版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
TACKLING
THECYBERSKILLSGAP
GlobalCyberSecurityReport2023
Expertsin
Technology
CONTENTS
03—IntroductionJamesMilligan,GlobalHeadofTechnologySolutions
04—Aboutthesurvey
05—OrganisationReportingstructure,attackexperiencesandstrategy
06—InvestmentShareofbudgetandchangestospendfor2023
07—HiringIn-demandskillsandrecruitingtalent
08—RetentionandskillsRetainingandupskillingexistingtalent
09—TheHaysview
10—CyberintheSpotlightvideoseries
11—Nextsteps
2|GlobalCyberSecurityReport2023
3|GlobalCyberSecurityReport2023
INTRODUCTION
THEDEMANDFORCYBERSKILLS
Whileitwasalreadybecominganecessityforthevastmajority
oforganisations,recenteventshavemeantthattherateofdigital
transformationhasacceleratedoverthelastthreeyears.Thatmeansanincreaseindatamanagement,whilehybridandremoteworkingmeansthatworkersneedsecureaccesstotheiremployers’servers.These
changeshaveaffordedthreatactorsgreateropportunitiestoexploitorganisationsandinfrastructurethaneverbefore,aswellasprovidedaddedmotive.
Allofthishasmeantthatthedemandforpeoplewithcybersecurity
skillshasincreased.AtHays,weplacedover750peopleintorolesin
2022asorganisationssoughtthetalentneededtoimplementtheir
defencestrategies.However,asthisdemandoutweighsthesupplyof
peoplewithexperienceoraccreditationsincybersecurity,it’snotalwaysstraightforwardtofillthoseroles.
Isthisskillsshortageaffectingorganisationssignificantly?And,ifso,how?
Thisiswhywe’vedecidedthatit’stherighttimetocreateourfirstglobalreport.Ourstudy,carriedoutinthefinalmonthsof2022,aimedtoexplorehoworganisationsaroundtheworldhaveadaptedtheircybersecurity
strategytotackletoday’sthreats,aswellasthechallengesthey’vefacedindoingso.Bysurveyingsecurityleadersfromacrossseveralindustriesandsenioritylevels,wewantedtodiscoverwhichfactorswereimpactingtheirabilitytohireandretaintalent,andwhetherthelevelofinvestmentfrom
theirorganisationismeetingtheirneeds.
Themostrevealingfindingwastheextenttowhichorganisationshavebeenimpactedbythelackofqualifiedcandidatesincybersecurity.
Overall,90percentofleaderssaidtheskillsgaphadaffectedtheirabilitytoimplementtheircybersecuritystrategy.
It’snotbeeneasytoaddress,either.Hiringtalentisanissue,withroughlytwothirdsofleadersadmittingthattheydonotratetheirorganisation’s
abilitytorecruitpeopleworkingincybersecurityhighly.Findingincentivestoretainandtrainyourexistingtalentbecomesevenmoreimportant,
especiallyastheyreceiveoffersfromorganisationsfacingthesameproblem.Providinglearningresourcesisattractivetoemployeesand,giventhebenefitsitbringstoanorganisation’scybersecuritystrategy,theinvestmentisworthit.
Despitethis,manyofourrespondentswereconcernedaboutthefundsbeingallocatedtocybersecuritywithintheirorganisation.Although
companieshavereactedtoglobaleventsbyputtingmoremoneyintosecurity,almosthalfofleadersexpectminimalchangetotheirbudgetin2023.
Ourstudyhasshownthatfindingandhiringtherighttalentisasignificantchallengeforbusinessesglobally,andthatthelackofskillsisaffectingsecurity.What’sthesolution?
90%ofleaderssaidtheskillsgap
hadaffectedtheirabilitytoimplementtheircybersecuritystrategy.
