The Cyber Security Review | Saturday, November 26, 2022
Hiring managers in cyber security are turning to exist employees in non-IT roles and providing professional development for junior-level staff to plug the talent gap.
FREMONT, CA: Organisations in the Asia-Pacific are turning to job advertisements, internships, and even applicants from other sectors to fill the cyber security talent shortage. The International Information System Security Certification Consortium (ISC)2) polled 787 respondents in Singapore, Hong Kong, Japan, and South Korea for its APAC cybersecurity recruiting managers research report.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
In Singapore, just under half of the respondents have found or hired cyber security talent through apprenticeship and internship programmes and recruitment agencies, compared to more than half of respondents (58 per cent) who rely on traditional job advertisements.
Companies have broadened their candidate sourcing strategies at the regional level, with hiring managers relying on current workers from non-traditional IT departments like customer service (43 per cent) and human resources (38 per cent) to fill entry-level and junior-level positions. Growing cyber security personnel deficit has been fueled by geopolitical tensions, macroeconomic instability, and expanding physical security challenges.
With APAC recording the second-highest increase in shortage year-over-year internationally, organisations in the region need to be innovative with their hiring practices for cyber security. Contrary to popular belief, an innovative strategy doesn't require employers to increase their hiring risks.
According to the (ISC)2 report, organisations can create more resilient and long-lasting cyber security teams by adopting a more cooperative hiring approach between HR and cyber security teams, identifying candidates with pertinent qualities and skills, and investing in their professional development.
62 per cent of respondents said they would employ a self-taught IT or cyber security professional despite their lack of job experience, with Singaporeans and Hongkongers being the most likely to do so. Prior professional experience was considered one of the most crucial qualities by 64 per cent of hiring managers in the region, followed by technical proficiency (56 per cent) and certificates (51 per cent)
The most highly regarded technical and non-technical qualities hiring managers look for from candidates are data security (34 per cent) and security administration (32 per cent), as well as the capacity to work well both alone and in a team (48 per cent) and (33 per cent). Additionally, the overwhelming majority of recruiting managers said that their companies offer some kind of professional development for their entry-level and junior employees. This includes anything from certification classes and training to paying for certification exam fees and mentorship programmes.
For entry-level and junior-level practitioners, in-house training programmes are regarded as the most successful means of talent development (60 per cent), followed by external training programmes (57 per cent), certifications (47 per cent), conferences (35 per cent), and mentorship (35 per cent). However, keeping young talent is equally important, especially in places like Australia and New Zealand (ANZ).
Employees with fewer than a year of experience are more likely to leave their jobs (64 per cent) than those with between one and two years of experience (44 per cent). The industry had a Net Promoter Score (NPS) for cyber security that was very poor at -9.4, making it on par with or even worse than the aviation and insurance sectors.
More in News