How to Close the Cybersecurity Talent Gap

144 views
•
May 6, 2015
by
RSAC Cybersecurity
YouTube video player
How to Close the Cybersecurity Talent Gap

TL;DR

Organizations can reduce the security talent shortage by embedding security into computer science education, every technical role, employee incentives, and university partnerships. They should retrain educators, evaluate student code for security, specify security skills in job descriptions, create targeted internships, reward developers who improve, and connect internal training credentials to important projects and career opportunities.

Transcript

Uh, my efforts at seating the audience worked well. Um, thank you very much for being here today. Welcome to another RSA Conference. It's awfully exciting. Um, what I wanna talk about is one of the biggest challenges that I think faces the IT industry, and in a sense, uh, all aspects of industry now that we're all consuming and depending on IT, and... Read More

Key Insights

  • The security talent shortage extends beyond dedicated security positions because developers and other technical employees also need enough security education to perform their regular responsibilities safely as organizations across many industries become dependent on information technology.
  • Security staffing was critically low in 2014, according to research cited from HP and the Ponemon Institute: roughly 40 percent of security roles were vacant, and the vacancy rate for senior individual contributors and managers reached 49 percent.
  • Leading computer science programs did not consistently require security education. Among the ten undergraduate programs examined, none required a security-focused course, and only three offered some software security material through a limited number of lectures rather than dedicated courses.
  • Computer science curricula require three connected reforms: security-aware teaching materials, retraining for professors and lecturers across subjects, and verification methods that let instructors evaluate student submissions for security as part of normal grading.
  • Organizational demand for security becomes visible when security skills appear in every relevant job description, security investments feature positively in customer and partner communications, and security priorities are discussed during outsourcing arrangements, mergers, and acquisitions.
  • Security-focused internships can create a practical hiring pipeline by bringing college juniors and seniors into an organization, teaching them the security knowledge the employer needs, and hiring successful participants as full-time employees after graduation.
  • Developer incentives can change organizational culture when bonuses reward both avoiding security mistakes and learning from identified problems by correcting them quickly, making security performance a visible priority throughout the development organization.
  • University partnerships can improve recruiting and education by connecting a company with a specific school, professor, or project. Companies contribute real-world information about attacks and responses, while professors can direct strong students toward employment opportunities.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How can organizations close the cybersecurity talent gap?

Organizations can address the gap through education, hiring, internal development, and academic partnerships. Recommended actions include improving computer science curricula, retraining educators, evaluating student code for security, including security skills in technical job descriptions, operating security-focused internships, rewarding developers for secure behavior, connecting training credentials to important projects, and sharing practical industry knowledge with professors and students.

Q: Why must computer science curricula include security?

Computer science curricula must include security because most programmers enter the workforce after undergraduate training, yet the programs examined did not make security a fundamental requirement. None of the ten leading programs studied required a security-focused course, and only three offered limited software security topics. Graduates therefore may begin professional development work without learning how to create secure software.

Q: What changes are needed in computer science education?

Computer science education needs changes in three areas. Textbooks, quizzes, laboratories, and other instructional materials should incorporate security. Professors and lecturers should receive updated training, including educators who teach operating systems, networks, and data structures. Finally, instructors need methods for grading major code submissions for security, because insecure work would not be acceptable in a professional environment.

Q: How should companies show that security is a hiring priority?

Companies should include the appropriate security skills in every relevant job description, including positions for programmers, testers, and IT operations engineers. They should also discuss security positively in communications with customers and partners and include it in decisions involving outsourcing, mergers, and acquisitions. These repeated signals demonstrate internally and externally that security is a genuine organizational priority.

Q: How can security internships help address talent shortages?

A security-focused internship program can bring college juniors and seniors into an organization before graduation. The employer can train these students in the specific security knowledge needed for its work while they are still relatively inexpensive to employ. Successful interns can then become full-time employees after completing school, creating a direct pipeline for attracting and developing security talent.

Q: How can employee incentives improve software security?

Employee incentives can reinforce security by financially rewarding developers who avoid mistakes, learn from discovered problems, and correct them quickly. The financial services example in the talk connected developer bonuses to measurements from a software security assurance program using static code review. This approach made security a visible priority across the development organization and supported broader cultural change.

Q: How does gamified security training support career development?

Gamified training can recognize employees with colored belts after they demonstrate particular security knowledge or complete specific instruction. Its greater value comes from linking those credentials to project governance. Projects with certain budgets or external visibility require appropriately trained security resources, making credentialed employees sought after and giving them a clear career path that supports attraction and retention.

Q: How can companies partner with universities to develop security talent?

A company can select a convenient or trusted university, identify a professor or project, and invest time, information, and resources in the relationship. Industry participants can share what attacks companies are seeing and which responses are realistic, addressing academia's limited real-world visibility. Professors can reciprocate through research collaboration and by directing their strongest students toward the company as potential recruits.

Summary & Key Takeaways

  • The security talent shortage affects both dedicated security teams and technical employees such as developers. Research cited in the talk found that roughly 40 percent of security roles were vacant throughout 2014, while vacancies among senior individual contributors and managers reached 49 percent, leaving organizations significantly understaffed against capable and motivated adversaries.

  • Computer science education must treat security as a fundamental requirement rather than a narrow specialty. Necessary reforms include updating textbooks, labs, quizzes, and other teaching materials, retraining professors across technical subjects, and enabling teaching staff to assess major programming projects for security so academic expectations reflect real workplace requirements.

  • Organizations can act sooner by placing security requirements in job descriptions, external communications, business relationships, internships, incentives, and internal training. They can also partner directly with nearby or trusted universities, professors, and research projects, sharing practical information while building recruiting pipelines and improving academia's visibility into current attacks and realistic organizational responses.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