Much has been made of the security skills shortage over the last few years. In headlines, at conferences, and in survey after survey, warnings are popping up, all with the same dire predictions: There are more and more ways for hackers to breach digital gates and not enough gatekeepers out there to stop them.
Theres no disputing we have more open security positions than we have available applicants to fill them. And, at first glance, the statistics are staggering: 3.5 million cybersecurity jobs will be available yet unfilled by 2021, despite ransomware attacks growing 350% year-over-year. Thats certainly cause for concern especially as attackers become more sophisticated, creating new techniques and approaches to overcome barriers intended to block them. But placing blame squarely on a security skills shortage overlooks the real issue at hand.
What we have in this industry isnt a skills shortage. Its a creativity problem in hiring. To close the existing talent gap and attract more candidates to the field, we need to do more to uncover potential applicants from varied backgrounds and skill sets, instead of searching for nonexistent unicorn candidates people with slews of certifications (like CISSP, CompTIAPenTest+, CySA+, CASP+, CEH, CISSP and CISM), long tenures in the industry (10+ or, in some cases, 20+ years of experience longer than most relevant technology has been around), and specialized skills in not one, but several, tech stacks and disciplines (from cloud security to app sec and compliance).
But how? By dropping the secret-handshake-society mindset that enables a lack of diversity in the workforce, deters new entrants to the field, and, ultimately, undermines our ability to stay secure in the long run.
Hiring a security team that thinks the same, is educated the same, and looks and talks the same leads to blind spots. Yet cybersecurity is wrapped up in an air of mystique, from the words we use (malware, ransomware, cryptojacking, encryption) to the image we present (shadowy figures in hoodies). And that reputation, as an exclusive, elite club has allowed hiring across the board to become homogeneous. According to a recent global study, 89% of the cybersecurity industry is male, with less than a third from underrepresented groups. And, only 7% of cybersecurity pros are under the age of 29.
Part of the problem is a lack of awareness about cybersecurity as a viable career path for candidates inside and outside of tech, largely due to our longstanding cloak and dagger approach to what we do. If you asked most folks outside of the industry what the work of a cybersecurity professional entails, Id imagine very few would be able to tell you. That needs to change. Expanding our recruiting pool and increasing the size of our talent pipeline starts with dropping our dark arts attitude and making security more accessible and easily understood whether its through increased visibility at job fairs and career days at a range of institutions, building a pipeline of mentorship programs, or hosting inter-departmental workshops and information sessions.
To reel in more candidates, we need to be verbose about the day-to-day responsibilities of the job, articulate a path for career growth, and dispel the lone wolf stereotype that permeates this line of work. The more we step out of the shadows and make cybersecurity more approachable, the easier it is for people to understand what a career in cybersecurity actually entails which, in turn, enables them to see themselves working in our industry.
Of course, a large part of the puzzle is expanding our hiring funnel by recruiting outside of our narrow channel of established candidates. Security wins when its multi-disciplinary and when we hire people from varied backgrounds. Yet we, as an industry, over-index on pedigree and certifications all the time, even though some of the greatest minds in our field dont have certifications, or for that matter, college degrees. Ive seen it happen firsthand a hiring committee more willing to hire candidates with a degree from an elite university and a splashy tech internship under their belt than a career changer from a separate, yet related, field. Ive even experienced it in my own career, with a startup manager once telling me to my face that I didnt look like security despite a resume and a computer engineering degree that said otherwise.
Cybersecurity isnt sorcery. Security-specific skills can be taught. We need to do away with narrow criteria for who will be a good fit for many security roles and shift the way we evaluate resumes so that we look critically at what a candidate is capable or doing instead of looking solely at what theyve already done. Too often, we look externally for certain skill sets to be filled before a candidate gets to us, either via degrees, certifications, or completed coursework. But the pool of talent that already has those skills is too small. To create the talent supply to fill demand, we need to reach talent that has the aptitude and ability to learn and apply the necessary skills for the job. That means organizations need to get creative and develop their own learning and development initiatives for skill-building, whether its a large-scale training initiative aimed at career changers, or something as simple as hosting workshops, meetups, lunch-and-learns, or informational office hours.
