The Chartered Institute of Information Security’s (CIISec) 2022/23 State of the Profession report has been published, revealing how security professionals feel about their careers and the industry, in addition to highlighting trends and challenges.
After surveying just over 300 people, it was found that cybersecurity professionals remain positive about the industry and their opportunities as a whole. For example, 84% of respondents said that the industry is growing or booming, with 80% saying they have good or excellent career prospects.
On this, Amanda Finch, CEO of CIISec, commented: “It’s good to see cybersecurity professionals are positive about their career prospects. The cybersecurity industry is thriving. It has many opportunities for people from almost any background, and the need for cybersecurity is greater than ever as threats continue to rise – making a critical function essentially recession-proof.
“However, the industry cannot rest on its laurels: it must do more to ensure talent is properly supported and not burnt out. Key to this will be equipping them with the right skills, and attracting fresh blood into the industry to ensure teams aren’t put under undue pressure.”
Regarding the stress, pressure, and burnout that Finch pointed to, the report highlights that the industry is still plagued by issues including stress and overwork. For instance, 22% of respondents work more than the 48 hours per week mandated by the UK Government, and 8% work more than 55 hours which, according to the World Health Organisation, marks the boundary between safe and unsafe working hours.
Further, when asked about what keeps them awake at night, the two main sources of stress for cyber professionals are day-to-day stress and workload, identified by 50%, and suffering a cyber-attack, cited by 32%.
Poor working environments — resulting from bad or ineffective leadership, tedious work or a lack of variety, and issues with teams or colleagues — were all top reasons for security workers to leave their jobs. However, it was poor remuneration that was cited as the number one factor prompting people to leave their roles, followed by a lack of opportunity and progression.
Recommended reading
- 52% of Business Experiencing More Cyber-attacks Than Last Year
- AI Concerns Are a Mixed Bag Among IT Decision Makers
- New CISO Report Highlights Increasing Influence and Deepening Pockets
CIISec’s survey also underscored the continued issue of skills shortages. However, respondents didn’t believe there was a lack of people, but rather a lack of skilled personnel.
Relatedly, respondents revealed that analytical and problem-solving skills, followed by communication, then technical skills are the key capabilities needed to tackle cyber-threats, highlighting how the industry requires a culmination of both technical and non-technical skills to succeed.
Commenting on this, Finch said: “Traditionally, the cyber security industry has been seen as super technical career. However, as we can see it is much more than that.
“It demands social, managerial, investigative, and even financial capabilities. The industry must start doing better at advertising the opportunities to use different skills to broaden cybersecurity’s appeal.
“At the same time, the industry needs to prioritise the people within it. This means creating an environment that they want to work in and can thrive. By doing this, the industry can continue to boom, and cyber security professionals can live long and fulfilled careers.”





