Why Is Filling Cybersecurity Roles So Hard?

Sisyphus tries the other way - panoramioIt is not your imagination. You are not unlucky. Hiring people for cybersecurity jobs often involves more risk and less reward than other kinds of recruiting. Frequently the cost, in time and effort, is higher and the reward, performance and tenure, is lower.

There are many reasons for this. For one thing, most executives outside of cybersecurity don't know much about the field. It is a rare executive who isn't at least broadly familiar with finance, accounting, marketing and sales. It is a rare executive who is familiar with cybersecurity.

You are likely not very familiar with the practice of cybersecurity because it is a relative newcomer to the C-Suite for most industries. The need has exploded. This means that there are too many openings chasing too few qualified applicants which has resulted in most of us having to settle for less than ideal candidates.

Settling for less than ideal candidates means having to use proxies and guesswork instead of the tried-and-true pillars of recruitment: education, certification and experience. "Skills and knowledge" if you prefer. Except that the required skills change very six months and the required knowledge is not much more stable. Therefore you really need to assess talent because talent adapts to future demands but skills are often only somewhat transferable. Out-of-date knowledge can worse than ignorance in that it misleads and leads to overconfidence. Instead of recruiting a profile that has worked often in the past you are trying to find a diamond in the rough--and you don't really know what a rough diamond looks like.

All this pressure on cybersecurity hiring has had a side-effect: short tenure. Two years is a common tenure. Six months is not unheard of. With too many jobs chasing too few qualified people, the good hires are in high demand and there is often someone with deeper pockets looking to poach your diamond. The bad hires--low talent people or people who just are not a good fit for your needs--are also able to leave, partly because when you hired them they became "experienced." This short tenure means that the return on investment is low even if you keep making great choices.

This set of challenges is why we at Pythia Cyber much prefer Talent Acquisition & Upskilling to traditional recruitment.

The talent acquisition part is pretty obvious: to make better, surer hires in cybersecurity you should hire talent. To hire talent you need better measures of talent than the usual weak proxies. Pythia Cyber's talent assessment instrument and associated reports give you those better measures.

The upskilling part is not quite as obvious: given the changing threat environment, your cybersecurity people need to constantly adapt to new threats while maintaining a high level of performance in combating current threats. Upskilling starts with hiring flexible, curious people but that is not the end. After you hire the right people you have to support their continuing education and their continuing evolution. You have to make sure that your culture is supportive and that your organization is maintaining commitment to the mission and not mere compliance with the procedures. Pythia Cyber's team dynamics review is great way to see how well you are doing in this regard.

Hiring cybersecurity personnel is hard. Keeping them focused on current threats while aware of coming threats is a constant challenge. We can help. Read more on our site.

Comments