Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

7/27/2016
08:38 AM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Cybersecurity Skills Shortage Puts Organizations At Risk, Study Shows

The oft-discussed and lamented cybersecurity skills gap isn't just a hiring issue, it's putting your organization at risk, Intel Security-CSIS study finds.

A report published today by Intel Security in partnership with the Center for Strategic and International Studies (CSIS) confirms the perceived cybersecurity skills shortage and the real risk that poses for organizations. 

The study, which surveyed eight countries -- Australia, France, Germany, Israel, Japan, Mexico, the United Kingdom (UK), and the United States (US) -- found that respondents overwhelmingly reported that a cybersecurity skills shortage does exist in their organizations (82%). 

What’s disconcerting about this study, says Candace Worley, vice president and general manager for enterprise endpoint security at Intel, is that respondents reported that “the lack of enough cybersecurity staff is contributing to security risk in their organization.” This should be a concern for all of us, she warns. 

Seventy-one percent of respondents said that this shortage in cybersecurity skills does direct and measurable damage: 25% lost proprietary data through cyberattacks, 33% say they are a target for hackers because of weak cybersecurity defenses, and 22% say they’ve suffered reputation damage due to the workforce shortage. 

Black Hat USA returns to the fabulous Mandalay Bay in Las Vegas, Nevada July 30 through Aug. 4, 2016. Click for information on the conference schedule and to register.

While governments have begun to take an increased interest in cybersecurity -- the US President’s Budget for fiscal year 2017 proposes $19 billion in Federal resources for cybersecurity -- 76% of respondents still feel that their governments aren’t investing enough in building cybersecurity talent.    

The study revealed that part of the skills shortage can be pinned on the gap between available cybersecurity education and the minimum credentials required for entry-level positions. Four in 10 respondents said that a bachelor’s degree would be required from job applicants seeking an entry-level cybersecurity position, and 38% of respondents from France and 32% from Germany said they’d require a master’s degree as their minimum credential. The researchers of this study found that only 7% of top universities in the countries researched offer undergraduate studies (major or minor) in cybersecurity. 

And while considered a requirement to apply, a bachelor’s degree in a technical field isn’t viewed as effective for acquiring cybersecurity skills as hands-on experience (such as internships or hack-a-thons) or professional certifications. 

Worley says that it’s important to drive excitement about cybersecurity in high school students, but that even if that education began today, “at best, those folks would be coming out of college in one to two, to three years. We’re going to have a talent shortage in the next three years and we need to make sure that it’s not a systemic issue.” 

In order to prevent that, Worley says closing the security skills gap is a challenge for all invested parties.

“This is putting pressure on government and organizations and companies that have security practices and vendors in this field to come together and address this as a community,” she says. In the interim, organizations should asses their risk tolerance and automate and outsource what they can to take the pressure off in-house teams, she says.

This buys some time to tackle the bigger, more complex projects, she says, like intrusion detection, secure software development, and attack mitigation, which were listed as the scarcest cybersecurity skills in the report

While building the cybersecurity workforce is not an easy challenge, Worley says, “We’re at a point now where we as a community, we win as an industry if we solve it.”

Related Content:

Emily Johnson is the digital content editor for InformationWeek. Prior to this role, Emily worked within UBM America's technology group as an associate editor on their content marketing team. Emily started her career at UBM in 2011 and spent four and a half years in content ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
mmccul
50%
50%
mmccul,
User Rank: Apprentice
7/27/2016 | 8:01:33 PM
Point missed in article
As a professional who has interviewed candidates for jobs in information security at multiple levels, I feel qualified to comment on the issues of finding good candidates.  There are multiple low level positions with very minimal requirements, but these positions (such as members of a SOC) are often ignored by these surveys, even though they often require extremely minimal background and provide a solid foundation in the field.  To say that such positions do not exist is to play the ostrich game.

The real problem I see is lack of training of management of what a professional in the field needs to be effective.  I often get unreasonable requests for job responsibilities from the manager; demands for skills not required as well as ignoring critical skills that the manager does not themselves posses and does not realize how crucial they are.  

A great way to improve the information security status of an organization would be to improve the low and mid-level management of such teams.  It would also help if organizations stopped focusing on the wrong problem.  A defensive expert is not a penetration tester, nor are they useful on my team.  As one coworker of mine phrased it, a pen tester knows one trick really well and they keep applying it across lots of applications, lots of systems until it works.  A defensive expert has to address every application, every threat, every system to ensure that the risks are identified, mitigated and addressed:  they have to have something in every column.  

 
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/21/2020
Cybersecurity Bounces Back, but Talent Still Absent
Simone Petrella, Chief Executive Officer, CyberVista,  9/16/2020
Meet the Computer Scientist Who Helped Push for Paper Ballots
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/16/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Latest Comment: Exactly
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-4590
PUBLISHED: 2020-09-21
IBM WebSphere Application Server Liberty 17.0.0.3 through 20.0.0.9 running oauth-2.0 or openidConnectServer-1.0 server features is vulnerable to a denial of service attack conducted by an authenticated client. IBM X-Force ID: 184650.
CVE-2020-4731
PUBLISHED: 2020-09-21
IBM Aspera Web Application 1.9.14 PL1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188055.
CVE-2020-4315
PUBLISHED: 2020-09-21
IBM Business Automation Content Analyzer on Cloud 1.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the i...
CVE-2020-4579
PUBLISHED: 2020-09-21
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a specially crafted HTTP/2 request with invalid characters. IBM X-Force ID: 184438.
CVE-2020-4580
PUBLISHED: 2020-09-21
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a specially crafted a JSON request with invalid characters. IBM X-Force ID: 184439.