classic | mobile
Follow us on:
Follow us on Facebook  Share via Twitter  Share via LinkedIn
 

Search...
Hi-Tech Security Solutions Business Directory
Residential Estate Security Handbook 2017


Security skills shortage?
May 2017, Cyber Security

It’s no secret that we’re currently faced with a global information security skills crisis. Given that the predicted increase in demand for information security professionals is exceeding the current rate of supply, we should be expecting a shortage as large as 1.5 million within five years, according to the Global Information Security Workforce Study.

Skilled security personnel are already feeling the effects of the crunch, evidenced in longer reaction times and the fact that only 20% of respondents felt confident that a system or data compromise response could be carried out within a single day, numbers that have dropped from 33% in 2013.

Simeon Tassev, MD and QSA, Galix Networking.
Simeon Tassev, MD and QSA, Galix Networking.

A recent Tripwire study discovered that roughly two-thirds of respondent organisations faced increased security risks due to the skills shortage, of these respondents, 69% have attempted to use technology solutions to fill the gap. It’s important to remember that technology can only fulfil its potential when interfaced with humanity, so businesses need to look at smarter ways to beef up on protection by applying intelligent security solutions that are outsourced to and overseen by security professionals.

No shortage of cyber threats

The skills shortage is both a problem and a challenge for South African businesses, however it’s not a challenge that is uniquely local. The main reason for such a global shortage is due to the length of time it takes to qualify as a security professional. With the various international certifications, even the most generic (like the Certified Information Systems Security Professional (CISSP) certification) has a minimum requirement of four to five years of working experience, and this is applicable to other certifications like compliance as well.

While it might take a long time for an individual to qualify, technology doesn’t wait. As we’ve seen, every year new technologies and new threats appear, and security professionals can’t qualify quickly enough to keep up with evolving cyber threats. Furthermore, there’s no quick-fix for this situation as it is not possible to fast-track the process, as the knowledge and experience is critical – the certification requires five years of experience because it takes time for individuals to be exposed to the various aspects of security and technology to gain the necessary skills.

This is a dangerous situation for South African businesses as the International Data Corporation has pointed out that some 52% of data that should be protected, isn’t. Furthermore, the IDC predicts that by 2018, roughly two-thirds of corporate networks will have experienced an Internet of Things security breach, while the Network Barometer Report points out that in 2015, at least 60% of all network devices had at least one security vulnerability, of which 76% were identified being more than two years old. All of these stats and figures point to the fact that organisations simply aren’t doing enough to ensure network security.

Bridge the gap, intelligently

It’s clear that security should be the single largest end-user computing concern for digital businesses. Nevertheless, what can organisations do when there simply aren’t enough professionals with the right skills for hire? Are automated security solutions effective enough to fill the gap?

The reality is that while there are various tools and automated security solutions that will assist, all of those tools will be exactly that – a tool for somebody to use. Individuals in charge of monitoring and using security solutions will require the skills and knowledge to interpret the output delivered by such tools in order to be truly effective. The most common way of working around a skills shortage is outsourcing.

This approach is successful when the right combination of tools is in place in order to minimise the amount of time required for a specialist to be physically involved in the security system. From an outsourcing perspective, instead of spending time sifting through logs, with the right tools, the specialist can turn to a summary report of all actions, or drill down and report on whatever is deemed necessary. This helps the specialist to maximise time, making it possible to provide the same functionality to many companies, not just one.

Technology is an ever-evolving entity – the pace of growing threats is simply too rapid to keep up with, causing the skills gap to widen even further. Given that it’s a problem that has no quick fix, it would be prudent for businesses to look to solutions that incorporate artificial intelligence – not in the Hollywood sense of the word, but rather more of an automated system with built-in intelligence.

By utilising such automated systems with intelligence, it is possible to minimise the amount of input needed from a security specialist to such an extent that he would only need to intervene in the case of an exception or crisis. With the right tools in place, and the right information security specialist, it becomes possible to automate 90% to 95% and reduce the required input of that specialist to only 5% to 10%, which should serve sufficiently to bridge the skills gap, allowing businesses to shield their digital assets effectively.

