Britain’s Cybersecurity Skills Gap

Globally, there were an estimated 3 million unfilled cybersecurity vacancies at the end of 2018 and it has been predicted that there could be as many as 3.5 million unfilled cybersecurity roles in the UK alone by 2022. In Britain, the UK government has created the Initial National Cyber Security Skills Strategy with the intention of resolving the skills shortage, but it is going to need a concerted effort from everyone involved to reduce the skills gap. 

This skills gap in the UK is the result of a number of factors, such as the outpacing of new technologies creating a shortage in specialist skills, a disconnect between education and the industry and gender inequality. Each one of these issues will need to be addressed by the industry and educators if this ever-increasing skills gap is to be closed. 

Specialist Skills
Many recruiters and employers claim that positions stay vacant because many candidates lack the required level of experience and the specialist skills needed to perform the role. However, with more and more positions opening up and remaining vacant, the industry will need to address this skills shortage and the reasons behind it. 

As an industry, cybersecurity is both aided and hindered by the rapid pace that technology evolves. As new technology is developed and introduced into the world those working in cybersecurity are tasked with adapting to this new technology.
With new technologies emerging every day, the UK’s skills gap is unlikely to lessen without major efforts from both employers and educators. The need for specialist skills in the industry that relate to new technologies such as cloud computing is readily apparent. These new technologies come with security vulnerabilities that require specialized training and knowledge to address. 

However, many graduates lack the understanding or experience of these new technologies due to how new they are. This would suggest that there is a disconnect between the industry and education and that the objectives of the industry aren’t being fully met by education institutions. 

The Disconnect Between Education And Industry
At the time of writing, there are only 4 specific cybersecurity bachelor’s degrees taught in the UK that have been approved by the National Cyber Security Centre. In addition, cybersecurity is rarely chosen as a specialism by students until Master’s level, resulting in very few graduates leaving university with a strong understanding of cybersecurity. 

The most in-demand specialist skill currently in demand in the UK is penetration testing. However, despite being a vital and sought after skill in graduates, there is only one course that is listed on the UCAS website that makes any reference to penetration testing. To begin to close the skills gap, there needs to be improved communication and cooperation between education and the industry. 

Cybersecurity businesses will need to identify their own weaknesses and work together with education providers to enhance student’s understanding and interest in the most in-demand areas of cybersecurity to help to tackle the skills shortage. 

Professional Certifications
However, not all of the responsibility for the skills shortage lies with education providers. Employers that are struggling to fill roles requiring more advanced skills need to develop and train their own staff to progress their teams. With so many businesses struggling to fill specialist roles, internal training and up-skilling could be essential in tackling the skills shortage. 
There is a range of professional certificates that are able to provide cybersecurity professionals with a more comprehensive understanding of specialist areas. For example, the Certified Ethical Hacker (CEH) qualification familiarises staff with penetration testing methods. 

Gender Inequality And Diversity
Another commonly suggested way to tackle the skills gap is to open the cybersecurity industry up to women and other diverse applicants. Only 16% of cybersecurity students that graduated in 2017 were women and women professional in cybersecurity are paid on average 25% less than their male counterparts. If the cybersecurity industry wants to resolve this skills gap it will need to entice as many candidates as possible and make efforts to diversify their talent pool. 

Other STEM industries that have made efforts to tackle gender inequality, such as engineering, are already beginning to see improvements in their own skills gaps. In any industry, diversity is essential and helps to create a team from a range of backgrounds and experiences that can work together to problem-solve from a range of angles. 

With the UK facing such a dramatic shortage of skilled cybersecurity staff in a vital industry it is imperative that we work to expand the perception of what a cybersecurity professional looks and thinks like to make the role as open and attractive to as many people as possible. 

About the Author:
Dan Baker is a Content Writer that works with SecureTeam, a cybersecurity consultant that provides a range of cybersecurity solutions to small and medium businesses across the UK. 

You Might Also Read:

Employee Training Is Vital For Commercial Cybersecurity:

Closing The Skills Gap Starts At School:

 

« Google Challenged For Collecting American Health Data
Killer Robots For Export »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

FT Cyber Resilience Summit: Europe

FT Cyber Resilience Summit: Europe

27 November 2024 | In-Person & Digital | 22 Bishopsgate, London. Business leaders, Innovators & Experts address evolving cybersecurity risks.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

High Technology Crime Investigation Association (HTCIA)

High Technology Crime Investigation Association (HTCIA)

HTCIA was formed to provide education and collaboration to our global members for the prevention and investigation of high tech crimes.

Canadian Centre for Cyber Security (CCCS)

Canadian Centre for Cyber Security (CCCS)

The Cyber Centre is the single unified source of expert advice, guidance, services and support on cyber security for government, critical infrastructure, the private sector and the public.

Cycuity

Cycuity

Cycuity (formerly Tortuga Logic) is a cybersecurity company that is transforming the way we secure silicon with comprehensive hardware security assurance.

Calero Software

Calero Software

Calero is a leading global provider of Communications and Cloud Lifecycle Management (CLM) solutions designed to simplify the management of voice, mobile and other unified communications services.

IBLISS Digital Security

IBLISS Digital Security

How cyber-resilient is your business now? We help companies to continuously answer this never-ending C-level question.

Critical Insight

Critical Insight

Critical Insight provide Managed Detection and Response, Vulnerability Detection, and Consulting Services to help you secure your mission-critical systems.

MSPAlliance

MSPAlliance

MSPAlliance is the world’s largest industry association and certification body for cloud computing and managed service professionals.

Microland

Microland

Microland’s delivery of digital is all about making technology do more and intrude less for global enterprises. Our services include Cloud & Data Center, Networks, Cybersecurity and more.

Next Peak

Next Peak

Next Peak provides cyber advisory and operational services based on deep business and national security experience, thought leadership, and a network of front-line defenders.

Xalient

Xalient

Xalient is an IT consulting and managed services business, specialising in modern, software-defined networking, security and communications technologies.

Invicti Security

Invicti Security

Invicti Security is an AppSec leader transforming the way web applications are secured.

BastionZero

BastionZero

BastionZero is leveraging cryptography to reimagine the tools used to manage remote access to servers, containers, clusters, applications and databases across cloud and on-prem environments.

Dutch Research Council (NWO)

Dutch Research Council (NWO)

The Dutch Research Council (NWO) is one of the most important science-funding bodies in the Netherlands and ensures quality and innovation in science.

Willyama Services

Willyama Services

Willyama Services is a certified Information Technology and Cybersecurity professional services business providing services to government and private sector clients.

Rezonate

Rezonate

Rezonate discovers, profiles, and protects Identities and their entire access journey to cloud infrastructure and critical SaaS applications. Preventing and stopping cyberattacks.

Jitterbit

Jitterbit

Jitterbit integrates critical business processes and enables application development to deliver the experiences and insights needed by enterprises of all sizes to accelerate their digital journey.