AtHays,weliketotalkaboutundiscoveredtalent.Ononehand,these
mightbepeopleouttherewhodon’thavetheexactexperiencethat
organisationsareseeking,butwouldbeahugeassetifthey’reopento
training.Ontheotherhand,undiscoveredtalentmayalsorefertothosewhoaren’tgiventhesameopportunitiesastheirpeersineithereducationortheworldofwork,butcanbringplentytoyourorganisation.Inadditiontopeoplecomingfromalowsocio-economicbackground,therearealso
thoseweaimtohelpthroughour
FocusingOnEmploymentInequity
report
,suchasthoselivingwithadisabilityoryoungpeoplestrugglingtostartonthecareerladder.
Inthisreport,you’llfindinsightsonallofthechallengesthatcyber
securityleadersarefacingin2023,fromprotectingtheirorganisationtoretainingtrainedemployees.Ifyouarehavingsimilarexperiencestoourrespondents,we’vealsosuggestedsomestepsthatyoucantaketoensuresustainablecybersecuritysuccess.
Lastly,I’dliketothankalloftherespondentswhotookthetimeto
completeoursurvey.Withoutyourhelp,wewouldnotbeabletoprovidetheseinsights.
JamesMilligan
GlobalHeadofTechnologySolutions,Hays
ABOUTTHESURVEY
Wecarriedoutourresearchacross29countries,surveyingover1,000cybersecurityleaders.Thestudyexploredhoworganisationsarerespondingtorecentglobalevents,theirinvestmentincybersecurity,theirchallengesinhiringandretainingstaff,aswellastheskillsourrespondentssoughtandhowtheseweredevelopedamongtheworkforce.
Whenexaminingthedata,weinvestigatedwhethertherewereanydiscrepanciesfromregiontoregion,inordertoprovidelocalinsights.However,ouranalysisrevealedlittletonovariation-thefindingsinthisreportreflectwhatishappeningaroundtheglobe,asleadersfacethesamechallengesandturntothesamesolutions.
UKIandEMEA
•Austria
•Belgium
•CzechRepublic
•France
•Germany
•Hungary
•Ireland
•Italy
•Luxembourg
•Poland
•Portugal
•SaudiArabia
•Spain
•Sweden
•Switzerland•UK
•UAE
Americas
•Brazil
•Canada
•Chile
•Colombia
•Mexico•USA
AsiaandANZ
•Australia
•China
•Japan
•Malaysia
•NewZealand
•Singapore
4|GlobalCyberSecurityReport2023
Employeesatourrespondents’organisations
5,000+
37%
101-1,000
25%
Senioritylevelofourrespondents
C-suite
16%
Director
24%
Manager
50%
1,001-5,000
21%
0-100
17%
10%
VP
experienced?
Whattypeofattackshave
Cybersecurityteamsarenotalwayspositionedstrategically
you
Manyleadersreportthatrecentglobalevents,suchasgeo-political
Phishing
84%
Malware/Virus
48%
34%
External
46%
ofleadersdonotbelievethattheircybersecurityteamreportsintotherightpartoftheirorganisation
Ransomware
31%
DataLoss/Theft
30%
Thepandemicandgeo-politicalclimatehaveaffectedorganisations’security
72%
ofleadersfeelthatrecent
globaleventshavehada
‘Major’or‘Moderate’impactontheirorganisation’scyberriskprofile
5|GlobalCyberSecurityReport2023
conflictsandthepandemic,haveaffectedthecyberriskprofileattheirorganisation.
Thepandemicinparticularhasacceleratedtheneedfordigital
transformation,whichhasgivengreateropportunitiestocyber
criminals-84percentofleadersreportingthattheirorganisation
experiencedaphishingattackin2022.Employeeshavehadto
becomesavvierasaresult,with77percentofleadersreportingthatcybersecurityawarenessisgreaterthanitwasthreeyearsago.
Organisationshavehadtorespondswiftlytocombatpotentialthreats,butincorporatingcybersecurityintotheirstrategyhasnotbeena
naturalprocessforeveryone.Athirdofleadersdonotagreethat
cybersecuritysitsinthecorrectreportinglinewithintheirbusiness.
