Much digital ink has been spilt on the plight of the cybersecurity workforce. Is there a talent shortage? A skills gap? Other, darker issues? Here’s what I think…
First, some back story… When I was getting started in infosec, back in 2010-ish, I remember the on-radio campaigns which spoke of endless opportunity in the up-and-coming “cybersecurity” field. Over time, the messaging became that of a severe shortage of people to staff in these roles. Even back then though, despite all the claims of a “shortage”, getting an actual infosec job wasn’t easy—even for someone with a relevant degree and a few certifications. In the years since, interest in cybersecurity as a profession has surged. You can thank the above-average pay, remote work, and other intrinsic benefits I suppose. These days, you could argue that we’ve hit some level of saturation, especially in the entry- and junior-level ranks. This is evidenced by the countless stories of aspiring infosec pros who go months on end, applying to 100’s of jobs and do countless interviews with nothing to show for it. Mind you, these are more often than not, individuals who have 4-year degrees, who have multiple certifications, and who have done many other things to prepare and boost their qualifications to best pitch themselves for mere entry-level roles. To me, I think this contradicts the theory that there is some sort of talent (pool) shortage. We’ve got plenty of people interested—raw and unrefined—but there, ready to get to work. So the question is then, if the cybersecurity workforce crisis isn’t one of a talent shortage, what is the issue? Does the existing and aspiring workforce suffer from a “skills gap”? To this, I think the answer is a resounding “yes”, but maybe not for all the reasons you might believe…
As I’ve already stated, even the entry-level aspirants and lucky receivers-of-jobs these days almost uniformly have 4-year degrees, one or more certifications, and plenty of other worthy accomplishments. Yet, this has not seemed to make a meaningful dent in the aforementioned “skills gap”. Consider now the slightly more tenured infosec pro. One who (if fortunate enough) not only has a few years of “experience” but also may have attended several trainings at this point and could then hold multiple certifications. Likely, many of those certs are from vendors like SANS, ISC2 and EC-Council. Yet again, the skill deficiencies persist. How is it that we have so many college-educated, multi-cert wielding, many-a-year-on-the-job-having infosec pros still having so little to show when it comes to real-world, applicable infosec skills and know-how? Let’s play the blame game…1
One of my weaker blames is that of training budgets. I think a lot of companies, and thus the industry as a whole, do an abysmal job providing adequate time and budget to train their infosec workforce. But, as you’ll see in a minute, access to what passes as “training” is hardly the problem, as the training, even if made SUPER-available, is just not closing the skills gap anyway.
My stronger blames lie with the tenured infosec community, the cybersecurity vendors, and corporate infosec programs themselves. Let’s start with the grizzled veterans of infosec—the folks with the skills. First, I want to point my finger there. There is real opportunity for mentorship, but I think as a whole, we have failed to build these bridges. We grumble and complain about “script-kiddies”, and “paper tigers” and whatever, but do we take the time to mentor and train? Nah.
Now let’s talk about what it means to get “experience” in infosec. I think overwhelmingly, infosec professionals are put on rails with respect to their job responsibilities. Here’s some tools you are expected to know how to operate, but not expected to know how they work under the hood. Here’s a framework you are expected to audit your IT program or business against. Here’s your corporate, technical “swim lane”, that you must operate within, and never stray outside of. That sorta thing. I don’t think infosec tools are inherently “bad”, or useless in terms of providing value or reducing risk, but as you can tell from the state of cybersecurity in the world, they are in no way the silver bullet. We continue to have breach after breach, security failure after security failure due to infosec 101 type-of-stuff—stuff the tools are not stopping. These companies have tools. We have personnel that operate them. That (buying and running tools), if anything, is what we’ve become good at. But it clearly isn’t enough! The infosec industry, we as engineers, were never meant to be exclusively put behind the limited capabilities of these tools. What if we could do something different? Like, look at these problems and come up with practical solutions based on a found understanding of infosec principles.
