Whether the chief culprit is the skills gap, burnout, recruiting issues, or a dynamic duo of those shortcomings, there's no shortage of the perils threatening the cybersecurity industry. When it comes to solutions, Immersive Labs' Director of Human Science Bec McKeown is taking a brainy approach by looking at the psychological demands of cybersecurity and how to build up a workforce that is equipped to endure.  

McKeown sat down with SDxCentral to break apart the exigent stresses on the cybersecurity workforce — and what the remedies might look like.

With an applied psychology background in high-stress fields — including the rail industry, aviation, and at the Ministry of Defense — McKeown’s experience shed a unique light on how to understand the brain’s behavior and how to start regaining control during a crisis such as a cybersecurity breach. “But it’s not easy,” she disclaimed.

Coping With Pressure

The Covid-19 Pandemic was taxing on all, but McKeown stressed how heavily it hit the Cybersecurity sector.

“I think people in cybersecurity probably felt it as much as people who worked in the health services,” she said. “[I]t was not just an emergency that happened over a couple of hours, days, weeks, months — it was a couple of years… And after two years of that level of pressure, how could anybody survive that?”   

McKeown’s approach to coping with that pressure boils down to the development of critical reflective practices in psychological resilience and cognitive agility. 

In reflecting on crisis events, McKeown clarified it wasn’t just the event and how the workers responded, but what happened just before the event, referred to as “Left of Bang” in military settings. Understanding this window is essential in advancing resilience.
 
To understand the psychology of resiliency, McKeown cited the four allied integrants of The Robertson Cooper Model:  

First comes purposefulness — developing the ability to change with growth-oriented self-awareness is key.  

Another pillar, social support, is shaped by building trusted relationships through rehearsals in a calm environment, rather than under pressure. “If there is some sort of threat to the organization or there's a big job that's going to take a lot of resources, both in terms of time and intensity, you will come through that so much better because you've got that trust and you're in that understanding,” McKeown said.

The model also holds confidence as a tenet — growing self-efficacy through a positive and realistic view of an individual’s own abilities and contributions.

Fourth and finally is adaptability — the capacity to switch focus and detect underlying patterns across time and scenarios for solutions. Adaptability can also be understood as cognitive agility, which she broke down into categories: flexibility — challenging the automatic response triggered in crisis with dimensional views, such as factoring business risk over simple technical goals; openness — being receptive to diverse perspectives to actively adapt to better solutions; and focus — identifying and focusing on what relevant information is essential for the solution.

Training this agility must be an interactive part of the day’s work, not sent to employees “on PowerPoint courses,” McKeown noted. “That isn’t how people learn best.” 

Study Shows… 

Immersive Labs' Cyber Workforce Benchmark Report (CWB) detailed a research-led comprehension of global cyber information, skills, and judgment. McKeown broke down some of the report’s key findings:

Developing cyber skills takes months, not days. "Cybersecurity teams inside large organizations take, on average, 96 days to develop the skills necessary to defend against breaking cyber threats," she explained. "One particular breaking threat took more than six months — 204 days — to master, on average."

Cybersecurity teams are also slower to develop than application security teams. “Seventy-eight percent of all application security skills are developed faster than the expected completion time as opposed to just 11% of cybersecurity labs,” McKeown explained. “The average application security lab is completed 2.5 minutes under the expected complete time — whereas the average time to complete cybersecurity labs is 17 minutes over.” McKeown noted this highlights the much-needed strategic alignment between AppSec and security teams to keep organizations secure.

Another finding: critical sectors are often left exposed. “Infrastructure and transport are the two slowest sectors to master the necessary cyber skills,” taking an average of 137 days, while government organizations do well in arming security teams with necessary skills — “a key federal initiative over the past year,” she added.

McKeown also shared that high-profile vulnerabilities see a significantly decreased time to capability. “The increase in sophisticated threats like Log4j is forcing organizations to find ways to ramp up skills faster and more efficiently, but unfortunately, a large gap still exists today.”

And finally, when it comes to determining the best defense against ransomware, people don’t always agree. In fact, “83% of [the study’s] participants chose not to pay the ransom” in a crisis scenario. 

“Eighteen percent of government crisis response teams paid the ransom, despite official guidance in most countries stating not to,” she explained. “The education around ransomware attacks — including how to recover and move forward — is critical to prevent further destruction across industries.”

The Road Ahead

Following her work on the company’s Crisis Simulator project, McKeown is now focused on how to fill cultural gaps and move away from the discussion just being about cybersecurity skills, “because it isn’t about that,” she explains. 

McKeown stressed that supporting initiatives of wellbeing to build resilience in the tech, processes, and people is the chief effort organizations can make to turn around the struggling labor market. 

“There seems to be a bit of a delta between what skills people have when they come out of university courses and what skills that they actually need in real life,” McKeown said, “and that delta seems to be mostly about soft skills.” 

“So how do you actually work in an organization? How do you work as a team?” These questions will continue to drive McKeown’s work in strengthening cybersecurity’s human-driven responses to the industry’s increasing challenges.