77%
ofleadersstatethatsecurityawarenessintheirorganisationisgreaterthanin2019
ORGANISATION
Inordertogaininsightsintohoworganisationsarerespondingtocyberthreats,
weneededtounderstandhowtheyarebeingaffectedandwheretheirsecurityteam
fitsinthereportingline.
Obtaininginvestmentincybersecurityhasbeeneasiersincethepandemic
Whatisyourorganisation’sannualspendincybersecurityinproportiontoITbudget?
Withsecurityaconcernacrosstheglobe,leadersarelookingfora
0-2%
Stronglyagree
14%
11%
3-4%
Agree
15%
34%
Neutral
5-6%
18%
37%
Disagree
7-8%
10%
14%
Stronglydisagree
3%
N/A
1%
9-10%
21%
11%+
22%
Investmentisnotnecessarilyalignedwithsecurityleaders’needs
47%
ofleadersexpect“Minimalchange”totheirbudget
in2023
6|GlobalCyberSecurityReport2023
financialcommitmentfromtheirorganisation.Overafifthofour
respondentsreportthatatleasttenpercentoftheirorganisation’sITspendisallocatedtosecurity.
However,whileonly17percentofleadersdisagreewiththestatementthatinvestmentincybersecurityhasbeeneasiertoreceivesince
thepandemic,almosthalfexpectminimalchangetotheirbudgetin2023.Asaresult,thereisaconcernoverwhetherinvestmentincybersecuritywillbesufficientfortacklingtoday’sthreats.
68%
ofleadersare“Extremely”,“Very”,or“Moderately”
concernedabouttheirbudgetin2023
INVESTMENT
Wewantedtoexplorehoworganisationsareinvestingincybersecurity,andwhethertheirbudgethasincreasedasaresultofglobaleventsandtrends.
seek
skills
front-line
recruitcybersecuritytalent
Organisations
Organisationsstruggleto
Topfivechallengesinhiringtalent
Whenaskedwhatwouldimprovethesecuritycapabilityattheir
organisation,leadersmostlynamedskillsthatwouldreinforce
thefrontlineofdefence,suchascloudsecurityandarchitecture.
Thisalignswithourowninsights,asgloballywe’reseeinghighestdemandforengineersandarchitects.However,thechallengeistofindworkerswiththeknowledgeandexperiencerequiredtofillroleswithintheirorganisation.
Meanwhile,leadersfacecompetitioninhiringthosewiththerightcredentials,who,inturn,areabletodemandahighersalary.Infact,twothirdsofleadersdonotratetheirabilitytoattractcybersecuritytalenthighly.
Thismeansthatorganisationsmustlookforunexploredoruntrainedtalent,anapproachthattheyareopento.Overhalfoftheleaders
surveyedstatethattheyarelikelytohireworkerswhodon’tholdformalaccreditations.
“Two-thirdsofleadersdonot
ratetheirabilitytoattractcybersecuritytalenthighly.”
7|GlobalCyberSecurityReport2023
1Salaryexpectation
2Missingskills
3Competition
4Lengthofworkingexperience
5Lackofexperienceatasimilarorganisation
Topfiveskills/implementationsthatwouldenhancesecuritycapability
1Cloudsecurity
2Governance,RiskandCompliance
3SecurityArchitecture
4SecurityEngineering
5
SIEM/SOC
HIRING
Withtheskillsgapposingproblemsintech,wewantedtounderstandthechallengesthat
organisationsfaceinrecruitingtalent.
66%
ofleadersdonotrate
theirorganisation’sability
toattractcybersecurity
talenthighly
talent
turning
Employersare
tounexplored
56%
ofleadersarelikelyto
recruitsomebodywithout
formalITsecurity
accreditations
Theshortageinskillsishavinganimpactacrosstheboard,with90percentofleadersrevealingthatithasaffectedtheirsecurityimplementation.Iftheexperiencedtalentisn’treadilyavailable,organisationsmustfindnewwaystofilltheseroles.
