How to Close the Cybersecurity Talent Gap

359 views
β€’
February 25, 2020
by
RSAC Cybersecurity
YouTube video player
How to Close the Cybersecurity Talent Gap

TL;DR

Close the cybersecurity talent gap by addressing the leadership and culture problems that undermine recruitment, engagement, and retention. Leaders should help employees believe in the mission and themselves, feel that they belong to an accountable team, and know that their contributions matter, while visibly defending the team against internal barriers such as budgets, bureaucracy, and counterproductive behavior.

Transcript

Ever wonder how to create lasting employee and management commitments? How to reduce the talent gap that is plaguing all of us, and how to do this with resilience? Our next speaker, Malcolm Harkins from Cymatic, will be speaking to us on, I Believe, I Belong, I Matter: Solving the Cyber Risk Talent Gap. Malcolm. Thank you. So you guys don't mind, I... Read More

Key Insights

  • The cybersecurity skills gap is partly a leadership gap because weak culture, inconsistent executive behavior, and poor board engagement can drive dissatisfaction and turnover even when qualified professionals are available or attracted to the mission.
  • The "I believe, I belong, I matter" framework identifies three conditions that can explain performance and retention problems: confidence in oneself and the mission, membership in an accountable team, and recognition that one’s work has meaningful value.
  • Belief is a force multiplier because employees with purpose and conviction can perform beyond what their team size might suggest. Managers create this effect by expressing confidence in people, clarifying the mission, and helping employees overcome perceived limits.
  • Credible leadership requires alignment between words and actions because employees observe what executives do after declaring cybersecurity important. A message loses credibility when leaders publicly endorse security but later compromise it through their decisions or behavior.
  • Belonging is built through shared identity and mutual accountability. The football example shows how repeatedly emphasizing the team, family, common history, collective effort, and responsibility to teammates can connect individual performance to a larger mission.
  • Cybersecurity leaders operate on two battlefields: an external battlefield involving threat actors and threat agents, and an internal battlefield involving budgets, bureaucracies, and behaviors. Leaders should manage internal obstacles so practitioners can focus on external risk.
  • Employee openness is a measure of leadership trust because people stop bringing problems forward when they believe a leader cannot help or does not care. Either conclusion prevents leaders from seeing and resolving important organizational issues.
  • The cybersecurity industry has economic incentives that deserve scrutiny because vendors profit from continued insecurity, risk, and cost. Security leaders should therefore examine whether outside partners genuinely support the organization’s mission rather than assuming interests are aligned.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How can leaders close the cybersecurity talent gap?

Leaders can reduce the cybersecurity talent gap by improving the conditions that attract, engage, and retain people. The talk recommends building three experiences: employees believe in themselves and the mission, feel that they belong to an accountable team, and know that their contributions matter. Leaders must also act consistently with their stated security priorities and protect teams from internal obstacles involving budgets, bureaucracy, and behavior.

Q: What does "I believe, I belong, I matter" mean at work?

"I believe" means having confidence in oneself, the messenger, and the organization’s purpose. "I belong" means identifying with a team that shares a mission and holds members accountable to one another. "I matter" means understanding that one’s work and presence have real value. Malcolm Harkins presents missing elements in this framework as common explanations for performance problems, disengagement, and employee turnover.

Q: Why is the cybersecurity talent gap also a leadership problem?

The talent gap is also a leadership problem because workplace culture and executive conduct influence whether professionals stay engaged or leave. The talk cites 60 percent job dissatisfaction, 56 percent reporting inadequate board engagement, and almost 40 percent of CISOs changing jobs because of cybersecurity culture. These figures suggest that recruiting more people alone cannot correct environments that weaken trust, purpose, and commitment.

Q: How does belief improve cybersecurity team performance?

Belief improves performance by giving employees purpose, conviction, and confidence that they can overcome limits. Harkins calls this a force multiplier for small teams that need to perform above what their size might suggest. Leaders cultivate belief by clearly communicating what they stand for, demonstrating confidence in employees, helping them through setbacks, and visibly acting in accordance with the mission they ask others to support.

Q: How can cybersecurity leaders create a sense of belonging?

Cybersecurity leaders create belonging by establishing a shared identity, emphasizing a common mission, and making colleagues accountable to one another. The football example illustrates how a leader connects current team members with the organization’s history, the wider community, and collective performance. Belonging becomes credible when leaders also accept responsibility for supporting their people and when the organization demonstrates that it values the security mission.

Q: Why must leaders align their actions with their security messages?

Leaders must align actions with messages because employees judge commitment by observed behavior, not ceremonial statements. The talk contrasts executives who declare cybersecurity important with decisions that compromise security afterward. If employees do not believe the messenger, they cannot fully believe the message. Leaders therefore need to clarify their convictions, communicate them repeatedly, and demonstrate those convictions through actual budget, policy, and operational choices.

Q: What are the two battlefields faced by a CISO?

A CISO faces an external battlefield of threat actors and threat agents, plus an internal battlefield of budgets, bureaucracies, and behaviors. Harkins argues that the leader should be capable of fighting the internal battle so the security team can concentrate on the external one. This division also demonstrates accountability: practitioners protect the organization from threats while their leader addresses institutional barriers that could prevent effective performance.

Q: Why should security teams keep bringing problems to leaders?

Teams should bring problems to leaders because open reporting allows leadership to understand and address risks. The talk uses Colin Powell’s statement that when soldiers stop bringing problems, they have either lost confidence that the leader can help or concluded that the leader does not care. Both outcomes represent leadership failure. Trustworthy leaders must therefore remain approachable, responsive, and visibly committed to helping employees resolve difficult issues.

Summary & Key Takeaways

  • The cybersecurity talent gap is partly a leadership gap. Survey figures cited in the talk show widespread job dissatisfaction, concern about organizational vulnerability, inadequate engagement with boards, and CISO turnover attributed to cybersecurity culture. These conditions weaken trust, commitment, recruitment, and retention even when organizations claim security is important.

  • The framework of "I believe, I belong, I matter" helps leaders diagnose performance, engagement, and turnover problems. Belief gives employees purpose and conviction. Belonging connects them to a shared mission and mutual accountability. Knowing that they matter requires leaders to demonstrate that each person and contribution has genuine value.

  • Effective cybersecurity leaders communicate what they believe and support those beliefs through visible action. They motivate people to struggle for shared aspirations, protect practitioners from internal battles involving budgets, bureaucracy, and behavior, and build resilient teams that can concentrate on external threats while remaining committed to one another and their mission.


Read in Other Languages (beta)

Share This Summary πŸ“š

Explore More Summaries from RSAC Cybersecurity πŸ“š