Cybersecurity Analytics and Operations Skills Shortage
Cybersecurity Analytics and Operations Skills Shortage
Ability to detect and respond to threats is greatly impeded by a lack of skills and staff. Leading organizations offer a few suggestions.
If you’ve followed my writing, you know that I passionately broadcast issues related to the global cybersecurity skills shortage. Allow me to report some sad news – things aren’t improving at all. In 2016, 46% of organizations reported a problematic shortage of cybersecurity skills. In 2017, the research is statistically the same as last year, 45% of organizations say they have a problematic shortage of cybersecurity skills.
Now these numbers point to an overall dearth of talent but the cybersecurity skills shortage is especially pronounced in cybersecurity analytics and operations. For example:
- According to 2016 research conducted by ESG and the Information Systems Security Association ( ISSA ) 33% of respondents said that their biggest shortage of cybersecurity skills was in security analysis and investigations. Security analysis and investigations represented the highest shortage of all security skill sets.
- Recent ESG research reveals that 54% of survey respondents believe that their cybersecurity analytics and operations skill levels are inappropriate, while 57% of survey respondents believe that their cybersecurity analytics and operations staff size is inappropriate.
The ramifications of skills and staff deficiencies are also apparent in the research. Cybersecurity operations staffs are particularly weak at things like threat hunting, assessing and prioritizing security alerts, computer forensics, and tracking the lifecycle of security incidents.
Of course, many CISOs propose an easy fix – simply hire more cybersecurity staff to bridge the knowledge and staffing gaps. In fact, 81% of the cybersecurity professionals surveyed say that their organization plans to add cybersecurity headcount this year.