Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Too Many Threats, Too Few Professionals
Articles

Too Many Threats, Too Few Professionals

ISBuzz TeamBy ISBuzz TeamMay 15, 2014Updated:December 4, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Healthcare Firm ILS Alerts 4.2 million people of Data Breach
Healthcare Firm ILS Alerts 4.2 million people of Data Breach
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

According to the Cisco Annual Security Report 2014 (graphic below), there are approximately one million unfilled Security jobs worldwide. The supposed ‘war on talent’ (a phrase I hugely dislike I must add) is nothing new, but to a lot of people data breaches and information security flaws are featuring in the mainstream news streams for the first time. So how do we as an industry go about attracting and, possibly more importantly, retaining top talent in Security? It got me thinking about some relatively simple steps that could be taken in the short term.

I specialise in recruiting Security professionals into End Users and Enterprises, and because of this I am privy to quite varying levels of maturity within internal and external security processes and policies. I am also able to speak with some incredible clients and candidates on a daily basis who are able to share stories of companies that lack genuinely specialist Information or IT Security teams or have poorly implemented policies (I’m fortunate to deal with companies that have quite excellent policies and teams in place at the same time, but that is for another blog!).

My point being, I feel there are two main ‘problems’ to overcome which will help bridge the talent gap.

Firstly, a lot of firms still seem to neglect how severe cyber threats genuinely are. The results of a recent study by Atomic Research () prompted many industry commentators to remark how “nearly all recently publicly declared breaches had gone on for months without detection”. Many of the CIO’s and CISO’s I speak with still feel that Security is viewed as a ‘bolt on’ rather than critical infrastructure in today’s business world. Because of this, opportunities are not being created for candidates to either enter the market or expand on their skill sets. With a lack of investment comes an unfortunate lack of up skilling, therefore the talent pool is not growing leaving opportunities unanswered.

A lot of the time security is seen as expensive, whether it is the processes and technology to be put into place or the staff being hired. So is there a way around one of those problems? Could firms open up positions to school leavers as well as graduates, or candidates with lower levels of experience but an eagerness to progress in our ever expanding industry? Again I often speak to candidates who despite having some industry experience cannot make the next step in their careers and feel that they stagnate without the opportunities to grow their knowledge and help protect their employers from ever changing breaches.

Secondly, and perhaps more simply, is how employers raise employee’s awareness of IT and Information Security. I read recently about how Channel 4 and AXA approach their employees and hold ‘drop in sessions’ about protecting their own devices, and therefore hoping they adopt the same mindset in the workplace. Relatively straightforward initiatives like this will help raise the profile of Security and perhaps increase interest from those that hadn’t previously thought about entering our industry. Whilst this isn’t the answer to all of our problems, it may certainly help make that gap a little bit smaller. Do you feel that your company could do something similar to help ease the gap?

I think if the industry opens up to those two points, amongst others, then the gap could start to bridge.

Jason Waterman, Principcal Consultant at Badenoch & Clark, @JasonWatermanBC

badenoch&ClarkJason has over 6 years recruitment experience purely within the security and technology markets. His aim is to develop long term, lasting partnerships with key decision makers, providing proven, cost effective and bespoke, recruitment delivery solutions whilst also building constructive and equally as important relationships with candidates. He has held a MIRP CertRP (REC) qualification since 2009 and was an Ambassador for the Institute of Recruiters (IOR) for over a year.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Understanding Cloud Access Security Brokers (CASB)

March 28, 202410 Mins Read

Decoding Cloud Security Posture Management (CSPM)

March 28, 202411 Mins Read

Master Cloud Compliance Tools: Achieve Regulatory Success

March 28, 202411 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}