Site navigation

Comment | Building Cyber Talent Takes More Than a Degree

Acumen Cyber

,

cyber skills gap
Universities can provide the technical foundations for a career in cybersecurity, but the industry itself has an equally important role to play in turning that knowledge into experience, judgement and confidence.

Cybersecurity has an unusual relationship with the skills shortage. In fact, the latest UK Government report on cybersecurity skills found that significant gaps remain across the workforce. Nearly half (49%) of businesses lack basic cyber skills, including the ability to configure firewalls, manage personal data securely and detect malware. Around three in ten (30%) also face advanced skills gaps in areas such as forensic analysis, interpreting malicious code and penetration testing.

The industry, for a long time, has been talking about the difficulty of finding experienced people, yet those experienced people have to start somewhere. It’s a vicious circle, if businesses want a stronger pipeline of cyber talent, they cannot simply wait for universities to produce graduates who are ready to walk straight into complex security roles.

Universities and employers need to build that pipeline together.

It’s an approach Abertay University in Dundee has embraced for years. Its Department of Cybersecurity and Computing combines practical teaching with close industry collaboration, with much of its teaching laboratory-based. Abertay was also the first university in the UK (and the world) to offer an Ethical Hacking degree.

Dr Natalie Coull, Head of the Department of Cybersecurity and Computing at Abertay University, says that connection with industry is fundamental to preparing students for employment.

“From the very beginning, the Ethical Hacking degree has been built on industry collaboration. Those relationships help us make sure that what we’re teaching reflects what employers actually need.

“We’re a very practical, hands-on university, but there are experiences that are difficult to recreate in a classroom. Internships give students the opportunity to apply what they’ve learned in a professional environment and develop the confidence and experience that can make a real difference when they graduate.”

Abertay’s relationship with Glasgow-based cybersecurity company Acumen Cyber is one example of that approach in action.

From learning cyber security to doing it in the real world 

Abertay Ethical Hacking student Ben Mchendry recently completed a internship within Acumen’s Security Operations Centre (SOC), working alongside its security engineers. Ben went into the internship hoping to gain experience with technologies and situations he would not normally encounter at university. What he came away with was not simply knowledge of more tools.

During the internship, Ben developed his skills using technologies including Elastic and SentinelOne, learned querying languages such as ES|QL, and KQL and gained experience investigating security alerts.

But one of the biggest lessons was context. “I’ve learned that not everything is as it seems just from looking at the problem and that the context surrounding it matters a lot.” Ben explains.

“Something can look extremely malicious, but when you look at the surrounding context you might realise it’s actually normal activity.”

That distinction is fundamental to working in a SOC. Security teams can receive enormous volumes of information, but effective security isn’t about reacting to every alert as an attack. Engineers need to understand what they are seeing, investigate it and make an informed judgement about what happens next.

Learning from people who do the job

For Peter King, Head of Security Operations at Acumen Cyber, this is where industry internships become particularly valuable.

“University gives students an incredibly important technical foundation, but there are aspects of security operations that are very difficult to teach without putting someone alongside people doing the job every day,” he says.

“You can teach somebody how a technology works or how to write a query, but experience teaches you what to look for, which questions to ask and why something that initially looks suspicious might be perfectly legitimate. That judgement develops by investigating, asking questions and learning from other engineers.”

Acumen operates a flat engineering structure within its SOC rather than the traditional Tier 1 to Tier 3 analyst model. Every investigation is owned from start to finish by a security engineer with the skills, experience and authority to see it through.

For Ben, that meant being able to work directly with experienced engineers. He carried out investigations and gathered evidence before sharing his findings with an accredited engineer who could review his conclusion and talk through the reasoning behind it.

Ben describes that experience as learning things “that not even training could teach”.

Peter believes giving students access to experienced practitioners is important if the industry wants to develop more rounded engineers.

“We don’t want somebody’s first year in cybersecurity to consist of looking at an alert, following a script and passing it to somebody else. If we’re serious about developing engineers, they need to understand the investigation around that alert.

“That doesn’t mean putting an intern in charge of a customer incident. It means giving them meaningful exposure, letting them investigate, question what they’re seeing and then having an experienced engineer review that thinking with them.”

Experience that goes beyond technical skills

Internships also expose students to something even the best-equipped university lab cannot completely reproduce: customers.

Ben learned that different organisations have different technologies, policies and levels of technical knowledge. Some allow security teams to take immediate action, while others require approval before actions such as isolating a machine or resetting credentials.

He also learned that explaining an investigation can be just as important as conducting it.
Those softer skills matter. Coull says, “Experience gained alongside a degree can be a significant factor in helping students secure employment, while internships can also build confidence in interviews and professional environments”.


Recommended reading


For employers, the benefit works both ways.

“Internships give us an opportunity to invest in the talent the industry is going to need in a few years’ time,” says Peter. “We’re constantly hearing about the cyber skills gap, but companies have to be part of solving it.

“It takes time from experienced engineers to mentor somebody properly, but that’s the point. Great engineers aren’t born knowing how to investigate an incident. They’re built through education, experience, curiosity and having good people around them.”

A shared responsibility

Abertay’s wider approach reflects that principle. Its cyberQuarter was established to bring academia and industry together, with attracting and retaining cybersecurity talent among its objectives.

For students such as Ben, the value of that relationship is much more immediate. His advice to anyone considering an internship is simple: look for somewhere where you will “actually learn things from, not just work”, and don’t be afraid to ask questions.

If the UK wants more experienced cyber security professionals, universities cannot be expected to create them alone. Education can build strong technical foundations. Employers can provide exposure to customers, real investigations, experienced colleagues and the everyday decisions that turn technical knowledge into professional judgement.

Acumen Cyber

Latest News

Cybersecurity Editor's Picks Recruitment Security

Comment | Building Cyber Talent Takes More Than a Degree

Culture Featured Technology

Inside TecTonic’s Growing Innovation Market Square

Cybersecurity

Revolut Leaked Customer Data to Fake Government Email Account

Cybersecurity Editor's Picks Security

Welsh SMEs Urged to Strengthen Cyber Defences