
teissTalk host Jenny Radcliffe was joined by Tony Clarke, VP, IT Operations & InfoSec, Marken; Lee Morton, Information Security Officer, On The Beach; and Andrew Hollister, Deputy CISO and VP Labs, LogRhythm.
Views on news
80% of organizations surveyed for Fortinet’s 2022 Cybersecurity Skills Gap Report said they had suffered at least one breach they could attribute to a lack of cybersecurity skills or awareness.
Forinet is committed to tackling the challenges revealed in the report through various initiatives, including programs focused on cybersecurity certifications and recruiting more women into cyber.
Scarcity of professionals also places those working in the industry at risk of burn-out. The article touches on cyber security awareness indicating that cybersecurity has relevance to the whole organisation not just to information security related roles. Another good news is that the majority of leaders now seems to ready to invest in security talent and training, although it also implies that currently they aren’t.
At present, it can take as long as three months to recruit a SOC analyst, which can be improved strategically either by implementing more automation or outsourcing. Factors that can stand in the way of information security training can vary from lack of funding to unwillingness to allocate time for it during working hours to lack of ambition on the part of employees.
If someone is after skills rather than certifications, there is a raft of free courses where they can hone their skills.
Experience versus obsession with certs
One of the biggest challenges is to find talent with the right mindset and approach who can become a strong and integral member of the team.
The selection process is a bit like courting while both parties are trying to find out whether they’re meant for each other. Some recruiters are looking at the quality of the person not just of their skills conducting friendly chats with the candidates as part of the selection process to have a sense of how they will interact with the team or whether they will be approachable enough.
If someone has qualities such as tenacity, willingness, the right approach, it will be easier to train them for the right level of skills than the other way round. If information security can translate its technical language into one based on business risk, which the C-suite will also understand, it will stand a better chance of getting a higher budget for training.
The panel has some mixed experience with external recruiters ranging from very professional ones to those who just forward cv-s without having any interaction with applicants. Certifications evidence the level of training but don’t guarantee competence.
Managers need to show interest in employees’ career development if they want to keep them, which can range from offering opportunities to visit conferences, or ongoing training programmes to helping them take the next step in their career or mentoring.
The panel’s advice
Make sure you pick or fund courses that offer relevant and up-to-date skills.
During recruitment, try to have a friendly chat with your candidate and learn about them outside the “can you do the job?” structure. Get them also interviewed by the team they’re going to work with.
If your organisation has its own talent acquisition team, spend some time with them to discuss what sort of skills and cultural fit the information security team is after (e.g., intellectual curiosity).
As for external recruiters, it’s key to have one that you trust.
Always offer remuneration commensurate with the level of skills and certifications required.
Watch it on-demand here.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543