enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

Professor of Information Systems and Technology Management At Graziadio Business School

Cybersecurity Attacks

Charla Griffy-Brown, Professor of Information Systems and Technology Management At Graziadio Business School

President Biden in March grabbed headlines when he warned about cybersecurity attacks. The need for experts is only going to get more real as more cyber hacks are reported (last month President Biden signed into law a requirement for key businesses to report to the government when they have been hacked).

II. The warning heightens the fact that there are too few cybersecurity experts in the U.S. The U.S. added more than 250,000 people to the cybersecurity workforce between 2020 and 2021. But the need for cybersecurity professionals increased by 30% in 2021 according to industry group (ISC)². That leaves about 400,000 open cybersecurity jobs in the U.S.

III. The scarcity of workers presents a multifaceted geopolitical, economic and social problem – it must be addressed with greater urgency through a comprehensive approach. According to Dr. Brown there are three areas in which the U.S. can close the gap in Cybersecurity worker shortage:

a. Enterprise security firms must be at the forefront of training professionals in critical cyber security areas – this must including recruiting and training professionals who do not want to or cannot attend college. Students in high school can learn cyber security approaches that enable them to enter the workforce, gain on the job experience and receive employer supported college level training.

b. The federal government has a critical role through programs like cybercareers.gov. One area in which the Federal Government should focus is in recruiting more women. In 2021, women represented just 25% of the global cybersecurity workforce. A survey commissioned by Microsoft Security found that, while 83% of respondents believed there was an opportunity for women in cybersecurity, only 44% of female respondents felt sufficiently represented in the industry.

"Enterprise Security Firms Must Be At The Forefront Of Training Professionals In Critical Cyber Security Areas – This Must Including Recruiting And Training Professionals Who Do Not Want To Or Cannot Attend College"

c. Higher education is also on the hook. In addition to a scarcity of high wage entry and mid-level jobs in Cybersecurity, there is a skills shortage at manager and senior levels. A report from cybersecurity research firm Stott and May revealed that most of the cybersecurity leaders are struggling with skills shortage. The research report “Cybersecurity in Focus 2020” highlighted that 76% of respondents believe there is a shortage of cybersecurity skills in their organization, which represents an improvement when compared to 2019 (88%).

IV. The Federal Government is right to be sounding the alarm bells. The problem is dire and the impact on the economy and national security cannot be understated. By the same token, legislators must resist the urge to overregulate. Technology firms involved in enterprise security on a large scale (aka BigTech) cannot be hamstrung by the very entity sounding the alarm.

V. Enterprise security, government and education need to work together to deliver a comprehensive solution. The U.S. must attack this problem with a national call to action -- like the wartime call to work in essential industries (think Rosie the Riveter). To do less is to put the economy and national security at risk.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.