Logo

CIISec and ISC2 publish guide on recruitment best practices

Attracting, recruiting and retaining a more diverse workforce will be critical for navigating the ever-evolving cyber threat landscape.

  • Wednesday, 19th June 2024 Posted 1 year ago in by Phil Alsop

The Chartered Institute of Information Security (CIISec) and ISC2 have published a joint guide, “Recruitment and Retention in Cybersecurity", designed to help organisations attract, recruit and retain a diverse array of cybersecurity talent. Research from ISC2 shows that whilst the global cybersecurity workforce grew in 2023 to a record high of 5.5 million people, the demand for skills is still outpacing growth. Globally, the cyber skills gap grew by 12.6% last year, with 4 million additional workers needed to fill the void, making recruitment more important than ever.

The detailed guide written by CIISec and ISC2 experts urges the industry to increase diversity in the hiring process. Advice to organisations ranges from how to identify and support new recruits, to retaining skilled employees – all from a broad array of backgrounds. Key points from the guide include:

Look beyond traditional job portals, advertising roles in unconventional venues such as military bases or university campuses, as well as approaching young talent directly on social media, tech communities or even in gaming arcades.

Hire based on transferable and non-technical skills, for example a finance professional’s risk management capabilities would be invaluable to the cybersecurity industry and shouldn’t be discounted. Likewise, many non-technical skills such as critical thinking and problem-solving are needed in cybersecurity.

Provide a comprehensive onboarding process, including a buddy system to help identify challenges and problems as well as areas of support.

Continuous training and mentoring to ensure new hires and existing staff are kept up to date with the latest trends, tools, and best practices of the fast-moving security industry, supporting career development and retention.

Provide a supportive environment to prevent burnout, with CIISec data showing that just 14% of cybersecurity professionals have a fully defined career path, it’s vital to give employees the right support to succeed.

Be prepared to offer salary increases, particularly early on, as new graduates often cycle through roles early in their careers to maximise earnings. Organisations must incentivise talent to stay by paying the going rate.

The guide also includes a thorough recruitment ‘basics’ checklist, which outlines the importance of challenging and meaningful work, culture and understanding employees, among others.

“Despite more people working in the cybersecurity industry than ever before, we’re not doing enough to retain them,” says Amanda Finch, CEO of CIISec. “The industry desperately needs guidance on how to improve hiring practices or we’ll lose out to other sectors, which we can’t afford. But retaining talent is just as important as attracting it, and organisations have to do more to support staff at all levels, equipping them to succeed.”

“The cybersecurity industry needs to recognise the need for greater diversity in teams urgently,” says Clar Rosso, CEO at ISC2. “We must shift our mentality and understand that the right people do not need to come from a traditional cyber background. By welcoming inclusivity and removing barriers to the profession, the cybersecurity industry will find new ways to solve challenges, and have a larger pool of talent to hire from.”

Payara Services merges its cloud and runtime solutions under one banner, streamlining enterprise Java deployments for enhanced productivity and...

Wavenet partners with 8x8

Posted 1 day ago by Aaron Sandhu
Wavenet partners with 8x8, marking a leap in enterprise communications and customer experience. Recognised with two EMEA Partner awards, Wavenet sets...
Westcon-Comstor strengthens its partnership with cybersecurity firm Proofpoint via a new AWS Marketplace agreement, benefiting European channel...

Veeam unveils new Data Cloud solutions for MSPs

Posted 2 days ago by Aaron Sandhu
Veeam Software expands its offerings with Veeam Data Cloud for Managed Service Providers, delivering robust data resilience and enhanced security.
Starburst introduces groundbreaking features to its data platform, promoting synchronous collaboration between humans and AI while ensuring data...
Netwrix introduces AI and data protection enhancements to their 1Secure™ SaaS platform to combat identity-based threats.

Barracuda Networks boosts AI-powered platform for MSPs

Posted 1 week ago by Aaron Sandhu
Barracuda Networks introduces new features to its AI-driven platform, enhancing automation and operations for MSPs.

Gcore thwarts massive 6 Tbps DDoS attack

Posted 1 week ago by Aaron Sandhu
Gcore effectively neutralises one of the largest DDoS attacks, emphasising the rising threat in digital infrastructures.