# Finding it hard to recruit good IT security managers? Don’t leave yourself vulnerable to attack
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2022-06-29
Category: TECHNOLOGY
Category URL: https://financedigest.com/category/technology
Meta Title: Increasing Demand for Cyber Security Staff: Where Are They?
Meta Description: Discover the latest insights on the shortage of cyber security professionals and how organisations can adapt to attract and retain talent in a changing
URL: https://financedigest.com/finding-it-hard-to-recruit-good-it-security-managers-dont-leave-yourself-vulnerable-to-attackhtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/istock-1011996682-1736815616529-compressed.jpg)

_By_ **_Dave Waterson,_** _CEO, SentryBay_

There is a growing demand for skilled cyber security staff and, it seems, a lack of candidates. Where are they all? The truth is that the pandemic shook up the [labour market](https://www.financedigest.com/spains-labour-market-resilient-as-unemployment-drops-in-nov.html "Spain’s labour market resilient as unemployment drops in Nov") and many executives at all levels and across all departments have moved on, including those in security.

According to ISACA’s recent [State of Cybersecurity Report 2022](https://www.isaca.org/go/state-of-cybersecurity-2022) which is conducted annually amongst security professionals around the world, any positive effect that the pandemic had on retention in 2020 had worn off a year later. As a result, 63% of respondents had unfilled [cyber security](https://www.financedigest.com/how-to-handle-cyber-security-during-mergers-and-acquisitions.html "How to Handle Cyber Security during Mergers and Acquisitions") positions, an increase of 8% over 2021. An additional 62% said they had understaffed [cyber security](https://www.financedigest.com/the-future-of-cyber-security.html "THE FUTURE OF CYBER SECURITY") teams, and a fifth reported that it was taking more than six months to fill open positions. This reflects what we at SentryBay have observed in the marketplace.

It’s not just that talent seems so hard to find, but that organisations have not kept up with the changing expectations of the [cyber security](https://www.financedigest.com/why-preparation-for-new-swift-cyber-security-standards-needs-to-start-now.html "‘Why preparation for new SWIFT cyber security standards needs to start now’") workforce. The [pandemic brought about a change in attitudes with many employees keen to see an improved](https://www.financedigest.com/how-to-improve-sales-during-a-global-pandemic.html "How to improve sales during a global pandemic") work-life balance. Flexible working arrangements are now expected by staff, but for companies, a [return to the physical office](https://www.financedigest.com/are-we-witnessing-the-great-return-to-the-office.html "Are we witnessing the great return to the office?") is preferred. On top of this, and against a backdrop of increasing food, retail, energy and petrol prices, higher [wages are in demand](https://www.financedigest.com/apples-australian-workers-go-on-christmas-strike-demanding-better-wages-work-terms.html "Apple’s Australian workers go on Christmas strike demanding better wages, work terms"). As the [requirement for talent increases](https://www.financedigest.com/anti-money-laundering-requirements-are-the-stakes-increasing.html "Anti-money laundering requirements: are the stakes increasing?"), candidates are using this situation to gain leverage, and if the job spec doesn’t suit them, they can afford to look elsewhere.

The battle to solve this problem is being fought on two fronts. The first is to adjust traditional approaches and increase transparency during the interview [process to ensure the expectations of both the candidate and the company](https://www.financedigest.com/companies-that-dont-upgrade-their-financial-processes-this-year-will-get-left-behind.html "Companies that don’t upgrade their financial processes this year will get left behind") are aligned. The second, however, is the looming worry of remaining cyber [secure in the absence of a fully staffed and qualified team and a rapid escalation in attacks](https://www.financedigest.com/2018-it-security-predictions-methods-for-attacks-investment-areas-cybersecurity-strategies.html "2018 IT Security Predictions-Methods For Attacks, Investment Areas & Cybersecurity Strategies").

**[Financial services](https://www.financedigest.com/how-financial-services-are-overhauling-security-to-defend-against-spoofing-scams.html "How financial services are overhauling security to defend against spoofing scams") companies must shore up their systems**

Considering that, according to some reports, cyber criminals are 300x more likely to target [financial services](https://www.financedigest.com/devops-the-secret-tool-thats-transforming-financial-services.html "DevOps: The Secret Tool that’s Transforming Financial Services") providers and businesses than any other industry, the need to shore up these systems and services has become acute. Now is the time to look at implementing cyber security measures that can deliver comprehensive protection for applications and data, regardless of where employees are working, and which can be automated to give the entire company protection quickly while [demanding the least from time-strapped security](https://www.financedigest.com/new-demands-on-network-security.html "NEW DEMANDS ON NETWORK SECURITY") teams.

