September 12, 2022 By Jennifer Gregory 2 min read

The skills gap in cybersecurity isn’t a new concern. But, new research revealed in Fortinet’s 2022 Cybersecurity Skills Gap report confirmed what many experts have assumed. The skills gap increased risk and was likely the direct cause of at least some breaches.

Data for the survey was collected from 1,223 IT decision-makers in countries across the globe. The majority of the respondents were C-level executives (34%) or directors (34%), with the remaining responses coming from a variety of positions, including owners, vice presidents and department heads.

Breaches due to skills gap

The most surprising finding: 80% of respondents had at least one breach marked down to the lack of cybersecurity skills or awareness. In addition, 64% of the surveyed companies lost revenue or paid fines as a result of the breaches.

Overall, 67% of respondents agreed that the shortage of qualified cybersecurity candidates increases the risk. However, the report found that the concern level wasn’t equal. Leaders from France (81%), North America (77%) and Hong Kong (77%) showed the highest level of concern and believe that skills shortages pose extra risks.

Skills gap leads to hiring and retention challenges

The skills gap showed up in both hiring and retaining talent, with 60% reporting that they struggle to recruit. Plus, 52% struggled to retain qualified workers. The most challenging positions to hire for due to the skills gap included cloud security (57%), security operations (50%) and network security (49%). Hiring new graduates showed the fewest problems, with only 24% struggling in this area.

However, the report also found some positives. Most notably, over the past three years, most (88%) of the surveyed organizations hired more female cybersecurity workers, and 67% hired more employees from minority groups. In addition, 53% sought out and hired more veterans.

Reducing the impact of the skills gap

The skills gap is a complex problem. It doesn’t have a solution that works across the board. Organizations and the industry can help, though.

  1. Consider remote work when hiring for positions. Organizations used to be limited to hiring employees living within commuting distance from the office. Most companies now have remote working processes and tools. Carefully consider whether each open position — especially those that need highly specialized skills — could be a remote position. By removing location restrictions, you can access a much larger number of candidates for each position.
  2. Carefully evaluate degree standards. Many cybersecurity positions do not require college degrees, but employers limit their candidates by requiring them. Consider how certifications and digital badges can show real-world skills. These are often a better measure of expertise than more general degree programs.
  3. Increase internships and apprenticeships. The key to reducing the skills gap starts with hiring more younger workers. Internships or apprenticeships create a funnel of qualified applicants.

The cybersecurity skills gap can have a big impact on an organization through breaches and fines. By knowing how it works, businesses can make reducing the skills gap and filling open positions a high priority. The cybersecurity skills gap isn’t just a human resource issue, it should be an organization-wide concern.

More from CISO

X-Force Threat Intelligence Index 2024 reveals stolen credentials as top risk, with AI attacks on the horizon

4 min read - Every year, IBM X-Force analysts assess the data collected across all our security disciplines to create the IBM X-Force Threat Intelligence Index, our annual report that plots changes in the cyber threat landscape to reveal trends and help clients proactively put security measures in place. Among the many noteworthy findings in the 2024 edition of the X-Force report, three major trends stand out that we’re advising security professionals and CISOs to observe: A sharp increase in abuse of valid accounts…

Boardroom cyber expertise comes under scrutiny

3 min read - Why are companies concerned about cybersecurity? Some of the main drivers are data protection, compliance, risk management and ensuring business continuity. None of these are minor issues. Then why do board members frequently keep their distance when it comes to cyber concerns?A report released last year showed that just 5% of CISOs reported directly to the CEO. This was actually down from 8% in 2022 and 11% in 2021. But even if board members don’t want to get too close…

The CISO’s guide to accelerating quantum-safe readiness

3 min read - Quantum computing presents both opportunities and challenges for the modern enterprise. While quantum computers are expected to help solve some of the world’s most complex problems, they also pose a risk to traditional cryptographic systems, particularly public-key encryption. To ensure their organization’s data remains secure now and in the future, chief information security officers (CISOs) should educate themselves about quantum computing, proactively address the coming quantum risks to cybersecurity and work to establish cryptographic agility in their enterprise.A future cryptographically…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today