{"id":23341,"date":"2024-09-27T22:57:16","date_gmt":"2024-09-27T18:57:16","guid":{"rendered":"https:\/\/me-en.kaspersky.com\/blog\/cybersecurity-talent-shortage\/23341\/"},"modified":"2024-09-27T22:57:22","modified_gmt":"2024-09-27T18:57:22","slug":"cybersecurity-talent-shortage","status":"publish","type":"post","link":"https:\/\/me-en.kaspersky.com\/blog\/cybersecurity-talent-shortage\/23341\/","title":{"rendered":"Cybersecurity talent shortages: the roots and the solutions"},"content":{"rendered":"<p>Skills shortages in the cybersecurity industry are hardly a new phenomenon; however, in recent years it has become painfully acute. The trigger was the coronavirus pandemic, which provoked rapid digitalization of most everything in the world, and an equally rapid increase in the number of cyberattacks. This led to demand for cybersecurity professionals seriously outstripping supply.<\/p>\n<p>ISC2, a leading cybersecurity expert-certification company, publishes its Cybersecurity Workforce Study every year. According to its <a href=\"https:\/\/media.isc2.org\/-\/media\/Project\/ISC2\/Main\/Media\/documents\/research\/ISC2_Cybersecurity_Workforce_Study_2023.pdf\" target=\"_blank\" rel=\"nofollow noopener\">latest report<\/a>, the number of cybersecurity specialists in the world increased by 8.7% between 2022 and 2023. Sounds great. The problem is, however, that the talent <em>shortage<\/em> also grew \u2013 by 12.6% over the same period. When the report went to press, the global staffing shortage in the cybersecurity industry stood at a whopping four million employees. So what\u2019s going on?<\/p>\n<h2>Cybersecurity in higher education<\/h2>\n<p>\nTo get an answer to this question, we conducted a <a href=\"https:\/\/www.kaspersky.com\/blog\/portrait-of-infosec-professional-report-2024\/\" target=\"_blank\" rel=\"noopener nofollow\">massive survey<\/a> of more than a thousand cybersecurity professionals from 29 countries. We interviewed employees across the board \u2013 from entry-level technicians to directors and SOC heads.<\/p>\n<p>Some interesting facts came to light as a result. Most interestingly, not all experts in the field had studied cybersecurity at college or university. The figures vary by region, but on average no more than half had done a dedicated course. What\u2019s more, the majority of respondents spoke of a lack of specialized cybersecurity courses in higher education on the whole.<\/p>\n<div id=\"attachment_52251\" style=\"width: 1210px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/37\/2024\/09\/27225636\/cybersecurity-talent-shortage-2.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-52251\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/37\/2024\/09\/27225636\/cybersecurity-talent-shortage-2.png\" alt=\"Availability of cybersecurity courses at degree level\" width=\"1200\" height=\"1246\" class=\"size-full wp-image-52251\"><\/a><p id=\"caption-attachment-52251\" class=\"wp-caption-text\">Respondents rated the availability of specialized cybersecurity courses in higher education institutions as poor. <a href=\"https:\/\/www.kaspersky.com\/blog\/portrait-of-modern-infosec-professional-research-2024-education\/\" rel=\"nofollow noopener\" target=\"_blank\">Source<\/a><\/p><\/div>\n<p>As for whether higher education is a must for a career in cybersecurity, respondents\u2019 views were decidedly <a href=\"https:\/\/www.kaspersky.com\/blog\/portrait-of-modern-infosec-professional-research-2024-education\/\" target=\"_blank\" rel=\"noopener nofollow\">mixed<\/a>: only half consider a degree to be either very or extremely useful; a quarter have a neutral opinion; and another quarter believe a degree to be totally useless.<\/p>\n<p>The main problem with formal cybersecurity education is that it forever lags behind real-world developments. Tools, technologies and threats are evolving so rapidly that knowledge acquired on a course becomes largely obsolete by graduation day.<\/p>\n<p>The surveyed cybersecurity specialists also noted that higher education often neither provides sufficient hands-on training, nor helps develop the skills needed to build a career in the field. So young professionals are often sorely unprepared for what awaits them in the real world.<\/p>\n<h2>Consequences for business<\/h2>\n<p>\nThe lack of hands-on experience means that many aspiring professionals make poor decisions, which can have major knock-on effects for employers. As nearly half of the respondents (46%) noted, it took them more than a year to get settled in their first job.<\/p>\n<p>At the same time, more than half (51%) admitted making serious mistakes in their first few years on the job. These were the top five mistakes mentioned:<\/p>\n<ul>\n<li>Not installing updates and patches in good time (43%)<\/li>\n<li>Using weak, easy-to-guess passwords (42%)<\/li>\n<li>Not backing up important data in good time (40%)<\/li>\n<li>Using outdated security measures (29%)<\/li>\n<li>Falling for phishing (29%)<\/li>\n<\/ul>\n<div id=\"attachment_52250\" style=\"width: 1946px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/37\/2024\/09\/27225709\/cybersecurity-talent-shortage-3.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-52250\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/37\/2024\/09\/27225709\/cybersecurity-talent-shortage-3.png\" alt=\"Mistakes in the first year at work\" width=\"1936\" height=\"594\" class=\"size-full wp-image-52250\"><\/a><p id=\"caption-attachment-52250\" class=\"wp-caption-text\">More than half of infosec professionals admit making serious mistakes in their first years in the job. <a href=\"https:\/\/www.kaspersky.com\/blog\/portrait-of-modern-infosec-professional-research-2024-struggles\/\" rel=\"nofollow noopener\" target=\"_blank\">Source<\/a><\/p><\/div>\n<p>Often, infosec experts have far higher privileges for and access to many systems not available to regular employees. Therefore, such mistakes can have catastrophic consequences for companies \u2013 ranging from critical infrastructure compromise and ransomware infection to industrial espionage and data leakage.