Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Operational Security

11/13/2017
02:00 PM
Curtis Franklin
Curtis Franklin
Curt Franklin
50%
50%

Cybersecurity Skills Gap Hits Across the Board

The massive shortfall in cybersecurity professionals is having an impact on organizations of all types and sizes.

One of the major threats to IT security is a shortage of skilled professionals. That's the word from pretty much everyone in the industry and it's a threat that is having an impact on organizations of all sizes and descriptions.

The shortage has been documented in numerous studies such as the recent survey commissioned by TripWire and conducted by Dimensional Research. The 2017 Skills Gap Survey indicated that 93% of IT security executives are worried about the skills gap, with more than 40% saying that their organization is already facing a skills gap in meeting security needs.

Issues in meeting cybersecurity personnel needs aren't restricted to private enterprise, either. At a recent cybersecurity summit, Rob Joyce, White House cybersecurity coordinater, said that many top cybersecurity positions remain unfilled more than a year after the last election. In an article on the Defense One web site, Joseph Marks reported Joyce saying that these are not positions being left intentionally unfilled, but rather positions that haven't been filled because of a lack of qualified applicants.

In another recent survey, this one conducted by the Information Systems Security Association (ISSA) and Enterprise Strategy Group (ESG), 70% of industry professionals responded that a cybersecurity skills shortage is having an impact on their organization.

 

In "The Life and Times of Cyber Security Professionals," ISSA and ESG report that a lack of adequate cybersecurity staff is seen as the number two factor contributing to the rise in successful attacks on data, following only the lack of adequate training for non-technical employees (which leaves the non-technical staff much more likely to succumb to social-engineering attacks such as phishing).

It must be noted that the story of a cybersecurity skills shortage is not one that is univerally told. Around this time last year Angela Bailey, chief human capital officer the the Department of Homeland Security wrote a blog post in which she said that DHS was having no trouble finding a wealth of qualified candidates for its vacancies. If true, this places DHS in a near-unique position among hiring organizations, making the advice on hiring Bailey offers in her blog post exceptionally valuable.

Much more common are reports and white papers from companies like McAfee offering advice on hacking the skills shortage. Advice on dealing with the shortage range from outsourcing to increasing reliance on automation in security to an aggressive approach to diversifying the cybersecurity work force.

All of these seem worthwhile responses but until a rising tide of qualified cybersecurity professionals lift capabilities across the industry the one thing that seems quite obvious is that CISOs and security managers need to try all of these -- and more -- to mitigate the impact too-few analysts and technicians will have on their organization's security.

Related posts:

— Curtis Franklin is the editor of SecurityNow.com. Follow him on Twitter @kg4gwa.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Cloud Security Threats for 2021
Or Azarzar, CTO & Co-Founder of Lightspin,  12/3/2020
Why Vulnerable Code Is Shipped Knowingly
Chris Eng, Chief Research Officer, Veracode,  11/30/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Assessing Cybersecurity Risk in Todays Enterprises
Assessing Cybersecurity Risk in Todays Enterprises
COVID-19 has created a new IT paradigm in the enterprise and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-27772
PUBLISHED: 2020-12-04
A flaw was found in ImageMagick in coders/bmp.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned int`. This would most likely lead to an impact to application availability, but could po...
CVE-2020-27773
PUBLISHED: 2020-12-04
A flaw was found in ImageMagick in MagickCore/gem-private.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned char` or division by zero. This would most likely lead to an impact to appli...
CVE-2020-28950
PUBLISHED: 2020-12-04
The installer of Kaspersky Anti-Ransomware Tool (KART) prior to KART 4.0 Patch C was vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges during installation process.
CVE-2020-27774
PUBLISHED: 2020-12-04
A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of a too large shift for 64-bit type `ssize_t`. This would most likely lead to an impact to application availability, but co...
CVE-2020-27775
PUBLISHED: 2020-12-04
A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type unsigned char. This would most likely lead to an impact to application availability, but c...