版權(quán)說(shuō)明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請(qǐng)進(jìn)行舉報(bào)或認(rèn)領(lǐng)
文檔簡(jiǎn)介
TACKLING
THECYBERSKILLSGAP
GlobalCyberSecurityReport2023
Expertsin
Technology
CONTENTS
03—IntroductionJamesMilligan,GlobalHeadofTechnologySolutions
04—Aboutthesurvey
05—OrganisationReportingstructure,attackexperiencesandstrategy
06—InvestmentShareofbudgetandchangestospendfor2023
07—HiringIn-demandskillsandrecruitingtalent
08—RetentionandskillsRetainingandupskillingexistingtalent
09—TheHaysview
10—CyberintheSpotlightvideoseries
11—Nextsteps
2|GlobalCyberSecurityReport2023
3|GlobalCyberSecurityReport2023
INTRODUCTION
THEDEMANDFORCYBERSKILLS
Whileitwasalreadybecominganecessityforthevastmajority
oforganisations,recenteventshavemeantthattherateofdigital
transformationhasacceleratedoverthelastthreeyears.Thatmeansanincreaseindatamanagement,whilehybridandremoteworkingmeansthatworkersneedsecureaccesstotheiremployers’servers.These
changeshaveaffordedthreatactorsgreateropportunitiestoexploitorganisationsandinfrastructurethaneverbefore,aswellasprovidedaddedmotive.
Allofthishasmeantthatthedemandforpeoplewithcybersecurity
skillshasincreased.AtHays,weplacedover750peopleintorolesin
2022asorganisationssoughtthetalentneededtoimplementtheir
defencestrategies.However,asthisdemandoutweighsthesupplyof
peoplewithexperienceoraccreditationsincybersecurity,it’snotalwaysstraightforwardtofillthoseroles.
Isthisskillsshortageaffectingorganisationssignificantly?And,ifso,how?
Thisiswhywe’vedecidedthatit’stherighttimetocreateourfirstglobalreport.Ourstudy,carriedoutinthefinalmonthsof2022,aimedtoexplorehoworganisationsaroundtheworldhaveadaptedtheircybersecurity
strategytotackletoday’sthreats,aswellasthechallengesthey’vefacedindoingso.Bysurveyingsecurityleadersfromacrossseveralindustriesandsenioritylevels,wewantedtodiscoverwhichfactorswereimpactingtheirabilitytohireandretaintalent,andwhetherthelevelofinvestmentfrom
theirorganisationismeetingtheirneeds.
Themostrevealingfindingwastheextenttowhichorganisationshavebeenimpactedbythelackofqualifiedcandidatesincybersecurity.
Overall,90percentofleaderssaidtheskillsgaphadaffectedtheirabilitytoimplementtheircybersecuritystrategy.
It’snotbeeneasytoaddress,either.Hiringtalentisanissue,withroughlytwothirdsofleadersadmittingthattheydonotratetheirorganisation’s
abilitytorecruitpeopleworkingincybersecurityhighly.Findingincentivestoretainandtrainyourexistingtalentbecomesevenmoreimportant,
especiallyastheyreceiveoffersfromorganisationsfacingthesameproblem.Providinglearningresourcesisattractivetoemployeesand,giventhebenefitsitbringstoanorganisation’scybersecuritystrategy,theinvestmentisworthit.
Despitethis,manyofourrespondentswereconcernedaboutthefundsbeingallocatedtocybersecuritywithintheirorganisation.Although
companieshavereactedtoglobaleventsbyputtingmoremoneyintosecurity,almosthalfofleadersexpectminimalchangetotheirbudgetin2023.
Ourstudyhasshownthatfindingandhiringtherighttalentisasignificantchallengeforbusinessesglobally,andthatthelackofskillsisaffectingsecurity.What’sthesolution?
90%ofleaderssaidtheskillsgap
hadaffectedtheirabilitytoimplementtheircybersecuritystrategy.
