August 17, 2017 By Scott Koegler 2 min read

The cybersecurity skills gap is not unlike the periodic dips in programming talent that occur as technology changes. The difference is that while a lack of programmers can delay program launches, empty seats in the cybersecurity domain can do immediate and lasting damage to your company and customers.

The dearth of cybersecurity professionals is a current fact of life, but enterprises can’t simply give up the effort to fill their open positions with highly qualified professionals to safeguard their operations. Instead, security leaders should use a combination of internal resource development and external recruitment to close ranks against cyberattacks.

Supply and Demand

According to Forbes, the demand for chief information security officers (CISOs) and other cybersecurity professionals is expected to reach 6 million by 2019, and Symantec CEO Michael Brown said he actually expects 1.5 million fewer applicants for those jobs. While companies wait for resumes to magically appear in the HR inbox, cybercriminals are taking advantage of the openings. This overwhelms both the staffs charged with keeping the company safe and the systems designed to protect enterprise assets.

Given these shortages, it’s no surprise that, according to Burning Glass Technologies’ “Job Market Intelligence: Cybersecurity Jobs, 2015” report, cybersecurity workers are demanding and receiving 9 percent, or $6,500, more per year than their peers in other IT positions. In other words, it isn’t that companies are being tight when they look to fill these jobs but a clear case of supply and demand. What factors, then, will attract the few available candidates without lowering recruiting standards?

Money Isn’t Everything

Obviously, salary is the leveling force in the workplace. It isn’t the only criterion, however, and attracting great employees that are eager to fill demanding positions requires more than just great pay.

Defending the enterprise against cybercrime is a long-term proposition facing long-term challenges, and companies need to protect themselves immediately and continuously. Management must focus on surviving the turnover of cyber professionals. That means developing an environment that attracts competent and motivated people, keeps them engaged with the company, and provides training and advancement opportunities that they can’t find elsewhere.

If you want to become the go-to employer for aspiring security nerds, you must be serious about becoming a hub of security education, research and overall knowledge. Demonstrate in your recruitment efforts that your commitment to security goes beyond just protecting company assets and that security is part of your culture. Emphasize that cybersecurity isn’t just an IT effort, and that C-level executives are committed to hiring the best security professionals to protect their company.

Bring in training resources and sponsor employee education, both internally and through external institutions. Offer incentives based on merit to attend industry events, then make certain your staff not only attends, but presents at conferences. Encourage them to participate in panel discussions and network with high-level industry executives.

A Long-Term Solution to the Cybersecurity Skills Gap

In short, employers must treat security professionals with at least as much respect and appreciation as they afford top-level executives and sales professionals. Your company’s future depends on your security team’s prowess.

The data shows that the cybersecurity skills gap is unlikely to fade anytime soon. The key to long-term success lies in your security leaders’ ability to stand out from the crowd of organizations desperate to recruit top-level talent.

Read IBM Executive the report: Addressing the Skills Gap with a New Collar Approach

More from CISO

Overheard at RSA Conference 2024: Top trends cybersecurity experts are talking about

4 min read - At a brunch roundtable, one of the many informal events held during the RSA Conference 2024 (RSAC), the conversation turned to the most popular trends and themes at this year’s events. There was no disagreement in what people presenting sessions or companies on the Expo show floor were talking about: RSAC 2024 is all about artificial intelligence (or as one CISO said, “It’s not RSAC; it’s RSAI”). The chatter around AI shouldn’t have been a surprise to anyone who attended…

Why security orchestration, automation and response (SOAR) is fundamental to a security platform

3 min read - Security teams today are facing increased challenges due to the remote and hybrid workforce expansion in the wake of COVID-19. Teams that were already struggling with too many tools and too much data are finding it even more difficult to collaborate and communicate as employees have moved to a virtual security operations center (SOC) model while addressing an increasing number of threats.  Disconnected teams accelerate the need for an open and connected platform approach to security . Adopting this type of…

The evolution of a CISO: How the role has changed

3 min read - In many organizations, the Chief Information Security Officer (CISO) focuses mainly — and sometimes exclusively — on cybersecurity. However, with today’s sophisticated threats and evolving threat landscape, businesses are shifting many roles’ responsibilities, and expanding the CISO’s role is at the forefront of those changes. According to Gartner, regulatory pressure and attack surface expansion will result in 45% of CISOs’ remits expanding beyond cybersecurity by 2027.With the scope of a CISO’s responsibilities changing so quickly, how will the role adapt…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today