TESTIMONIALS

โ€œReceived the latest edition of Professional Security Magazine, once again a very enjoyable magazine to read, interesting content keeps me reading from front to back. Keep up the good work on such an informative magazine.โ€

Graham Penn
ALL TESTIMONIALS
FIND A BUSINESS

Would you like your business to be added to this list?

ADD LISTING
FEATURED COMPANY
Cyber

Professional standards are evolving

by Mark Rowe

Cybersecurity is one of the world’s most critical professions. Organisations routinely grant external security providers access to sensitive systems, confidential data, operational technology, cloud and even critical national infrastructure. Few industries outside healthcare, engineering or finance are trusted with this level of access to information, says Martin Walsham, Director of Cybersecurity at AMR CyberSecurity – Part of Infinum.

Despite this, cybersecurity lacks the universal professional standards found in other high-trust fields. No one would knowingly visit a dentist without recognised qualifications, ongoing professional development and independent oversight. The same principle should apply to cybersecurity providers, particularly those delivering penetration testing and services involving access to sensitive environments.

Penetration testers, for example, are often granted access to the very systems designed to keep attackers out. That level of access needs trust, accountability and independently validated competence.

An industry with uneven standards

Cybersecurity is still relatively young and evolving rapidly. There are many highly skilled and ethical professionals across the sector, but capability, governance and quality can vary significantly.

Even the term ‘penetration test’ can mean very different things depending on who is selling it. In some cases, what is described as a penetration test can amount to little more than running a vulnerability scanner. Report quality can also vary significantly, with organisations sometimes getting long technical reports without a clear explanation of what the findings mean for their business or what to do about them.

For organisations without much internal security expertise, distinguishing genuine operational excellence from polished marketing is difficult. This is where independent accreditation and independently verified professional certification have a crucial role to play.

Strong foundations

The UK is well placed when it comes to building a more professionalised cybersecurity industry. The National Cyber Security Centre’s CHECK scheme is an established assurance model for penetration testing of central government, public sector bodies and UK critical national infrastructure. The NCSC assesses companies offering CHECK services against its methodology, while also setting requirements around technical competence and professional standards.

CHECK also demonstrates how organisational assurance and individual professional standards can work together. All CHECK Team Leaders must now hold and maintain, as a minimum, a ‘Principal’ Cyber Security Professional title in Security Testing awarded by the UK Cyber Security Council, while CHECK Team Members must hold and maintain, as a minimum, a ‘Practitioner’ title in Security Testing.

This is important because cybersecurity services are ultimately delivered by people, not an organisation’s certificate on a wall.

With the UK already having the building blocks for a more professionalised industry, the challenge now is extending adoption across the whole market.

Accreditation is only part of the answer

Independent accreditation bodies such as CREST have an important role to play. CREST provides independently assessed standards covering areas including penetration testing, incident response and threat intelligence. Its standards assess technical capability alongside organisational maturity, methodology and other service-specific requirements.

CREST, along with The Cyber Scheme, also provides individual professional certifications. This is important because organisational accreditation and individual competence are complementary. A company can have strong processes and governance while the people actually delivering a particular engagement have very different levels of experience and competence.

Buyers need to consider both the assurance of the organisation and the qualifications, professional standing and practical experience of the individuals doing the work. Cybersecurity services are ultimately delivered by people, not an organisation’s certificate on a wall.

The UK Cyber Security Council was established to address the professionalisation challenge.It is the UK’s professional body for cybersecurity and sets standards for professional competence and commitment. Its framework has four professional titles – Associate, Practitioner, Principal and Chartered – and it maintains a public register of professionally registered practitioners.

There are signs that these standards work as part of assurance frameworks. The NCSC’s adoption of UK Cyber Security Council professional titles within the CHECK scheme is one example.

However, adoption of the Council’s professional standards and Chartered scheme has been strongest in government and among accredited cybersecurity service providers, with more limited adoption across the wider private sector.

The next stage has to be making recognised professional standards more widely understood and valued by all employers and buyers. Professional registration and recognised standards have to become something organisations actively look for. They canโ€™t be something required only by a section of the market.

Regulation helps drive professionalisation

The UK’s Cyber Security and Resilience Bill is progressing through Parliament. During the recent committee stage, amendments were considered, including proposals on the statutory functions of the UK Cyber Security Council.

The Bill will expand the regulatory framework around cyber resilience, including supply chain security, incident reporting and organisational accountability. It also brings additional organisations into scope, including relevant managed service providers, while providing powers to designate critical suppliers.

More organisations will need external providers to help them meet expectations. Regulation, however, is not a substitute for professional standards. Organisations need to be able to demonstrate that they are managing cyber risk, but they also need confidence in the competence of the people and providers they trust to help them do that.

Organisations depend on interconnected suppliers and specialist cybersecurity providers. So, supplier assurance should consider whether a provider has appropriate policies and controls, as well as whether it has the professional capability to deliver the services.

This doesn’t mean a new certification or compliance requirement is needed every time there is a new cyber risk. The UK has established frameworks that can provide a foundation.

Cyber Essentials, for example, is designed as a baseline rather than a comprehensive answer to more advanced or targeted threats. The Defence Cyber Certification scheme is a useful example of how established frameworks can be built upon. DCC incorporates Cyber Essentials, with additional cyber resilience requirements layered on top.

We should be aiming for regulation, standards and assurance frameworks that complement one another, address genuine gaps and give organisations a coherent understanding of what good looks like.

Professionalism matters

Cybersecurity evolves quickly so static qualifications are not enough. Cloud architectures, AI-driven threats, operational technology and complex supply chains all need professionals who continuously develop their knowledge.

Professionalisation can’t mean passing an examination once and retaining a title indefinitely. It needs to involve continuing professional development, ethical expectations and periodic reassessment of competence. Professional status has greatest value when it demonstrates an ongoing commitment to maintaining standards.ย  Professionalisation in cybersecurity is about building trust, consistency and accountability. It is also about helping organisations make informed decisions when selecting cybersecurity partners.

Independent accreditation and recognised professional standards won’t eliminate risk, but they do provide important benchmarks for competence, governance and ethical conduct. And in an industry where trust is so important, this matters.

The UK already has many of the foundations it needs. Regulation will help drive demand for these standards, but we need the whole industry to embrace them. We want organisations to start demanding the same level of independently validated professionalism from their cybersecurity providers as they do from other trusted professions.

Related News

  • Cyber

    Reporting portal

    by Mark Rowe

    UK financial regulators have come up with a single portal for incident and third party reporting. The watchdog the FCA points to…

  • Cyber

    Managing cloud challenge

    by Mark Rowe

    Management of cloud cyber security is the chief challenge for UK central government, a cyber firm’s survey suggests. Given the vast amount…