How to Retain and Grow Cybersecurity Talent

165 views
•
May 16, 2019
by
RSAC Cybersecurity
YouTube video player
How to Retain and Grow Cybersecurity Talent

TL;DR

Retain cybersecurity talent by creating a positive, psychologically safe workplace with clear roles, training, career development, and succession planning. A common language for projects and tasks helps employees understand their responsibilities and growth paths, while leaders must support workforce development, secure realistic staffing budgets, and manage upward when organizational change does not begin at the top.

Transcript

We've got 50 minutes on the topic that is plaguing us most, and I am definitely gonna dump content on you that I really believe can change the game if you implement it. So questions during, uh, are certainly, uh, good for me, and I'll absolutely leave time at the end. My name is Deidre Diamond. I'm the founder and CEO of CyberSN and brainbabe.org. ... Read More

Key Insights

  • Retention is the foundation of cybersecurity recruiting because employees who experience a positive environment are more likely to stay and recommend their organization. The speaker argues that companies that learn how to retain talent will also improve their ability to attract it.
  • A positive workforce environment is a major retention factor because 62 percent of people who recently left their companies reportedly said they would have stayed under better conditions. This makes culture, support, psychological safety, and employee development operational priorities rather than optional benefits.
  • Cybersecurity roles are unusually complex because the field contains 35 job categories and more than 100 titles. Broad labels such as engineer, analyst, and GRC can conceal many distinct profiles, which creates confusion in hiring, staffing, responsibility assignment, and career planning.
  • Psychological safety is essential to workforce happiness because cybersecurity professionals face mental health pressures, organizational reluctance to fund adequate staffing, and situations where one person effectively performs three jobs. Leaders are responsible for creating environments in which employees can receive support and succeed.
  • Clear career development depends on a common language for cybersecurity projects and tasks. Defining work consistently can help organizations distinguish roles, communicate responsibilities, identify training needs, and create succession plans that show employees how they can progress without leaving the company.
  • Leadership responsibility begins with accepting accountability for other people. The speaker argues that anyone holding a management or leadership title must care for the humans they oversee and should not treat business performance, successful projects, employee happiness, and supportive relationships as mutually exclusive outcomes.
  • Frequent executive turnover limits organizational progress because a senior hire may require at least one year to become situated and another year to produce meaningful progress. If that person leaves around 24 months, a substantial portion of the tenure may also have been spent searching for another position.
  • Managing upward is necessary when workforce improvements do not flow from executives or boards. The speaker recommends situational leadership as a model for influencing upward, while emphasizing that cybersecurity leaders still need suitable budgets, organizational support, and recruiting resources to build effective teams.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How can organizations retain cybersecurity talent?

Organizations can retain cybersecurity talent by creating a positive workforce environment, offering psychological safety, training employees repeatedly, clarifying roles and responsibilities, and building visible career development and succession plans. The talk recommends using a common language for cybersecurity projects and tasks so employees understand their current work, required skills, and potential progression. Leaders must also provide realistic staffing support and budgets.

Q: Why does workplace culture affect cybersecurity retention?

Workplace culture affects retention because employees are more likely to remain where they feel supported, respected, developed, and safe. The talk states that 62 percent of people who recently left their companies said they would have stayed if they had experienced a positive workforce environment. Culture therefore influences whether professionals remain committed or quietly begin searching for another job.

Q: How does a common cybersecurity language support career development?

A common language for cybersecurity projects and tasks gives organizations a consistent way to describe work, responsibilities, and required capabilities. This is important because cybersecurity contains 35 job categories and more than 100 titles, while labels such as engineer, analyst, and GRC can represent multiple profiles. Clear definitions support training plans, career paths, hiring decisions, and succession planning.

Q: Why are cybersecurity job titles difficult to use in hiring?

Cybersecurity job titles are difficult to use because the same broad title can describe substantially different responsibilities. The speaker notes that engineers and analysts can each represent many profiles, while GRC work also varies. With 35 job categories and more than 100 titles, recruiters and managers may misunderstand candidates or requirements unless projects, tasks, roles, and responsibilities are defined more precisely.

Q: What causes mental health pressure in cybersecurity roles?

Mental health pressure can arise from how coworkers treat one another, insufficient organizational support, unclear responsibilities, and inadequate budgets. The talk also describes cybersecurity as a relatively new workforce discipline in which professionals may be expected to perform the equivalent of three jobs. These conditions can create overwhelm, especially when leaders lack the staff or resources needed to distribute work appropriately.

Q: Why should cybersecurity leaders prioritize retention over recruitment?

Cybersecurity leaders should prioritize retention because a workplace that keeps employees can also become better at attracting them. The speaker argues that organizations do not need separate strategies for getting and retaining talent when strong retention produces reputation, relationships, and continuity. By contrast, persistent turnover weakens commitment, forces repeated hiring, and leaves employees searching privately while still working for their current organizations.

Q: How does short executive tenure affect cybersecurity programs?

Short executive tenure can prevent cybersecurity programs from reaching sustained progress. The speaker says a senior hire may need at least one year to become situated and another year to make progress. If executives leave after approximately 24 months, and spend six months to a year searching for their next role, both the organization and the individual lose substantial productive time.

Q: What should cybersecurity managers do when executives do not lead workforce change?

Cybersecurity managers should learn to manage upward when improvements do not originate with chief executives, boards, or other senior leaders. The talk points to situational leadership as a useful model for this purpose. Managers should communicate staffing needs, seek appropriate budgets, clarify responsibilities, advocate for training and succession planning, and remain accountable for the people whose work and development they oversee.

Summary & Key Takeaways

  • Cybersecurity organizations should focus first on retaining employees because a positive workplace can also strengthen recruitment. The talk cites workforce dissatisfaction, frequent job changes, unclear responsibilities, excessive workloads, and inadequate support as interconnected problems. Leaders can address them through training, psychological safety, clear career paths, and genuine responsibility for employee development.

  • Cybersecurity workforce planning is complicated by extensive role variation. The speaker identifies 35 job categories and more than 100 titles, noting that labels such as engineer, analyst, and GRC can represent very different profiles. A common language for projects and tasks can clarify responsibilities, improve hiring, and support structured succession planning.

  • Long tenures and deliberate development can benefit employees and organizations alike. Senior hires may need a year to become situated and another year to make progress, so departures around 24 months can undermine performance. Organizations should provide adequate budgets, specialized recruiting support, role clarity, mentorship, training, and environments where people feel supported.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