavior between colleagues of similar rank, such as exclusion, humiliation, technical gatekeeping, or reputational sabotage.
Why is horizontal mobbing especially dangerous in this field?
The work depends on trust, fast information sharing, and calm coordination under pressure, so persistent hostility between peers can directly weaken operational performance.
How can organizations reduce horizontal mobbing among peers?
They need clear reporting channels, leadership accountability, workload reviews, psychosocial risk management, and a culture that does not confuse cruelty with competence.