For more information contact Galix, 086 124 2529, simeon@galix.com


Credit(s)
Supplied By: Galix Networking
Tel: +27 11 472 7157
Fax: +27 11 472 8841
Email: info@galix.com
www: www.galix.com
  Share via Twitter   Share via LinkedIn      

Further reading:

  • Securing your access security
    November 2017, G4S South Africa, Impro Technologies, This Week's Editor's Pick, Access Control & Identity Management, Cyber Security
    While one may not consider access control solutions a prime hacking target, any connected device is a target in today’s world.
  • The missing mobile puzzle piece
    November 2017, Securicom IT Solutions, Cyber Security, IT infrastructure
    Companies are neglecting to define what resources can be accessed via mobile and have not identified what devices are already accessing the network.
  • Back(up) by popular demand
    November 2017, Cyber Security
    The market is demanding backup and storage solutions that are simple to operate, efficient, safe and that collate data in a centralised location, for easy accessing from anywhere, and on any device.
  • SOLID webKey is simple security
    November 2017, This Week's Editor's Pick, Cyber Security, News
    Ansys débuts its first consumer cybersecurity product with an all-in-one account protection device.
  • Physical and cyber defence centre
    November 2017, This Week's Editor's Pick, Cyber Security, News
    XON and NEC Africa will launch their joint Cyber Defence Operation Centre (CDOC), the only such facility from a single service provider in Africa that offers end-to-end physical and cyber defence services.
  • SA manufacturing companies take note
    November 2017, Dimension Data, Cyber Security, Security Services & Risk Management
    South Africa’s manufacturing sector is under growing threat of cyber attack, says Sean Duffy, executive of security solutions for MEA at Dimension Data.
  • Advanced malware protection
    November 2017, Duxbury Networking, Products, Cyber Security
    Intercept-X includes root-cause analytics and advanced malware clean up together with advanced anti-exploit features that block zero-day threats without the need for traditional file scanning.
  • South Africa is a target for cyber attacks
    November 2017, This Week's Editor's Pick, Cyber Security, Security Services & Risk Management
    South Africa is currently a magnet for cyberattacks, with hackers set on stealing data.
  • Sophos XG Firewall
    November 2017, Cyber Security, Products
    Firewall offers complete identification of unknown application traffic by using information directly from the endpoint, automatically identifies, classifies and controls custom, evasive and generic web applications.
  • Ransomware defined 2017
    November 2017, This Week's Editor's Pick, Cyber Security
    Ransomware ravaged Windows, but attacks on Android, Linux and MacOS systems also increased, while just two strains of ransomware were responsible for 89.5% of all attacks in 2017.
  • Packaged cyber-threat service
    October 2017, GNL Cyber, News, Cyber Security
    Gold ‘N Links Cyber introduces GNL CYBER 360, a per user, next generation cyber-threat packaged service.
  • More than physical intrusion
    October 2017, Mining (Industry), Cyber Security
    Mining and manufacturing sectors are becoming increasingly vulnerable to cyber attack. This is highlighted in Dimension Data’s Global Threat Intelligence Report for 2017.

 
 
         
Contact:
Technews Publishing (Pty) Ltd
1st Floor, Stabilitas House
265 Kent Ave, Randburg, 2194
South Africa
Publications by Technews
Dataweek Electronics & Communications Technology
Electronic Buyers Guide (EBG)

Hi-Tech Security Solutions
Hi-Tech Security Business Directory (HSBD)

Motion Control in Southern Africa
Motion Control Buyers’ Guide (MCBG)

South African Instrumentation & Control
South African Instrumentation & Control Buyers’ Guide (IBG)
Other
Terms & conditions of use, including privacy policy
PAIA Manual
         
    Mobile | Classic

Copyright © Technews Publishing (Pty) Ltd. All rights reserved.