


“There is skills shortage”; “there is a skills gap”; this is all we seem to see posted on Linkedin and Cyber Security Twitter these days. Is this the truth? What skills are there a shortage for? Are we short of SOC Analyst I, or Junior SOC Analyst’s? Maybe we are actually short of Senior RED Team SOC Team Lead’s. The insanity that is Cyber / Information Security job titles (or even whether we call it Cyber or Information Security) is a sign of an (ironically) immature industry. To compound the issue of a “skills shortage” try searching for a junior or entry level cyber job without being bombarded with adverts promising “guaranteed £50k job after doing this course”, we aren’t doing a good job of is attracting and training people.
We advise, guide, implement, review, and audit systems, data structures, business processes based on maturity and set targets for how mature a business needs to be. However, we have not introspected that to ourselves we are damaging our long-term survival as a legitimate, trusted, and essential part of any business organization by not knowing ourselves. Why do some Junior job roles still ask for multi-year experience, while some management level roles don’t require technical aptitude or knowledge.
When I look back at my early career in IT, I remember how disjointed IT was. Essentially reporting to finance and having little to no control over direction (I am aware this still happens more than we like to admit); now we have Security reporting to IT; repeating the same cycle all over again: one such job advert I saw had an information Security Manager reporting to the Deputy Head of IT! Not even Head of IT!
There is seemingly no structure to cyber security roles and responsibilities compared to say financial roles – Finance analysts, financial controllers, finance managers, CFO’s etc. all have known, dedicated, and documented responsibilities and a structured hierarchy. Is it possible (or even desired) to copy this into Cyber? The core of this is that security is seen as a specialism of IT, rather than (in my opinion) the other way round. IT projects, such as a new email system, can be delivered without security involved or even consulted, however delivering a security project without IT is not possible.
So, what can we do about? How can we make a difference to the industry we all find ourselves in, and no doubt find ourselves overworked. We need to begin to push for the “seat at the table”, we need to elevate security the way IT was when it came out from finance’s shadow, we need to bring security into the light and out of IT’s shadow.