August 10, 2022 By Jennifer Gregory 2 min read

A recent survey found that the majority of organizations struggle to retain cybersecurity workers. By focusing on improving retention, businesses can also reduce their digital risk.

Increased retention concerns

As new cybersecurity concerns increase, businesses also face an uphill battle to retain the talent needed to keep their data safe. A recent State of the Cybersecurity Workforce study reported that 43% of organizations saw an increase in attacks in the last year. It’s even more challenging to deal with this when they are constantly filling open positions. That means inexperienced workers or not enough people handling the infrastructure.

A key finding from the report was that 60% of respondents have issues retaining cybersecurity workers. That’s a 7% increase from last year. Plus, 63% of respondents have open positions. The survey included multiple industries, with 25% of respondents in the technology services/consulting industry, 21% in finance and 16% in the government.

The report also found a connection between increased attacks and retention issues. Of respondents who faced more attacks in the past year, 69% report being somewhat or very understaffed. This finding illustrates the critical nature of addressing retention issues as a key part of reducing risk and vulnerabilities. However, the study also found that lower retention rates make it harder to retain employees going forward. 73% of groups who are very understaffed reported challenges retaining workers.

Reasons for retention issues

The survey notes that the lower retention numbers are likely due, at least in part, to the current tensions between employees and leadership throughout all departments and industries. Many workers want to continue the flexibility of remote working, while some employers want their staff at the physical office building. Many companies have made changes to return-to-work mandates in hopes of reducing attrition, but there is not enough data yet to determine if these changes make an impact on cybersecurity retentions.

Other reasons cited by respondents for retention challenges include:

  • Recruited by other companies (59%)
  • Poor financial incentives (48%)
  • Limited promotion and development (47%)
  • High work stress levels (45%)
  • Lack of management support (34%).

Importance of retention will increase in the future

Because the demand for the cybersecurity profession is only going to increase, organizations that have low retention rates will struggle even more. 92% expect the demand for technical cybersecurity workers to increase in the future. Plus, 63% predict an increase in demand for executive-level workers in this field.

The key is to focus not only on reducing cybersecurity risk but on hiring and retaining top talent. By creating a positive work environment that includes competitive benefits, professional development and an upward career path, you can retain cybersecurity workers while improving cyber defenses.

More from News

FBI, CISA issue warning for cross Apple-Android texting

3 min read - CISA and the FBI recently released a joint statement that the People's Republic of China (PRC) is targeting commercial telecommunications infrastructure as part of a significant cyber espionage campaign. As a result, the agencies released a joint guide, Enhanced Visibility and Hardening Guidance for Communications Infrastructure, with best practices organizations and agencies should adopt to protect against this espionage threat. According to the statement, PRC-affiliated actors compromised networks at multiple telecommunication companies. They stole customer call records data as well…

Zero-day exploits underscore rising risks for internet-facing interfaces

3 min read - Recent reports confirm the active exploitation of a critical zero-day vulnerability targeting Palo Alto Networks’ Next-Generation Firewalls (NGFW) management interfaces. While Palo Alto’s swift advisories and mitigation guidance offer a starting point for remediation, the broader implications of such vulnerabilities demand attention from organizations globally. The surge in attacks on internet-facing management interfaces highlights an evolving threat landscape and necessitates rethinking how organizations secure critical assets. Who is exploiting the NGFW zero-day? As of now, little is known about the…

Will arresting the National Public Data threat actor make a difference?

3 min read - The arrest of USDoD, the mastermind behind the colossal National Public Data breach, was a victory for law enforcement. It also raises some fundamental questions. Do arrests and takedowns truly deter cyberattacks? Or do they merely mark the end of one criminal’s chapter while others rise to take their place? As authorities continue to crack down on cyber criminals, the arrest of high-profile threat actors like USDoD reveals a deeper, more complex reality about the state of global cyber crime.…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today