Your Greatest Cyber Talent Threat Is Not Your External Applicants -- But What Is It?



This is a bit of a poll question for you. What's your biggest threat when it comes to your cybersecurity operations?

Is it...

A. Your external applicants

B. Your cybersecurity leaders

C. Your cybersecurity managers

D. Your cyber-engineers

This week I read a piece, "The hiring tunnel is now an attack surface," advocating for the position that applicants are the greatest threat. In essence the argument boiled down to: they're a threat because they're outside your cyber-system (i.e. they are applicants), they could be malicious actors looking to infiltrate your systems, and they can/will defeat your applicant process.

I only paid attention to this post because it was boosted by Steve Hunt on LinkedIn. Steve is a really smart guy and what he says, matters.

Here is how Steve summarized the 'attack surface' post:

1. Candidate fraud is an organizational risk, not just a hiring risk. [It affects] operational effectiveness, information security, compliance, and organizational reputation

2. Talent acquisition is the first team to encounter candidate fraud, but fraud prevention requires collaboration among Security, Legal, IT and business leadership.

3. [Traditional talent acquisition metrics punish recruiters that invest in fraud detection]…time-to-fill goes up, cost-per-hire goes up, pipeline conversion rates go down. A recruiter who adds friction to catch fraud is hurting their own performance. Until talent acquisition scorecards include measures of quality-of-hire the incentive structure punishes the right behavior.

4. Most accuracy statistics in this marker are self-reported by vendors against methodologies they designed on populations they selected…buyers should weight structural questions and third-party certifications more heavily than accuracy presentations when evaluating vendors.

Two points came out of the threat post & Steve's reaction for me. 

First, hiring is a type of "mini-max" function where you find a balance of costs or risks relative to reward. Whenever you bring someone into the team that hire is the least risky choice of candidates you've reviewed who also has the most talent. Most hiring functions focus on potential without acknowledging the risks.

Second, like most things, the more you hurry the hiring process the greater the risk you're going to mess something up. That does not mean you need to take for-frickin'-ever to make a hire after 5 or more rounds of interviews. It means that your employee lifecycle functions -- talent acquisition, onboarding, upskilling/re-skilling, performance management, etc. -- are mis-aligned. You probably only find that out when you "need" to make a new hire "now." 

The problem with believing that your applicant funnel is a threat vector is that, actually, all candidates -- even executives -- are a threat because they're moving into a new role and while all new hires are certified rock stars on Day 1 they might fail by Day 90. 

Your greatest cyber talent threat is your cyber talent management strategy. As our friend Barry Conchie recently noted on LinkedIn: "Great organisations don’t just 'build talent.' They distinguish between performance, experience, potential, and capability, then make evidence-based decisions about each."

Remember: there are no HR emergencies. And if there are, it's because no one thought through how to mitigate cyber talent risks at all steps of the hire-to-retire process.

Ask us how you can create a strategy that works for you.

Comments