{"id":68593,"date":"2022-02-17T12:49:44","date_gmt":"2022-02-17T12:49:44","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/2022\/02\/17\/why-evolving-hiring-paradigms-is-key-to-solving-the-uaes-cybersecurity-skills-gap\/"},"modified":"2023-05-25T10:29:16","modified_gmt":"2023-05-25T09:29:16","slug":"why-evolving-hiring-paradigms-is-key-to-solving-the-uaes-cybersecurity-skills-gap","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2022\/02\/17\/why-evolving-hiring-paradigms-is-key-to-solving-the-uaes-cybersecurity-skills-gap\/","title":{"rendered":"Why evolving hiring paradigms is key to solving the UAE\u2019s cybersecurity skills gap"},"content":{"rendered":"\n<p><em>The burgeoning skills gap is a heavily discussed topic among cybersecurity professionals as they attempt to find a solution to this ongoing problem. Toni El Inati, RVP Sales, META &amp; CEE, Barracuda Networks, says it isn\u2019t just training, but rather constant, career-long commitment to upskilling and adapting that will prove to be the hallmark of top cybersecurity professional.<\/em><\/p>\n\n\n\n<p>With the UAE leading the region in terms of digital maturity, it\u2019s no surprise that cybersecurity failure has now ranked as the greatest risk to the country, according to the World Economic Forum\u2019s <a href=\"https:\/\/www.weforum.org\/reports\/global-risks-report-2022\" target=\"_blank\" rel=\"noreferrer noopener\"><em>The Global Risks Report 2022<\/em><\/a>. For businesses in the country, this challenge is exacerbated by an ever-widening cybersecurity skills gap.<\/p>\n\n\n\n<p>Organisations have been forced to respond by placing new recruits on the proverbial frontlines of the battle against cyberthreats, many of whom aren\u2019t yet up to the task. A global&nbsp;<a href=\"https:\/\/venturebeat.com\/2021\/11\/24\/report-cybersecurity-recruitment-training-misses-the-mark\/\" target=\"_blank\" rel=\"noreferrer noopener\">survey<\/a> of cybersecurity professionals working in enterprise IT organisations conducted by Cyberbit, a provider of a platform for training cybersecurity professionals, found that 41% use on-the-job training to train new team members. That compares to just over a quarter that provide access to security courses, and 22% that make use of simulation-based training tools such as cyber labs, cyber ranges, or red vs. blue training. Not surprisingly, only 45% of respondents said they felt their team was adequately skilled in intrusion detection, while even less (42%) said they adequately understood network monitoring.<\/p>\n\n\n\n<p>In times of urgency and crisis, it\u2019s understandable that businesses won\u2019t have the luxury of upskilling new personnel to the point where they\u2019re hardened veterans. But just as the realisation that cybersecurity threats are only set to worsen dawns, so too must the realisation that the \u2018quick fix solution\u2019 of placing insufficiently trained staff in demanding roles and then offering them the opportunity to upskill &#8211; a recipe for disaster in the long run.<\/p>\n\n\n\n<p>Poorly trained workers are much more likely to suffer from poor morale. Each security incident that goes undetected for months results in an emotional toll. One of the reasons cybersecurity turnover rates are so high is that many cybersecurity professionals become disheartened. Without the opportunity to ramp up their abilities, these new recruits will constantly find themselves on the backfoot and often in the uncomfortable position of having to answer to management for lapses in their organisation\u2019s security posture.<\/p>\n\n\n\n<p><strong>The trouble with training<\/strong><\/p>\n\n\n\n<p>While it would appear that cybersecurity training for industry professionals offers a simple and effective solution, this doesn\u2019t account for the complete picture. Just as it is often stated that no solution offers the \u2018silver bullet\u2019 to addressing all cyberthreats, training cannot guarantee future success.&nbsp;Cybersecurity threats&nbsp;are evolving faster than training programmes can keep pace with. No matter how talented any cybersecurity professional may be, there will always be days when the bad guys have developed some new technique that has never been seen before.<\/p>\n\n\n\n<p>More challenging still, the need for many of the skills that new recruits are being taught today are likely to become unnecessary in the months ahead as cybersecurity becomes more automated. Advances in, for example, Artificial Intelligence (AI) will not replace the need for cybersecurity professionals anytime soon. However, the bar in terms of the knowledge that will be required will soon be higher as more low-level tasks that allowed entry-level cybersecurity professionals to be trained on the job are simply no longer required.&nbsp;Entry-level cybersecurity tasks&nbsp;such as log monitoring, maintaining backups and managing updates are all becoming increasingly automated.<\/p>\n\n\n\n<p>So, it isn\u2019t just training, but rather constant, career-long commitment to upskilling and adapting that will prove to be the hallmark of a top cybersecurity professional. Unfortunately, many human resources professionals are out of touch with this reality. Instead of hiring candidates who are willing to be trained, they post entry-level positions that, for example,&nbsp;require certifications that take years to acquire.<\/p>\n\n\n\n<p>Only a third (33%) of the respondents to the aforementioned Cyberbit survey reported that human resources recruiters for their company usually or always understand the requirements for working on a cybersecurity team. Additionally, 70% of respondents said that cybersecurity candidates are being assessed in the same way as other workers \u2014 through interviews \u2014 rather than&nbsp;using tools to assess their practical skills.<\/p>\n\n\n\n<p><strong>Reassessing hiring<\/strong><\/p>\n\n\n\n<p>These challenges can only be addressed by a radical revaluation of hiring policies. In the fast-paced world of cybersecurity, hard-earned skills and certifications that were months or years in the making can be rendered obsolete in far shorter timeframes. New technologies will constantly erode the value of low-level skills, while new threats will promote the need for constant learning.<\/p>\n\n\n\n<p>In such a stressful work environment, only the most ardent and determined of recruits will have the unshakable will to \u2018stay the course\u2019 and constantly seize upskilling opportunities in their quest to becoming invaluable industry veterans.<\/p>\n\n\n\n<p>The most important thing to HR teams to evaluate therefore when it comes to hiring cybersecurity professionals is now going to be attitude. After all, skills can only be acquired by the willing and able. The most important thing is to determine as early as possible who has the fortitude to do the job not only as it is known today, but the willingness to adapt to how it will inevitably evolve tomorrow.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The burgeoning skills gap is a heavily discussed topic among cybersecurity professionals as they attempt to find a solution to this ongoing problem. Toni El Inati, RVP Sales, META &amp; CEE, Barracuda Networks, says it isn\u2019t just training, but rather constant, career-long commitment to upskilling and adapting that will prove to be the hallmark of [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":68596,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,6,78,9961,13,79],"tags":[14171,14478,8510,3901,184],"class_list":["post-68593","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-insights","category-regional-news-newsletter","category-thought-leadership","category-top-stories","category-used","tag-barracuda-networks","tag-cyberbit","tag-cybersecurity-skills-gap","tag-cybersecurity-threats","tag-uae"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/68593","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=68593"}],"version-history":[{"count":11,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/68593\/revisions"}],"predecessor-version":[{"id":68715,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/68593\/revisions\/68715"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/68596"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=68593"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=68593"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=68593"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}