Has Demand For Cyber Security Skills Hit Crisis Point?

The Parliament's Joint Committee on the National Security Strategy, a cross-party group that works across both the Commons and Lords, published a report in July that exposed the UK's chronic lack of digital skills, even within some of its own security agencies.

A summary to the report, entitled Cyber Security Skills and the UK's Critical National Infrastructure, reads as follows: "During our ongoing inquiry into the cyber security of the UK's critical national infrastructure (CNI), we heard that although the UK has one of the most vibrant digital economies in the world, there is not currently the cyber security skills base to match, with both the Government and private sector affected by the shortage in skills".

The committee heard from some of those at the forefront of the UK's cyber security industry. Ciaran Martin, CEO of the National Cyber Security Centre (NCSC), who told the committee he found it a "constant and difficult challenge" to recruit the deep technical expertise needed. It also heard from Rob Crook, managing director of Cyber and Intelligence at the defence engineering and cyber security company Raytheon UK, who put the vacancy rate in the company's cyber security unit at 20–30%.

The committee says it was "struck by the Government's apparent lack of urgency in addressing the cyber security skills gap in relation to CNI", and that it believes the government lacks the ability and understanding to address the gap between skills supply and demand.

The need for new blood

Fixing the problem may prove to be quite a challenge. BCS, the Chartered Institute for IT, says it was dismayed by this year's GCSE results which showed a 16.6% fall in the number of students sitting a computing-related topic. When IT Pro spoke to BCS, a spokesperson told us that we "need a critical mass of new blood entering the profession to close that skills gap".

The spokesperson pointed to the UK's National Security Strategy 2016-2021, which had identified that "the lack of young people entering the profession" and "the absence of established career and training pathways into the profession" were two of the main factors contributing to the skills gap.

As we reported in August, analysis of figures released by UCAS in August showed a noticeable decline in the number of students pursuing STEM-related subjects at university, despite a growth in interest at A-level.

BCS proposed fostering more "apprenticeships in cyber security, which as well as providing an extremely worthwhile career, are also well-paid, with salary expectations typically 15% above the industry standard".

However, according to Bryan Betts, principal analyst at Freeform Dynamics, this "arms race" has been a prevailing problem for many years and almost certainly going to get worse.

"There is some good news on the horizon – more students passing A-level computing this year, for instance – but of course they're going to need to learn a lot more to be useful in cybersecurity," he explains.

Making cyber security attractive

Talal Rajab, head of programme for Cyber and National Security at techUK, told us the organisation is working closely with Department for Digital, Culture, Media and Sport (DCMS) on setting up a "professional body for cyber security that would grant royal chartered status to cyber professionals". This would effectively raise the position above other IT industries, where professionals would be required to act in accordance with ethical guidelines, for the good of the public.

BCS appears to be in broad agreement with this strategy. "Cyber events continue to have a growing impact on our society, and we can no longer manage this as a technology issue in isolation," its spokesperson told us. "The demands of the organisations and institutions like the NHS that we protect, mean that the whole issue of cyber risk management needs to be professionalised."

Prestige is certainly one way to attract more people to the profession, but they won't all want to work for a public body.

"People with strong cybersec skills are out there, but there's not nearly enough, and many of them don't want to work for a government," says Betts. "That might change if the UK government could foster a startup-like environment, but the current lot give the impression they'd have trouble fostering a hamster, never mind a startup."

Cyber security skills strategy

As Betts explains, the major problem facing the government is that this issue requires a long-term commitment, as "it's probably a ten-year project to build up the skills base".

And there's the rub. While there's a challenge in recruiting right now, it could get a lot worse if we don't have a plan in place to ensure that people take up the kinds of subjects at school that will encourage them towards a career in cyber security.

The Joint Committee on the National Security Strategy is backing the proposal for such a plan. Its report urges the government to work with industry to help formulate a robust education policy that will deliver the skills needed in the future, as well as support continuing professional development for educators. It also suggests reskilling and using aptitude rather than qualifications as a basis for recruitment.

The committee also believes "the Government's immediate priority should be the publication of a cyber security skills strategy," as until the homegrown workforce is available, the industry needs to be aware of how the government plans to alleviate the strain.

Perhaps when that appears, we will get a better idea of the government's strategies for the months and years ahead.

ITPro:

You Might Also Read:

AI & Machine Learning Are Adding To The Skills Shortage

« Millions Of WiFi Routers Are At Risk Of Hacking
Spyware Proliferates To 45 Countries »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

ANS Group

ANS Group

ANS are a strong team of straight-talking tech and business experts. Our mission is to make digital transformation accessible to all.

Hack in the Box Security Conference (HitBSecConf)

Hack in the Box Security Conference (HitBSecConf)

HITBSecConf is a platform for the discussion and dissemination of next generation computer security issues. Our events feature two days of training and a two-day multi-track conference

Sikur

Sikur

Sikur have developed a communication platform that sets new boundaries for corporate privacy and security.

LEPL Cyber ​​Security Bureau - Georgia

LEPL Cyber ​​Security Bureau - Georgia

The aim of the LEPL Cyber Security Bureau is to create and strengthen stable, efficient and secure systems of information and communications technologies.

infySEC

infySEC

InfySEC is an information security services organization offering Security Technology services, Security Consulting, Security Training, Research & Development.

Level Effect

Level Effect

Level Effect is developing new capabilities to bring a unique perspective on proactive network defense and advanced security analytics.

Cyber Pathways

Cyber Pathways

Cyber Pathways brings together the next generation of Cyber professionals along with delegates who are looking to cross train and enter the cyber market.

Vietnamese Security Network (VSEC)

Vietnamese Security Network (VSEC)

Vietnamese Security Network (VSEC) is an information security company providing website vulnerability scanning and monitoring services.

World Informatix Cyber Security (WICS)

World Informatix Cyber Security (WICS)

World Informatix Cyber Security provides a range of cyber security services to protect valuable information assets to global business and governments.

Technology Innovation & Startup Centre (TISC)

Technology Innovation & Startup Centre (TISC)

TISC is a startup incubator at the Indian Institute of Technology Jodhpur (IITJ) and we back deep-tech startups.

Phished

Phished

Phished is an AI-driven platform that focuses on the human side of cybersecurity. By combining fully automated training software with personalised, realistic simulations of cyberattacks.

BlueAlly

BlueAlly

BlueAlly helps clients scale, optimize, and manage their IT resources to reach their business goals.

Ethiopian Cybersecurity Association (ECySA)

Ethiopian Cybersecurity Association (ECySA)

ECySA was formed to play an influential part in the ongoing and dawning cybersecurity practices of Ethiopia, efficiently creating public and private awareness on all kinds of cyber risks and threats.

Training.com.au

Training.com.au

Training.com.au is a comparison website through which those looking to learn about different aspects of cyber security can compare learning courses from training providers from across Australia.

Assured Clarity

Assured Clarity

Assured Clarity are a global consultancy, specialising in Risk Management and Data Privacy, through Education, Awareness and Training, throughout an organisation.

NOYB

NOYB

NOYB is a non-profit organization aiming to close the gap between privacy laws and the reality of corporate practice.