The science of securing cyber skills

1 February 2018 Information Security, Training & Education

A recent scientific report found that our memories simultaneously generate two forms of personal experience. The hippocampus captures knowledge for the short term and the cortex banks it for the future. Businesses would do well to emulate such foresight and mental dexterity when it comes to bridging what is fast becoming a cavernous cybersecurity skills gap. As technology rapidly transforms the way we live and work, how do decision-makers secure the talent that will lay the foundations for the future?

Martin Walshaw, senior systems engineer at F5 Networks.
Martin Walshaw, senior systems engineer at F5 Networks.

The skills gap

We live in a security conscious, app-powered, multi-cloud world and the demand for expertise capable of deciphering advanced technology and adding strategic value is reaching fever pitch. Cisco estimates there are a million unfilled cybersecurity jobs worldwide and Symantec predicts that the figure will rise to 1.5 million by 2019. In fact, Facebook security head honcho, Alex Stamos, recently summarised the situation. “Things are getting worse”, he said, speaking at the 2017 Black Hat conference. “We do not have enough people and not the right people to make the difference.”

The digital world is dynamic and complex, leaving slow-moving businesses without integrated security solutions vulnerable and uncompetitive. The skill deficit is especially pronounced when cloud technology is involved, because speed to market, agility, and innovation are increasingly becoming business prerequisites. Those firms without the in-house resources to handle data and application migration are under intense pressure. The need to manage and migrate apps more efficiently, whether public or private, has gained unstoppable momentum. The drive to reduce operational costs and keep the business profitable is unavoidable.

According to F5’s State of Application Delivery (SoAD) Report, 34% of surveyed customers cited the ‘skills gap’ as a significant security challenge. A scarcity of cybersecurity experts clearly needs urgent attention and only a robust combination of investment, business resource, political will, and cultural change can shift the tide.

Shaping the future

Today’s youngsters are technologically immersed in an unprecedented way. Their lives are shaped by data both in the way they learn and play. To ensure they become responsible, vigilant cybercitizens, it is crucial to integrate smarter security disciplines into their school curriculum and home life from the outset, whether for personal protection or longer-term employment prospects.

Governments and academic institutions frequently tout the importance of STEM (science, technology, engineering, and mathematics) skills at school, but the acronym is arguably a letter shy. In today’s digital society, perhaps we should re-consider STEMS by adding ‘S for Security’ to the education agenda. By bringing the subject into the daily programme, students will understand the issues and quickly follow best practice to discern right from wrong. Tackling the problem early on also paves the way for improving the current problem of an insufficient number of security specialists graduating from university.

There is also significant potential to more actively encourage women to pursue cybersecurity as a career. According to the Global Information Security Workforce Study, only 7% currently do so, but there is a growing appetite to change this issue. The male dominated IT industry has a big responsibility here. As ever, sustainable success will be dependent on government and industry collaboration, as well as incentivisation schemes.

More than ever before, women have the opportunity to benefit from cybersecurity as a fulfilling, rewarding and valuable profession. The career possibilities are endless in a market that is fast-paced, dynamic and at the forefront of cutting-edge technology. The message given by a male dominated industry is currently murky and misdirected. We need to do more to secure talent effectively and from all areas of society.

It is also time to remove the public’s misconception that cybersecurity is a dark science conducted by boffins in white coats. Cybersecurity is, and always will be, an everyday part of our lives and not a function to just sit at the ‘digital-doorstep’ of corporate companies. Whether banking on-line, buying goods at a store or simply installing the latest IoT-enabled gadgets in our homes, security is also an individual responsibility to protect sensitive information.

Mind the data

Scientific discoveries about how our minds work bring fresh evidence for how we develop cognitive capabilities. Greater effort is required to improve cybersecurity awareness and nurturing knowledge from early learning techniques to a better understanding of cyber threats at work, and in the home.

Research by the Ponemon Institute found worrying levels of business readiness for cybersecurity threats and revealed that 42% of CISOs worldwide branded their staffing as inadequate. Interestingly, 50% consider computer learning and artificial intelligence important to address staffing shortages.

Now is the time to scale our skills and invest more in the next generation of industry experts, so we can all become more security-savvy cybercitizens.