But herein lies the problem. The modern infosec “pro” is no longer conditioned to solve ad-hoc problems, or problems of complexity. We’ve been on rails too long. If the tool can’t solve it, how could we? If it’s not one of the exact usecases covered in the Day 4 lab of our latest SANS course, what’re we supposed to do about it! If it doesn’t fit neatly into one of our precious CISSP knowledge domains then oh no! We’ve lost our way, and with it, we’ve abstracted too much of the basics, the real engineering away. It should be expected that all infosec pros are able to do some relatively basic stuff—across operating systems, with standard networking protocols, with industry-standard, open-source tooling. We should be able to hack together basic scripts to do simple things. We should understand the tech stack and supporting protocols of any run-of-the-mill web application. But can you really say that even 20% of infosec “professionals” know these things? I’d say not. But I sure as hell would bet that each of us know one or more enterprise tools super-duper good. How many infosec folks out there can operate Splunk with medium-to-advanced proficiency but can’t actually pull and decipher a packet capture? How many VM analysts can pull off all sorts of wizardry with Tenable, but couldn’t practically exploit a real vulnerability? We’ve become too reliant on tools, and we’ve creatively and technically boxed in our security workforce as a result.
Training vendors aren’t closing the skills gap. “Work experience” is not closing the skills gap. Those of us with useful knowlege, and wisdom to share, are not helping to close the skills gap. The skills gap is real my friends, and there is blame to go ‘round.
I feel I can speak on this topic because I’m a product of it. Get this cert. Get that cert. Use this tool. Use that tool. Getting certs and knowing how to use tools has been pretty great for my career, but what have I learned? Have I really advanced my knowledge? The issue with so many “trainings” these days too is that they don’t teach core concepts. They don’t cover fundamentals. They like to focus on the shiny things. The abstractions. The tools. The practical, yet hyper-specific usecases. They hold your hand through exercises and labs, giving you a false sense of know-how, but when you are turned loose in a real-world, corporate setting, you are left wondering “what do I do?”. That’s if you even get a chance to use what limited skills you may have picked up in training on the job. For most, I feel like they’ll go get training for something, and then return back to their routine daily job responsibilities, which require no practical usage of what they had learned in training. So that knowledge, when not practiced, will fade away. Plus, we’ve all just been conditioned to pick up certs, and put fancy letters in our email signatures and LinkedIn bios, entirely discounting the journey that got us there. Get a cert, get a better job. Rinse and repeat.
We need to adapt. Let’s open up the cyber-swim-lanes. Let’s establish lines of mentorship from professional generation to professional generation. Let’s build training into our corporate culture and then give professionals the space to practice it, to operate with creative license, to solve problems—not with tools, but through the application of actual security fundamentals. I mean we all learn it. It’s really not arcane magic. We all have the “CIA Triad” etched into our cyber-brainz. We can all do a risk assessment—we just have become so vendor-tool-addled and compliance-pilled that we’ve forgotten how to look at things holistically, do actual root-cause analysis, troubleshoot at a low level—really solve issues, in the bespoke and tailored manner in which we otherwise could. The answer to your next cybersecurity issue shouldn’t immediately be a phone call to <INSERT VENDOR NAME> to add-on another paid module in some tool. What if instead, you engaged your cybersecurity workforce, and I mean the actual engineers, not the “cyber leadership”, and asked, “how do we solve this problem”? Then, give them the space to actually do it. I’ve seen it work—honestly, I have. The knock-on effects can be wondrous too. Save money on tooling subscriptions, have a more engaged infosec team, actually reduce risk, build a real culture of engineering, that sorta thing.
I don’t want to trivialize the difficult nature of the infosec industry at large. If things were so easy, I imagine it would have been solved—right? But I think it’s safe to say that a crisis does exist. It’s also fair to say that the way we’ve been doing things just isn’t working. More SANS training isn’t bridging the gap (no offense SANS!). More team charters and vendor tools hasn’t bridged the gap. It’s time to do things differently.
Look, maybe it’s just me. Maybe I’m just projecting my own shortcomings. Not everyone suffers the same, and not every company has the same all-around deficiencies. This is just the way I see things. Looking “across the industry” though, I’m seeing some of the same patterns, and I don’t think I’m terribly far off.