AtHays,weliketotalkaboutundiscoveredtalent.Ononehand,these
mightbepeopleouttherewhodon’thavetheexactexperiencethat
organisationsareseeking,butwouldbeahugeassetifthey’reopento
training.Ontheotherhand,undiscoveredtalentmayalsorefertothosewhoaren’tgiventhesameopportunitiesastheirpeersineithereducationortheworldofwork,butcanbringplentytoyourorganisation.Inadditiontopeoplecomingfromalowsocio-economicbackground,therearealso
thoseweaimtohelpthroughour
FocusingOnEmploymentInequity
report
,suchasthoselivingwithadisabilityoryoungpeoplestrugglingtostartonthecareerladder.
Inthisreport,you’llfindinsightsonallofthechallengesthatcyber
securityleadersarefacingin2023,fromprotectingtheirorganisationtoretainingtrainedemployees.Ifyouarehavingsimilarexperiencestoourrespondents,we’vealsosuggestedsomestepsthatyoucantaketoensuresustainablecybersecuritysuccess.
Lastly,I’dliketothankalloftherespondentswhotookthetimeto
completeoursurvey.Withoutyourhelp,wewouldnotbeabletoprovidetheseinsights.
JamesMilligan
GlobalHeadofTechnologySolutions,Hays
ABOUTTHESURVEY
Wecarriedoutourresearchacross29countries,surveyingover1,000cybersecurityleaders.Thestudyexploredhoworganisationsarerespondingtorecentglobalevents,theirinvestmentincybersecurity,theirchallengesinhiringandretainingstaff,aswellastheskillsourrespondentssoughtandhowtheseweredevelopedamongtheworkforce.
Whenexaminingthedata,weinvestigatedwhethertherewereanydiscrepanciesfromregiontoregion,inordertoprovidelocalinsights.However,ouranalysisrevealedlittletonovariation-thefindingsinthisreportreflectwhatishappeningaroundtheglobe,asleadersfacethesamechallengesandturntothesamesolutions.
UKIandEMEA
?Austria
?Belgium
?CzechRepublic
?France
?Germany
?Hungary
?Ireland
?Italy
?Luxembourg
?Poland
?Portugal
?SaudiArabia
?Spain
?Sweden
?Switzerland?UK
?UAE
Americas
?Brazil
?Canada
?Chile
?Colombia
?Mexico?USA
AsiaandANZ
?Australia
?China
?Japan
?Malaysia
?NewZealand
?Singapore
4|GlobalCyberSecurityReport2023
Employeesatourrespondents’organisations
5,000+
37%
101-1,000
25%
Senioritylevelofourrespondents
C-suite
16%
Director
24%
Manager
50%
1,001-5,000
21%
0-100
17%
10%
VP
experienced?
Whattypeofattackshave
Cybersecurityteamsarenotalwayspositionedstrategically
you
Manyleadersreportthatrecentglobalevents,suchasgeo-political
Phishing
84%
Malware/Virus
48%
34%
External
46%
ofleadersdonotbelievethattheircybersecurityteamreportsintotherightpartoftheirorganisation
Ransomware
31%
DataLoss/Theft
30%
Thepandemicandgeo-politicalclimatehaveaffectedorganisations’security
72%
ofleadersfeelthatrecent
globaleventshavehada
‘Major’or‘Moderate’impactontheirorganisation’scyberriskprofile
5|GlobalCyberSecurityReport2023
conflictsandthepandemic,haveaffectedthecyberriskprofileattheirorganisation.
Thepandemicinparticularhasacceleratedtheneedfordigital
transformation,whichhasgivengreateropportunitiestocyber
criminals-84percentofleadersreportingthattheirorganisation
experiencedaphishingattackin2022.Employeeshavehadto
becomesavvierasaresult,with77percentofleadersreportingthatcybersecurityawarenessisgreaterthanitwasthreeyearsago.
Organisationshavehadtorespondswiftlytocombatpotentialthreats,butincorporatingcybersecurityintotheirstrategyhasnotbeena
naturalprocessforeveryone.Athirdofleadersdonotagreethat
cybersecuritysitsinthecorrectreportinglinewithintheirbusiness.
