A new way to secure security staff?

Findings from new study of tenured cybersecurity professionals and those seeking their first security role urges hiring organisations to re-evaluate their cybersecurity team-building practices.

(ISC)² – the world’s largest non-profit association of certified cybersecurity professionals – has released the findings of its 2021 Cybersecurity Career Pursuers Study, which provides insights on how to successfully staff up a balanced and diverse cybersecurity team with a broad range of skills. The research reflects the opinions of 2,034 cybersecurity professionals (professionals) and cybersecurity jobseekers (pursuers) throughout the US and Canada. Findings help hiring organisations understand the experiences of those who have done the job and the expectations of those who are about to enter the field.

Recruiters and hiring managers may need to adjust the tactics they use to proactively identify internal and external candidates, (ISC)2 analysis of the study suggests. Findings point to strong agreement about:

·Tasks and experiences that make a cybersecurity professional successful

·The value of mentorship

·Key career moments when pursuers typically seek a cybersecurity path

·What attracts people to cybersecurity

·Candidate qualities that are strong indicators of future success

The study also provides feedback from respondents in their own words. Professionals were asked about tasks performed early in their careers that were most beneficial to their long-term success, as well as how they gained confidence that cybersecurity was the right career choice. Pursers were asked similar questions, including what tasks they expect to be assigned upon entering the field, what challenges they anticipate and why they are confident cybersecurity is the right career for them.

“One of the biggest challenges we have in cybersecurity is an acute lack of market awareness about what cybersecurity jobs entail,” said Clar Rosso, CEO of (ISC)2. “There are wide variations in the kinds of tasks entry-level and junior staff can expect. Hiring organisations and their cybersecurity leadership need to adopt more mature strategies for building teams. Many organisations still default to job descriptions that rely on cybersecurity ‘all stars’ who can do it all. The reality is that there are not enough of those individuals to go around, and the smart bet is to hire and invest in people with an ability to learn, who fit your culture and who can be a catalyst for robust, resilient teams for years to come.”

Recruiting Beyond IT

(ISC)2 recommends, based on the research, that with skilled cybersecurity talent increasingly scarce, organisations must adopt more pragmatic approaches to team building. This starts by relying less on the recruitment of cybersecurity ‘unicorns’ with many years of experience, advanced certifications and deep technical acumen, or sourcing new talent exclusively from IT. Instead, organisations must take broader approaches: curate role-specific requirements; invest in their cybersecurity team’s training and professional development, as well as commit to upskilling and reskilling home-grown talent to help team members translate tangential skills into valuable risk management and security know-how. The (ISC)2 report lays out 10 key actionable strategies for hiring managers to review when building their teams.

Additional highlighted findings include:

  • While cybersecurity professionals tend to be highly educated, just 51% have degrees in computer and information services. Less than half (42%) of the professionals who responded said a dedicated security education is critical for a role in cybersecurity.
  • While IT jobs are the leading gateway to cybersecurity roles, that entry pathway is shifting. Half of those newer to the field (with less than three years of experience) came from an IT background, compared to 63% of those with between three and seven years of experience in the field.
  • By a wide margin, fewer professionals who are relatively new to the field (less than three years) consider IT experience to be critical (46%) than do their more senior colleagues (69%)
  • Military veterans and those with law enforcement experience make up 31% of the cybersecurity professional respondents, affirming these backgrounds as ripe areas for recruitment
  • Cloud security was rated by professionals as the most important technical skill new entrants to the field should learn, while problem solving was the top-rated “soft skill” they should have. Both areas were simultaneously the top-rated responses by career pursuers too.
90% adopting or considering SASE, 74% reallocated funds to cybersecurity among multiple indicators o...
US pipeline cyberattack is a ‘timely reminder’ highlighting the need for cyber insurance, Bloomberg...
62% of UK survey respondents consider human error their organisation's biggest cyber vulnerability a...
Digital transformation pushed to the top of the priority list for central Government.
Innovative automated threat detection, investigation and response (TDIR) products illuminate industr...
Increase in phishing and ransomware attacks - along with continued high numbers of Web Application A...
Manufacturing, finance and healthcare industries hit hard as attackers take advantage of global dest...
400% increase in OpenVPN Attacks and 86% rise in short duration floods while the risk of a repeat at...