Inordertoclosetheskillsgap,leadersbelieveupskillingand
cross-trainingtheirteammembers(i.e.teachingthemhowtoperforminnewroles)arethebestroutestosuccess.Indeed,manyleaders
reportthattheirorganisationinvestsintrainingemployees;however,thisinvestmentdoesnotstretchtoretainingtheirexistingtalent,as
employersinsteadofferwork-lifebalanceperksovermonetaryreward.
RETENTION&SKILLS
Inadditiontohiring,howareorganisationsretainingexistingtalent
andequippingthemwiththeskillstheyneed?
Skillsshortages
areaffectingsecurity
90%
ofleadersbelieveaskills
shortagehasimpactedtheirabilitytoimplementtheir
cybersecuritystrategy
“Manyleadersreportthattheirorganisationinvestsintrainingemployees;however,this
investmentdoesnotstretchtoretainingtheirexistingtalent”
8|GlobalCyberSecurityReport2023
Skillsdevelopmentisusedforthebenefitoforganisationsandworkersalike
Topfivestrategiestoclosethecybersecurityskillsgap
1Upskilling
2Cross-training
3Recruitmentpartner
4Hire,trainanddeploy
5Universityoutreach
Topfivestrategiesforcybersecuritytalentretention
1Remoteandhybridworkingarrangements
2Work-lifebalance/Wellnessoffering
3Flexiblehours
4Professionaldevelopmentopportunities
5Careergrowth&progression
It’snecessarytoequiptheworkforcewithnewskills
71%
ofleaderssaythattheir
organisationinvests
inupskillingitscyber
securityworkforce
THEHAYSVIEW
Haysexpertsgivetheirthoughtsonthefindingsinourreport
andwhattheymeanforleadersin2023.
EdmondPang
Director,CyberSecurity,APAC
Similartothegloballandscape,thereis
nosurprisethatcyberthreatshaveincreasedintheAPACregiongivenCOVIDlockdownsbeingtheperfectstorm,withsomehigh-profile
breacheshighlightedinthemedia.Asaresult,we’reseeingcountriessteppingupwiththeirpoliciesandinvestmentintocyber.
Forexample,Australiahasincreasedpenaltiesforbusinessesthatdonotsufficientlyprotectcustomerdata,whiletheSecurityOfCritical
InfrastructureAct(SOCI)hasbeenamendedtostrengthenthesecurityandresilienceofcriticalinfrastructure.NewZealandhasupdatedandfinalisedtheNewZealandInformationSecurityManual(NZISM)withfourpolicychangesinSeptember2022.Japanhassteppedupon
regulatoryrequirementsinindustriessuchasBankingandInsurance,andtheMalaysiangovernmenthasannouncedincreasedfundingsintotheTech&Cybersecurityspace.
Overall,theAPACcybermarketwillcontinuetobehotbutthereare
extremechallengesrelatedtotheconstantwarfortalents.Apartfromthetypicalsecurityroles,wehaveseenanincreasedneedfortalents
withinGRC,CTi,IAMandSecurityForensicsacrosstheregion,butagainalackofsuitabletalentswithinthemarket.
JamesWalsh
Director,CyberSecurity,UK&Ireland
Asacrosstherestoftheglobe,thecyberthreattoUK&Iorganisationshasbeengrowingexponentially.Thereisabattletocombatavarietyofthreatactorsacrossallsectorsand,everincreasingly,awarfor
talenttoo.
Asanindustry,wehavetolookmoreatbringingindiversetalent
poolsthatofferdifferentskillsandapproachestotackletheproblems.Apositivefromthereportisthatover70percentoforganisationsinvestinupskillingtheircyberprofessionals.ThroughourPermanent,Contract,StatementofWorkandHireTrainDeployoffering,wearehelping
organisationstoimprovetheirsecuritypostureanddiversity.
