Ninety Percent of Security Leaders Warn of Skills Shortage
Most IT security decision-makers are struggling to recruit workers to address a shortage of skilled professionals, despite business backing to do so, according to new research.
Global cybersecurity recruitment firm Stott and May teamed up with venture investor Forgepoint Capital to compile the Cyber Security in Focus study. It features responses from cybersecurity directors, security operations directors and VPs of product security in EMEA and North America.
Some 87% of respondents admitted they are suffering skills shortages, with over a third (35%) claiming positions were left unfilled after a 12-week period.
As a result, in-house skills (43%) were cited as the most significant barrier to strategy execution, above budget (35%), technology (13%) and board-level buy-in (9%).
The challenges around hiring have also led to a surge in salaries: 54% of hiring managers believe that these have increased more than 11% year on year in the sector.
The study also highlighted something of a contradiction. Security is gaining board-level buy-in. Some 80% of security leaders said their business perceives the function as a “strategic priority,” up from 54% last year. In addition, 100% agree that the business feels the function plays a role in improving the overall value proposition to customers.
However, over half (51%) of respondents argued that cybersecurity investment is still not keeping pace with digital transformation.
As investments in digital increase, sourcing the right engineering-centric CISOs will be the key to success, according to Forgepoint Capital managing director William Lin.
“A lot of digital transformation is inherently going to be driven by engineering, and finding a CISO that can empower developers with knowledge, tooling and experience will enable outcomes to be achieved faster and more securely,” he argued.
Heather Paunet, SVP at Untangle, argued that closing the cyber skills gap will require the industry to promote itself to would-be recruits better.
“There also needs to be organizational change that recognizes the severity and devastation cyber-attacks can cause and makes cybersecurity a priority. Companies need to ensure this investment isn’t just in technology, but also in their current workforce with continual training, advancement opportunities and recognition,” she added.
“In addition, IT education programs need to do the profession justice and emphasize the different roles and careers available in cybersecurity.”
According to the latest ISC2 survey, global skills shortages fell for the second consecutive year in 2021 to 2.7 million, including a shortfall of 377,000 in the US and 33,000 in the UK.
More Stories
New MacStealer Targets Catalina, Newer MacOS Versions
The malware can extract information from documents, browser cookies and login information Read More
Can zero trust be saved?
Graham Cluley Security News is sponsored this week by the folks at Kolide. Thanks to the great team there for...
Part of Twitter source code leaked on GitHub
Part of Twitter’s source code has been leaked and posted on GitHub by an unknown user. GitHub took down the...
Hacks at Pwn2Own Vancouver 2023
An impressive array of hacks were demonstrated at the first day of the Pwn2Own conference in Vancouver: On the first...
France bans TikTok, all social media apps from government devices
The French government has banned TikTok and all other “recreational apps” from phones issued to its employees. The Minister of...
How often should security audits be?
The content of this post is solely the responsibility of the author. AT&T does not adopt or endorse any of...