ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

teissTalk: Bridging your cyber skills gap - training and retaining talent

Linked InXFacebook
bookmark_borderSave to Library

On 30 March, teissTalk host Thom Langford was joined by  Emilio Iasiello, Global Cyber Threat Intelligence Manager, Dentons; Nick Mullen, Project Manager - Information Security, Mutual of Omaha; Mike Gillespie, Founder and Thought Leader, Advent IM Limited.


Views on news


The cybersecurity talent shortage is one of the top challenges putting organizations at risk, as clearly demonstrated by the results of the latest Global Cybersecurity Skills Gap Report from Fortinet. Currently, an estimated 3.4 million professionals are needed to fill the global cybersecurity workforce gap.

 

Despite the title, the report suggests that there is no direct correlation between the cyber skills gap and breaches. 80 % of the breaches that the article refers to as cyber attacks are human-facilitated phishing, spearphishing, malware and ransomware relying on employees to let them in. This is not about skills shortages but organisations’ ability to prepare their staff to become part of the business’s cyber security posture. Security awareness programmes may not bring the desired outcomes as it’s IT experts who are in charge of it who may not be that strong on communication and business skills.

 

That’s why soft skills have become essential to filling these roles. Another problem is the lack of enough youth entering the profession. Unlike engineers or doctors, information security professionals are expected to specialise from day one. But if there is a young person who is good at coding, they’ll be thought to be destined to become a pen tester. Instead, they should be given some general training in all expert areas and soft skills, so they can decide what they want to specialise in.

 

But we shouldn’t forget either that a couple of decades ago this whole industry didn’t exist, therefore today’s security professionals can’t have a long history in cyber security but, rather, come from IT or other business areas (we have a former English literature teacher and a biomedical scientist on the panel). Employer often don’t know too much about cyber security certificates except that they want their candidates to have them. CISOs often have the responsibilities of the DPO too. 


Certifications versus training


Certificates are mainly to prove that someone is familiar with some general concepts but don’t evidence that someone has the skills to use the necessary tools in their day-to-day job.

 

There is a need for a foundation education programme that provides future security experts with some broad church skills before they start to specialise. The value of in-house training and apprenticeships shouldn’t be underestimated, though.

 

The UK Security Council has been set up to bring together all the disparate institutes, special organisations and other interested bodies with the view to the betterment of the profession. Government in the UK has a role to play too in shaping early education that prepares young people for cyber security careers. Gen Zed doesn’t seem to be overly excited about these roles and now its gen Alpha (10-12 year olds) who should be prepared for future roles in cyber security. Today’s 20 year olds, however, seem to be interested in the profession but don’t know how to get into the field.

 

They often only see SOC and pen testing as potential career paths, which two roles make up only about 2% of all jobs in the field and they are not even the most attractive career opportunities regarding pay and working hours.

 

Some of the best experts come from unlikely places such as the Air Force as fully trained and motivated experts, who use the training as a steppingstone into the cyber security industry. 


The panel’s advice


Entry level requirements are unrealistic for cyber security jobs. 


Cyber security professionals should take over the responsibility of recruiting new people for their teams unless HR really knows what exactly they re after. 


Despite the job being not so attractive, you can keep SOC experts by either offering them good money or great opportunities to learn in order to get ready for the next step in their security career.  

 

Train people so they can leave but treat them, so they don’t want to.


Look for individuals who are curious. 


We need to think of ways in which we can make the profession into one that our grandchildren will be keen to take. 

Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543