
It is time cyber-security professionals got a seat at the top table in business. Steven Wood at OpenText Cybersecurity explains why
Our sector is facing an existential crisis. The yawning cyber-security skills gap has become a chasm. The numbers do not lie – the cyber-security workforce gap was over 50,000 in the UK last year, an increase of 73%.
More people with the right abilities, skills, experience, and certifications are needed to protect organisations from an increasingly sophisticated cyber-threat landscape – one which is estimated to have doubled in a year, according to a 2022 study.
Despite this, there is a diminishing talent pool with disaffected workers seeking new opportunities in alternative career paths. We have reached a point where many organisations experience talent retention challenges, with the demand for talent far outpacing the supply of qualified professionals.
The competition for talent has become so intense some 60% of companies say they have had cyber-security staff poached.
So, what is creating this disconnect? Cyber-security does not have the voice or prevalence it deserves at the very top. Let me explain further.
While cyber-security is viewed by the C-Suite with obvious importance, it perhaps is not given the same level of priority or urgency as say, sustainability.
The cyber-security role is inherently unjust. Cyber-teams seldom get recognition when things are safe and sound, yet the full brunt of customers, employees, leadership, and shareholder dissatisfaction bares down when an incident arises, not to mention the threat of financial and reputational damage.
In fact, for the second successive year in a row, cyber-incidents is the number one risk to business in 2023, outranking supply chain issues, natural disasters, workforce shortages and macro-economic developments – this according to the annual Allianz Risk Barometer survey.
Furthermore, the public discourse around AI does not appreciate the risk being introduced into the business by these new technologies. Frameworks and best practices for AI are still in their infancy and so cyber-security teams remain duty-bound to protect the business, maintain compliance and promote innovation.
This all without the time and resources to upskill, nor the voice at the table to help guide and inform the decision makers. These challenges only serve to make the job stressful.
Staying ahead of the innovation curve is one tough task, and for people working in cyber-security, protecting the ‘front line’ is a stressful, high-stakes job. Working from behind closed doors, people in the sector are left without the status, kudos, and pay they deserve.
It is perhaps no surprise that a high percentage of workers in the sector say they have experienced stress or burnout, according to a range of surveys from different vendors.
Alarmingly, according to Gartner, 25% of cyber-security leaders are looking for entirely different roles due to stress in the workplace.
Moreover, those individuals who do find a way to thrive in these roles are coaxed away to the few companies who have the budgets to gather the best the market have to offer.
Without the right budgets, support, and appropriate level of appreciation for their work, cyber-security talent feels neither supported nor nurtured.
And if the sector is bleeding talent, it creates a vacuum which will inevitably be exploited by attackers. A culture change is required, led from the top.
We need to shift the understanding of a cyber-professional’s role. And with that, giving cyber-security professionals more expansive responsibility – underlining how their work can affect all areas of a business.
Furthermore, there is a need to recruit from more diverse backgrounds, such as race, socio-economic and gender. Only with a wider catchment of recruits, and more robust internship and mentorship programs, can we hope to stem the bleed.
Cyber-security is a collective effort. We cannot expect the cyber-security professional alone to keep us safe. We need to change the way we view cyber-security from top to bottom.
Only when organisations appreciate there are no demarcated areas between our work and home digital existence, can we evolve our security posture. We need to stop presenting ourselves as soft targets and become more security-minded digital citizens.
But our cyber-security teams are the change agents we need to enact this gear shift.
This is especially important because human error accounts for most cyber-security breaches – some 95% according to a previous study by IBM – this is a very well-established fact in our sector.
Awareness, training, and making people the first line of defence, is a clear first step to supporting this idea.
The wider organisation can also use this as an opportunity to connect with their cyber-security colleagues. There is value in deliberate training and development, building a culture of security advocacy.
Senior leadership need to drive from the front on training, creating a bias towards cyber-security as a way of existing and cementing its importance in the minds of employees.
Immediately this positions the cyber-security profession as a key player in facilitating the protection of the organisation and mitigating risk.
But this only goes so far. New skills and technology are also needed to help meet the growing cyber-threat.
Next-generation cyber-security tools and threat intelligence, such as user education, DNS protection, and malware detection are all table stakes in a layered approach to proactive protection . Afterall, as AI “ups the ante” in the cyber-game of cat and mouse, threat actors cannot be allowed to gain the upper hand – we need to fight fire with fire.
Giving our people the tools to do the job, and appreciating the effort required to keep up with the latest threats, supports the need for recognition.
But to recognise its true status, cyber-security leaders need to have a seat at the boardroom table – as many do not.
Only then can they fully integrate and protect every area of the business, with the right level of strategic focus. Workplace projects need to be incubated, developed, and delivered with cyber-security as a foundation stone alongside customer value and profit.
If we present the role of a cyber-security professional as important, worthwhile, and valued, then we can inspire more professionals to choose it as their career path.
CEOs and fellow members of the C-Suite should not underestimate the value of cyber-security.
The vital work done by the profession has to be a strategic priority, with the team members given the recognition they deserve.
Making cyber-security more attractive and accessible as a supported career path will increase the talent pool – creating the desperately needed next generation who will keep our businesses and people safe.
Steven Wood is Director of Sales Engineering at OpenText Cybersecurity
Main image courtesy of iStockPhoto.com
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543