ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Addressing the cyber skills gap

cyber skills shortage
cyber skills shortage

Sophia Dozier at Rapid7 explains how the cyber security industry can tackle the ‘Great Resignation’

 

The global health crisis, Covid-19, continues to have a dramatic impact on community, business, and our personal lives. This crisis has prompted millions of people to re-evaluate their career plans and resign from companies and roles with which they have had decade long relationships.

 

In May, the World Economic Forum warned of “the largest exodus of employees on record” and reported that almost 4.5 million people in the US voluntarily resigned in November 2021, an all-time monthly record.

 

In addition, a recent study revealed that 69 percent of UK employees would consider a career change if given the opportunity. This is particularly problematic in cyber security — a field already suffering from a long term skills shortage.

 

The trend has come to be popularly known as “The Great Resignation” as companies fret about sustaining headcounts for critical roles. But avid reframers like myself prefer to call it “The Great Reimagination.” While the current situation might represent a challenge, it’s also an opportunity to take a step back and rethink how we do things.

 

The cyber security industry’s skills gap has been fuelled by its rapid growth, but also compounded by historical choices and processes rooted in conscious and unconscious bias, minimal cyber security career training, and inaccessibility to those in marginalised communities.

 

In reimagining these processes, now is the time for industry leaders to be honest about their strategies and choose to be intentionally inclusive of marginalised groups, finally elevating incredibly talented and brilliant professionals that were previously overlooked.

 

Rapid7 recently released our 2022 Social Good Report, outlining our effort to drive access and inclusion in cyber security, but also to change the narrative of our industry. Leaders looking to strengthen their talent can begin by adopting an open mind and taking a critical look at their company structure and culture.  

 

Diverse by design

Historically, cyber security has been a largely white and male dominated industry. Organisations in this space must be diligent about creating opportunity and increasing representation from intentionally marginalised communities. And in tandem, we must be vigilant that our workspace(s) and broader employee behaviour is rooted in inclusion.

 

Investing in all the elements it takes to develop a truly diverse and thriving workforce takes dedication, perseverance, patience and commitment from every area of the business, at all levels.

 

It is time that business solutions and teams reflect the world they are seeking to support. The possibilities are truly endless when you begin championing people and approaches that contradict the current system, which was built by a few for many.

 

Through a very intentional approach to people strategy and workforce growth, we can not only help reverse the cyber security skills gap, but significantly impact what the future talent and innovations of this industry look like.

 

When a product is created by a subset of individuals, with limited variety in lived experience, there will be higher levels of bias present in its development. The impact biased products can have on a community during stages of product adoption can have long lasting, negative impact.

 

As responsible technologists we must find ways to mitigate this risk, and one way we can do that is through building multidimensional, diverse teams, which thereby regularly challenge individual assumptions and increase the likelihood that a product will truly support global users. 

 

A commitment to diversity, equity, and inclusion (DEI) is about more than just following frameworks and implementing initiatives; the “never done” mindset must be embodied. This means going beyond DEI requirements, volunteer service minimums, and Environmental, Social, and Governance (ESG) frameworks.

 

Instead, we must recognise our ongoing obligation and commitment to building a better future for all our employees and customers, as well as the communities in which we work. The cyber security industry secures the world, not just a subset that looks like the industry’s long time leaders.

 

Flexibility, pay equity, and data

Flexibility is key to attracting and retaining a diverse workforce. The complexities of modern life do not always align with traditional 9-to-5 working hours. Leaders should be thoughtful about the creation, design, and construction of professional spaces. Teams should have the flexibility to do their best work, which is achieved by offering hybrid working models for most roles.

 

A hybrid model allows employees to collaborate, network, and build amazing teams and allows you to make adjustments for those who need workplace accommodations.

 

Pay equity must also be a priority. This means fair and equal pay for employees in the same job, level, and location, controlling for pay differentiators such as performance and experience, regardless of gender, race and/or hidden traits not easily visible. Organisations may benefit from conducting a comprehensive pay equity survey to determine whether there are any differences in pay based on gender.

 

Dig into your people data. Embrace it! It can be a mountain to climb, but your data is going to be crucial to how you support your employees. Build your data dashboards in a way that allows you to view overarching trends, but also gives you the ability to dig deep into specific business areas, roles/functions, office locations, etc. Work to adopt tools that communicate with one another, so you can overlay data from complementary areas like engagement and exit surveys.

 

Building with intent

For some time, DEI strategy has been seen as a “nice to have,” but those days are long past. DEI must now be accepted as a “must have” in order to remain relevant, competitive, and provide the best solutions to customers. Change the narrative around DEI; it is not a barrier, but a game changer and morally right.

 

Let’s change the way the industry approaches challenges. Let’s change the way we hire. Let’s change the historical narrative that cyber security is only a career for the few.

 

“The Great Resignation” is an opportunity to build with intention and reject processes and strategies that have overlooked and even ignored the humanity of business: the people.

 

Organisations that follow a values-based approach, rooted in policies of transparency and accountability, can help influence and build a future that is truly inclusive, equitable, and equal.

 

We should avoid the negativity swirling around “The Great Resignation” and instead turn it into “The Great Reimagination”, creating something far better than anything your organisation and the cyber security community have previously experienced.

 

The journey will not be without challenges or even setbacks, but when has that ever stopped those who want to be the best?

 


 

Sophia Dozier is Director of Diversity, Equity, and Inclusion at Rapid7

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543