MiguelDuran
Director,CyberSecurity,NorthAmerica
MichaelBeaupre
HeadofCyberSecuritySolutions,EMEA&DACH
Cybercrimetearsthroughourliveslikearagingstormanddoesnot
discriminate.Itcandevastateanycompanyanywhere.Fromsmalllocalbusinessestolargeglobalenterprisesandeverythinginbetween.
Arewecollectivelypreparedtoweatherthesecyberstorms?Themajority
ofemployersarestrugglingtohiretoptalentandseethisgapasasignificantrisktotheircybersecuritystrategies.Wemustpartnerasacommunity
anddevelopnewandinnovativewaystoattract,train,andretaincybersecuritytalent.
Overtwo-thirdsofsecurityleaderspolledaroundtheworldareworriedabouttheirbudget,andwemustjointlyoptimiseourinvestmentsin
cybersecuritytechnologyandcapability.Thismeansworkingtogetherwithcybersecurityprovidersandtalentprovidersonabroadscaleandengagingboardlevelleaderstoidentifythemostcriticalassetsineachcompany.Wecan’taffordtoprotecteverything,andwemustprioritisebasedonrisk,resiliency,andoperationalrelevance.
Understandingthatweareallinthisfighttogetherandthechallengeswefacearenotuniquetoourcountriesorourindustrieshelpsussharesolutionsandcapabilitiesacrossboundaries.Cybercriminalsknownoboundaries,andourresponsesshouldharmoniseacrossborders.
IamveryexcitedforthisinauguralreleaseoftheHaysGlobalCyber
SecurityReport.Withtheever-growingdemandinthemarket,weat
Hayswantedtoprovideacomprehensivedeepdiveintotheglobalandregionalchallengessecurityleadersfaceandhowkeyglobaleventshaveaffectedthethreatlandscape,alongwithhowtoadaptandovercomeinaheightenedskill-shortageeconomy.
This,alongwithourannualsalaryguide,willbeagreattoolforcyberleaderstouse,andhelpovercomeinternalconversationsaroundhowtopivotinthisfluidstatewearecurrentlyin.
Asanindustry,wehavetolook
moreatbringingindiversetalentpoolsthatofferdifferentskillsandapproachestotackletheproblems.
9|GlobalCyberSecurityReport2023
CYBERINTHESPOTLIGHTVIDEOSERIES
InourYouTubemini-series,wespoketocybersecurityleadersworldwidetogaininsights
intothewaytheywork,thechangesthey’reseeingandthechallengestheynavigate.
DeepayanChanda
PrincipalCybersecurityArchitect,Lab49
Withthisconstantskillsshortagechallenge,ITcertificationsoranykindofeducationincybersecuritydoplayavaluablerole.However,inordertogetthemostvalueoutofcertifications,peopleshouldalignthesewiththecareerpaththey’rechoosing.Ibelievethatmostcertificationsarenotdependentonlocation.
Therearemultiplethingswecandotohireandretaintalent.Letthe
candidateoremployeeknowwhattheroleisallabout–thereshouldbenoambiguityintheroledefinition.Keepaneyeonmarkettrends,
ascompensationdoesplayahugepartinretainingtalentonacase-by-casebasis.Lastly,andpossiblythemostimportant:empowertheroleitself.Peoplewanttoseetheimpactoftheworktheyaredoingand,ifthatisnotvisible,thenit’sreallyachallengetokeeptalent.
Watchthefullinterviewhere
fenerg
NiamhMuldoon
CISO,Fenergo
Attractingtalentisonething,retainingtalentissomethingdifferent.It’suptoaCISOtoretaintoptalent.It’saboutunderstandingwherepeoplewanttogointheircareerandfuellingthemwiththeskillset,expertiseandexperiencetogetthere.Peopleneedtoknowthebigpictureandunderstandwhattheycangetintermsofopportunitiesfromtheirorganisation.
