The cybersecurity skills gap is not unlike the periodic dips in programming talent that occur as technology changes. The difference is that while a lack of programmers can delay program launches, empty seats in the cybersecurity domain can do immediate and lasting damage to your company and customers.

The dearth of cybersecurity professionals is a current fact of life, but enterprises can’t simply give up the effort to fill their open positions with highly qualified professionals to safeguard their operations. Instead, security leaders should use a combination of internal resource development and external recruitment to close ranks against cyberattacks.

Supply and Demand

According to Forbes, the demand for chief information security officers (CISOs) and other cybersecurity professionals is expected to reach 6 million by 2019, and Symantec CEO Michael Brown said he actually expects 1.5 million fewer applicants for those jobs. While companies wait for resumes to magically appear in the HR inbox, cybercriminals are taking advantage of the openings. This overwhelms both the staffs charged with keeping the company safe and the systems designed to protect enterprise assets.

Given these shortages, it’s no surprise that, according to Burning Glass Technologies’ “Job Market Intelligence: Cybersecurity Jobs, 2015” report, cybersecurity workers are demanding and receiving 9 percent, or $6,500, more per year than their peers in other IT positions. In other words, it isn’t that companies are being tight when they look to fill these jobs but a clear case of supply and demand. What factors, then, will attract the few available candidates without lowering recruiting standards?

Money Isn’t Everything

Obviously, salary is the leveling force in the workplace. It isn’t the only criterion, however, and attracting great employees that are eager to fill demanding positions requires more than just great pay.

Defending the enterprise against cybercrime is a long-term proposition facing long-term challenges, and companies need to protect themselves immediately and continuously. Management must focus on surviving the turnover of cyber professionals. That means developing an environment that attracts competent and motivated people, keeps them engaged with the company, and provides training and advancement opportunities that they can’t find elsewhere.

If you want to become the go-to employer for aspiring security nerds, you must be serious about becoming a hub of security education, research and overall knowledge. Demonstrate in your recruitment efforts that your commitment to security goes beyond just protecting company assets and that security is part of your culture. Emphasize that cybersecurity isn’t just an IT effort, and that C-level executives are committed to hiring the best security professionals to protect their company.

Bring in training resources and sponsor employee education, both internally and through external institutions. Offer incentives based on merit to attend industry events, then make certain your staff not only attends, but presents at conferences. Encourage them to participate in panel discussions and network with high-level industry executives.

A Long-Term Solution to the Cybersecurity Skills Gap

In short, employers must treat security professionals with at least as much respect and appreciation as they afford top-level executives and sales professionals. Your company’s future depends on your security team’s prowess.

The data shows that the cybersecurity skills gap is unlikely to fade anytime soon. The key to long-term success lies in your security leaders’ ability to stand out from the crowd of organizations desperate to recruit top-level talent.

Read IBM Executive the report: Addressing the Skills Gap with a New Collar Approach

More from CISO

Who Carries the Weight of a Cyberattack?

Almost immediately after a company discovers a data breach, the finger-pointing begins. Who is to blame? Most often, it is the chief information security officer (CISO) or chief security officer (CSO) because protecting the network infrastructure is their job. Heck, it is even in their job title: they are the security officer. Security is their responsibility. But is that fair – or even right? After all, the most common sources of data breaches and other cyber incidents are situations caused…

Transitioning to Quantum-Safe Encryption

With their vast increase in computing power, quantum computers promise to revolutionize many fields. Artificial intelligence, medicine and space exploration all benefit from this technological leap — but that power is also a double-edged sword. The risk is that threat actors could abuse quantum computers to break the key cryptographic algorithms we depend upon for the safety of our digital world. This poses a threat to a wide range of critical areas. Fortunately, alternate cryptographic algorithms that are safe against…

How Do You Plan to Celebrate National Computer Security Day?

In October 2022, the world marked the 19th Cybersecurity Awareness Month. October might be over, but employers can still talk about awareness of digital threats. We all have another chance before then: National Computer Security Day. The History of National Computer Security Day The origins of National Computer Security Day trace back to 1988 and the Washington, D.C. chapter of the Association for Computing Machinery’s Special Interest Group on Security, Audit and Control. As noted by National Today, those in…

Emotional Blowback: Dealing With Post-Incident Stress

Cyberattacks are on the rise as adversaries find new ways of creating chaos and increasing profits. Attacks evolve constantly and often involve real-world consequences. The growing criminal Software-as-a-Service enterprise puts ready-made tools in the hands of threat actors who can use them against the software supply chain and other critical systems. And then there's the threat of nation-state attacks, with major incidents reported every month and no sign of them slowing. Amidst these growing concerns, cybersecurity professionals continue to report…