Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

7/27/2016
08:38 AM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Cybersecurity Skills Shortage Puts Organizations At Risk, Study Shows

The oft-discussed and lamented cybersecurity skills gap isn't just a hiring issue, it's putting your organization at risk, Intel Security-CSIS study finds.

A report published today by Intel Security in partnership with the Center for Strategic and International Studies (CSIS) confirms the perceived cybersecurity skills shortage and the real risk that poses for organizations. 

The study, which surveyed eight countries -- Australia, France, Germany, Israel, Japan, Mexico, the United Kingdom (UK), and the United States (US) -- found that respondents overwhelmingly reported that a cybersecurity skills shortage does exist in their organizations (82%). 

What’s disconcerting about this study, says Candace Worley, vice president and general manager for enterprise endpoint security at Intel, is that respondents reported that “the lack of enough cybersecurity staff is contributing to security risk in their organization.” This should be a concern for all of us, she warns. 

Seventy-one percent of respondents said that this shortage in cybersecurity skills does direct and measurable damage: 25% lost proprietary data through cyberattacks, 33% say they are a target for hackers because of weak cybersecurity defenses, and 22% say they’ve suffered reputation damage due to the workforce shortage. 

Black Hat USA returns to the fabulous Mandalay Bay in Las Vegas, Nevada July 30 through Aug. 4, 2016. Click for information on the conference schedule and to register.

While governments have begun to take an increased interest in cybersecurity -- the US President’s Budget for fiscal year 2017 proposes $19 billion in Federal resources for cybersecurity -- 76% of respondents still feel that their governments aren’t investing enough in building cybersecurity talent.    

The study revealed that part of the skills shortage can be pinned on the gap between available cybersecurity education and the minimum credentials required for entry-level positions. Four in 10 respondents said that a bachelor’s degree would be required from job applicants seeking an entry-level cybersecurity position, and 38% of respondents from France and 32% from Germany said they’d require a master’s degree as their minimum credential. The researchers of this study found that only 7% of top universities in the countries researched offer undergraduate studies (major or minor) in cybersecurity. 

And while considered a requirement to apply, a bachelor’s degree in a technical field isn’t viewed as effective for acquiring cybersecurity skills as hands-on experience (such as internships or hack-a-thons) or professional certifications. 

Worley says that it’s important to drive excitement about cybersecurity in high school students, but that even if that education began today, “at best, those folks would be coming out of college in one to two, to three years. We’re going to have a talent shortage in the next three years and we need to make sure that it’s not a systemic issue.” 

In order to prevent that, Worley says closing the security skills gap is a challenge for all invested parties.

“This is putting pressure on government and organizations and companies that have security practices and vendors in this field to come together and address this as a community,” she says. In the interim, organizations should asses their risk tolerance and automate and outsource what they can to take the pressure off in-house teams, she says.

This buys some time to tackle the bigger, more complex projects, she says, like intrusion detection, secure software development, and attack mitigation, which were listed as the scarcest cybersecurity skills in the report

While building the cybersecurity workforce is not an easy challenge, Worley says, “We’re at a point now where we as a community, we win as an industry if we solve it.”

Related Content:

Emily Johnson is the digital content editor for InformationWeek. Prior to this role, Emily worked within UBM America's technology group as an associate editor on their content marketing team. Emily started her career at UBM in 2011 and spent four and a half years in content ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
mmccul
50%
50%
mmccul,
User Rank: Apprentice
7/27/2016 | 8:01:33 PM
Point missed in article
As a professional who has interviewed candidates for jobs in information security at multiple levels, I feel qualified to comment on the issues of finding good candidates.  There are multiple low level positions with very minimal requirements, but these positions (such as members of a SOC) are often ignored by these surveys, even though they often require extremely minimal background and provide a solid foundation in the field.  To say that such positions do not exist is to play the ostrich game.

The real problem I see is lack of training of management of what a professional in the field needs to be effective.  I often get unreasonable requests for job responsibilities from the manager; demands for skills not required as well as ignoring critical skills that the manager does not themselves posses and does not realize how crucial they are.  

A great way to improve the information security status of an organization would be to improve the low and mid-level management of such teams.  It would also help if organizations stopped focusing on the wrong problem.  A defensive expert is not a penetration tester, nor are they useful on my team.  As one coworker of mine phrased it, a pen tester knows one trick really well and they keep applying it across lots of applications, lots of systems until it works.  A defensive expert has to address every application, every threat, every system to ensure that the risks are identified, mitigated and addressed:  they have to have something in every column.  

 
Mobile Banking Malware Up 50% in First Half of 2019
Kelly Sheridan, Staff Editor, Dark Reading,  1/17/2020
7 Tips for Infosec Pros Considering A Lateral Career Move
Kelly Sheridan, Staff Editor, Dark Reading,  1/21/2020
For Mismanaged SOCs, The Price Is Not Right
Kelly Sheridan, Staff Editor, Dark Reading,  1/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: I've never actually seen the corporate ladder before.
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
How Enterprises are Attacking the Cybersecurity Problem
How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-18898
PUBLISHED: 2020-01-23
UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers escalate privileges from user tss to root. This issue affects: SUSE SUSE Linux Enterprise Server 15 SP1 trousers versions prior to 0.3.14...
CVE-2019-19837
PUBLISHED: 2020-01-23
Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote information disclosure of bin/web.conf via HTTP requests.
CVE-2020-7210
PUBLISHED: 2020-01-23
Umbraco CMS 8.2.2 allows CSRF to enable/disable or delete user accounts.
CVE-2019-19835
PUBLISHED: 2020-01-23
SSRF in AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote denial of service via the server attribute to the tools/_rcmdstat.jsp URI.
CVE-2020-5216
PUBLISHED: 2020-01-23
In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.9.0, 5.2.0, and 6.3.0. If user-supplied input was passed into append/override_content_security_policy_directives, a newline could be injected leading to limited header injection. Upon seei...