We’reveryfocusedontechnology.Ifyoutakeastepbackandlookat
whatinformationisallabout,it’sconfidentiality,integrityandavailabilityofdata.Theopportunitythereistothinkaboutsecurityinawider
context,andnotjustfocusontechnology.
Watchthefullinterviewhere
10|GlobalCyberSecurityReport2023
RonBushar
SeniorVPandGlobalGovernmentCTO,Mandiant
Inthesamewaythatthere’saglobalarmsraceincyber,there’saglobaltalentraceinthesamedimension.
We’verecognisedthatyoucan’tcontinuetotaketheapproachof,“Ionlywantthebestpersonincyberintelligence,Ionlywantthebestincidentresponseguyintheworldetc.”There’sonlyafewofthose,sowehavetoshiftourthinkingaroundhowtotrainandequipthenextgeneration.
Don’tjustlookatsomebody’sresumeandsay,“theydon’thave20years
ofexperienceandadegreeincybersecurity,sothey’renogood”.Itis
soimportanttoembracediversity,expandyourapertureofwhoyou’re
attractingtocometotheorganisationandthentakethetimetotrainthem.
Ican’ttellyouhowmanycandidatescomethroughthatyouwouldsay
don’thavethetraditionalexperience,buthavebeenabletocomeintoarole,trainwithexpertsinthefieldandquicklybecomeextremelycapable.
Watchthefullinterviewhere
Itissoimportanttoembracediversity,expandyourapertureofwhoyou’re
attractingtocometotheorganisationandthentakethetimetotrainthem.
NEXTSTEPS
Thisreporthashighlightedthattheskillsshortageincybersecurityishaving
animpactonorganisations’defencestrategies.Withthisskillsgapposing
aproblemformanycybersecurityleaderswhoarehiring,it’simportantthat
organisationsfindaneffectivesolution.Herearesomerecommendations
wehavefornextsteps:
Considerunexploredtalent
Althoughtheymaynothavetheexperienceorcompleteskillset,therearepeopleouttherewiththelearningmindsettohelpyourbusiness.Broadenyoursearchandthinkabouttherelevantskillsanyrecruitswouldneedandwhichtheycouldbuilduponwiththerighttraining.
Similarly,there’stalentwiththeskillsyou’rel
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 2024-2030年中国定制酒行业营销创新模式及未来5发展趋势报告
- 2024年物流驾驶员服务外包合同
- 眉山职业技术学院《灾害卫生学》2023-2024学年第一学期期末试卷
- 2024年度拍卖艺术品线上线下销售合作协议范本3篇
- 马鞍山职业技术学院《企业经营实战》2023-2024学年第一学期期末试卷
- 马鞍山学院《机器学习及应用》2023-2024学年第一学期期末试卷
- 2024年模具设计与生产合同
- 洛阳职业技术学院《公共卫生理论和实践》2023-2024学年第一学期期末试卷
- 2025年连云港货运上岗证模拟考试0题
- 2024年古建筑修复施工劳务分包合同范本及细则2篇
- 期末综合卷(含答案) 2024-2025学年苏教版数学六年级上册
- 2025春夏运动户外行业趋势白皮书
- 中医筋伤的治疗
- 【MOOC】英文技术写作-东南大学 中国大学慕课MOOC答案
- 2024年21起典型火灾案例及消防安全知识专题培训(消防月)
- 人教版四年级上册数学【选择题】专项练习100题附答案
- 从创意到创业智慧树知到期末考试答案章节答案2024年湖南师范大学
- DL-T 1476-2023 电力安全工器具预防性试验规程
- 国开《Windows网络操作系统管理》形考任务4-配置故障转移群集服务实训
- 计价格[1999]1283号_建设项目前期工作咨询收费暂行规定
- 毕业设计(论文)RLC测量仪设计
评论
0/150
提交评论