Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Operational Security

11/13/2017
02:00 PM
Curtis Franklin
Curtis Franklin
Curt Franklin
50%
50%

Cybersecurity Skills Gap Hits Across the Board

The massive shortfall in cybersecurity professionals is having an impact on organizations of all types and sizes.

One of the major threats to IT security is a shortage of skilled professionals. That's the word from pretty much everyone in the industry and it's a threat that is having an impact on organizations of all sizes and descriptions.

The shortage has been documented in numerous studies such as the recent survey commissioned by TripWire and conducted by Dimensional Research. The 2017 Skills Gap Survey indicated that 93% of IT security executives are worried about the skills gap, with more than 40% saying that their organization is already facing a skills gap in meeting security needs.

Issues in meeting cybersecurity personnel needs aren't restricted to private enterprise, either. At a recent cybersecurity summit, Rob Joyce, White House cybersecurity coordinater, said that many top cybersecurity positions remain unfilled more than a year after the last election. In an article on the Defense One web site, Joseph Marks reported Joyce saying that these are not positions being left intentionally unfilled, but rather positions that haven't been filled because of a lack of qualified applicants.

In another recent survey, this one conducted by the Information Systems Security Association (ISSA) and Enterprise Strategy Group (ESG), 70% of industry professionals responded that a cybersecurity skills shortage is having an impact on their organization.

 

In "The Life and Times of Cyber Security Professionals," ISSA and ESG report that a lack of adequate cybersecurity staff is seen as the number two factor contributing to the rise in successful attacks on data, following only the lack of adequate training for non-technical employees (which leaves the non-technical staff much more likely to succumb to social-engineering attacks such as phishing).

It must be noted that the story of a cybersecurity skills shortage is not one that is univerally told. Around this time last year Angela Bailey, chief human capital officer the the Department of Homeland Security wrote a blog post in which she said that DHS was having no trouble finding a wealth of qualified candidates for its vacancies. If true, this places DHS in a near-unique position among hiring organizations, making the advice on hiring Bailey offers in her blog post exceptionally valuable.

Much more common are reports and white papers from companies like McAfee offering advice on hacking the skills shortage. Advice on dealing with the shortage range from outsourcing to increasing reliance on automation in security to an aggressive approach to diversifying the cybersecurity work force.

All of these seem worthwhile responses but until a rising tide of qualified cybersecurity professionals lift capabilities across the industry the one thing that seems quite obvious is that CISOs and security managers need to try all of these -- and more -- to mitigate the impact too-few analysts and technicians will have on their organization's security.

Related posts:

— Curtis Franklin is the editor of SecurityNow.com. Follow him on Twitter @kg4gwa.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/17/2020
Cybersecurity Bounces Back, but Talent Still Absent
Simone Petrella, Chief Executive Officer, CyberVista,  9/16/2020
Meet the Computer Scientist Who Helped Push for Paper Ballots
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/16/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-14180
PUBLISHED: 2020-09-21
Affected versions of Atlassian Jira Service Desk Server and Data Center allow remote attackers authenticated as a non-administrator user to view Project Request-Types and Descriptions, via an Information Disclosure vulnerability in the editform request-type-fields resource. The affected versions are...
CVE-2020-14177
PUBLISHED: 2020-09-21
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Regex-based Denial of Service (DoS) vulnerability in JQL version searching. The affected versions are before version 7.13.16; from version 7.14.0 before 8.5.7; from versio...
CVE-2020-14179
PUBLISHED: 2020-09-21
Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint. The affected versions are before version 8.5.8, and from...
CVE-2020-25789
PUBLISHED: 2020-09-19
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. The cached_url feature mishandles JavaScript inside an SVG document.
CVE-2020-25790
PUBLISHED: 2020-09-19
** DISPUTED ** Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive. NOTE: the vendor disputes the significance of this report because "admins are considered trustworthy"; however, the behavior "contradicts our secu...