De-emphasizing degrees and certifications in job postings levels the playing field and creates more opportunities for diamond-in-the-rough candidates to stand out to hiring managers. Case in point: One of the best and brightest security professionals I ever mentored started her career as a front desk receptionist. She didnt have the credentials that other cybersecurity professionals had starting out, but she was used to understanding the nuances of human behavior and picking up on anomalies, a critical skill for cybersecurity experts. With guidance and mentoring, she has gone on to become a senior technical program manager in information security.
Rethinking the way we evaluate resumes also means a shift in how we write job posts and how we evaluate candidates once they walk in the door. That means incorporating a first-principles problem-solving approach to recruiting. Oftentimes we ask, What do we think this job opening should be, and has a candidate done that job elsewhere before? Instead, we should ask, What is this person going to do? What is their job going to be? And how should we test for that job?
Inclusive language has been shown, across the board, to increase the quality and depth of talent, with Deloitte indicating companies that harness inclusive talent and recruiting strategies have 30% higher revenue per employee than those that dont. Cybersecurity shouldnt be any different. When it comes to job postings, the language we use should be aimed at drawing people in, instead of blocking people out. That starts with incorporating inclusive and easily-understood language (eg: Develop easy-to-use tools and light-weight processes that will help our engineers seamlessly write secure code.), instead of implicit messages that dissuade candidates from applying (eg: leading with years of experience requirements, or a laundry list of security-specific buzzwords that are indecipherable to most of the outside world).
But adding inclusive language to job posts only goes so far. Once candidates arrive on-site, replacing traditional, academic skills tests with interactive exercises and values and motivations assessments can go a long way in enabling hiring managers to explore and evaluate a candidates ability to find real-world solutions, both on their own and alongside the teams theyd be working with. That way, we assess candidates for true security mindset and problem-solving skills, beyond their ability to manage security tools.
Cybersecurity doesnt have a skills shortage. We have a culture problem that manifests in the ways we source and recruit talent. By removing barriers to entry, prioritizing potential over pedigree, and re-engineering the way we recruit and interview candidates, we can welcome more cybersecurity professionals into the herd instead of continuing the ongoing unicorn hunt that will get us nowhere.
Fredrick Flee Lee is CISO of Gusto.
Original post:
Calling BS on the security skills shortage - VentureBeat
- The Impact of AI on Human Behavior: Insights and Implications - iTMunch - January 23rd, 2025 [January 23rd, 2025]
- Disturbing Wildlife Isnt Fun: IFS Parveen Kaswan Raises Concern Over Human Behavior in Viral Clip - Indian Masterminds - January 15th, 2025 [January 15th, 2025]
- The interplay of time and space in human behavior: a sociological perspective on the TSCH model - Nature.com - January 1st, 2025 [January 1st, 2025]
- Thinking Slowly: The Paradoxical Slowness of Human Behavior - Caltech - December 23rd, 2024 [December 23rd, 2024]
- From smog to crime: How air pollution is shaping human behavior and public safety - The Times of India - December 9th, 2024 [December 9th, 2024]
- The Smell Of Death Has A Strange Influence On Human Behavior - IFLScience - October 26th, 2024 [October 26th, 2024]
- "WEIRD" in psychology literature oversimplifies the global diversity of human behavior. - Psychology Today - October 2nd, 2024 [October 2nd, 2024]
- Scientists issue warning about increasingly alarming whale behavior due to human activity - Orcasonian - September 23rd, 2024 [September 23rd, 2024]
- Does AI adoption call for a change in human behavior? - Fast Company - July 26th, 2024 [July 26th, 2024]
- Dogs can smell human stress and it alters their own behavior, study reveals - New York Post - July 26th, 2024 [July 26th, 2024]
- Trajectories of brain and behaviour development in the womb, at birth and through infancy - Nature.com - June 18th, 2024 [June 18th, 2024]
