Site navigation

DIGIT Interview: Richard Holmes, VP of Cyber Security Services, CGI UK

Duncan MacRae

,

Richard Holmes, CGI UK

Richard Holmes, VP of cyber security services, CGI UK, who is one of this year’s Scottish Cyber Awards judges, gives his take on the current state of Scotland’s cyber security sector.

What would you say has been the biggest trend in Scottish cyber security over the past year or so?

We see increasingly a continuation of the strong demand for the skills in cyber. Each year, as a company, we do something called ‘voice of the client’, which is essentially going out and having a business-focused discussion about trends for our clients. And we do that on a global basis and speak to more than 1,000 customers.

What we’ve seen this year is an increasing prioritisation of cyber security-related work. We interview both business leaders and IT leaders, if you like, within organisations – it’s about a 50/50 split. In the past year we, among both of those groups, we saw a jump in priority of cyber security, with it becoming an increasingly important area of investment.

That’s for a number of reasons. One of which is that there’s been a change in the legislative landscape, in GDPR and network and information security directive. There’s increasing legislative focus that’s caused companies to respond.

Equally, as well, the continuing change in the threat landscape and the need for companies to improve their operational security and monitoring in response to various attacks that are reasonably well publicised in the media

Both of those things are the root causes of driving increased awareness and priority at the leadership level. We see this in customers from across geographies and pretty much across all market sectors.

How is that threat landscape changing?

There are a number of things driving the threat landscape. In general, to a good degree, one of the drivers is connectivity. And it’s really the connectivity of systems that’s one of the main dimensions that leads to threat vectors in organisations. What you see is a continual increase in the society of network systems. Whether it be trends such as the IoT, both in peoples’ social lives but also in the engineering and manufacturing sectors. There’s an increasing drive for more connectivity, which leads to more complexity and, to a reasonable degree, to more threats.

This requires, therefore, a bit more thought and focus on some of the security issues. I think, as well, in terms of looking forward more, things like increased automation and machine learning both affect the threat landscape. I think we’ll see a continuing trend in scale and automation of cyber attacks. It does seem that those who instigate cyber attacks – the bad guys – are just as innovative of taking advantage of new technology solutions to help scale and be agile etc as the defenders.

We’ll see a continuing trend towards more emergence of automated attacks and intelligent automation in the threat vector. And that will need to be matched by the uptake of that capability in defence, as well.

Would you say there are any cyber security challenges that are unique to Scotland?

Scotland’s got a reasonably diverse range of sectors, whether it be financial services, energy utilities and broader manufacturing. There’s quite a broad range of sectors represented in Scotland and as a result, in general, the threat landscapes are pretty similar to many other parts of the world.

At CGI we’ve rapidly grown our business in Scotland. So, from a personal perspective, I’ve been on a bit of a journey over the last few years with increasing engagement and awareness of cyber in Scotland.

I think that something that is unique to Scotland is that there’s a different feel to the cyber ecosystem – linking through the various stakeholders, whether it is academia and the creation and growth of skills in cyber security, through to the actions of the Scottish Government and various Scottish bodies, like the Scottish Business Resilience Centre, through to a reasonably thriving SME community.

There are quite a lot of SMEs relating to cyber, through to some pretty big corporate organisations, whether it be on the supplier side like CGI but also the financial institutions and other stakeholders that have a stake in cyber security.

Security always has a bit of a community. Across the rest of the UK, it’s surprising how there’s a good network of contacts, but I think that’s multiplied in the Scottish context and that brings with IoT some opportunities for Scotland. Having an ecosystem of organisations doing world class stuff can lead to more agility and responsiveness. That’s an opportunity for Scotland.

How would you rate the level of cyber security training in Scotland?

Whether it be institutions like Strathclyde Uni, Napier Uni and the like, or some of the training that has spawned from the SMEs, I think there’s some world-class training in Scotland. Napier is the classic example, of course, in terms of its world-class cyber security education community in a number of flavours. And Napier having been around for a bit longer, that spawns people who’ve been through that process who often want to live and work in Scotland – to stay in the area – and there’s a multiplying effect.

Do you think there enough jobs here for people with cyber security training?

I’d say to a reasonable extent that there are. For the past two years, we’ve been looking to actively recruit in Scotland. One of the philosophies of CGI is that, while we’re a global company we absolutely look to have our workforce often located in the same area as our clients.

We want local expertise and local delivery. We’ve been recruiting in cyber and I think my biggest challenge is recruitment and retention. We’ve got a lot of people we employ in London and the South East but I would say we’ve found it just as hard to recruit people in Scotland as we have down south. We definitely haven’t felt that we’ve turned up in Scotland and there are lots of people with cyber skills who’re kicking around as good candidates. It’s a pretty hard market in Scotland.

Some people might choose to go away for a bit. I know a number of people who, once they’ve been educated, they might choose to move away. They might choose to move south of the border for a bit just to explore life elsewhere, but they absolutely want to come back and live and grow their careers in Scotland. We see that happening, but I don’t think there’s a big exodus of Scottish cyber resource south because people can’t find jobs north of the border.

How diverse do you feel the Scottish cyber security workforce is?

I definitely know that in general in IT and in cyber, there’s a diversity problem, and companies need to strive to do more to reach the broadest possible source of candidates, whether it be gender diversity or educational background diversity, or people on the spectrum in terms of their backgrounds.

There are lots of cases where people from non-traditional backgrounds can be absolutely great at cyber. One of the things about cyber security is that involves a very broad set of skills overall. With cyber, one of the challenges is ‘what is cyber?’ It involves a broad range of skills and understanding and that does, at least, bring a benefit. People from all sorts of backgrounds can find rewarding careers in cyber security. It’s not just for techies.

I think young people are certainly becoming more interested in cyber security and technology in general. We recently had a ‘bring your daughter to work’ day. As it happens, I’ve got three daughters and two of them were in the age range that we targeted the day at, so I brought two of my daughters along to work for the day. We did that in a number of locations, including Glasgow, for example.

It only reaches a small proportion of girls but if more companies did that type of thing that’s what we need. The girls got to do a variety of tasks and met various role models who spoke to them about cyber security and the careers they’re building, just to get the message out that it’s not just for boys. The more that happens the better.

Richard Holmes is a judge of the Scottish Cyber Awards 2018, organised by the Scottish Business Resilience Centre, which is being held on 28th November at Sheraton Grand Hotel, Edinburgh.

Duncan MacRae

Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data