人才稀缺市场下保护你的企业——信息安全(英文版)_14页
报告摘要
PROTECTING YOUR ORGANIZATION IN A TALENT-SCARCE MARKET
Core Content
This document outlines the challenges and implications of the global information security talent shortage, emphasizing the increasing strategic importance of information security in today's business environment. It highlights the need for organizations to adapt their talent acquisition, management, and development strategies to address this critical issue.
Main Points
-
Security is in the spotlight: High-profile breaches have brought information security into the mainstream, increasing awareness and demand for security expertise. Organizations are now more focused on security threats, but readiness remains low.
-
Security breaches are inevitable: The document stresses that the question is not whether breaches will happen, but when and how severe they will be. Cyber threats are becoming more sophisticated and frequent.
-
Cost of breaches is rising: The average cost of a data breach is $3.8 million, with $154 per lost/stolen record containing sensitive information. There was a 38% increase in security breaches in 2015 compared to 2014.
-
Talent shortage is severe: The global demand for information security professionals is expected to grow to 2.5 million by 2019, while supply is projected to grow only by 1 million, leading to a 1.5 million gap.
-
Organizations are turning to contractors: 40% of organizations currently use contractors in information security, and 27% plan to increase their use. Contractors provide flexibility and access to expertise, but can lead to a loss of in-house knowledge and situational awareness.
-
Workforce composition is unbalanced: Most organizations rely on in-house staff (52%), while 15% use only contractors. A balanced approach (33%) is seen as more effective for addressing shortages and building long-term internal capabilities.
-
Experienced talent is scarce: Senior security professionals are in high demand but short supply. These roles require real-world experience and a nuanced understanding of organizational risks and strategies.
-
Education pipeline is broken: Traditional academic programs are not keeping up with the fast-paced evolution of security threats. There is a need for alternative education and training methods, such as technical colleges and work-study programs.
-
Certifications are not enough: While certifications are valued, they do not guarantee performance. Real-world experience and job history are more indicative of an individual's capability in information security roles.
Key Recommendations
-
Make information security talent management a priority: Ensure executive leadership is informed and involved in security decisions. The CISO should be a strategic business leader who can bridge the gap between technical and non-technical stakeholders.
-
Evaluate your staff annually: Conduct a skills inventory to identify and track critical security skills, and ensure coverage is adequate to meet current and future needs.
-
Develop talent from within: Cross-train existing employees with security exposure to build internal capabilities. This approach reduces acquisition costs and improves cultural fit.
-
Carefully screen new talent: Avoid hiring "pretenders" who use buzzwords in their resumes. Use experienced security staff to conduct deeper assessments of candidates.
-
Manage your talent supply chain innovatively: Explore contract expertise, project-based consulting, and temporary staffing as viable options for addressing short-term and specialized security needs.
-
Collaborate with talent agents: These agents should have deep security knowledge and innovative recruitment strategies. Regularly evaluate their performance to ensure they meet the evolving needs of the industry.
Conclusion
The shortage of experienced information security talent is unlikely to be resolved in the short term. Organizations must adopt innovative and flexible strategies to manage and expand their security workforce. This includes improving executive awareness, investing in alternative education and training models, and fostering collaboration across the industry to build a more resilient and capable security workforce.
试读结束,高清完整版pdf/doc/ppt,请点下载