- AI model predicts human behavior from our poor decision-making - Big Think - June 18th, 2024 [June 18th, 2024]
- ZkSync defends Sybil measures as Binance offers own ZK token airdrop - TradingView - June 18th, 2024 [June 18th, 2024]
- On TikTok, Goldendoodles Are People Trapped in Dog Bodies - The New York Times - June 18th, 2024 [June 18th, 2024]
- 10 things only introverts find irritating, according to psychology - Hack Spirit - June 18th, 2024 [June 18th, 2024]
- 32 animals that act weirdly human sometimes - Livescience.com - May 24th, 2024 [May 24th, 2024]
- NBC Is Using Animals To Push The LGBT Agenda. Here Are 5 Abhorrent Animal Behaviors Humans Shouldn't Emulate - The Daily Wire - May 24th, 2024 [May 24th, 2024]
- New study examines the dynamics of adaptive autonomy in human volition and behavior - PsyPost - May 24th, 2024 [May 24th, 2024]
- 30000 years of history reveals that hard times boost human societies' resilience - Livescience.com - May 12th, 2024 [May 12th, 2024]
- Kingdom of the Planet of the Apes Actors Had Trouble Reverting Back to Human - CBR - May 12th, 2024 [May 12th, 2024]
- The need to feel safe is a core driver of human behavior. - Psychology Today - April 15th, 2024 [April 15th, 2024]
- AI learned how to sway humans by watching a cooperative cooking game - Science News Magazine - March 29th, 2024 [March 29th, 2024]
- We can't combat climate change without changing minds. This psychology class explores how. - Northeastern University - March 11th, 2024 [March 11th, 2024]
- Bees Reveal a Human-Like Collective Intelligence We Never Knew Existed - ScienceAlert - March 11th, 2024 [March 11th, 2024]
- Franciscan AI expert warns of technology becoming a 'pseudo-religion' - Detroit Catholic - March 11th, 2024 [March 11th, 2024]
- Freshwater resources at risk thanks to human behavior - messenger-inquirer - March 11th, 2024 [March 11th, 2024]
- Astrocytes Play Critical Role in Regulating Behavior - Neuroscience News - March 11th, 2024 [March 11th, 2024]
- Freshwater resources at risk thanks to human behavior - Sunnyside Sun - March 11th, 2024 [March 11th, 2024]
- Freshwater resources at risk thanks to human behavior - Blue Mountain Eagle - March 11th, 2024 [March 11th, 2024]
- 7 Books on Human Behavior - Times Now - March 11th, 2024 [March 11th, 2024]
- Euphemisms increasingly used to soften behavior that would be questionable in direct language - Norfolk Daily News - February 29th, 2024 [February 29th, 2024]
- Linking environmental influences, genetic research to address concerns of genetic determinism of human behavior - Phys.org - February 29th, 2024 [February 29th, 2024]
- Emerson's Insight: Navigating the Three Fundamental Desires of Human Nature - The Good Men Project - February 29th, 2024 [February 29th, 2024]
- Dogs can recognize a bad person and there's science to prove it. - GOOD - February 29th, 2024 [February 29th, 2024]
- What Is Organizational Behavior? Everything You Need To Know - MarketWatch - February 4th, 2024 [February 4th, 2024]
- Overcoming 'Otherness' in Scientific Research Commentary in Nature Human Behavior USA - English - USA - PR Newswire - February 4th, 2024 [February 4th, 2024]
- "Reichman University's behavioral economics program: Navigating human be - The Jerusalem Post - January 19th, 2024 [January 19th, 2024]
- Of trees, symbols of humankind, on Tu BShevat - The Jewish Star - January 19th, 2024 [January 19th, 2024]
- Tapping Into The Power Of Positive Psychology With Acclaimed Expert Niyc Pidgeon - GirlTalkHQ - January 19th, 2024 [January 19th, 2024]
- Don't just make resolutions, 'be the architect of your future self,' says Stanford-trained human behavior expert - CNBC - December 31st, 2023 [December 31st, 2023]
- Never happy? Humans tend to imagine how life could be better : Short Wave - NPR - December 31st, 2023 [December 31st, 2023]
- People who feel unhappy but hide it well usually exhibit these 9 behaviors - Hack Spirit - December 31st, 2023 [December 31st, 2023]
- If you display these 9 behaviors, you're being passive aggressive without realizing it - Hack Spirit - December 31st, 2023 [December 31st, 2023]
- Men who are relationship-oriented by nature usually display these 9 behaviors - Hack Spirit - December 31st, 2023 [December 31st, 2023]
