Big Data. Big Decisions
InformationWeek
Special Coverage Series


Security Skills Shortage, Or Training Failure?

Most IT security groups are short-handed and can't find good people to hire, research says. But the real issue may be failure to invest in training new and current personnel.

11 Security Sights Seen Only At Black Hat
11 Security Sights Seen Only At Black Hat
(click image for larger view and for slideshow)
Almost two-thirds of businesses say their information security departments are understaffed, and 51% say they can't find people with the required security skills.

Those findings come from a new Forrester Consulting report, "Security Intelligence Can Deliver Value Beyond Expectations And Needs To Be Prioritized," that was commissioned by IBM Global Technology Services. To make its point, the report largely references a Forrester Research survey of 2,400 executives and technology decision-makers at North American and European businesses, conducted more than a year ago.

According to the report, 53% of businesses say they can't find enough suitable employees to run in-house security intelligence programs. It describes security intelligence as "the real-time collection, normalization, and analysis of the data generated by users, applications and infrastructure that impacts the IT security and risk posture of an enterprise."

Not coincidentally, the report notes that security intelligence programs can be largely automated, thus eliminating the need for so many warm bodies. Cue complementary findings, such as one chart titled: "security intelligence as a service overcomes all challenges to deliver amazing value," which is sourced to a May 2012 survey of "75 North American, U.K., and Indian IT security enterprise decision-makers."

[ You don't want to get burned by this one. Read Reveton Malware Freezes PCs, Demands Payment. ]

Stepping back for a minute, whose fault is it that businesses, by their own admission, are facing a supposed talent shortage? Writing last year in The Wall Street Journal, human resources expert Peter Cappelli at the University of Pennsylvania's Wharton School lambasted business executives who said they didn't have sufficient access to talented personnel, when the very same people too often budgeted nothing for training, for either existing personnel or new hires, thus trapping their potential workforce in a Catch-22 situation. "One can't get work experience in school, and that's where training comes in," he said.

Likewise, in response to an InformationWeek column earlier this year that analyzed the supposed IT skills shortage, former hiring managers shared tales of "corporate cheapskates" who pursue the low-cost option at any cost, and failed to reinvest in their workforce, and then complained that they don't have enough fully trained--by others--personnel at their immediate disposal. "The moral compass is busted," said one Oracle/JDE consultant, noting that the days of many businesses investing in their employee's personal development appeared to be long gone.

In other words: Stop complaining about the skills shortage, and do something about it, both through training, as well as by working with local colleges and placement programs. "To get America's job engine revving again, companies need to stop pinning so much of the blame on our nation's education system," Cappelli said. "They need to drop the idea of finding perfect candidates and look for people who could do the job with a bit of training and practice."

Without a doubt, creating a top-notch information security program will demand investment, not least in training. And according to the Forrester survey, the information security risks that businesses must mitigate are very real: 72% of businesses said they're battling escalating and ever-evolving threats, 75% said knowing which threat to prioritize is a struggle, and 68% said that preventive measures are going by the wayside, owing to workload.

Given the escalating threat level, a recent study from IBM found--unsurprisingly--that chief information security officers (CISOs) are facing greater board-room pressure to improve their businesses' information security programs. Obviously, doing so will require spending money, and preferably to avoiding breaches, rather than simply to respond to them. "We know that it's much more expensive to implement your security controls afterwards," said Luba Cherbakov, a VP at IBM Security Services, speaking by phone.

For businesses that lack even a CISO, help is to hand--again, for a price. Multiple consulting companies, including CSC and IBM, offer placeholder CISO programs that can immediately put a temporary security executive in place, and then help the business build up their program and hire a suitable CISO replacement.

Beyond hiring a good CISO and investing in training for frontline security personnel, the information security calculus also requires knowing when it's best to outsource. Top candidates, according to Forrester, include outsourcing for email hygiene purposes (42% of respondents say they do this), firewall management (33%), vulnerability management (23%), and access management (22%).

Furthermore, many of these types of services work best when they tap into a bigger-picture view, either via the aforementioned type of threat or security intelligence feed, or simply handing specific functions off entirely to a managed services provider. Cherbakov, for example, said that IBM's managed service program processes over 15 billion potential security events per day, drawing information from over 3,700 clients. Having that volume of data to analyze makes it easier to spot many types of online threats and attacks.

In other words, when it comes to addressing information security challenges, help is to hand. So rather than whining about a skills shortage, businesses need to hire a great CISO, train personnel to handle the latest threats, outsource when it makes economic sense, and keep the budget flowing. If your business isn't helping to employ and train the next generation of information-security professionals, then it's part of the security problem.

Cloud services can play a role in any BC/DR plan. Yet just 23% of 414 business technology pros responding to our 2011 Business Continuity/Disaster Recovery Survey use services as part of their application and data resiliency strategies, even though half (correctly) say it would reduce overall recovery times. Our The Cloud's Role In BC/DR report shows how the combination of cloud backup and IaaS offerings can be a beneficial part of a "DR 2.0" plan. (Free registration required.)



Related Reading


More Insights




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

BYTE encourages readers to engage in spirited, healthy debate, including taking us to task. However, BYTE moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. BYTE further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.

Follow InformationWeek

By The Numbers

What Are Your Primary Concerns About Using Big Data Software?

Base: 417 respondents at organizations using or planning to deploy data analytics, BI or statistical analysis software
Data: InformationWeek 2013 Analytics, Business Intelligence and Information Management Survey of 541 business technology professionals, October 2012

What Do You Think?

What's your attitude about SQL analysis on top of Hadoop?
We want fast, standard SQL analysis capabilities on Hadoop ASAP
Hadoop is for unstructured data; SQL is for relational databases
We'll give SQL on Hadoop a try, but relational DBs will remain the mainstay
Given strong SQL support on Hadoop, we'd nix the data warehouse
We're not interested in Hadoop
No opinion



Related Content

From Our Sponsor

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Business leaders often need a visual snapshot of data to quickly grasp and use it. This paper identifies five challenges in presenting data and how visual analytics can resolve them. Solutions are suggested to overcome the challenges of: speed, data clarity, data quality, displaying meaningful results, and dealing with outliers.

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Today's competitive advantage requires a deeper understanding of your business, your market and your customers. As an IT executive, you can drive that knowledge transformation. In this white paper, learn how to make decisions as a strategic business leader and three steps to begin an analytics initiative within your enterprise.

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

High-performance data visualization turns sophisticated analyses into meaningful graphics, leading to faster and smarter decision making. In this white paper, learn how visual analytics can transform big data, with additional features such as real-time functionality, mobile compatibility, robust applications for technical groups and accessibility for nontechnical users.

Big Data: Lessons from the Leaders

Big Data: Lessons from the Leaders

Financial performance, competitive advantage, operational efficiency, strategic decision making - every business goal can extract value from big data, and the time for doubt or inaction has long passed. In this Economist Intelligence Unit report, in-depth interviews with data pioneers reveal the link between the effective use of big data and the bottom line among other results.

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Which came first, the data or the decision? This white paper makes the case for having a decision in mind, then tailoring big data's volume, variety and velocity to achieve business results such as overcoming customer dissatisfaction or creating well-informed strategies in real time.

Informationweek Reports

Research: The Big Data Management Challenge

Research: The Big Data Management Challenge

The challenge of big data is real, but most organizations don't differentiate 'big data' from traditional data, and nearly 90% of respondents to our survey use conventional databases as the primary means of handling data. We'll help you understand what constitutes big data (it's not just size) and the numerous management challenges it poses.