77%
ofleadersstatethatsecurityawarenessintheirorganisationisgreaterthanin2019
ORGANISATION
Inordertogaininsightsintohoworganisationsarerespondingtocyberthreats,
weneededtounderstandhowtheyarebeingaffectedandwheretheirsecurityteam
fitsinthereportingline.
Obtaininginvestmentincybersecurityhasbeeneasiersincethepandemic
Whatisyourorganisation’sannualspendincybersecurityinproportiontoITbudget?
Withsecurityaconcernacrosstheglobe,leadersarelookingfora
0-2%
Stronglyagree
14%
11%
3-4%
Agree
15%
34%
Neutral
5-6%
18%
37%
Disagree
7-8%
10%
14%
Stronglydisagree
3%
N/A
1%
9-10%
21%
11%+
22%
Investmentisnotnecessarilyalignedwithsecurityleaders’needs
47%
ofleadersexpect“Minimalchange”totheirbudget
in2023
6|GlobalCyberSecurityReport2023
financialcommitmentfromtheirorganisation.Overafifthofour
respondentsreportthatatleasttenpercentoftheirorganisation’sITspendisallocatedtosecurity.
However,whileonly17percentofleadersdisagreewiththestatementthatinvestmentincybersecurityhasbeeneasiertoreceivesince
thepandemic,almosthalfexpectminimalchangetotheirbudgetin2023.Asaresult,thereisaconcernoverwhetherinvestmentincybersecuritywillbesufficientfortacklingtoday’sthreats.
68%
ofleadersare“Extremely”,“Very”,or“Moderately”
concernedabouttheirbudgetin2023
INVESTMENT
Wewantedtoexplorehoworganisationsareinvestingincybersecurity,andwhethertheirbudgethasincreasedasaresultofglobaleventsandtrends.
seek
skills
front-line
recruitcybersecuritytalent
Organisations
Organisationsstruggleto
Topfivechallengesinhiringtalent
Whenaskedwhatwouldimprovethesecuritycapabilityattheir
organisation,leadersmostlynamedskillsthatwouldreinforce
thefrontlineofdefence,suchascloudsecurityandarchitecture.
Thisalignswithourowninsights,asgloballywe’reseeinghighestdemandforengineersandarchitects.However,thechallengeistofindworkerswiththeknowledgeandexperiencerequiredtofillroleswithintheirorganisation.
Meanwhile,leadersfacecompetitioninhiringthosewiththerightcredentials,who,inturn,areabletodemandahighersalary.Infact,twothirdsofleadersdonotratetheirabilitytoattractcybersecuritytalenthighly.
Thismeansthatorganisationsmustlookforunexploredoruntrainedtalent,anapproachthattheyareopento.Overhalfoftheleaders
surveyedstatethattheyarelikelytohireworkerswhodon’tholdformalaccreditations.
“Two-thirdsofleadersdonot
ratetheirabilitytoattractcybersecuritytalenthighly.”
7|GlobalCyberSecurityReport2023
1Salaryexpectation
2Missingskills
3Competition
4Lengthofworkingexperience
5Lackofexperienceatasimilarorganisation
Topfiveskills/implementationsthatwouldenhancesecuritycapability
1Cloudsecurity
2Governance,RiskandCompliance
3SecurityArchitecture
4SecurityEngineering
5
SIEM/SOC
HIRING
Withtheskillsgapposingproblemsintech,wewantedtounderstandthechallengesthat
organisationsfaceinrecruitingtalent.
66%
ofleadersdonotrate
theirorganisation’sability
toattractcybersecurity
talenthighly
talent
turning
Employersare
tounexplored
56%
ofleadersarelikelyto
recruitsomebodywithout
formalITsecurity
accreditations
Theshortageinskillsishavinganimpactacrosstheboard,with90percentofleadersrevealingthatithasaffectedtheirsecurityimplementation.Iftheexperiencedtalentisn’treadilyavailable,organisationsmustfindnewwaystofilltheseroles.
Inordertoclosetheskillsgap,leadersbelieveupskillingand
cross-trainingtheirteammembers(i.e.teachingthemhowtoperforminnewroles)arethebestroutestosuccess.Indeed,manyleaders
reportthattheirorganisationinvestsintrainingemployees;however,thisinvestmentdoesnotstretchtoretainingtheirexistingtalent,as
employersinsteadofferwork-lifebalanceperksovermonetaryreward.
