As the cybersecurity talent shortage has reached nearly 4 million, Immersive Labs CEO and Founder James Hadley argues that the overreliance on industry certifications is widening the gap rather than bridging it.

Certifications, while useful, do not necessarily equate to real-world expertise, which can create a false sense of security for organizations.

“One of the main challenges is that the skills that are required for hands-on cyber roles, there's no easy way of getting those and demonstrating them to be job ready,” Hadley said.

In addition, to excel in cybersecurity in a practical role, professionals should have several attributes or traits, including analytical thinking, problem-solving, troubleshooting, perseverance, curiosity and the ability to self-research.

“The way that you test out is through multiple choice exam, rather than: 'Hey, I need you actually to do this for a threat you haven't seen before or to use analytical thinking and problem-solving.' And it's really hard to prove that and measure it,” he added.

On the recruiting side, organizations today are relying on certifications or degrees for cybersecurity hiring, which may result in rejecting qualified applicants or creating a costly barrier to entry for early-career and diverse security talent.

Certifications don't replace actual skills

“Organizations today are relying on certifications or degrees around cybersecurity, but they're not actually [giving] you the skills you need to be job-ready,” Hadley said.

“There's no easy way for employers to measure or prove knowledge, skills and judgment as it relates to cyber. It's really hard,” he added. “So what they tend to do is mandate a number of years of experience — even for an entry-level role — which means that the funnel is dramatically shortened for entry-level talent.”

Proving rather than claiming cyber skills

To address this, Hadley said organizations shouldn't expect candidates to have a computer science degree, cybersecurity certifications or years of experience; instead, they should take a skills-based approach, identify hidden talent internally and look at different ways to bring in talent through upskilling programs.

For example, U.S. National Cyber Director Harry Coker announced earlier this year that the White House is working to help industry partners fill cyber vacancies on federal contracts by reducing “unnecessary barriers, like requiring four-year degrees, which are leaving out untold numbers of talented professionals.”

“We're starting to see a shift, especially in larger enterprises, where it's moving toward proving skills rather than claiming skills,” Hadley said.

He added that experienced cybersecurity professionals also should prove their skills are up to date based on the latest threat trends because the cybersecurity landscape evolves very fast.

“I think that should be on a six-month or quarterly basis if you're in a hands-on role,” he said. “That's going to be the future for you proving cyber capability within organizations.”

Most popular cybersecurity certifications

There are many popular cybersecurity certifications, including the following:

  • Certified Information Systems Security Professional (CISSP) from (ISC)2
  • Security+ from CompTIA
  • Certified Information Security Manager (CISM) from ISACA
  • Certified Advanced Security Practitioner (CASP+) from CompTIA
  • The Certified Ethical Hacker (CEH) exam

The O’Reilly 2024 Tech Trends report revealed the most popular ones are CISSP and Security+. CISSP is an exam for experienced security professionals, requiring at least five years’ experience before taking the exam. Its content usage declined 4.8% year over year. Security+ is an entry-level exam, which saw the greatest growth in content usage by 5.8%.

CISM focuses on risk assessment, governance, and incident response, which saw a 54% increase in content usage. CASP+ and CEH went up by 10% and 4.1% respectively.

Hadley argues the rapid pace of change in the cybersecurity industry renders many certifications out of date.

“To be good in your job at cyber, you need to say what was happening yesterday [and] today, not what a book was written about three years ago. That isn't going to help you because cyber moves really quickly,” he said. “The idea that you can rely on someone because they passed the multiple choice exam three years ago, that isn't helpful, that doesn't prove that they've got the skills and that interest and hunger that you need to be good in cyber.”

However, Hadley admits some certifications still hold value for professionals in the industry. “I'm not trying to rubbish all sorts of certifications. I think CompTIA has its place where it shows someone has the willingness to try and prove that they have that real basic layer of fundamentals, [such as] networking, operating systems, etc. … Which means they have that fundamental IT and then you need to layer on cybersecurity on top.”

But some certifications from cybersecurity vendors may be designed to help make their products more sticky among the customers, he added.