Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Five Solutions To The Information Security Skills Crisis
Articles

Five Solutions To The Information Security Skills Crisis

Nicole MillsBy Nicole MillsFebruary 26, 2021Updated:February 14, 20236 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
businesses evade the ever increasing threat to their data security
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The dearth of talent entering the cybersecurity industry paints a worrying picture. There is an acute skill shortage of three million unfilled roles according to (ISC)2’s 2020 Cybersecurity Workforce Study. Here at Infosecurity Europe we recently ran a poll to explore current issues around the skills shortage within the sector, particularly within the context of the pandemic.

35.9 per cent of the respondents to Infosecurity Europe’s poll said that their organisation currently has a hiring freeze on cybersecurity roles which is hardly surprising given the economic uncertainty we all find ourselves in. Looking forward, and once this freeze is lifted, what’s needed is an holistic approach to attract and retain the next generation Infosecurity workforce. With the help of some of our esteemed colleagues from our CISO community here are five ways in which we could make some advances in solving the skills crisis facing our industry.

Make Cybersecurity Apprenticeships more widely available

42 per cent of respondents felt that apprenticeships were the solution to attracting younger people into cybersecurity. While there are opportunities for young people to join cybersecurity apprenticeship schemes, they are still not widely available. In a previous role I worked at a local further education college and had first-hand experience creating an apprenticeship programme. We had great success striking up relationships with local companies securing jobs for young people. The benefits are plentiful, but it requires a joined-up approach from both sides to make it work. It’s not a straightforward area for companies to get into but if managed within an HR team with a good provider it offers huge success and opportunity. Internships are also another option that could be considered help to solve the challenge.

Include cybersecurity in the school curriculum

It can be argued that we are waiting too long to attract the right people in. Cybersecurity has become such a crucial aspect of our day to day lives so we should be including it as part of the school curriculum. Just as with other professions we need to be inspiring and educating people from a young age of the wide and varied opportunities our sector offers. If left too late as Amar Singh, CEO Cyber Management Alliance, practising CISO and Trusted Advisor says “By the time they’re 16 or 18 this becomes more difficult because they may have chosen other passions and career-paths.”

Reviewing recruitment strategies

We should be looking to cast out net wider If we are trying to attract more people into our industry. This could mean looking at other people within your organisation who could be suited to a role in cybersecurity. As an industry are we guilty of creating the problem ourselves by not employ people because they don’t have technical qualifications or a degree? It is widely recognised that softer skills have a key role to play in cybersecurity strategies.

Often there will be highly suitable candidates already within your organisation. Heidi Shey, Principal Analyst serving Security and Risk Professionals with Forrester Research, agrees: “We need to really expand our view, looking at non-traditional backgrounds for different types of roles. What is it you really need in terms of the skills? And what are the things you could train someone up to do? You’re looking for that one candidate who has everything already, and that can really narrow down the field and make it more difficult to recruit.”

Creating a mentor scheme

The pandemic has further highlighted the importance of creating a proper support network for workers and even more so with the majority of the country finding itself remote-working. Indeed, a third of our respondents (37.2 per cent) believe that sustaining motivation and wellbeing is the greatest skills-related challenge faced by cybersecurity professionals right now. Having a supportive network is equally important wherever the workforce is located and whatever stage of their career they are in. Taking time to mentor people and helping them develop their skills is central to attracting and keeping them in the industry.

Keeping motivated and in good mental health during the pandemic could be particularly tough for new joiners. “We have people who’ve never physically stepped foot in their office, or met their colleagues,” says Paul McKay, Senior Analyst – Security and Risk, Forrester Research. “It’s also challenging for junior professionals not having support structures in terms of the mentorship and oversight of more senior folks, or being with peers of their own age who are all going through the same journey.”

With reference to the pandemic effective team-working skills was cited as a major challenge for remote workers by 26% of poll respondents. Steve Wright, Partner, Privacy Culture, agrees: “To not engage in a social way is possibly one of the worst things that could happen to our species, because we’re designed to be with people and bounce off each other. We need to think about how we can better support each other and collaborate now we don’t have that camaraderie in the office, to help make sure people still feel associated and included, and that they know you still care about them.”

Attracting more diverse candidates

This goes hand in hand with looking at recruitment strategies As Mark Nicholls, CISO of Chime Group says “There are so many good people out there, and we need to be more open. There are advantages to having diverse teams that represent the business you’re trying to protect, and having non-security folks bringing different ideas to the table.”

Attracting candidates from more diverse backgrounds also come under this. For example, if we are aiming to attract more women into cybersecurity then this can’t simply be statement. We must deliver on it. Careful consideration needs to be given to culture and ensuring that it reflects those you are aiming to entice in.  

Troy Hunt, Microsoft Regional Director and Founder of Have I Been Pwned, indicates the need for greater inclusiveness: “Technology in general is very male-dominated, and there’s a lot of women in particular feel excluded by that. There’s also much more introverted behaviour, and – in my experience at least – obnoxious behaviour! We need to create an environment that people of all backgrounds want to be in; that removes any barriers making them reticent about being part of the industry.”

Our industry gives us much to be optimistic about with exciting technological breakthroughs at every turn. To cope with its fast-paced nature, however, we must ensure that we do everything we can to attract and retain a steady pipeline of talent into our industry. Early engagement and education opportunities to attract and maintain more people hold the key to its long-term sustainability.

Nicole Mills

    The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

    Share. Facebook Twitter LinkedIn Email Copy Link

    Related Posts

    Roblox Under Fire: Lawsuit Alleges Secret Data Tracking of Kids

    May 13, 20254 Mins Read

    Understanding Cloud Access Security Brokers (CASB)

    March 28, 202410 Mins Read

    Decoding Cloud Security Posture Management (CSPM)

    March 28, 202411 Mins Read
    ISB-Bora-Side-Bar

    No se ha podido establecer conexión. Error 429

     
    ISB-Bora-Side-Bar
    Black ISB Logo

    Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

    X (Twitter) LinkedIn Facebook RSS

    Working With Us

    • About Us
    • Advertise With Us
    • Contact Us

    Write For Us

    • How To Contribute

    The Pages

    • Privacy Policy
    • Cookie Policy
    • AI Policy
    • Terms & Conditions
    • Copyright Notice

    Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}