RETENTION&SKILLS
Inadditiontohiring,howareorganisationsretainingexistingtalent
andequippingthemwiththeskillstheyneed?
Skillsshortages
areaffectingsecurity
90%
ofleadersbelieveaskills
shortagehasimpactedtheirabilitytoimplementtheir
cybersecuritystrategy
“Manyleadersreportthattheirorganisationinvestsintrainingemployees;however,this
investmentdoesnotstretchtoretainingtheirexistingtalent”
8|GlobalCyberSecurityReport2023
Skillsdevelopmentisusedforthebenefitoforganisationsandworkersalike
Topfivestrategiestoclosethecybersecurityskillsgap
1Upskilling
2Cross-training
3Recruitmentpartner
4Hire,trainanddeploy
5Universityoutreach
Topfivestrategiesforcybersecuritytalentretention
1Remoteandhybridworkingarrangements
2Work-lifebalance/Wellnessoffering
3Flexiblehours
4Professionaldevelopmentopportunities
5Careergrowth&progression
It’snecessarytoequiptheworkforcewithnewskills
71%
ofleaderssaythattheir
organisationinvests
inupskillingitscyber
securityworkforce
THEHAYSVIEW
Haysexpertsgivetheirthoughtsonthefindingsinourreport
andwhattheymeanforleadersin2023.
EdmondPang
Director,CyberSecurity,APAC
Similartothegloballandscape,thereis
nosurprisethatcyberthreatshaveincreasedintheAPACregiongivenCOVIDlockdownsbeingtheperfectstorm,withsomehigh-profile
breacheshighlightedinthemedia.Asaresult,we’reseeingcountriessteppingupwiththeirpoliciesandinvestmentintocyber.
Forexample,Australiahasincreasedpenaltiesforbusinessesthatdonotsufficientlyprotectcustomerdata,whiletheSecurityOfCritical
InfrastructureAct(SOCI)hasbeenamendedtostrengthenthesecurityandresilienceofcriticalinfrastructure.NewZealandhasupdatedandfinalisedtheNewZealandInformationSecurityManual(NZISM)withfourpolicychangesinSeptember2022.Japanhassteppedupon
regulatoryrequirementsinindustriessuchasBankingandInsurance,andtheMalaysiangovernmenthasannouncedincreasedfundingsintotheTech&Cybersecurityspace.
Overall,theAPACcybermarketwillcontinuetobehotbutthereare
extremechallengesrelatedtotheconstantwarfortalents.Apartfromthetypicalsecurityroles,wehaveseenanincreasedneedfortalents
withinGRC,CTi,IAMandSecurityForensicsacrosstheregion,butagainalackofsuitabletalentswithinthemarket.
JamesWalsh
Director,CyberSecurity,UK&Ireland
Asacrosstherestoftheglobe,thecyberthreattoUK&Iorganisationshasbeengrowingexponentially.Thereisabattletocombatavarietyofthreatactorsacrossallsectorsand,everincreasingly,awarfor
talenttoo.
Asanindustry,wehavetolookmoreatbringingindiversetalent
poolsthatofferdifferentskillsandapproachestotackletheproblems.Apositivefromthereportisthatover70percentoforganisationsinvestinupskillingtheircyberprofessionals.ThroughourPermanent,Contract,StatementofWorkandHireTrainDeployoffering,wearehelping
organisationstoimprovetheirsecuritypostureanddiversity.
MiguelDuran
Director,CyberSecurity,NorthAmerica
MichaelBeaupre
HeadofCyberSecuritySolutions,EMEA&DACH
Cybercrimetearsthroughourliveslikearagingstormanddoesnot
discriminate.Itcandevastateanycompanyanywhere.Fromsmalllocalbusinessestolargeglobalenterprisesandeverythinginbetween.