<\/p>\n<h2>Patching the talent shortage<\/h2>\n<p>\nOf course, the problem of cybersecurity staffing shortages is too big for a quick-fix solution. Only with a long-term and comprehensive approach will it be possible to fill the deficit of qualified specialists.<\/p>\n<p>Our focus at Kaspersky is on two priorities. The first is the need to establish more effective cooperation between business and academic education. To ensure that graduates meet employers\u2019 requirements, higher education institutions need to be helped to adapt their programs to real-world developments to make them more flexible.<\/p>\n<p>To that end, we\u2019ve long been working closely with numerous educational organizations. In particular, through our <a href=\"https:\/\/academy.kaspersky.com\/academy-alliance\/\" target=\"_blank\" rel=\"noopener\">Kaspersky Academy Alliance<\/a> partner program, colleges and universities have access to world-class know-how, lectures, trainings and technologies, and can integrate industry expertise into curricula in line with the latest trends.<\/p>\n<p>The second priority we see is that business needs to give infosec employees \u2013 especially entry-level specialists \u2013 the opportunity to fill any gaps in theoretical knowledge and, more importantly, practical skills needed to do the job. With the rapidly evolving techscape and threatscape, professionals need to constantly upskill to stay on top.<\/p>\n<p>Available to both organizations and individuals, our <a href=\"https:\/\/academy.kaspersky.com\/\" target=\"_blank\" rel=\"noopener\">Kaspersky Academy<\/a> corporate education program and our <a href=\"https:\/\/xtraining.kaspersky.com\/?icid=me-en_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener\">Kaspersky Expert Training<\/a> online courses can greatly help with your professional training needs. Within these programs, we offer courses and trainings based on decades of experience of leading experts spanning all cybersecurity fields.<\/p>\n<h2>Mitigation<\/h2>\n<p>\nLastly, a few tips that won\u2019t directly fix the talent shortage worldwide, but will make it less acute within your organization:\n<\/p>\n<ul>\n<li>To lessen the burden on the infosec department, train employees in the basics of cybersecurity: our <a href=\"https:\/\/k-asap.com\/en\/?icid=me-en_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder____kasap___\" target=\"_blank\" rel=\"noopener\">Kaspersky Automated Security Awareness Platform<\/a> provides everything you need for this.<\/li>\n<li>The IT service\u2019s practical skills in recognizing signs of an attack also help reduce the workload of the infosec department. Such skills can be acquired, for example, by taking our cybersecurity <a href=\"https:\/\/academy.kaspersky.com\/courses\/cito-cybersecurity-for-it-online\/?icid=me-en_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener\">training for general IT specialists<\/a>.<\/li>\n<li>Another way to relieve the talent shortage is to deploy robust, time-saving tools, such as <a href=\"https:\/\/me-en.kaspersky.com\/next?icid=me-en_kdailyplacehold_acq_ona_smm__onl_b2b_kdaily_wpplaceholder_sm-team___knext____655fe72318f39647\" target=\"_blank\" rel=\"noopener\"> Kaspersky NEXT XDR<\/a>.<\/li>\n<li>If you lack highly-qualified specialists in-house, consider engaging third-party services, such as <a href=\"https:\/\/me-en.kaspersky.com\/enterprise-security\/managed-detection-and-response?icid=me-en_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener\">Managed Detection and Response<\/a> and <a href=\"https:\/\/me-en.kaspersky.com\/enterprise-security\/incident-response?icid=me-en_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener\">Incident Response<\/a>.<\/li>\n<\/ul>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kasap\">\n","protected":false},"excerpt":{"rendered":"<p>We explore the root causes of the talent crisis in the cybersecurity industry and look for possible solutions.<\/p>\n","protected":false},"author":2767,"featured_media":23343,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1318,1916],"tags":[1518,1457,2733,346,1368,167,2625,585,700,521,1367,2557,2558],"class_list":{"0":"post-23341","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-business","8":"category-enterprise","9":"tag-awareness","10":"tag-business","11":"tag-courses","12":"tag-education","13":"tag-employees","14":"tag-kaspersky-academy","15":"tag-kaspersky-asap","16":"tag-report","17":"tag-research","18":"tag-threats","19":"tag-training","20":"tag-trainings","21":"tag-xtraining"},"hreflang":[{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/cybersecurity-talent-shortage\/23341\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/cybersecurity-talent-shortage\/28077\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/cybersecurity-talent-shortage\/28230\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/cybersecurity-talent-shortage\/38295\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/cybersecurity-talent-shortage\/52249\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/cybersecurity-talent-shortage\/28332\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/cybersecurity-talent-shortage\/34156\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/cybersecurity-talent-shortage\/33812\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/me-en.kaspersky.com\/blog\/tag\/education\/","name":"Education"},"_links":{"self":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/23341","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/2767"}],"replies":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=23341"}],"version-history":[{"count":1,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/23341\/revisions"}],"predecessor-version":[{"id":23342,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/23341\/revisions\/23342"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/23343"}],"wp:attachment":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=23341"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=23341"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=23341"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}