August 17, 2017 By Scott Koegler 2 min read

The cybersecurity skills gap is not unlike the periodic dips in programming talent that occur as technology changes. The difference is that while a lack of programmers can delay program launches, empty seats in the cybersecurity domain can do immediate and lasting damage to your company and customers.

The dearth of cybersecurity professionals is a current fact of life, but enterprises can’t simply give up the effort to fill their open positions with highly qualified professionals to safeguard their operations. Instead, security leaders should use a combination of internal resource development and external recruitment to close ranks against cyberattacks.

Supply and Demand

According to Forbes, the demand for chief information security officers (CISOs) and other cybersecurity professionals is expected to reach 6 million by 2019, and Symantec CEO Michael Brown said he actually expects 1.5 million fewer applicants for those jobs. While companies wait for resumes to magically appear in the HR inbox, cybercriminals are taking advantage of the openings. This overwhelms both the staffs charged with keeping the company safe and the systems designed to protect enterprise assets.

Given these shortages, it’s no surprise that, according to Burning Glass Technologies’ “Job Market Intelligence: Cybersecurity Jobs, 2015” report, cybersecurity workers are demanding and receiving 9 percent, or $6,500, more per year than their peers in other IT positions. In other words, it isn’t that companies are being tight when they look to fill these jobs but a clear case of supply and demand. What factors, then, will attract the few available candidates without lowering recruiting standards?

Money Isn’t Everything

Obviously, salary is the leveling force in the workplace. It isn’t the only criterion, however, and attracting great employees that are eager to fill demanding positions requires more than just great pay.

Defending the enterprise against cybercrime is a long-term proposition facing long-term challenges, and companies need to protect themselves immediately and continuously. Management must focus on surviving the turnover of cyber professionals. That means developing an environment that attracts competent and motivated people, keeps them engaged with the company, and provides training and advancement opportunities that they can’t find elsewhere.

If you want to become the go-to employer for aspiring security nerds, you must be serious about becoming a hub of security education, research and overall knowledge. Demonstrate in your recruitment efforts that your commitment to security goes beyond just protecting company assets and that security is part of your culture. Emphasize that cybersecurity isn’t just an IT effort, and that C-level executives are committed to hiring the best security professionals to protect their company.

Bring in training resources and sponsor employee education, both internally and through external institutions. Offer incentives based on merit to attend industry events, then make certain your staff not only attends, but presents at conferences. Encourage them to participate in panel discussions and network with high-level industry executives.

A Long-Term Solution to the Cybersecurity Skills Gap

In short, employers must treat security professionals with at least as much respect and appreciation as they afford top-level executives and sales professionals. Your company’s future depends on your security team’s prowess.

The data shows that the cybersecurity skills gap is unlikely to fade anytime soon. The key to long-term success lies in your security leaders’ ability to stand out from the crowd of organizations desperate to recruit top-level talent.

Read IBM Executive the report: Addressing the Skills Gap with a New Collar Approach

More from CISO

Making smart cybersecurity spending decisions in 2025

4 min read - December is a month of numbers, from holiday countdowns to RSVPs for parties. But for business leaders, the most important numbers this month are the budget numbers for 2025. With cybersecurity a top focus for many businesses in 2025, it is likely to be a top-line item on many budgets heading into the New Year.Gartner expects that cybersecurity spending is expected to increase 15% in 2025, from $183.9 billion to $212 billion. Security services lead the way for the segment…

On holiday: Most important policies for reduced staff

4 min read - On Christmas Eve, 2023, the Ohio State Lottery had to shut down some of its systems because of a cyberattack. Around the same time, the Dark Web had a “Leaksmas” event, where cyber criminals shared stolen information for free as a holiday gift. In fact, the month of December 2023 saw more than 2 billion records breached and 1,351 disclosed security incidents, according to research from IT Governance — an increase of 332% and 187%, respectively, over the month of…

Overheard at RSA Conference 2024: Top trends cybersecurity experts are talking about

4 min read - At a brunch roundtable, one of the many informal events held during the RSA Conference 2024 (RSAC), the conversation turned to the most popular trends and themes at this year’s events. There was no disagreement in what people presenting sessions or companies on the Expo show floor were talking about: RSAC 2024 is all about artificial intelligence (or as one CISO said, “It’s not RSAC; it’s RSAI”). The chatter around AI shouldn’t have been a surprise to anyone who attended…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today