Can Automation Help Bridge The Cyber Skills Gap?

Never has it been more difficult for organisations to attract and retain key cybersecurity staff. Given that the cybersecurity workforce gap expanded by 26.2% in 2022, the global shortfall of cyber professionals now stands at 3.4 million according to (ISC)², leaving many enterprises struggling to hire the experts they need to properly protect themselves against modern cyber threats.

Critically, those facing internal skills shortages become increasingly susceptible to breaches. ISACA found that of those businesses that suffered a cyber attack in the past year, nearly seven in 10 (69%) were somewhat or significantly understaffed.

Further, Fortinet’s 2022 Cybersecurity Skills Gap Research Report reveals that eight in 10 organisations have been subject to at least one breach which could otherwise have been avoided with better cybersecurity skills and/or awareness. 

It is vital that organisations work to prioritise a reduction in breach risk given the potential implications. In 2022, the average cost of a data breach has reached a record high of US$4.35 million, according to the latest Cost of a Data Breach Report by the Ponemon institute. However, impacts are not solely financial.

The IDC previously found that four in five consumers will defect from a business if their information is compromised in a security breach, while another independent study has shown that more than half of office workers would reconsider working for an organisation that had fallen victim to an attack.

The Role Automation Has To Play

Any idea that we can simply “ride out” the skills gap is unrealistic. Something must change. Indeed, without action, the current skills crisis will only continue to grow, leaving businesses increasingly exposed to cyber threats.
Thankfully, organisations are actively looking for workarounds and solutions, with 57% now automating aspects of the job, and a further 26% intending to do so in the near future.

While Artificial Intelligence (AI) continues to advance, technology isn’t likely to completely displace cyber experts anytime soon. What these solutions can instead do is automate repeatable processes, freeing up security teams to focus on higher value tasks. 

But how exactly can security teams embrace automation and machine learning to alleviate the pressures on their security teams? Here, we outline three key solutions to consider:

User & Entity Behaviour Analytics (UEBA)

UEBA is an advanced machine learning-driven solution that works by creating a framework of behavioural norms for each individual network user or entity, enabling it to identify any unusual activity that then strays outside these baselines. In other words, it enables analysts to spot, review and address anomalous actions that may be either malicious or risky and prevent damages and data loss incidents with ease. 

Threat Intelligence

By tapping into information from a wide range of either internal or external sources, be it security vendors, intelligence groups or otherwise, security teams can proactively identify trends and adapt their security strategies accordingly. Of course, trawling through vast amounts of data manually will feel like searching for a needle in a haystack. Therefore, analysts should leverage automation to combine their own intelligence and previous experiences with those of many other organisations into a central feed at speed, providing a single source of truth from which make informed strategic decisions can be made. 

Security Orchestration, Automation & Response (SOAR)

SOAR is a third technology to consider, designed specifically to aggregate and prioritise alerts to accelerate threat investigation and remediation by guiding analysts towards consistent and optimal responses. Underpinned by playbook automation, SOAR pulls all cyber incidents and supporting data together in one place to create structured workflows for day-to-day security analyst tasks that improve response and remediation. Critically, it can use a range of information to recommend an action to a security analyst, enabling them to simply approve or execute a decision.

A Converged Solution Is Key

UEBA, threat intelligence automation and SOAR are just three solutions among a sea of hundreds. However, while it might be tempting to invest in every shiny new solution, such an approach can be detrimental. Not only will a wide collection of automated security tools cost a lot, but it will also make the lives of the security teams that they have been acquired to serve more difficult, leaving them in a position where they must learn to navigate and maximise the use of tens of disparate tools.

To avoid these issues, organisations should look to adopt a converged security solution based on SIEM technology. IT and security complexities often arise from the need to integrate a variety of different technologies that are evolving in scope and functionality all the time.

By combining multiple solutions into one centralised platform, integration demands will ease while transparency into total cost of ownership and performance will improve. 

Without question, UEBA, threat intelligence automation and SOAR can help organisations by empowering security professionals and freeing them up to focus on high value tasks. However, it is the convergence of these technologies that promises to be the real gamechanger in helping businesses to navigate the cyber skills gap thus lowering the barrier to for entry level positions and giving organisations the ability to upskill and train as they see fit. 

Tim Wallen is Regional Director, UKI & BeNeLux for Logpoint

You Might Also Read: 

Simplifying Workflows With Centralized Tools & Automation:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« Demystifying Data Privacy Compliance
Microsoft 365 Under Threat From A New Phishing Tool »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

Perimeter 81 / How to Select the Right ZTNA Solution

Perimeter 81 / How to Select the Right ZTNA Solution

Gartner insights into How to Select the Right ZTNA offering. Download this FREE report for a limited time only.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

Malware.lu

Malware.lu

Malware.lu is a repository of malware and technical analysis. The goal of the project is to provide samples and technical analysis to security researchers.

Sentropi

Sentropi

Sentropi is an online protection solution against charge backs, account takeovers, identity thefts and online scams.

United Security Providers

United Security Providers

United Security Providers is a leading specialist in information security, protecting IT infrastructures and applications for companies with high demands on security.

Infodas

Infodas

Infodas provides Cybersecurity and IT consulting / system integration services as well as a range of innovative Cybersecurity products to public sector and commercial clients.

Seekurity

Seekurity

Seekurity is an information security consulting firm specialized in all areas of Cyber Security including Penetration Testing, Vulnerability Assessments and Risk Management.

Blockchain Firm

Blockchain Firm

Blockchain Firm is a leading Blockchain based software solutions and service provider with our roots of expertise running deep into the technology.

Satori Cyber

Satori Cyber

The Satori Cyber Secure Data Access Cloud is the first solution on the market to offer continuous visibility and granular control for data flows across all cloud and hybrid data stores.

Avertro

Avertro

Avertro helps leaders manage the business of cyber. We help explain cybersecurity to executives, forecasting outcomes, right-sizing your spend, and validating your cyber strategy.

AVANTEC

AVANTEC

AVANTEC is the leading Swiss provider of IT security solutions in the areas of cloud, content, network and endpoint security.

Integrity

Integrity

Integrity is a PCI QSA and ISO 27001 certified company specialized in Information Security and IT Consulting.

Conquest Cyber

Conquest Cyber

Conquest Cyber builds adaptive risk management programs where innovation is most needed – within defense, intelligence, federal civilian agencies and the industrial base that supports them.

Tenable

Tenable

Organizations around the world rely on Tenable to help them understand and reduce cybersecurity risk across their attack surface—in the cloud or on-premises, from IT to OT and beyond.

Gorilla Technology Group

Gorilla Technology Group

Gorilla specializes in video analytics, OT network security and big data to support a wide range of solutions for commercial, industrial, cities and government purposes.

Marlink

Marlink

Marlink smartly integrates hybrid, future-ready network solutions so you can benefit from the best available connectivity and IT to accelerate your digitalisation and empower your remote operations.

Certera

Certera

Certera is a modern and affordable SSL Certificate, Code Signing Certificate, and Cyber Security Services provider.

KTrust

KTrust

KTrust provides Continuous Threat Exposure Management for Kubernetes environments.