The widening talent gap in cybersecurity has been long lamented. Still, it remains unsolved — and it’s only getting worse.
While there are an estimated 4.7 million global cybersecurity professionals (not surprisingly, the highest number ever) the industry is short roughly 3.4 million workers. Right now in the U.S. alone, there are more than 663,000 open cybersecurity positions.
But why? Legacy practices, tight budgets, close-mindedness, lack of diversity, cybersecurity as an afterthought — all are factors contributing to the problem, experts say.
“It’s on the market itself, companies being out of touch, unrealistic,” said Jeremy Ventura, director of security strategy and field CISO at automated threat protection company ThreatX.
Federal action on cybersecurityTalent is at a premium at a time when the average cost of a data breach in the U.S. sits at $4.5 million, according to IBM’s latest research. Furthermore, Fortinet reports that 80% of organizations suffered one or more breaches that they could attribute to a lack of cybersecurity skills or awareness.
Concern around the shortage has reached the White House, which just this week released a National Cyber Workforce and Education Strategy. The federal plan consists of four pillars:
- Equip every American with foundational cyber skills
- Transform cyber education
- Expand and enhance America’s cyber workforce
- Strengthen the federal cyber workforce
In implementing the plan, the Office of the National Cyber Director will explore establishing a standing advisory committee and periodic summits. It plans on taking a data-driven approach to identify gaps, develop performance measures and regularly communicate progress to stakeholders, and use data to assess progress toward goals. The administration said it will also work with Congress to prioritize cyber workforce and education activities.
“At this important inflection point in our country’s history, building a workforce that fuels the prosperous economy that Americans deserve while advancing the security interests of the country will require targeted investments by government at all levels, industry, academia and nonprofit institutions,” the strategy document concludes.
But why is there a talent shortage?There’s no one simple answer as to the why, experts say. As with anything, there is a confluence of factors at work.
To start, Ventura noted, it can be an intimidating field to get into, with enterprises demanding advanced skills and arbitrary years of experience — referred to by some as “legacy hiring criteria” — that can put off and reject young professionals, forcing them to pursue other careers or avenues.
Indeed, studies have found that young workers have concerns about cultural divides between junior and senior employees, citing a “gatekeeping” culture that limits opportunity and advancement. (“Gatekeeping” meaning artificial or unnecessary barriers such as requirements for education, certifications or certain skills.)
Similarly, many point to the “good old boy” mentality — enterprises may say they have diversity, equity and inclusion (DEI) programs, but don't have great track records in actually attracting diverse talent.
Furthermore, organizations with the greatest staffing shortages do not prioritize cybersecurity or budgeting for the department, don't offer competitive wages and don’t sufficiently train staff or offer opportunities for advancement.
As a result, overburdened cybersecurity teams don’t have enough time for proper risk assessment and management and are slow to patch critical systems; the issue also leads to oversights in processes and procedures and misconfigured systems.
Furthermore, chief information security officers (CISOs) are overly stressed and increasingly abandoning the profession. BlackFog research found that nearly one-third (32%) of CISOs and cybersecurity leaders in the U.S. and UK were considering quitting their current roles due to a lack of work-life balance, too much time spent “firefighting” rather than strategizing and the struggle to keep up their team’s skills.
Mentorship is criticalAnother critical factor: An overall lack of mentorship. Enterprises leaders globally must be proactive in offering fellowship programs, co-ops, internships, scholarships and free training (as conferences can be expensive, to the tune of thousands of dollars), Ventura said. They should also consider partnering with local communities and national organizations such as Girls Who Code.
“Businesses need to absolutely take an intuitive, not just sponsor but partnership, it’s only going to help the entire industry,” he said.
At the same time — and no matter where they are in their careers — all cybersecurity professionals should proactively serve as mentors, while also being mentees themselves.
“No one’s perfect,” said Ventura. “No matter where you are in life, having mentors and being a mentor is extremely important.”
Opening doors to bolster cybersecurityStressing the DEI piece, Ventura said that enterprises should not only look to diversify hiring, but provide programming and events and internally safe spaces — such as a Slack community — for minorities or LGBTQ+ individuals and their allies.
“That plus is important — allyships,” Ventura said. “Mentorship, allyship, diversity and inclusion is super important.”
Ageism is a critical point to address, too. Many talk and ask about breaking into security as a young professional, but what about those mid- or late-career professionals? Experienced professionals can bring much to the table, but ageism exists across the board, and it’s something that “as an industry we don’t talk about enough, for sure,” Ventura said.
By contrast, “you know what group will actually accept people? The hacker community,” he said, calling it “amazing” that ransomware groups are better at attracting talent than corporate companies and those of “all walks of life, all around the world.”
The industry must open doors and respect people of all different backgrounds. Because “the more diverse we are as an industry, the better off we’re going to be.”
Cybersecurity talent in unexpected areasOrganizations should also consider upskilling existing employees from departments outside security, or looking to candidates without traditional technical training.
Ryan Kovar, leader of Splunk’s security research team SURGe, suggested recruiting individuals in liberal arts programs. They can be great candidates because they tend to have strong critical thinking skills and are often “quick studies.” When given general cybersecurity subject knowledge — via generative artificial intelligence tools, for example — they can be “let loose on a problem,” he said.
The same can be said of military veterans, who are already of a defense mentality and quick to adapt.
As a case in point, Kovar pointed to a recent five-day course held by the Alperovitch Institute that taught a group of so-called nontechnical professionals the core concepts of reverse engineering in malware with “ChatGPT as a little study buddy.”
“I’m a huge advocate of looking at unusual places for cybersecurity talent,” he said.
Be hungry in a fast-paced landscapeVentura himself didn’t start out on a cybersecurity career path — he explained that he intended to go into law enforcement. But while in his junior year as an undergrad, he had an opportunity to work in the cybersecurity department at Raytheon. The role piqued his interest and he pivoted, eventually earning a Master’s Degree in cybersecurity and homeland security.
“I always thought it was a really smart, intellectual field — which it is — but I thought you had to be a hacker or a coder,” he said. “There are so many different opportunities and career fields in the cybersecurity realm.”
This can include, for instance: account management, consulting, sales, marketing or customer support.
For those seeking a career in the field, Ventura advises, “network, network, network.” Get into cybersecurity communities, ask questions, share opinions, have a voice.
“It’s not who you know,” he emphasized. “It’s who knows you.”
He ultimately underscored three important traits (which could really apply to any candidate, no matter the industry): “Hungry, humble and smart.”
If you’re hungry, you’re enthusiastic, keeping up with news and trends. If you’re humble, you’re willing to learn and think outside the box. And, being smart means having the ability to problem solve, translate technical jargon, do technical writing and work authoritatively.
In the end, cybersecurity is fast-paced and never boring, Ventura said. “I hate and love when people ask me ‘Where do you see yourself in five years?’’’ he said. “In cybersecurity, you can't really answer where you’ll be in five years. Security is changing so fast.”
Comments