TESTIMONIALS

“Received the latest edition of Professional Security Magazine, once again a very enjoyable magazine to read, interesting content keeps me reading from front to back. Keep up the good work on such an informative magazine.”

Graham Penn
ALL TESTIMONIALS
FIND A BUSINESS

Would you like your business to be added to this list?

ADD LISTING
FEATURED COMPANY
Cyber

Experience counts – not just certificates

by Mark Rowe

The cybersecurity industry continues to lament the skills shortage, but it needs to remove outdated recruitment policies to win in the race for talent, says Anna Webb, Head of Global Security Operations, at the IT support and managed security operations company, Kocho.

Last year’s ISC2 Cybersecurity Workforce Study found 63 per cent of firms around the world reported staff shortages.Yet, despite this, women represent just a quarter of the cybersecurity workforce globally, while in the UK the figure is only 17pc. But recruitment problems – either through bias or poor HR practice – are not limited to gender, or even neurodiversity, about which there has been considerable publicity. One of the continuing drags is an excessive focus on formal educational qualifications, neglecting an untapped pool of talent, ambition and practical experience, to the detriment of the industry.

There is a significant group of people from varied backgrounds and ages who are unlikely to be given the chance of a career in cybersecurity unless attitudes change. The industry must appreciate that people with hands-on experience in cybersecurity offer advantages, even if their qualifications are non-traditional.

Many will have joined businesses or organisations straight from school or college and gone on to build real-world experience across security practice and technology in a range of industries. Their route into cybersecurity could have been from tech-dominated industries such as telecoms – and theirmotivation and curiosity are likely to be big factors. They are likely to be good problem-solvers or have communication or leadership skills. This is especially true of ex-military personnel.

As a result, they will understand the importance of collaboration and how to get on with non-specialists. In managed SecOps, for example, partnerships matter, and regular and informal communication is important.Recruits with practical experience may also have skills in specific areas such as zero trust, security analysis or cloud that are in short supply.

Cybersecurity recruiters should spot this level of aptitude and give credit for expertise acquired through frontline work rather than study. Awareness is growing, however. The ISC2 workforce study, for instance, found 38 per cent came into the industry without IT or cybersecurity education.

Of course, firms still need to offer the chance to achieve certifications and formal qualifications. And to achieve the broadest appeal among age groups, they must be ready to offer flexible work patterns that adapt to family or caring commitments.

Diversity has shown its worth

Firms must also adapt to the needs and work styles of recruits with autistic spectrum conditions or ADHD. The process should begin with job descriptions focusing less on soft skills, for example. Cognitive diversity has many advantages for cybersecurity teams, providing a greater range of skills and outlooks that are invaluable when exploring vulnerabilities, for example.

Global IT services company DXC’s Dandelion Program is often cited in this area. It was established in 2014 to expand the skills of neurodivergent people and enable them to gain long-term IT roles. It claims a 92 per cent retention rate and productivity increases of between 30pc and 40pc for the 29 participating teams around the globe. The World Economic Forum also highlights how neurodiverse recruits have been more productive than their neurotypical colleagues at major companies such as JP Morgan, Microsoft and SAP.

Building more diverse teams isn’t just ethically sound, it can help alleviate the pressure facing current cybersecurity professionals. In-house research found that 59% of UK cyber professionals reported high team stress levels. Broader recruitment can help distribute workload, reduce single points of failure, and create more resilient teams better equipped to handle pressure.

Changing young attitudes through mentoring

The shortage of women is a more long-term problem, however, that requires cybersecurity firms to change hearts and minds in the education system. The perception that cyber security is a male-dominated profession starts young. I know this from my own experience of being actively discouraged – even by people with good intentions.

That is why mentoring is so important, like going into schools and colleges to share experiences and educate young people about the realities of a career in cybersecurity. It is vital to focus on the assumptions that hold back many girls from entering the field.

The myth that cybersecurity is solely about computer skills or coding must also disappear. Young people need to know the industry values a wider array of talents – from analytical thinking and problem-solving to communication skills and creative approaches to threat detection. Project managers and those with a knack for teaching others all have crucial roles to play. Those in the industry need to emphasise that cybersecurity is a highly dynamic world where practitioners have to adapt to evolving threats and technologies. For instance,college courses lag some way behind current cyber reality.

Open-minded outlooks provide more talent

All these initiatives need to be part of a change in mindset about recruitment if the industry is to harvest the most extensive range of talents available. The industry should be more open to people without high levels of formal qualifications, to women, and those from less conventional backgrounds and career paths. It must be better at spotting talent – either from an interesting CV or a high-functioning natural aptitude. It is obvious the world has many people whose natural abilities could help protect businesses and government organisations. We must recruit more of them.

Related News

  • Cyber

    ChatGPT’s third birthday

    by Mark Rowe

    Sunday, November 30 marks three years since ChatGPT was released to the public. In that time, OpenAI’s generative AI (GenAI) has changed…

  • Cyber

    Cyber in factories

    by Mark Rowe

    Cyber attacks are no longer just an IT issue for manufacturers. They are disrupting production lines, increasing costs and putting customer deliveries…