Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Careers & People

2/24/2016
10:30 AM
Joshua Goldfarb
Joshua Goldfarb
Commentary
Connect Directly
Twitter
RSS
E-Mail vvv
50%
50%

Public Vs. Private: Is A Prestigious Infosec College Degree Worth It?

Today's graduates coming into the information security industry from private universities aren't ready for the workforce.

I’m a big believer in taking security lessons from the analog world, including advice from someone many might consider the most unlikely of people – American rapper Eminem.  Eminem can teach us a lot about information security, especially with respect to the security leaders of tomorrow.

Consider “Lose Yourself,” Eminen’s hit song about taking advantage of the moment:

 Look, if you had, one shot, or one opportunity

To seize everything you ever wanted. In one moment

Would you capture it, or just let it slip?

What does that have to do with educating information security professionals? During the course of my travels, I regularly receive two pieces of feedback related to staffing and talent: It is difficult to find people with the right skills to fill open positions; and, there is more work to do than the number of positions we have to fill.

People, including me, often address the second point through solutions like automation, orchestration, improved workflow and operational efficiency.  I’ve written a fair bit on a number of these topics in the past, as have several others in the field. But it’s far more difficult to solve the cybersecurity skills gap problem.

Sure, I hear a lot of talk about the lack of skilled security professionals. But as for how to address this challenge?  That is something that is almost never discussed.  Perhaps we feel helpless or merely accept it as an unchangeable fact. One way to approach this issue is to “grow” our own.  By that I mean looking for analytical people, providing them the opportunity to gain experience on the job, and turning them into security professionals over a period of time. 

A better way

It seems obvious to me that if we are looking for the next generation of security professionals and security leaders, we should be looking at universities. After all, universities are where young people go to learn the skills that will carry them through their adult professional lives.  Unfortunately, many universities disagree with me on that. 

Let me elaborate by sharing a story. From time to time, university students reach out to me to ask a few questions or discuss a few information security-related issues. I’m always happy to speak with them, as I see it as a great way to try and encourage young people to pursue a career in our field.

Recently, a student at a prestigious private university approached me with this type of request.  The student was looking to perform research for his thesis on current challenges and future directions in information security. The student seemed to be intelligent, well-mannered, and an astute listener. Unfortunately, it was evident from our discussion that this prestigious private university had not prepared the student with any practical exposure to information security involving real-world scenarios and operational problems. 

Something as simple as spending a few hours or days with information security professionals on the job could bring students such relevant experiences.  And what about actively integrating such experiences into the academic curriculum to give students a more focused base from which to invest their creative energies.

Public v. private

Contrast this to public universities that I’ve had the privilege to work with as an advisor and/or speaker, such as University of Colorado Boulder and the University of Maryland. Visits to those universities and discussions with students show that the education they are receiving around information security is far more practical and applicable to the world in which we live.  It’s no surprise that this is the case. Industry experts are consulted regarding the curriculum, experienced practitioners are often invited to speak or meet with students, and classroom and lab environments contain real-world assignments and equipment.

Private universities will tell you that they need to stay true to their research focus, and that they need to be able to recruit faculty fitting to such a prestigious institution. I certainly get an earful of messaging along those lines from my alma mater. That may very well be the case, but allow me to ask a simple question. If a university is going to take $250,000 from hard working families, shouldn’t it produce information security graduates qualified for the positions of today and the leadership roles of tomorrow?  I think most of us in the profession would agree that we need universities to help us out a bit more in that endeavor.  The graduates we’re getting today, particularly from private universities, aren’t ready for the workforce.

Let’s take another look at Eminem’s lyrics in this context. Universities have one shot. One opportunity. One moment. The experience a young person has at university and the skills he or she learns will shape his or her entire adult professional life. If I were a university looking to educate the information security leaders of tomorrow, I would ask myself one question: Will we capture the opportunity, or just let it slip?

More on this topic:

Interop 2016 Las VegasFind out more about security threats at Interop 2016, May 2-6, at the Mandalay Bay Convention Center, Las Vegas. Register today and receive an early bird discount of $200.

Josh (Twitter: @ananalytical) is an experienced information security leader who works with enterprises to mature and improve their enterprise security programs.  Previously, Josh served as VP, CTO - Emerging Technologies at FireEye and as Chief Security Officer for ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
dfunk1
50%
50%
dfunk1,
User Rank: Strategist
2/25/2016 | 9:25:53 AM
Public Vs. Private
I think that, perhaps counter-intuitively, that there is a lot more competition for the dollars with the Public schools than the Private.  With the Private schools, the students go for the name, and mom and dad pay.  With the Public schools, a significant slice of the student population is paying their own way (either their own money, or hard-earned benifits from work), are doing the school after work, and they are VERY interested in results, and they have a better idea of how the work world works than the average High School senior.  Those students have very high expectations, and will leave in a second if they are not being met.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
2/24/2016 | 11:04:11 PM
public vs private
I'm sure, as with most cases, it depends on the specific public or private universities, but the point is well taken; a quality information-security education (or other education, for that matter) can easily be had for pennies on the dollar from a public university.

Or for free from a private university via edX, for that matter (as long as you don't care about the degree).
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/13/2020
Omdia Research Launches Page on Dark Reading
Tim Wilson, Editor in Chief, Dark Reading 7/9/2020
Russian Cyber Gang 'Cosmic Lynx' Focuses on Email Fraud
Kelly Sheridan, Staff Editor, Dark Reading,  7/7/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-19338
PUBLISHED: 2020-07-13
A flaw was found in the fix for CVE-2019-11135, in the Linux upstream kernel versions before 5.5 where, the way Intel CPUs handle speculative execution of instructions when a TSX Asynchronous Abort (TAA) error occurs. When a guest is running on a host CPU affected by the TAA flaw (TAA_NO=0), but is ...
CVE-2020-11749
PUBLISHED: 2020-07-13
Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. A network administrator scanning a SNMP device can trigger a Cross Site Scripting (XSS), which can run arbitrary code to allow Remote Code Execution as root or apache2.
CVE-2020-5766
PUBLISHED: 2020-07-13
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in SRS Simple Hits Counter Plugin for WordPress 1.0.3 and 1.0.4 allows a remote, unauthenticated attacker to determine the value of database fields.
CVE-2020-15689
PUBLISHED: 2020-07-13
Appweb before 7.2.2 and 8.x before 8.1.0, when built with CGI support, mishandles an HTTP request with a Range header that lacks an exact range. This may result in a NULL pointer dereference and cause a denial of service.
CVE-2019-4591
PUBLISHED: 2020-07-13
IBM Maximo Asset Management 7.6.0 and 7.6.1 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force ID: 167451.