We need to believe the data here. It's human nature to want most what we don't have. These numbers say loud and clear: My organization doesn't value my opinion and doesn't recognize when I'm doing my job well, so it can keep innovation. I just want a job that I can actually do and that occasionally lets me go home and spend some time with my family.
Security pros are putting in long hours defending the company's interests as best they can, just as business leaders are making dangerous decisions against (or without) the advice of security managers. Smart CIOs will facilitate a discussion about resetting risk management expectations as business gets on a better footing. Business practices that trade information security for short-term profits are the sort that come back to bite hard, and form an abject lesson for the need to constantly align business priorities and IT realities.