August 20, 2020 By Sue Poremba 3 min read

The cybersecurity talent gap is real. The 2019/2020 Official Annual Cybersecurity Jobs Report predicts that there will be 3.5 million security jobs left unfilled globally by 2021. The cybersecurity profession hit a 0% unemployment rate and the pay is good. So, why are security leaders struggling to fill positions? It could be because they are looking for the perfect candidate that doesn’t exist. Meanwhile, their newest security team member may already be working in their company.

Unrealistic Guidelines for Cybersecurity Professional Careers

Traditionally, the standard for entry-level cybersecurity professionals was five years of experience and several certifications, most specifically the Certified Information Systems Security Professional (CISSP) certificate. Even interns, who work with a company, have a tough time getting hired. Those who put in five years in the field and gained the certification typically aren’t looking for entry-level jobs.

Job descriptions also don’t match the actual duties. Cyber threats constantly shift, and technology is constantly updated. So, there needs to be a lot of flexibility in the search. Unfortunately, job descriptions are often written by people who aren’t working in the field. They follow a basic template, both overestimating and underestimating the actual needs of the position.

Finally, there is a tendency to overlook talent who don’t check off all the right boxes. Anyone who has attended a security conference knows how homogeneous the demographic is. Most climb the same ladder to get to the job. But, defining what that ladder is means a lot of potential great hires are ignored.

Looking Right in Front of You

Because cybersecurity is time-sensitive and requires urgent attention, decision-makers need to be creative about developing a security team. Looking internally should be the first option, and that means looking beyond IT.

Cybersecurity requires a variety of skills. Technical skills are taught. Soft skills, such as communication, writing, problem solving, management and work ethic, come naturally. Every security team needs someone who can work directly with the organization’s entire staff and clearly articulate security problems and behaviors; someone who is approachable; someone who isn’t afraid to take the lead and fix a problem. Most importantly, this will be someone who already has an interest in cybersecurity and follows good cyber hygiene practices.

Behavioral analytics is also a popular function in attack prevention. While this can be done with artificial intelligence (AI) tools, it also helps to have a human who can provide security awareness training and be able to detect what employee behaviors could predicate potential threats.

How to Find the Right Future Cybersecurity Professional

How do you figure out who in the company is a good candidate for a cybersecurity career? One way is to create a company-wide security team with one or two representatives from each department. Work with department heads to find out who meet some of the criteria you’re looking for — someone good with computer technology, is a self-starter and can communicate security issues back to co-workers. As the team meets regularly, you’ll learn who has the right characteristics like passion, strategic thinking and creativity to understand the mind of a threat actor.

Putting together a security team will help you build a cybersecurity culture within the company. Everyone should be cyber aware and be doing their part to protect corporate assets from threats. Use incentives and rewards to encourage the type of culture. Take note of who is succeeding in practicing good security habits. They also could be future security professionals.

Finally, work with corporate leadership to offer the type of formal technical training that the potential security professional will need. It could be a couple of courses in security for IT workers already adept with computer skills, or more in-depth technical training in computer architecture, cloud computing, programming and specific training your company needs.

The cyber skills gap isn’t going to disappear overnight, but you can reduce unfilled entry-level positions in your company by taking a hard look at the talent already in house.

More from CISO

X-Force Threat Intelligence Index 2024 reveals stolen credentials as top risk, with AI attacks on the horizon

4 min read - Every year, IBM X-Force analysts assess the data collected across all our security disciplines to create the IBM X-Force Threat Intelligence Index, our annual report that plots changes in the cyber threat landscape to reveal trends and help clients proactively put security measures in place. Among the many noteworthy findings in the 2024 edition of the X-Force report, three major trends stand out that we’re advising security professionals and CISOs to observe: A sharp increase in abuse of valid accounts…

Boardroom cyber expertise comes under scrutiny

3 min read - Why are companies concerned about cybersecurity? Some of the main drivers are data protection, compliance, risk management and ensuring business continuity. None of these are minor issues. Then why do board members frequently keep their distance when it comes to cyber concerns?A report released last year showed that just 5% of CISOs reported directly to the CEO. This was actually down from 8% in 2022 and 11% in 2021. But even if board members don’t want to get too close…

The CISO’s guide to accelerating quantum-safe readiness

3 min read - Quantum computing presents both opportunities and challenges for the modern enterprise. While quantum computers are expected to help solve some of the world’s most complex problems, they also pose a risk to traditional cryptographic systems, particularly public-key encryption. To ensure their organization’s data remains secure now and in the future, chief information security officers (CISOs) should educate themselves about quantum computing, proactively address the coming quantum risks to cybersecurity and work to establish cryptographic agility in their enterprise.A future cryptographically…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today