August 10, 2022 By Jennifer Gregory 2 min read

A recent survey found that the majority of organizations struggle to retain cybersecurity workers. By focusing on improving retention, businesses can also reduce their digital risk.

Increased retention concerns

As new cybersecurity concerns increase, businesses also face an uphill battle to retain the talent needed to keep their data safe. A recent State of the Cybersecurity Workforce study reported that 43% of organizations saw an increase in attacks in the last year. It’s even more challenging to deal with this when they are constantly filling open positions. That means inexperienced workers or not enough people handling the infrastructure.

A key finding from the report was that 60% of respondents have issues retaining cybersecurity workers. That’s a 7% increase from last year. Plus, 63% of respondents have open positions. The survey included multiple industries, with 25% of respondents in the technology services/consulting industry, 21% in finance and 16% in the government.

The report also found a connection between increased attacks and retention issues. Of respondents who faced more attacks in the past year, 69% report being somewhat or very understaffed. This finding illustrates the critical nature of addressing retention issues as a key part of reducing risk and vulnerabilities. However, the study also found that lower retention rates make it harder to retain employees going forward. 73% of groups who are very understaffed reported challenges retaining workers.

Reasons for retention issues

The survey notes that the lower retention numbers are likely due, at least in part, to the current tensions between employees and leadership throughout all departments and industries. Many workers want to continue the flexibility of remote working, while some employers want their staff at the physical office building. Many companies have made changes to return-to-work mandates in hopes of reducing attrition, but there is not enough data yet to determine if these changes make an impact on cybersecurity retentions.

Other reasons cited by respondents for retention challenges include:

  • Recruited by other companies (59%)
  • Poor financial incentives (48%)
  • Limited promotion and development (47%)
  • High work stress levels (45%)
  • Lack of management support (34%).

Importance of retention will increase in the future

Because the demand for the cybersecurity profession is only going to increase, organizations that have low retention rates will struggle even more. 92% expect the demand for technical cybersecurity workers to increase in the future. Plus, 63% predict an increase in demand for executive-level workers in this field.

The key is to focus not only on reducing cybersecurity risk but on hiring and retaining top talent. By creating a positive work environment that includes competitive benefits, professional development and an upward career path, you can retain cybersecurity workers while improving cyber defenses.

More from News

DOD establishes Office of the Assistant Secretary of Defense for Cyber Policy

2 min read - The federal government recently took a new step toward prioritizing cybersecurity and demonstrating its commitment to reducing risk. On March 20, 2024, the Pentagon formally established the new Office of the Assistant Secretary of Defense for Cyber Policy to supervise cyber policy for the Department of Defense. The next day, President Joe Biden announced Michael Sulmeyer as his nominee for the role. “In standing up this office, the Department is giving cyber the focus and attention that Congress intended,” said…

CISA releases landmark cyber incident reporting proposal

2 min read - Due to ongoing cyberattacks and threats, critical infrastructure organizations have been on high alert. Now, the Cybersecurity and Infrastructure Security Agency (CISA) has introduced a draft of landmark regulation outlining how organizations will be required to report cyber incidents to the federal government. The 447-page Notice of Proposed Rulemaking (NPRM) has been released and is open for public feedback through the Federal Register. CISA was required to develop this report by the Cyber Incident Reporting for Critical Infrastructure Act of…

Recent developments and updates in Biden cyber policy

3 min read - The White House recently released its budget for the 2025 fiscal year, which supports the government’s commitment to cybersecurity. The cybersecurity funding allocations line up with the FY 2025 cybersecurity spending priorities released last year that included the following pillars: Defend critical infrastructure Disrupt and dismantle threat actors Shape market forces to drive security and resilience Invest in a resilient future Forge international partnerships to pursue shared goals. In 2023, the White House released a 35-page document detailing the new…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today