75% of companies 'lack enough security staff'

Most firms struggle to fend off cyber attacks due to few skilled workers

Three-quarters of companies do not have enough skilled security workers to protect against cyber attacks, a new study suggests.

Security company Tripwire's research revealed that out of 500 IT security employees surveyed, only 25% felt that their companies' IT departments had enough people with enough skills to combat a major cyber security breach.

This lack of trained professionals is putting organisations at risk, and 66% of respondents reported that it was actively increasing security risks in their organisation.

Almost 70% have tried to plug the skills gap in their organisation with security but that's not enough, according to Tripwire's senior director of IT security and risk strategy, Tim Erlin.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

"Having the right tools is only part of the solution," he said. "A lack of cybersecurity skills not only degrades an organisation's ability to respond to incidents, it also inhibits organisations from developing and deploying effective prevention."

This survey, along with many similar ones, reveals that there simply aren't enough people working in the cybersecurity field, but it also gives a clue as to why. The industry currently has a huge problem when it comes to the recruitment and development of new infosec professionals.

When questioned, over 70% of respondents admitted that they or their organisation found it difficult to hire cybersecurity experts, and almost 80% said that they had no facilities for increasing the expertise of existing security staff, and over half reported experiencing problems with staff retention.

Hiring, training, and retaining security personnel is clearly a problem for many companies, but while almost 30% admitted that their existing programmes were ineffective, a full half of respondents stated that they had no such programmes at all.

"Cybersecurity is a growth industry for employees," Erlin said, "and supply is falling far short of demand. Smart organisations need to establish effective programs for educating and developing employee skills around information protection."

Featured Resources

What you need to know about migrating to SAP S/4HANA

Factors to assess how and when to begin migration

Download now

Your enterprise cloud solutions guide

Infrastructure designed to meet your company's IT needs for next-generation cloud applications

Download now

Testing for compliance just became easier

How you can use technology to ensure compliance in your organisation

Download now

Best practices for implementing security awareness training

How to develop a security awareness programme that will actually change behaviour

Download now
Advertisement

Recommended

Visit/security/internet-security/354417/avast-and-avg-extensions-pulled-from-chrome
internet security

Avast and AVG extensions pulled from Chrome

19 Dec 2019
Visit/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you
Security

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

Visit/policy-legislation/data-governance/354496/brexit-security-talks-under-threat-after-uk-accused-of
data governance

Brexit security talks under threat after UK accused of illegally copying Schengen data

10 Jan 2020
Visit/operating-systems/microsoft-windows/354526/memes-and-viking-funerals-the-internet-reacts-to-the
Microsoft Windows

Memes and Viking funerals: The internet reacts to the death of Windows 7

14 Jan 2020
Visit/network-internet/broadband/354530/openreach-offers-free-full-fibre-installation-for-thousands-of
broadband

Openreach offers free full-fibre installation for thousands of homes

14 Jan 2020
Visit/security/vulnerability/354524/microsoft-to-patch-extraordinarily-serious-cryptographic-flaw
vulnerability

Microsoft to patch ‘extraordinarily serious’ cryptographic flaw

14 Jan 2020