We live in a digital world and the amount of technology to be secured — not to mention scores and scores of data — continues to grow exponentially.

But the workforce hasn’t kept up: According to ISC2, the industry is short roughly 4 million cybersecurity professionals worldwide.

“We need to fill the pipeline of cybersecurity talent in order to keep up with the pace of technology innovation,” said Maarten Van Horenbeeck, chief security officer at Adobe. “Developing talent requires growing individuals, and growth doesn’t happen overnight, so the best way to improve security outcomes tomorrow is to start building it today.”

Here, Van Horenbeeck shares his advice and Adobe’s internal and external efforts to help address this critical issue and build out cybersecurity capabilities worldwide.

Ensuring a diversity of talent

One important way Adobe infuses its talent pipelines is through partnerships with various universities.Van Horenbeeck’s team helps craft curriculum and has also incorporated cybersecurity-focused internships.

As a result, “we’ve hired a few amazing interns and are excited to see the impact they make,” said Van Horenbeeck.

The company also works with BlackGirlsHack, which helps women of color pursue careers in information security and cybersecurity; this collaboration involves sharing skills training and offering mentorship opportunities.

“There is no way we can do this alone, so we really appreciate working with these fantastic organizations to develop a stronger, more diverse cybersecurity workforce,” said Van Horenbeeck.

How NGO partnerships, rapidly-moving internal projects help advance skills

Another way that existing team members upskill their talent — while performing important work — is through nonprofit work.

For instance, Adobe works with the CyberPeace Institute, which matches team members with nongovernmental organizations (NGOs) to help them become more cyber resilient.

“This allows our cybersecurity professionals at Adobe to further their skills that they can then bring back to their team,” said Van Horenbeeck.

For instance, one senior security engineer from the San Jose office helped an NGO by “delving into the dark web” to identify leaked credentials that, if left unidentified, could be used to compromise their organization.

Another security engineer focusing on incident response in the company’s Romania office worked with an NGO that supports victims of explosive weapons in conflict zones. He not only helped them craft an incident response plan, but sharpened his cybersecurity skills and built out his career.

Internally, too, Adobe is also looking to “get creative” around solving specific security problems, tapping diverse skill sets for such tasks, said Van Horenbeeck.

“Adobe has long been a company that attracts creators of all backgrounds, and within the security team too, we value intrapreneurship,” he said.

For instance, in the last year, the security team has partnered with developers, machine learning (ML) engineers and security compliance professionals to build two artificial intelligence (AI) bots they dubbed Jarvis and Sherlock. These tools aim to reduce “busy work” and help employees understand how to implement security controls and get security work done faster.

“This type of rapid innovation needs a culture that’s built on top of many different views,” said Van Horenbeeck. “A narrow mindset simply doesn’t get you there in time.”

Emphasizing ‘capacity building’

Cybersecurity skills, expertise and tools are not distributed equally, Van Horenbeeck pointed out. However, as we are all interconnected, risks have the potential of accumulating and can have broad ripple effects.

To address this, the concept of “capacity building” is the development and strengthening of the skills, instincts, abilities, processes and resources that organizations and communities need to survive, adapt and thrive in a fast-changing world, he explained.

“In the cyber world, we need to equip individuals and organizations with the knowledge, skills and tools they need to defend themselves online,” said Van Horenbeeck.

Adobe has a “unique role” to play here, he pointed out. Over the years, the company has invested in various cybersecurity approaches and technologies, and does its part to share its experiences in blogs, white papers and conference presentations.

For instance, the company recently published technical research papers on its data analysis platform, and how Adobe manages a large-scale endpoint detection and response (EDR) solution.

“We’re hopeful that these publications will, in part, help others who are going down the same path,” said Van Horenbeeck. “Capacity building isn’t just about providing aid, it’s about building a partnership where both parties have an opportunity to grow.”

Removing ‘gates’ in hiring

In building out their cybersecurity teams, leaders should be thoughtful about the things they really need to hire for and find the best candidates for that role, Van Horenbeeck advised.

Over the years, many hiring managers have become accustomed to looking for the same certification and educational background to identify a candidate as a great “security fit,” he noted.

“In some ways, that means specific certifications, training and programs have become almost ‘gates’ people need to cross into security,” said Van Horenbeeck.

However, some of the most successful people Adobe has hired have been creative thinkers who don’t always have traditional backgrounds, but were able to “take a problem, engage with others, and figure out the best way to solve it.” Recent interns (and ultimate hires) have been successful in tackling a broad set of challenges and rotating between teams.

Other security leaders have reported the same, he noted. A broader set of candidates and “diverse and inclusive” interview panels can create a culture that allows for learning new skills on the job and create better, more effective teams.

Van Horenbeeck pointed out that much of what security teams do is less technical; they are often more involved in convincing people to build secure business processes.

“This requires empathy, communication skills and an understanding of others, more than it requires a four-year engineering degree,” said Van Horenbeeck.

Collaborations help build strong, successful communities

In the security field, nothing is more important than the network you build, Van Horenbeeck asserted.

“Find others who are facing the same issues and collaborate with them, and you’ll grow your own capabilities,” he said.

Sharing concerns with others and learning from each other’s experiences is crucial to building a strong and successful community. As he noted, most significant security incidents don’t just affect one organization “they tend to affect many of us.” In those incidents, your network isn’t just a benefit, “it’s a critical part of being effective at securing products and environments.”

To this end, Adobe has long been a member of the Forum of Incident Response and Security Teams (FIRST), which works to build more effective incident response practices. The company is also involved with the Cloud security alliance (CSA), Women in Cybersecurity (WiCyS) and the Information Technology Information Sharing and Analysis Center (IT-ISAC).

Van Horenbeeck pointed out that “these networks are only as effective as you allow them to be. The more you provide to a community, the more you will get back.”

He and his leadership team continuously sit together and talk about the right ways of partnering with these organizations to improve their own security practices and share what they learn.

Ultimately, “we’re excited to be part of this community and to work together with others to protect the next digital generation,” said Van Horenbeeck.