Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Cybersecurity Brain Drain: The Silent Killer
Articles

Cybersecurity Brain Drain: The Silent Killer

ISBuzz TeamBy ISBuzz TeamNovember 16, 2016Updated:July 30, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Joanne Godfrey at AlgoSec examines what organizations can do to address the cyber-security skills gap.

It is well known that organizations today are facing an unprecedented number of cyber threats. From DDoS to ransomware, from phishing attacks to malware, the list of possible attack vectors is seemingly endless. However there is one threat that organizations face which is quietly and stealthily eroding their defenses.  What’s worse, this threat cannot be detected by any enterprise security products, yet it presents a very real long-term risk to their organizations:  the cybersecurity brain drain.

The Information Systems Security Association (ISSA) and analyst firm ESG, recently released a report  which revealed that nearly half (46%) of businesses surveyed have a ‘problematic shortage of cybersecurity skills’, while nearly half of security professionals said they are approached for other jobs at least once a week!  Moreover, 65% of security professionals ‘struggle to define their career paths’ due to poorly-defined training and development processes, and the lack of a career map in cybersecurity, among other factors. The cyber threat landscape is changing so rapidly that security professionals legitimately fear becoming deskilled:  56% of respondents said that their current employer simply doesn’t deliver the right levels of training to keep up with new risks, threats and security products.

Boredom damaging long term security

The findings follow on from AlgoSec’s 2016 ‘State of Automation in Security’ report which highlighted another key factor that’s contributing to the brain drain. It showed that skilled security staff are spending much of their valuable time ‘keeping the lights on’– manually maintaining and making changes to existing systems, trawling through endless security alert logs, and making device configuration changes – to plug security holes and keep things running smoothly.  Not only is this type of repetitive, manual work unrewarding and boring, leading to staff dissatisfaction, it’s also counterproductive. As our survey showed, manual security changes often resulted in outages and security breaches.  Furthermore, this menial work left staff without enough time to focus on more strategic business issues.

The net result is that security staff turnover rates are high, leaving organizations struggling to fill the gaps when key personnel leave, and hindering their ability to build comprehensive, long-term cybersecurity strategies to protect and enable their businesses.

Addressing the problems with automation

So what can be done? Clearly, organizations have a responsibility to improve their IT security training and staff retention programs – in particular to attract talented junior staff.  But of course, these measures cannot be implemented overnight – they take time and resources.

More than half our survey respondents believed that automating security processes could replace many of the repetitive, mundane tasks, such as managing security changes and preparing for regulatory audits. In addition to freeing up staff to focus on more strategic initiatives, automation significantly speeds up these processes and reduces the number of mistakes made. Not only that, by proactively assessing the risk of each and every change, automation helps organizations remain continually compliant, something more and more auditors are now demanding, as well as improve their overall security posture. And, as an added bonus, automation solutions track and document everything, thereby reducing the reliance on the team veterans who may or may not remember this information.

Turning security into a strategic asset

But automation can do much more than simply help security staff with the day-to-day management of their security processes. It can also play a critical role in strategic business and security projects. For example, when migrating business applications to the cloud, security automation solutions can identify and map application connectivity prior to the migration – a task that’s typically extremely manual, slow and costly.  Automation gives the security team the information they need to correctly migrate and configure business application connectivity in the cloud quickly and securely – without risking an outage or creating security holes. And assuming it supports a multi-vendor and multi-platform environment, automation removes the need to have domain experts for each specific security vendor’s products and platforms deployed across the enterprise network.  In addition, it enables the security team to manage the entire environment holistically – which eliminates blind spots and improves the organization’s overall security posture.

Augmenting, not replacing

While automation clearly delivers many security and business benefits, it is not about replacing skilled staff with technology. Rather, automation is about giving security staff the opportunity to fully utilize and advance their skills. An experienced, qualified security team is a huge asset to the organization – especially now – so they really shouldn’t be spending their time manually sifting through logs or tweaking firewall rules, when they could be actively developing your overall security strategy to counter the next generation of cyber threats.

[su_box title=”About Joanne Godfrey” style=”noise” box_color=”#336588″][short_info id=’71131′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

Lazarus Group Turns to Medusa Ransomware in Escalating Global Extortion Campaign

February 26, 20263 Mins Read

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}