| | March -20198IN MY OPINIONToo Few Cybersecurity Pros Is Continuing Challenge in 2019By Robert R. Ackerman Jr., Founder and MD, AllegisCyber, and Co-founder and Executive, DataTribeIt's the beginning of March 2019 and there is ostensibly a piece of good news on the cyber front. Major cyber attacks have been in a lull in recent months. The good tidings are fleeting, however. Attacks typically come in waves. The next one is due, and 2019 will be the worst year yet--a sad reality as companies increasingly pursue digitization to drive efficiency and simultaneously move into the "target zone" of cyberattacks.This bad news is compounded by the harsh reality that there are not nearly enough cybersecurity pros to properly respond to all the threats.The technology industry has never seen anything quite like it. Seasoned cyber pros typically earn $95,000 a year, often markedly more, and yet job openings can linger almost indefinitely. The ever-leaner cybersecurity workforce makes many companies desperate for help. Between September 2017 and August 2018, U.S. employers posted nearly 314,000 jobs for cybersecurity pros. If they could be filled, that would boost the country's current cyber workforce of 714,000 by more than 40 percent, according to the National Initiative for Cybersecurity Education. In light of the need, this is still the equivalent of pocket change. Global Gap of Nearly three Million Cybersecurity PositionsIn a recent study, (ISC)2--the world's largest nonprofit association of certified cybersecurity pros--said there is now a gap of almost three million cybersecurity jobs globally--substantially more than other experts said might be the case years into the future. Companies are trying to cope in part by relying more aggressively on artificial intelligence and machine learning, but this is still at a relatively nascent stage and can never do more than mitigate the problem. Big companies have their hands full, and it's even worse for smaller enterprises. They're attacked more--sometimes as a conduit to their larger business partners--because their defenses are weaker. So what kind of cyber talent are companies and government entities looking for?Preferably, they want people with a bachelor's degree in programming, computer science or computer engineering. They also warm up to an academic background replete with courses in statistics and math. They want cybersecurity certifications as well, and, of course, experience in specialties plagued by staffing shortages, such as intrusion detection, secure software development and network monitoring.These are ideal candidates, but, in fact, the backgrounds of budding cyber pros need not be nearly this good. Only Recently Has Formal Training Existed Cybersecurity has long been a field that has embraced people with nontraditional backgrounds. Almost no cybersecurity pro over 30 today has a degree in cybersecurity and many don't even have degrees in computer science. Professionals need some training to become familiar with select tools and technologies--usually at a community college or boot camp--but even more they need curiosity, knowledge of the current threat landscape and a strong passion for learning and research. Particularly strong candidates have backgrounds as programmers, systems administrators and network engineers.Asking too much from prospective pros isn't the only reason behind the severe cyber manpower shortage. In general, corporations do too little to help their cyber staffs stay technically current and even less when it comes to helping their IT staffs pitch in.(ISC) 2 formalized a study of more than 3,300 IT professionals approximately 18 months ago and learned that Robert R. Ackerman Jr.
< Page 7 | Page 9 >