Arewecollectivelypreparedtoweatherthesecyberstorms?Themajority
ofemployersarestrugglingtohiretoptalentandseethisgapasasignificantrisktotheircybersecuritystrategies.Wemustpartnerasacommunity
anddevelopnewandinnovativewaystoattract,train,andretaincybersecuritytalent.
Overtwo-thirdsofsecurityleaderspolledaroundtheworldareworriedabouttheirbudget,andwemustjointlyoptimiseourinvestmentsin
cybersecuritytechnologyandcapability.Thismeansworkingtogetherwithcybersecurityprovidersandtalentprovidersonabroadscaleandengagingboardlevelleaderstoidentifythemostcriticalassetsineachcompany.Wecan’taffordtoprotecteverything,andwemustprioritisebasedonrisk,resiliency,andoperationalrelevance.
Understandingthatweareallinthisfighttogetherandthechallengeswefacearenotuniquetoourcountriesorourindustrieshelpsussharesolutionsandcapabilitiesacrossboundaries.Cybercriminalsknownoboundaries,andourresponsesshouldharmoniseacrossborders.
IamveryexcitedforthisinauguralreleaseoftheHaysGlobalCyber
SecurityReport.Withtheever-growingdemandinthemarket,weat
Hayswantedtoprovideacomprehensivedeepdiveintotheglobalandregionalchallengessecurityleadersfaceandhowkeyglobaleventshaveaffectedthethreatlandscape,alongwithhowtoadaptandovercomeinaheightenedskill-shortageeconomy.
This,alongwithourannualsalaryguide,willbeagreattoolforcyberleaderstouse,andhelpovercomeinternalconversationsaroundhowtopivotinthisfluidstatewearecurrentlyin.
Asanindustry,wehavetolook
moreatbringingindiversetalentpoolsthatofferdifferentskillsandapproachestotackletheproblems.
9|GlobalCyberSecurityReport2023
CYBERINTHESPOTLIGHTVIDEOSERIES
InourYouTubemini-series,wespoketocybersecurityleadersworldwidetogaininsights
intothewaytheywork,thechangesthey’reseeingandthechallengestheynavigate.
DeepayanChanda
PrincipalCybersecurityArchitect,Lab49
Withthisconstantskillsshortagechallenge,ITcertificationsoranykindofeducationincybersecuritydoplayavaluablerole.However,inordertogetthemostvalueoutofcertifications,peopleshouldalignthesewiththecareerpaththey’rechoosing.Ibelievethatmostcertificationsarenotdependentonlocation.
Therearemultiplethingswecandotohireandretaintalent.Letthe
candidateoremployeeknowwhattheroleisallabout–thereshouldbenoambiguityintheroledefinition.Keepaneyeonmarkettrends,
ascompensationdoesplayahugepartinretainingtalentonacase-by-casebasis.Lastly,andpossiblythemostimportant:empowertheroleitself.Peoplewanttoseetheimpactoftheworktheyaredoingand,ifthatisnotvisible,thenit’sreallyachallengetokeeptalent.
Watchthefullinterviewhere
fenerg
NiamhMuldoon
CISO,Fenergo
Attractingtalentisonething,retainingtalentissomethingdifferent.It’suptoaCISOtoretaintoptalent.It’saboutunderstandingwherepeoplewanttogointheircareerandfuellingthemwiththeskillset,expertiseandexperiencetogetthere.Peopleneedtoknowthebigpictureandunderstandwhattheycangetintermsofopportunitiesfromtheirorganisation.
We’reveryfocusedontechnology.Ifyoutakeastepbackandlookat
whatinformationisallabout,it’sconfidentiality,integrityandavailabilityofdata.Theopportunitythereistothinkaboutsecurityinawider
context,andnotjustfocusontechnology.
Watchthefullinterviewhere
10|GlobalCyberSecurityReport2023
RonBushar
SeniorVPandGlobalGovernmentCTO,Mandiant
Inthesamewaythatthere’saglobalarmsraceincyber,there’saglobaltalentraceinthesamedimension.
We’verecognisedthatyoucan’tcontinuetotaketheapproachof,“Ionlywantthebestpersonincyberintelligence,Ionlywantthebestincidentresponseguyintheworldetc.”There’sonlyafewofthose,sowehavetoshiftourthinkingaroundhowtotrainandequipthenextgeneration.
