Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


02:00 PM
Owanate Bestman
Owanate Bestman
Connect Directly
E-Mail vvv

Is COVID-19 Intensifying the Need for Security Staffing?

Overall, security practitioners should find themselves in a better working situation than many other professionals. However, we are not immune.

A global recession is almost a certainty — the impact on hiring is likely to be devastating, so where does this leave cybersecurity? Let's look at some of the factors that can help us make an educated prediction.

The Current Threat Landscape
Globally, there has been a significant increase in ransomware, fake COVID-19 apps, and targeted phishing scams. The current state of fear and uncertainty provides an ideal breeding ground for those with malicious intent. Working from home has become the new norm and an attractive proposition for opportunists. We have seen targeted hacking campaigns aimed at specific industries in both the public and private sectors, in turn leading to increased ransomware — in some cases, a 4,000% increase, as cited in the Canadian press.

Industry Alignment
Surprisingly, some industries are seeing growth while others are struggling, and their survival is questionable. Registered jobs on LinkedIn grew 6.9% year-on-year within the logistics and transportation sector. We have also seen growth in technology firms (hardware and networking) as well as healthcare. The list of industries suffering is vast and includes aviation, car manufacturing, and hospitality/events services.

Overall, security practitioners find themselves in a better working situation than many other professionals; however, we are not immune. Security is often industry-aligned, and as one CISO told me after his funding was slashed as a result of COVID-19, "Owanate, what's the point of spending on staffing security, if, in the end, we have nothing to secure?" This serves as a bleak reminder that the journey of a cybersecurity professional in the commercial aviation sector is far removed from a security professional in the healthcare sector. One size does not fit all.

Consultancies and managed service providers that have the versatility to change their industry sector may be best served to align with growth industries that are likely to increase hiring to fulfil demand.

Legislation & GDPR Governance
Companies are still obliged to meet regulatory and legislative requirements. However, for now, we have seen a more relaxed approach from the UK's Information Commissioner's Office (ICO) in line with GDPR regulations, which states: We won't penalize organizations that we know need to prioritize other areas or adapt their usual approach during this extraordinary period. "The ICO has even deferred fines for incidents that occurred in 2018: £183 million for British Airways and £99 million for Marriott International. Furthermore, we expect to see privacy laws in proposals around facial recognition, COVID-19 tracking apps, and other controversial initiatives relaxed. Additionally, a significant percentage of security hiring during 2018 and 2019 was in response to GDPR legislation, so it is logical to suspect that firms may take their foot off the gas, demoting data protection compliance in the knowledge that the authorizing body will take a more relaxed approach. 

Overall, I have seen relatively little uptake of furloughing staff within security. With cybercrime more profitable than the global illegal drug trade, firms have an incentive to pay accordingly for the best talent. Many governments are issuing caps on furlough pay. In most cases, the furlough cap would not come close to the salary levels for midlevel to senior security professionals.

  • UK: 80% of regular salary up to a monthly cap of £2,500 (US$3,113)
  • Denmark: 75% of regular salary up to a monthly cap of 23,00 Kr (US$3,368)
  • Australia: AUD$3,000 per four weeks (USD$1,925)

Cybersecurity Staffing Futures
Firms are facing demands to respond to the significantly increased threat landscape. There is also the ongoing obligation to meet industry standards and legislation, even with a relaxed GDPR approach. This increased pressure on security, as well as risk management departments, is likely to translate into an industry-aligned increase in head count. To enable firms to provide a rapid response, additional head count will take the form of contractors and consultants. Executives will expect a swift return on investment and are likely to turn to "hired guns" to fight the initial fires and implement new frameworks and policies where appropriate. They are also likely to prioritize this over hiring permanent personnel, particularly struggling firms that are still bombarded with threats. 

Professional businesses at this time must work remotely, for good reason. While not without its challenges, remote working is nothing new for cybersecurity professionals and policies are in place. However, even the staunchest business continuity policies are stress-tested at this time. In addition, you should expect more funding and emphasis on business continuity and operational resilience moving forward.

COVID-19 will prove a catalyst for those firms that have not implemented or formed a digital transformation initiative. This cannot be accomplished without cybersecurity staff — expect gradual growth in this area. A whole essay could be written on this topic alone. We can also assume that the need for robust, flexible, and efficient security protocols will be greater than ever. The current climate of confusion, uncertainty, and fear will continue to provide a breeding ground for exploiters. Hence, at a time when cost-cutting seems a prudent and logical step, prudence must be weighed against the risk associated with underfunding security. 

The bad news: I foresee a stagnation in security hiring for the time being. But with the ever-growing need to protect assets, the commercial requirement to move to digital and the increasing need for operational resilience, a rise in cybersecurity hiring is surely inevitable. 

Related Content:

A listing of free products and services compiled for Dark Reading by Omdia analysts to help meet the challenges of COVID-19. 

Owanate is a global recruiter who specializes in cybersecurity.  He is the founder of Bestman Solutions where he advises CISO's, security leaders and human resource departments on market trends and a variety of factors that may affect their hiring requirements.  ... View Full Bio

Recommended Reading:

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/25/2020
Hacking Yourself: Marie Moe and Pacemaker Security
Gary McGraw Ph.D., Co-founder Berryville Institute of Machine Learning,  9/21/2020
Startup Aims to Map and Track All the IT and Security Things
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/22/2020
Register for Dark Reading Newsletters
White Papers
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2020-09-25
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, when determining the common dimension size of two tensors, TFLite uses a `DCHECK` which is no-op outside of debug compilation modes. Since the function always returns the dimension of the first tensor, malicious attackers can ...
PUBLISHED: 2020-09-25
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, a crafted TFLite model can force a node to have as input a tensor backed by a `nullptr` buffer. This can be achieved by changing a buffer index in the flatbuffer serialization to convert a read-only tensor to a read-write one....
PUBLISHED: 2020-09-25
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, if a TFLite saved model uses the same tensor as both input and output of an operator, then, depending on the operator, we can observe a segmentation fault or just memory corruption. We have patched the issue in d58c96946b and ...
PUBLISHED: 2020-09-25
In TensorFlow Lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, saved models in the flatbuffer format use a double indexing scheme: a model has a set of subgraphs, each subgraph has a set of operators and each operator has a set of input/output tensors. The flatbuffer format uses indices f...
PUBLISHED: 2020-09-25
In TensorFlow Lite before versions 2.2.1 and 2.3.1, models using segment sum can trigger writes outside of bounds of heap allocated buffers by inserting negative elements in the segment ids tensor. Users having access to `segment_ids_data` can alter `output_index` and then write to outside of `outpu...