New online cybersecurity training

Kaspersky Lab research shows that 44% of businesses in South Africa admit that they don’t know enough about the IT security threats targeting them, and it comes as no surprise that they are concerned about becoming cyberattack victims as a result.

To help IT teams tackle these challenges, Kaspersky Lab has launched Cybersecurity for IT Teams Online, its new interactive training course designed to help IT teams develop their basic information security skills. The skills teams acquire during the course will help enterprise support staff increase the quality of their cyber defences.

According to the Kaspersky Lab IT Security Economics Report, 53% of local companies are concerned about employees lacking cybersecurity awareness – something that can lead to cybersecurity incidents. One of the factors behind this disturbing statistic is the lack of basic skills in working with information security tools among IT support specialists. After all, they are the first to encounter requests from employees about problems potentially linked to cyber threats, whether it’s a suspicious email or the ‘Blue Screen of Death’. To help companies strengthen their first line of IT defence, Kaspersky Lab has introduced its first online training specifically aimed at IT administrators and support staff.

Cybersecurity for IT Teams Online is a modular training course with a unique interactive programme that allows IT specialists to gain practical skills in recognising possible attack scenarios, as well as master the mechanics of collecting preliminary data about incidents in order to send them to an information security service. Cybersecurity for IT Teams Online was created in SCORM 1.2, integrated into corporate learning management systems (LMS) with Internet browser access, and includes four thematic modules:

• Malicious software

• Potentially unwanted programs and files (PuPs)

• Investigation basics

• Phishing and open source intelligence

Each module includes a small theory block and 4-10 practical exercises. The new course will help IT specialists learn how to use IT security tools such as utilities for the detailed analysis of Process Hacker/Process Explorer in the system, tools for storing the hard disk image and obtaining a memory dump (e.g., FTK Imager), a framework for reconnaissance in open sources (e.g., Recon-ng) and many others. The approach recommended by Kaspersky Lab includes the training course lasting one year, with participants spending 45-60 minutes a week on the programme.

For more information, go to https://www.kaspersky.com/enterprise-security/security-awareness





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
Upgrade your PCs to improve security
Information Security Infrastructure
Truly secure technology today must be designed to detect and address unusual activity as it happens, wherever it happens, right down to the BIOS and silicon levels.

Read more...
Open source code can also be open risk
Information Security Infrastructure
Software development has changed significantly over the years, and today, open-source code increasingly forms the foundation of modern applications, with surveys indicating that 60 – 90% of the average application's code base consists of open-source components.

Read more...
DeepSneak deception
Information Security News & Events
Kaspersky Global Research & Analysis researchers have discovered a new malicious campaign which is distributing a Trojan through a fake DeepSeek-R1 Large Language Model (LLM) app for PCs.

Read more...
SA’s strained, loadshedding-prone grid faces cyberthreats
Power Management Information Security
South Africa’s energy sector, already battered by decades of underinvestment and loadshedding, faces another escalating crisis; a wave of cyberthreats that could turn disruptions into catastrophic failures. Attacks are already happening internationally.

Read more...
Almost 50% of companies choose to pay the ransom
News & Events Information Security
This year’s Sophos State of Ransomware 2025 report found that nearly 50% of companies paid the ransom to get their data back, the second-highest rate of ransom payment for ransom demands in six years.

Read more...
Gallagher Security achieves ISO 27001 recertification
News & Events Training & Education
Gallagher Security has successfully achieved certification to the updated ISO/IEC 27001:2022 standard for Information Security Management Systems (ISMS). This accomplishment builds on previous certifications and reflects a continued commitment to the highest standards of information security.

Read more...
Survey highlights cost of cyberdamage to industrial companies
Kaspersky Information Security News & Events
The majority of industrial organisations estimate their financial losses caused by cyberattacks to be over $1 million, while almost one in four report losses exceeding $5 million, and for some, it surpasses $10 million.

Read more...
Digital economy needs an agile approach to cybersecurity
Information Security News & Events
South Africa is the most targeted country in Africa when it comes to infostealer and ransomware attacks. Being at the forefront of the continent’s digital transformation puts South Africa in the crosshairs for sophisticated cyberattacks

Read more...
SIEM rule threat coverage validation
Information Security News & Events
New AI-detection engineering assistant from Cymulate automates SIEM rule validation for SecOps and blue teams by streamlining threat detection engineering with automated testing, control integrations and enhanced detections.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.