Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Operational Security

11/13/2017
02:00 PM
Curtis Franklin
Curtis Franklin
Curt Franklin
50%
50%

Cybersecurity Skills Gap Hits Across the Board

The massive shortfall in cybersecurity professionals is having an impact on organizations of all types and sizes.

One of the major threats to IT security is a shortage of skilled professionals. That's the word from pretty much everyone in the industry and it's a threat that is having an impact on organizations of all sizes and descriptions.

The shortage has been documented in numerous studies such as the recent survey commissioned by TripWire and conducted by Dimensional Research. The 2017 Skills Gap Survey indicated that 93% of IT security executives are worried about the skills gap, with more than 40% saying that their organization is already facing a skills gap in meeting security needs.

Issues in meeting cybersecurity personnel needs aren't restricted to private enterprise, either. At a recent cybersecurity summit, Rob Joyce, White House cybersecurity coordinater, said that many top cybersecurity positions remain unfilled more than a year after the last election. In an article on the Defense One web site, Joseph Marks reported Joyce saying that these are not positions being left intentionally unfilled, but rather positions that haven't been filled because of a lack of qualified applicants.

In another recent survey, this one conducted by the Information Systems Security Association (ISSA) and Enterprise Strategy Group (ESG), 70% of industry professionals responded that a cybersecurity skills shortage is having an impact on their organization.

 

In "The Life and Times of Cyber Security Professionals," ISSA and ESG report that a lack of adequate cybersecurity staff is seen as the number two factor contributing to the rise in successful attacks on data, following only the lack of adequate training for non-technical employees (which leaves the non-technical staff much more likely to succumb to social-engineering attacks such as phishing).

It must be noted that the story of a cybersecurity skills shortage is not one that is univerally told. Around this time last year Angela Bailey, chief human capital officer the the Department of Homeland Security wrote a blog post in which she said that DHS was having no trouble finding a wealth of qualified candidates for its vacancies. If true, this places DHS in a near-unique position among hiring organizations, making the advice on hiring Bailey offers in her blog post exceptionally valuable.

Much more common are reports and white papers from companies like McAfee offering advice on hacking the skills shortage. Advice on dealing with the shortage range from outsourcing to increasing reliance on automation in security to an aggressive approach to diversifying the cybersecurity work force.

All of these seem worthwhile responses but until a rising tide of qualified cybersecurity professionals lift capabilities across the industry the one thing that seems quite obvious is that CISOs and security managers need to try all of these -- and more -- to mitigate the impact too-few analysts and technicians will have on their organization's security.

Related posts:

— Curtis Franklin is the editor of SecurityNow.com. Follow him on Twitter @kg4gwa.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/3/2020
Pen Testers Who Got Arrested Doing Their Jobs Tell All
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/5/2020
New 'Nanodegree' Program Provides Hands-On Cybersecurity Training
Nicole Ferraro, Contributing Writer,  8/3/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-15820
PUBLISHED: 2020-08-08
In JetBrains YouTrack before 2020.2.6881, the markdown parser could disclose hidden file existence.
CVE-2020-15821
PUBLISHED: 2020-08-08
In JetBrains YouTrack before 2020.2.6881, a user without permission is able to create an article draft.
CVE-2020-15823
PUBLISHED: 2020-08-08
JetBrains YouTrack before 2020.2.8873 is vulnerable to SSRF in the Workflow component.
CVE-2020-15824
PUBLISHED: 2020-08-08
In JetBrains Kotlin before 1.4.0, there is a script-cache privilege escalation vulnerability due to kotlin-main-kts cached scripts in the system temp directory, which is shared by all users by default.
CVE-2020-15825
PUBLISHED: 2020-08-08
In JetBrains TeamCity before 2020.1, users with the Modify Group permission can elevate other users' privileges.