Many cybersecurity experts are aware that there is a skills gap in the field they work in. It has a huge impact on companies' ability to protect their networks and data. The coronavirus pandemic only deepened this problem, while at the same time exposing economic issues that forced many companies to make budget cuts and lay off even the most important team members. Meanwhile, for cybercriminals, the pandemic became a perfect opportunity to carry out attacks, as a significant number of employees moved to working from home.

What consequences will the skills gap have?

In a recent study conducted by Fortinet, it turned out that 68% of surveyed companies had problems with recruiting, hiring and retaining qualified cybersecurity employees. For such an important field, this is an alarming statistic. In addition, 73% of respondents experienced at least one security breach in the past year that could have been avoided if employees had greater awareness of cyber hygiene principles.

– The lack of adequately qualified personnel has far-reaching consequences for the security of the IT environment and data, as well as for operational technology (OT) environments. At the same time, the number and sophistication of cyberattacks on companies is constantly growing, and if successful, they can be devastating and cause downtime costing hundreds of thousands of pounds – says Jolanta Malak, Fortinet director in Poland.

How to find the best candidate?

How to find the best candidate?

One of the biggest problems when recruiting a security specialist is the expectations of company boards regarding the candidate's competence and experience. As a rule, they significantly exceed what can be achieved within 5, 7 or even 10 years of a professional career. Moreover, narrowing employment opportunities to only those who would meet specific requirements regarding experience and length of service often excludes the most gifted and talented graduates. Meanwhile, they are usually the ones eager to learn and curious about the opportunities that working in cybersecurity offers.

What should the job interview focus on?

Employment policy should therefore focus on candidates' actual skills and innate strengths, not just on "x years" of experience. Job interviews can cover issues such as communication and leadership skills, analytical and mathematical abilities, understanding of abstract ideas, or the scope of independence and autonomy. This will say much more about a candidate than their "dry" CV.

How to train new and current employees?

Next, company boards should implement periodic training programs under which new employees can gain the skills needed to monitor networks, detect threats and mitigate their effects. It is worth covering existing employees with similar training as well. It may turn out that one of them will bring a new perspective to IT security issues.

Concepts from the article

How to solve recruitment problems in cybersecurity?

CV — Computer Vision. A field of AI that enables the analysis of images and video. CV systems can recognize objects, text, scenes, faces, image quality and generate descriptions of visual materials.

Why it matters: It allows a machine to see what is in a photo: a product, a face, text, a logo. In an editorial office, it speeds up describing, tagging and selecting thousands of photos.

When it is used: For automatic photo descriptions (ALT), graphic moderation, logo recognition and organizing archives.

What happens if it is omitted: Without computer vision, every graphic has to be described and catalogued by a person — a photo archive without descriptions is practically unsearchable.

Summary

The Fortinet study shows that 68% of companies have problems recruiting and retaining cybersecurity experts, and 73% of respondents experienced a security breach in the last year that could have been prevented. The skills gap deepened by the pandemic increases vulnerability to attacks that can cost hundreds of thousands of pounds.

Experts advise that instead of requiring many years of experience, companies should focus on candidates' soft skills and potential, and then invest in periodic training. Such a strategy can open the door to a cybersecurity career for talented graduates and existing employees.