News

New study shows skills gap exists among cybersecurity professionals

New research from BAE Systems finds a gap between the number of skilled cybersecurity professionals and the number of available positions in corporate America.

The BAE study says 50 percent of businesses claim there is a lack of staff with the required security skills and expertise. Further, 40 percent of companies said they do not have adequate training to capture best practices from experienced staff for more junior employees.

The research also discovered that 37 percent of mid-sized organizations are still investigating security alerts manually, while 7 percent are doing nothing with the warnings they receive.

“A lack of skilled cybersecurity resources is leaving essential work undone, and putting Americans at risk,” Colin McKinty, vice president of Cyber Security Strategy with BAE Systems Applied Intelligence, said. “Alerts go ignored because there are too few team members, and if one of those alerts indicated suspicious activities that could lead to a legitimate threat of an imminent breach, the company has now lost critical time to secure its corporate and customer data, and protect its reputation.”

To address the skills gap, 43 percent of the organizations surveyed are planning to train up existing staff, while 36 percent plan to grow their team. Further, 42 percent of IT professionals plan to buy additional tools while 54 percent are seeking security monitoring tools that identify existing vulnerabilities and high priority incidents. Also, 54 percent are looking to reduce the time between a breach and when the incident is reported.

Among large companies with over 500 employees, 78 percent said they are satisfied or very satisfied with their current tools with only 7 percent expressing dissatisfaction. However, at mid-sized companies, 17 percent are dissatisfied with their existing solutions. Specifically, 37 percent of mid-sized businesses are manually investigating all logs and alerts.

“Identifying cyber risks is complex and time-consuming, and every day there is the risk of missing serious attacks before they cause significant impact, compromising company information, and the larger implications and costs associated with a high-profile breach,” McKinty said. “The future of security technology is real-time. Businesses need to be confident that attacks and risks on their network are being identified as they happen, without the need for large, dedicated security teams, or time-consuming manual investigations of alerts.”

The survey, conducted in November 2017, polled 600 IT decision-makers in the U.K. and the United States, from organizations with between 250 and 9,999 employees, in a variety of sectors.

Dave Kovaleski

Recent Posts

DoD challenge brings opportunities for nine new ideas in talent management

A Department of Defense (DoD) 2040 Task Force (D2T) challenge on talent management innovation drew…

16 hours ago

TSA publishes final rule on Flight Training Security Program improvements

For the first time since its creation in 2004, the Transportation Security Administration’s (TSA) Flight…

16 hours ago

FEMA launches new hurricane season campaign with multicultural messaging on flood risks

The 2024 Hurricane Season Campaign began for the Federal Emergency Management Agency (FEMA) this week,…

2 days ago

SERVICE Act of 2024 seeks DOJ pilot program, grants for local veteran response teams

As a way to support veterans, U.S. Reps. Maria Elvira Salazar (R-FL), Dale Strong (R-AL),…

2 days ago

DHS publishes guidelines for securing critical infrastructure and weapons against AI threats

Mere days after the Department of Homeland Security formed a new Artificial Intelligence (AI) Safety…

3 days ago

U.S. Army and European Command awards KBR $771M contract

KBR will continue to provide life support, equipment readiness, training and supply chain solutions for…

3 days ago

This website uses cookies.