I'm Calling BS on the Cyber Security Skills Shortage!
This is not a photo of an actual poo.

I'm Calling BS on the Cyber Security Skills Shortage!

I've been doing this cyber industry thing for a while now. Informally for 3 years, formally for a bit over a year. I've learnt a heck of a lot from some amazing people, and I'm exposed to amazing / scary ideas, news and content every single day.

But the big focus in our industry is tech. I talk to recruiters, cyber tech companies, and companies with cyber security issues, and they talk tech.

Geez it's hard to get good tech resources they say. I need someone to run my SOC, or a Splunk expert, or a good pen tester.

Cyber criminals largely don't care - they adapted years ago, and their main target hasn't been tech for a long time!

Lets Talk Irrational

Nice and simple - most breaches are through staff. They are the primary target no doubt. Some people will quote that staff are involved in up to 98% of breaches. It doesn't matter the exact number, it's really high!

So cyber criminals are targeting staff. And what do we do? Throw more money at tech. That is irrational, pure and simple. I'm not a rocket scientist, but out of this knowledge, I'm fairly confident in saying that if you want to do better with cyber security, train your damn staff!

What's Going on Out There

Small businesses are generally unaware that untrained staff are most likely to be their downfall, and don't know about the multitude of scams we face.

Most small businesses I encounter know about 30% of the information they need to know to stay safe from IT criminals re staff awareness. That is one glaring big hole!

Generally they don't see it as a real problem, they don't want to spend the money, they'd rather take the risk. Save a few grand now, hopefully don't burn a few hundred grand later.

Bigger business is doing cookie cutter compliance training. Yep we did awareness training, tick the box, sweet! Yes, it's way better than nothing, but ask someone what they remember of the awareness training in a years time, and you'll find that you've been accepting significant risk over that time!

Some companies do face to face training. That's always going to get better engagement, but can we really expect this knowledge to last a year? How do we keep them informed of new threats? How do we keep them thinking about cyber security awareness every single day, without annoying them?

The Solution

Come on, it's obvious! Yes we need good tech, but a key requirement is well informed staff who will do these basic things:

  1. Be suspicious. They need to be constantly thinking about whether something could be a scam.
  2. Stop. Don't click on random stuff, don't let someone through that door, don't give out that information to someone you don't know and trust.
  3. Think. Apply your knowledge critically to determine if it is a scam.
  4. Act. If it's a scam, deal with it appropriately. If you're not sure, don't act - find someone to help you!

That's 99% of the battle won right there! And how do we achieve this?

  • By embracing cyber security.
  • By getting everyone to understand that it's part of their job now.
  • By embedding it into the corporate culture, so that staff are always thinking about it, and are constantly given good timely information to keep them on their toes, but without annoying them or hindering their work.
  • By rewarding staff for their efforts, and being creative and keeping it fun.
  • By talking about it with our friends and family. By sharing information so that people are exposed to the different types of scams, and become more aware and knowledgeable over time.

Final Thoughts

So no, I don't think we have a cyber security skills shortage. I think we have a focus problem because we're spending most of the IT sec budget to fix the smallest issue, and that to me is nuts. Don't get me wrong, we need good tech - when we don't have that, cyber criminals will just move the goal posts again. But right now we should focus on good culture if we want to do better at this battle.

Agree / disagree? Let me know why.

Carol Pagnon

Governance, Risk, Assurance, Finance Executive & Advisor

5 年

I agree with you to a large degree. If we changed the business focus & regular employee training /awareness on 'data safety & security' relevant to their roles and business impact instead of just a tech term 'cybersecurity' this would improve the organisational culture. Tech roles are part of but not all of the solution to improved cybersecurity and overall data security.

Brad Wilkins

Head of Distribution at CyberArk | Channel Leader | Distribution Professional

5 年

Hmmm. ... so you’re saying people need to be smarter... good stuff Mike.

Shaibal Chakrabarty, Ph.D.

Global Leader in Cybersecurity, Managed Services, Strategic Alliances and Research

5 年

I am beginning to agree with Mike....

Shaibal Chakrabarty, Ph.D.

Global Leader in Cybersecurity, Managed Services, Strategic Alliances and Research

5 年

Mark Stafford?- in your picture: "In 1966 Cadillac WAS..." and "In 1973 Oldsmobile WAS...."? ;)? :P?

回复
Douglas E.

Dark by Design ZeroTrust Principal Executioner.

5 年

Once the biz allows cybersecurity team to do it's job instead of appeasing the users for an overly permissive network, the problem will self correct. Currently infosec is a low priority for the biz.?

要查看或添加评论,请登录

Mike Ouwerkerk的更多文章

  • How to get staff to watch awareness videos

    How to get staff to watch awareness videos

    Cyber security awareness is not a one off initiative. People will slowly forget information they are taught, that's a…

    1 条评论
  • Compliance Does Not Equal Security

    Compliance Does Not Equal Security

    I train a lot of people, and I always like to ask whether they have done this type of training before. Largely people…

    3 条评论
  • 10 Hard Truths About Cyber Security Awareness

    10 Hard Truths About Cyber Security Awareness

    I've been in the trenches of cyber security awareness for quite a few years now. In that time I've made a lot of…

    3 条评论
  • How do we spot deep fakes? Don’t bother!

    How do we spot deep fakes? Don’t bother!

    If you haven’t heard of deep fakes, it’s the use of technology to pretend to be someone. You can recreate someone’s…

  • Conversations with a Romance Scammer

    Conversations with a Romance Scammer

    OK, I'm out - "She" wants to have a voice chat. For the last week or so I've been chatting to a romance scammer.

    17 条评论
  • "Human Error" in Cyber Security - It's not what you think!

    "Human Error" in Cyber Security - It's not what you think!

    It's a constant message in cyber security - companies are being breached, and they blame "human error" for about 90% of…

    8 条评论
  • Cyber Security Cultural Change for SMEs

    Cyber Security Cultural Change for SMEs

    The war with cyber criminal scumbags wages on, and unfortunately the battle is still being lost by the good guys…

    5 条评论
  • Toot Toot Here Comes the Deep Fake Pain Train

    Toot Toot Here Comes the Deep Fake Pain Train

    The Scam Picture this: The receptionist gets to work, and there's a voicemail from the IT Manager saying that cleaners…

    2 条评论
  • The Benefits of Cyber Crime

    The Benefits of Cyber Crime

    Yeah I'm gonna go there. Doom and gloom is all we hear, the global economy is losing trillions, companies are getting…

    18 条评论
  • It's All About the Lightbulb Moments

    It's All About the Lightbulb Moments

    Metrics in cyber security awareness can be a bit of an art form, and will need to vary between organisations. But I…

社区洞察

其他会员也浏览了