One of the [main vulnerabilities is the endpoints being used by employees](https://www.financedigest.com/employee-wellbeing-main-priority-for-uk-banks-as-they-seek-to-attract-quality-talent.html "Employee wellbeing main priority for UK banks as they seek to attract quality talent"), from laptops and mobile phones through to tablets, IoT devices and desktop PCs. In physical offices these are usually [secured through strong corporate protection](https://www.financedigest.com/5-ways-to-protect-your-company-from-cyber-security-threats.html "5 Ways to Protect Your Company From Cyber Security Threats"), but in today’s more flexible working environment, devices are as itinerant as their users. It takes only one unsecured endpoint connected to the corporate network – in the [office or remotely – to open](https://www.financedigest.com/barclays-private-bank-opens-new-office-in-verbier-switzerland-for-2022-23-ski-season.html "Barclays Private Bank opens new office in Verbier, Switzerland for 2022/23 Ski Season") a gap which, if compromised, can lead to a cyber attack.

Unfortunately, standard [security measures are not enough](https://www.financedigest.com/the-challenge-of-keeping-data-secure-why-in-house-security-isnt-enough.html "The challenge of keeping data secure: why in-house security isn’t enough"), even if they combine antivirus, internet protection and endpoint detection and response (EDR). They were not designed to [manage remote devices](https://www.financedigest.com/the-clot-management-devices-market-to-be-digitally-absorbent.html "The Clot Management Devices Market to be digitally absorbent"), and that combination of solutions will identify less than 50% of the attacks that are occuring today.

If enterprise cyber teams are being forced to prioritise their efforts, [endpoint security is a great place to start since they are so often the favoured access point for cyber-attackers who use the keyboard and screen as the attack](https://www.financedigest.com/new-intelligence-points-to-pro-ukraine-group-in-nord-stream-attack-nyt.html "New intelligence points to pro-Ukraine group in Nord Stream attack -NYT") vector to steal sensitive data.

Kernel-level keyloggers, for example, bury into the system silently and sit at a low-level, harvesting keys that are tapped onto the keyboard. Obviously, the benefit to the keylogger is from grabbing passwords, [security details and other sensitive data](https://www.financedigest.com/2023-fintech-prediction-secure-and-private-data-usage-is-key.html "2023 FinTech Prediction: Secure and Private Data Usage is Key") which they will later use.

Screen capture attacks work in a similar way, tracking and capturing personal details as they are displayed, putting at [risk the data](https://www.financedigest.com/tesla-to-warn-of-data-privacy-risk-from-car-security-cameras-in-germany.html "Tesla to warn of data privacy risk from car security cameras in Germany") held within applications. Some [financial companies](https://www.financedigest.com/how-can-financial-services-companies-compete-more-effectively-in-times-of-uncertainty.html "How can Financial Services Companies compete more effectively in times of uncertainty?") advise their staff to use two-factor authentication, deploy complex passwords and update them regularly, but the risk remains to information held within applications.

What organisations most benefit from is a fortified environment that allows employees, both in the office and working remotely, to [securely connect to their network](https://www.financedigest.com/uks-morgan-advanced-materials-reports-cyber-security-incident-on-its-network.html "UK’s Morgan Advanced Materials reports cyber security incident on its network"). And it is not just the benefits this kind of environment provides against cyberattacks, but in ensuring they comply with [industry regulations](https://www.financedigest.com/how-solvency-ii-transformed-itself-the-fund-industry-and-regulation.html "How Solvency II transformed itself, the fund industry and regulation"), international laws and local guidance.

**[Winning the battle](https://www.financedigest.com/fraud-wars-how-can-biometrics-help-win-the-card-fraud-battle.html "Fraud Wars: How Can Biometrics Help Win The Card Fraud Battle?") on the cyber front**

Looking again at the ISACA report it is possible to [see a correlation between staffing levels](https://www.financedigest.com/fraport-sees-2023-passenger-traffic-at-80-90-of-pre-pandemic-levels.html "Fraport sees 2023 passenger traffic at 80-90% of pre-pandemic levels"), retention and cyberattacks – 69% of respondents whose organisations experienced more cyberattacks over the past year said that they were somewhat or significantly understaffed.

Solving this problem by finding and keeping new, highly qualified security talent, is the answer, of course, however it is likely to take some [time and a new approach](https://www.financedigest.com/anti-money-laundering-time-to-take-a-new-approach.html "ANTI-MONEY LAUNDERING: TIME TO TAKE A NEW APPROACH?") to cybersecurity investment. Meanwhile, security teams [need bolstering with the use of dedicated solutions that are designed to minimise management](https://www.financedigest.com/struggling-banks-need-to-modernise-and-improve-software-quality-management.html "Struggling Banks Need to Modernise and Improve Software Quality Management"), maximise automation, and deliver protection where it is needed most, at endpoint devices.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

