ESG data indicates that enterprise organizations are either cybersecurity skill “haves” or “have nots” If you’ve read my blog with any regularity, you know that the cybersecurity skills shortage is a topic that is near-and-dear to me. Forget about things like the threat landscape, mobile security, and cloud security, if we don’t have enough skilled security professionals, we are all in trouble.I’ll be presenting on this topic at the RSA Conference next month but here’s a bit of very troubling data in the meantime. ESG asked 315 security professionals working at enterprise organizations (i.e. more than 1,000 employees) whether they were familiar with multiple types of malware techniques. Overall, the results were pretty dismal. For example:50% of security professionals are “not very familiar” or “not at all familiar” with Command & Control (C&C) communications techniques.40% of security professionals are “not very familiar” or “not at all familiar” with polymorphic malware.40% of security professionals are “not very familiar” or “not at all familiar” with metamorphic malware.29% of security professionals are “not very familiar” or “not at all familiar” with zero-day malware.ESG also analyzed this data through a segmentation model that divided the entire survey population into 3 categories: Advanced organizations (i.e. those with superior cybersecurity skills and resources, 24% of the total), Progressing organizations (i.e. those with average cybersecurity skills and resources, 52% of the total) and Basic organizations (i.e. those with below average cybersecurity skills and resources, 24% of the total). As if the overall population’s cybersecurity skills deficiencies weren’t bad enough, the ESG research data indicates that cybersecurity skills issues are divided between “haves” and “have nots.” Looking at the data above through the segmentation model: 24% of security professionals working at advanced organizations are “not very familiar” or “not at all familiar” with Command & Control (C&C) communications techniques, 48% of those working at progressing organizations are “not very familiar” or “not at all familiar” with Command & Control (C&C) communications techniques, and 82% of those working at basic organizations are “not very familiar” or “not at all familiar” with Command & Control (C&C) communications techniques.17% of security professionals working at advanced organizations are “not very familiar” or “not at all familiar” with polymorphic malware, 36% of those working at progressing organizations are “not very familiar” or “not at all familiar” with polymorphic malware, and 72% of those working at basic organizations are “not very familiar” or “not at all familiar” with polymorphic malware.8% of security professionals working at advanced organizations are “not very familiar” or “not at all familiar” with metamorphic malware, 37% of those working at progressing organizations are “not very familiar” or “not at all familiar” with metamorphic malware, and 81% of those working at basic organizations are “not very familiar” or “not at all familiar” with metamorphic malware.16% of security professionals working at advanced organizations are “not very familiar” or “not at all familiar” with zero-day malware, 27% of those working at progressing organizations are “not very familiar” or “not at all familiar” with zero-day malware, and 46% of those working at basic organizations are “not very familiar” or “not at all familiar” with zero-day malware.So there is a security skills gaps everywhere but especially at progressing and basic organizations. Remember that these two sub-segments make up 76% of the entire enterprise market. Additionally, progressing and basic organizations come in all sizes and from every industry. If this isn’t cause for alarm, I don’t know what is. We really need to have a serious discussion about how to bridge this gap as soon as possible. Related content analysis 5 things security pros want from XDR platforms New research shows that while extended detection and response (XDR) remains a nebulous topic, security pros know what they want from an XDR platform. By Jon Oltsik Jul 07, 2022 3 mins Intrusion Detection Software Incident Response opinion Bye-bye best-of-breed? ESG research finds that organizations are increasingly integrating security technologies and purchasing multi-product security platforms, changing the industry in the process. By Jon Oltsik Jun 14, 2022 4 mins Security Software opinion SOC modernization: 8 key considerations Organizations need SOC transformation for security efficacy and operational efficiency. Technology vendors should come to this year’s RSA Conference with clear messages and plans, not industry hyperbole. By Jon Oltsik Apr 27, 2022 6 mins RSA Conference Security Operations Center opinion 5 ways to improve security hygiene and posture management Security professionals suggest continuous controls validation, process automation, and integrating security and IT technologies. By Jon Oltsik Apr 05, 2022 4 mins Security Practices Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe