Share

Related Links

Related Stories

  • Blurring the Lines: Information Security in the Public and Private Sectors
    There are similarities and differences in the approach to information security in both the private and public sectors, including the relevant laws and regulations. The (ISC)² U.S. Government Advisory Board lends its observations regarding information security strategy and implementation within these two realms, along with factors seen as key drivers in both the public and private sectors.
  • Look Back and Move Forward
    The beginning of a new year is often a time for predictions or, sometimes, reassertions. Drew Amorosi revisits past prognostications from Infosecurity’s editorial board to assess its foretelling prowess, examine the year that was 2010, and gather some new projections for 2011 and beyond
  • Look Back and Move Forward
    The beginning of a new year is often a time for predictions or, sometimes, reassertions. Drew Amorosi revisits past prognostications from Infosecurity’s editorial board to assess its foretelling prowess, examine the year that was 2010, and gather some new projections for 2011 and beyond
  • From the Eye of the Storm: 2011 Information Security Predictions
    Last January, Infosecurity magazine published prognostications by the (ISC)² Advisory Board of the Americas (ABA) regarding the information security field in 2010. Unlike many who have attempted to envision the future, the ABA has gone back and reviewed the accuracy of its predictions and provided a letter grade for each. The ABA will then offer new predictions for 2011.
  • The Good, the Bad, and the Ugly Insider Threats
    Whether intentional or unintentional, insider threats take many forms. The (ISC)² US Government Advisory Board Executive Writers Bureau examines this dichotomy and how it is being affected by both regulatory considerations, and the rapidly changing technology landscape
    Members' Content

Top 5 Stories

News

Infosecurity experts hard to get despite economic downturn

05 June 2009

Hiring managers are struggling to fill infosecurity positions due to a mismatch between salary expectations and skill levels, and current demand, information security education and certification organisation (ISC)2 has found it its latest jobs survey.

Florida-based (ISC)2 interviewed more than 2800 information security experts of which 775 had hiring responsibilities. Of these, 44% were looking to hire additional information security staff this year and over 11% planning to add more than three people.

Areas of expertise most sought (in descending order):
  • Operations security
  • Information risk management
  • Access control systems and methodology
  • Applications and systems development security
  • Security management practices

More than 80% of hiring managers said they find it challenging to find the right candidate despite the economic downturn. According to (ISC)2, the range of concerns included: a lack of desired skills or lack of available professionals within a local area; poor cultural fit; and salary demands that are too high for available budgets – particularly from people previously working in the financial services sector.

“Demands on professionals are changing. Companies want more for their investment, and professionals need to keep their skills and expectations in line with what businesses are looking for”, said John Colley, CISSP, managing director EMEA at (ISC)2. “Training and professional development will be essential for individuals as they manage their careers in this tough economy.”

Budget cuts and outsourcing

The survey, which was carried out in April and May 2009, found that outsourcing is having an impact, but that “activity on this front may be slowing”. Although 30% reported increased levels of outsourcing of security functions, only 18.7% expect the situation to worsen over the next six months. Budget cuts could also be slowing.

Almost 72% saw information security budget reductions in the period October 2008 to March 2009, and 53.6% said their information security departments had experiences at least one lay-off in the past few months.

Looking forward, however, 62% said they do not expect any additional information security budgets cuts for the remainder of the year, and 9% expected an increase. 59% said no additional personnel cuts would be forthcoming in the remainder of the year.

“In this environment, companies may be tempted to make rash security decisions made in the panic to cut costs. Organisations are advised to proactively analyse how cuts affect their risk profile and avoid costly repercussions resulting from breaches and mandated reparations”, said W. Hord Tipton, CISSP-ISSEP, CAP, CISA, CNSS, executive director for (ISC)2.

Increasing attacks

At the same time as information security budgets are shrinking, the number of attacks is increasing, (ISC)2 warns. Internal hacking against the system is up 18.4%, external attacks 33.3%, intellectual property theft 27.8% and fraud and embezzlement is up 28.3%.

This article is featured in:
Business Continuity and Disaster Recovery  • Public Sector  • Security Training and Education

 

Comment on this article

You must be registered and logged in to leave a comment about this article.