- A look at the curious 'winter break' behavior of ChatGPT-4 - ReadWrite - December 14th, 2023 [December 14th, 2023]
- Neuroscience and Behavior Major (B.S.) | College of Liberal Arts - UNH's College of Liberal Arts - December 14th, 2023 [December 14th, 2023]
- The positive health effects of prosocial behaviors | News | Harvard ... - HSPH News - October 27th, 2023 [October 27th, 2023]
- The valuable link between succession planning and skills - Human Resource Executive - October 27th, 2023 [October 27th, 2023]
- Okinawa's ants show reduced seasonal behavior in areas with more human development - Phys.org - October 27th, 2023 [October 27th, 2023]
- How humans use their sense of smell to find their way | Penn Today - Penn Today - October 27th, 2023 [October 27th, 2023]
- Wrestling With Evil in the World, or Is It Something Else? - Psychiatric Times - October 27th, 2023 [October 27th, 2023]
- Shimmying like electric fish is a universal movement across species - Earth.com - October 27th, 2023 [October 27th, 2023]
- Why do dogs get the zoomies? - Care.com - October 27th, 2023 [October 27th, 2023]
- How Stuart Robinson's misconduct went overlooked for years - Washington Square News - October 27th, 2023 [October 27th, 2023]
- Whatchamacolumn: Homeless camps back in the news - News-Register - October 27th, 2023 [October 27th, 2023]
- Stunted Growth in Infants Reshapes Brain Function and Cognitive ... - Neuroscience News - October 27th, 2023 [October 27th, 2023]
- Social medias role in modeling human behavior, societies - kuwaittimes - October 27th, 2023 [October 27th, 2023]
- The gift of reformation - Living Lutheran - October 27th, 2023 [October 27th, 2023]
- After pandemic, birds are surprisingly becoming less fearful of humans - Study Finds - October 27th, 2023 [October 27th, 2023]
- Nick Treglia: The trouble with fairness and the search for truth - 1819 News - October 27th, 2023 [October 27th, 2023]
- Science has an answer for why people still wave on Zoom - Press Herald - October 27th, 2023 [October 27th, 2023]
- Orcas are learning terrifying new behaviors. Are they getting smarter? - Livescience.com - October 27th, 2023 [October 27th, 2023]
- Augmenting the Regulatory Worker: Are We Making Them Better or ... - BioSpace - October 27th, 2023 [October 27th, 2023]
- What "The Creator", a film about the future, tells us about the present - InCyber - October 27th, 2023 [October 27th, 2023]
- WashU Expert: Some parasites turn hosts into 'zombies' - The ... - Washington University in St. Louis - October 27th, 2023 [October 27th, 2023]
- Is secondhand smoke from vapes less toxic than from traditional ... - Missouri S&T News and Research - October 27th, 2023 [October 27th, 2023]
- How apocalyptic cults use psychological tricks to brainwash their ... - Big Think - October 27th, 2023 [October 27th, 2023]
- Human action pushing the world closer to environmental tipping ... - Morung Express - October 27th, 2023 [October 27th, 2023]
- What We Get When We Give | Harvard Medicine Magazine - Harvard University - October 27th, 2023 [October 27th, 2023]
- Psychological Anime: 12 Series You Should Watch - But Why Tho? - October 27th, 2023 [October 27th, 2023]
- Roosters May Recognize Their Reflections in Mirrors, Study Suggests - Smithsonian Magazine - October 27th, 2023 [October 27th, 2023]
- June 30 Zodiac: Sign, Traits, Compatibility and More - AZ Animals - May 13th, 2023 [May 13th, 2023]
- Indiana's Funding Ban for Kinsey Sex-Research Institute Threatens ... - The Chronicle of Higher Education - May 13th, 2023 [May 13th, 2023]
- Have AI Chatbots Developed Theory of Mind? What We Do and Do ... - The New York Times - March 31st, 2023 [March 31st, 2023]
- Scoop: Coming Up on a New Episode of HOUSEBROKEN on FOX ... - Broadway World - March 31st, 2023 [March 31st, 2023]
- Here's five fall 2023 classes to fire up your bookbag - Duke Chronicle - March 31st, 2023 [March 31st, 2023]
- McDonald: Aspen's like living in a 'Pullman town' - The Aspen Times - March 31st, 2023 [March 31st, 2023]
- Children Who Are Exposed to Awe-Inspiring Art Are More Likely to Become Generous, Empathic Adults, a New Study Says - artnet News - March 31st, 2023 [March 31st, 2023]
- DataDome Raises Another $42M to Prevent Bot Attacks in Real ... - AlleyWatch - March 31st, 2023 [March 31st, 2023]
- Observing group-living animals with drones may help us understand ... - Innovation Origins - March 31st, 2023 [March 31st, 2023]