Studies and reports warn that there is a gap measured in millions of people between the demand for cybersecurity roles and the those who can fill them.
However, I do not think we have the cyber skills shortage that we think we do. There are deeper issues that those reports do not expose.
The cyber skills shortage reports are created by counting the number of available workers verses the number of open job listings, or directly asking large employers how many workers they want versus how many they can get.
While these are useful studies on their own, they do not explore whether the employer demand, or if the method of filling positions, makes sense.
The reports also do not explain why many cybersecurity workers express frustration that their job-hunting process is difficult and complex. That despite the shortage, the time to land a job can be long and the requirements unrealistic.
I propose that there are four interconnected factors that contribute to the creation of a false skills gap that, if addressed, could mean that organisations meet their goals and reduce their cybersecurity risk. These are:
- Poor security strategy
- Attempting to retain skills that should be borrowed
- Expecting workers with highly niche skills across multiple domains
- Expecting cybersecurity workers to have a specific education and career path
Security strategy
Cybersecurity is highly complex, highly technical, and the risks are invisible and difficult to understand. Creating a strategy to tackle that sort of challenge is a learning process.
However, many organisations attempt to compensate for an inadequate strategy by applying more people to their problems.
When more issues arise, the defacto, if not deliberate, strategy is to hire more security professionals to shoulder the responsibility. Security becomes the Security Department’s problem.
This is like trying to keep a leaking ship afloat by hiring more people to join the bucket line. The need for more people can feel very real, and it can even be measurable, but it is an inefficient and ineffective approach when the core problem should be addressed instead.
Finding the best place to address systemic security problems would reduce the need for a constant stream of new workers.
Retaining Skills In-House
Company loyalty and valuing an increasing head-count is a hold-over from a pre-millennial approach to doing business.
To “own” skills, especially when those skills are in short supply, is a natural desire. If the needed skills are on the payroll and not in the overhead budget, there is a sense that the risks of losing that skill are minimised.
However, with so many organisations doing the same thing, there is a pull on the talent pool that cannot be maintained, and retention risks are still high.
The result for workers with in-demand skills is that they might rotate between companies in quick succession creating a shortage across all companies that looks bigger than if different approaches were used.
Ultimately, this means that those workers are inefficiently tied up in a single organisation when they could be solving strategic problems for multiple organisations.
Demand for multi-niche skills
Every organisation has problems that only an experienced technical expert can address.
However, because of the perception of the small size of the security talent pool, organisations seek out these experienced technical experts and expect them to also tackle other specialised problems.
Because hiring managers, in general, may not understand the cybersecurity field, this can create either unrealistic expectations for a potential candidate, i.e. looking for unicorns, or expectations of highly skilled workers to perform the security equivalent of manual labour.
This results in the all-too-common job postings for junior roles with senior certifications, requests for improbable skill combinations, or other situations where organisations seek a key person to solve all their security strategy problems.
Instead of looking for more and more people to join the bucket line on the leaking ship, these organisations are looking for master shipbuilders who can also carry buckets all day.
These roles go unfilled for longer periods of time, and when filled, are often soon empty again after the worker experiences burnout.
Specific Education and Career Path
When looking for candidates for cybersecurity roles, organisations tend to look for people with specific education, experience, and career paths that create a specific type of expert, even if what the organisation needs is something completely different.
This process creates the problem of the multi-niche expert above, except that all it is anticipates that cybersecurity experts specialise in a small set of cybersecurity niches, whether the job requires that expertise or not.
For example, twenty-year veterans in the cybersecurity field did not start out the way that fresh graduates start today. There were no cybersecurity degrees, no security certifications, no bug bounty programmes, no cyber firing ranges, and there was a much smaller pool of security-specific products and services to master.
Cybersecurity professionals came from all fields and backgrounds to create the field as it exists today. For many of the problems that organisations face, they do not need someone trained as a security analyst or a penetration tester, yet these are the expected skills for most junior positions and these are the core skills taught in degree programmes.
The result is that organisations are hyper-focused on candidates with a narrow set of skills and do not consider people from outside of the sector who have the abilities to address their security problems. And this becomes a vicious cycle.
Because of the demand for certain skills, the cybersecurity industry trains and floods the talent pool with specialised and certified workers. This then becomes the expected path for experts, so those outside this path are not considered, increasing the demand for these skills.
Each of these factors feed and support each other. The perceived problems create a demand for more and more people to fix the wrong symptoms, which depletes the small talent pool and creates the artificial demand for individuals with multiple, but narrow skillsets.
The end result is the industry responding to create a near monoculture in skillsets to fix the wrong symptoms, which sets the standard for all workers, regardless of the problem.
Addressing the shortage
The chain of skill shortage problems starts with a misidentification of the underlying security problems.
While it is easy to say that an organisation should design a perfect network and have people who never make mistakes, that is not realistic.
There will always be stop-gap measures that need to be applied, but the organisation must have a focus on fixing the underlying problems.
Likewise, the organisation must take on the responsibility of operating securely and assigning staff where it makes sense, as well as transitioning to technical solutions where possible.
Many processes can be automated or replaced by technology, which would reduce the demand for new people. The right technologies can also act as a force multiplier to help the organisation do more with less.
Organisations should seek to properly understand its problems and look outside the cybersecurity ecosystem for people to address them.
It can be easier to train an expert from a non-security field in the required security aspects of a problem than trying to fit a general security expert in an area where they have no experience.
That requires re-classifying problems from cybersecurity to general business, and investing in making security training available throughout the organisation.
Recommended
- Leader Insights | What will 2022 bring for martech?
- Scots female founders to meet former Apple advisor in trade mission
- Fintechs say using data is major technical challenge
Where specific skillsets are required, organisations should feel more comfortable reaching out to freelancers and contractors who can manage their time across multiple organisations.
There is also a very mature Managed Security Service Provider (MSSP) market that can take a lot of work away from an organisation while providing access to the highly skilled people the organisation needs.
As the digital economy grows and as cyber threats evolve, there is a very real shortage of people in roles to support organisations to manage their risks and counter cyber threats.
However, the shortage is not what most people think, and there are many ways to address this so that an organisation is not left to flounder.
With a shift in perspective, all organisations can solve their underlying problems, bolster the workforce they have, and leverage outside resources to ensure that the organisation can navigate their challenges successfully.
Scot-Secure 2022 | Scotland’s Largest Annual Cyber Security Summit
Jordan Schroeder will speaking at DIGIT’s 8th annual Scot-Secure Summit the on 23rd March at Dynamic Earth in Edinburgh and streamed live.
Scot Secure will focus on promoting best-practice cyber security; looking at the current trends, key threats, and offering practical advice on improving resilience and implementing effective security measures.
For more information, visit www.scot-secure.com.