Don’tjustlookatsomebody’sresumeandsay,“theydon’thave20years
ofexperienceandadegreeincybersecurity,sothey’renogood”.Itis
soimportanttoembracediversity,expandyourapertureofwhoyou’re
attractingtocometotheorganisationandthentakethetimetotrainthem.
Ican’ttellyouhowmanycandidatescomethroughthatyouwouldsay
don’thavethetraditionalexperience,buthavebeenabletocomeintoarole,trainwithexpertsinthefieldandquicklybecomeextremelycapable.
Watchthefullinterviewhere
Itissoimportanttoembracediversity,expandyourapertureofwhoyou’re
attractingtocometotheorganisationandthentakethetimetotrainthem.
NEXTSTEPS
Thisreporthashighlightedthattheskillsshortageincybersecurityishaving
animpactonorganisations’defencestrategies.Withthisskillsgapposing
aproblemformanycybersecurityleaderswhoarehiring,it’simportantthat
organisationsfindaneffectivesolution.Herearesomerecommendations
wehavefornextsteps:
Considerunexploredtalent
Althoughtheymaynothavetheexperienceorcompleteskillset,therearepeopleouttherewiththelearningmindsettohelpyourbusiness.Broadenyoursearchandthinkabouttherelevantskillsanyrecruitswouldneedandwhichtheycouldbuilduponwiththerighttraining.
Similarly,there’stalentwiththeskillsyou’rel
溫馨提示
- 1. 本站所有資源如無(wú)特殊說(shuō)明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請(qǐng)下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請(qǐng)聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁(yè)內(nèi)容里面會(huì)有圖紙預(yù)覽,若沒(méi)有圖紙預(yù)覽就沒(méi)有圖紙。
- 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
- 5. 人人文庫(kù)網(wǎng)僅提供信息存儲(chǔ)空間,僅對(duì)用戶上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對(duì)用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對(duì)任何下載內(nèi)容負(fù)責(zé)。
- 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請(qǐng)與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時(shí)也不承擔(dān)用戶因使用這些下載資源對(duì)自己和他人造成任何形式的傷害或損失。
最新文檔
- 2024保安服務(wù)合同(范本)公司保安合同范本
- 2024年丙丁雙方關(guān)于購(gòu)買房產(chǎn)合同標(biāo)的的協(xié)議書
- 2024年簡(jiǎn)單貨物運(yùn)輸合同格式
- 2024年度金融風(fēng)險(xiǎn)管理系統(tǒng)定制開發(fā)合同
- 2024合同補(bǔ)充協(xié)議
- 2024年協(xié)議離婚應(yīng)當(dāng)注意的要點(diǎn)
- 網(wǎng)吧轉(zhuǎn)讓合同范本
- 律師代理公司股票上市合同范本
- 2024日本留學(xué)租房合同簽訂須知
- 2024借款居間服務(wù)合同
- 2024江蘇省沿海開發(fā)集團(tuán)限公司招聘23人高頻難、易錯(cuò)點(diǎn)500題模擬試題附帶答案詳解
- 2024年計(jì)算機(jī)二級(jí)WPS考試題庫(kù)380題(含答案)
- 22G101三維彩色立體圖集
- 大學(xué)生安全文化智慧樹知到期末考試答案章節(jié)答案2024年中南大學(xué)
- 建筑施工安全生產(chǎn)治本攻堅(jiān)三年行動(dòng)方案(2024-2026年)
- 人教版小學(xué)英語(yǔ)單詞表(完整版)
- DL-T 1476-2023 電力安全工器具預(yù)防性試驗(yàn)規(guī)程
- 國(guó)家開放大學(xué)《心理健康教育》形考任務(wù)1-9參考答案
- MOOC 法理學(xué)-西南政法大學(xué) 中國(guó)大學(xué)慕課答案
- 用友華表伙伴商務(wù)手冊(cè).
- 大學(xué)生健康人格與心理健康PPT課件
評(píng)論
0/150
提交評(píng)論