With attacks growing ever more sophisticated and ramping up by the day, enterprises are warranted in their alarm over the cybersecurity workforce shortage.

By one estimate, the labor pool must grow by a staggering 75% to adequately defend today’s organizations.

This dire situation calls for new methods to pump fresh (and diverse) talent into the industry, experts agree — one method being entry-level certificates, which many organizations are increasingly seeking out or even launching on their own.

“While change is in the air, people still tend to hire or want to hire individuals coming from IT backgrounds — but there simply aren’t enough IT professionals around,” said Clar Rosso, CEO of nonprofit training consortium ISC2, which recently launched a new entry-level certificate program in collaboration with IBM.

“It’s important that we have programs in place that attract people from different types of backgrounds into cybersecurity,” Rossoa said:

A multitude of cybersecurity certifications to address skills gap

In a recent survey by Fortinet, 82% of respondents said their organizations would benefit from cybersecurity certifications, and 90% would pay for an employee to obtain such credentials.

Rosso noted that in the U.S., education is “widely available” and often free.

“There are really a lot of organizations that have jumped on and said ‘We’re willing to help,’” she noted.

ISC2, for one, offers its entry-level Certified in Cybersecurity (CC) training program that has now been earned by 50,000 people. Further, the organization has made a One Million Certified in Cybersecurity pledge to offer free CC online training and exams to a million people.

Other top certification programs include CompTIA Security+, EC-Council’s Certified Ethical Hacker and the Certified Information Systems Auditor (Cybersecurity and Infrastructure Security Agency (CISA)) and Certified Information Security Manager (CISM) certificates from IT professional association ISACA.

Google also offers a free Cybersecurity Professional Certificate and Cisco and the SANS Institute have launched programs that are free of charge. The Fortinet Training Institute is similarly committed to training one million people in cyber by 2026.

“Leaders are turning more and more to certifications to validate individual skills,” Fortinet researchers write. “Well-designed certification programs aim to establish not only technical competencies but also a deeper understanding of how to apply those competencies.”

Teaming up with IBM, Coursera ‘powerhouses’

The new IBM and ISC2 beginner-level Cybersecurity Specialist Professional Certificate is offered in 22 languages and based on content from ISC2’s CC training, which covers five key areas:

  • Security principles
  • Business continuity, disaster recovery and incident response
  • Access controls concepts
  • Network security
  • Security operations

Of CC training feedback, Rosso said, “people like the education and experience. They say it’s hard, but we like it to be hard — it shouldn’t be easy, it should be representative of the difficult side of cyber.”

She pointed out that Coursera has millions of users and IBM hundreds of thousands of employees. It is a big win to team up with such “powerhouses” to “elevate the cyber literacy of all sorts of folks,” she said.

“It’s a big open door to having people from all sorts of backgrounds skill themselves up in the space,” said Rosso, “giving them the opportunity to start a career in cybersecurity that might not otherwise be accessible to them.”

Bias, unnecessarily high requirements diluting cybersec workforce

ISC2 and other industry groups have “forever” tracked the workforce gap, Rosso noted, identifying the biggest deficiencies in cloud security, zero trust and artificial intelligence (AI) and machine learning. It’s a big topic at industry events, she noted, such as last month’s Munich Security Conference.

There are many underlying reasons for the shortage, she said, one of the most significant being bias.

“People bring lots of bias into hiring processes, conscious or unconscious,” said Rosso. Often, if prospects don’t have the same education and experience as managers, they’re less likely to be recruited.

“That is truly the biggest barrier,” she said.

This requires an industry-wide paradigm shift away from technical skills to nontechnical skills such as analytical thinking, professional skepticism, problem-solving abilities, communication and project management experience, creativity and willingness to collaborate.

“The mythology of cybersecurity runs strong that it’s only for technical people,” said Rosso. “It can be a bit of an uphill battle to get people to experiment and explore.”

People who are attracted to cybersecurity often have proclivities toward public service and are committed to lifelong learning, said Rosso.

In the cybersecurity industry, she emphasized “it’s not like you just get a degree and you’re done, you’re constantly learning to evolve as the threat landscape evolves.”

Military veterans, for instance, have the “unique advantage” of having a defense mentality, Fortinet researchers point out. They can quickly learn new skills and more easily transition between roles.

“The industry has much to gain by attracting individuals from this group and building on their existing training and skills — both technical and soft skills,” they emphasize.

‘Right-sizing’ job descriptions

To truly identify the best workers for the job, organizations must “right size their job descriptions,” said Rosso, and ensure they are looking for recruits at the proper levels.

For instance, does a certain entry-level position require a four-year degree? No, Rosso said; many cybersecurity professionals do have degrees, she conceded, but they often earn them after entering the industry.

Similarly, business leaders sometimes require credentials such as ISC2’s Certified Information Systems Security Professional (CISSP) or Systems Security Certified Practitioner (SSCP) certifications. But that’s like asking for a certified public accountant (CPA) designation for someone helping out with the budget in the finance department.

“You don’t need that for an entry-level job,” said Rosso.

Progress being made (in some areas)

The industry is (slowly) reversing the trend, Rosso noted, and the talent pool is increasingly inclusive.

“We’re seeing a number of people coming from much more diverse backgrounds, ethnically, racially, geographically,” she said, adding that those earning certifications also broadly range in age from 20s to 50s (and older).

Still, she lamented, “we haven’t quite cracked the female nut.”

This isn’t because women aren’t entering the industry; rather, they’re often dissuaded after taking on cybersecurity roles because they don’t feel organizational environments are inclusive and there’s no one else like them there to relate to.

Organizations must be aware of this, build cultures where individuals can thrive and provide resources to help new entrants navigate new environments, she said.

“The more diversity you have when you’re trying to solve a problem, the more you’re going to end up with better outcomes,” said Rosso.

It comes down to investing in security workforces and shifting views to security as a “business and strategic imperative” as opposed to a cost center.

Ultimately, “it’s all of us working together that is going to solve this problem,” said Rosso.