Overcoming the cybersecurity talent shortage together
TODAY’S digital world is evolving at a breakneck pace with the advent of artificial intelligence (AI) and ChatGPT, while geopolitical and cyber risks remain front and centre. This means cybersecurity has a more crucial role than ever, and should be at the forefront of every business leader’s mind.
However, the shortage of cybersecurity talent continues to hinder companies’ efforts to keep their digital space safe. Of 1,520 global IT leaders polled in Splunk’s latest 2023 State of Security report, close to nine in 10 said they face challenges with cybersecurity staffing and/or skills. Additionally, eight in 10 said that staffers have been forced to take on responsibilities that they aren’t ready for, and a similar proportion reported that critical employees have left for other jobs due to burnout.
In Singapore, a recent Ministry of Manpower report on annual job vacancies showed continued demand for tech talent. Two of the top 10 fastest-growing jobs over the past five years in the city-state were in cybersecurity, according to a 2023 LinkedIn report.
Tackling cybersecurity as a team
Despite the talent shortage, it is essential that companies evolve to tackle cybersecurity adequately – data from our State of Security report shows that downtime from cybersecurity incidents is costing companies 2.7 per cent of annual revenue. This evolution starts with the chief information security officer (CISO), whose role has changed over the years from a technical position focused on compliance to a strategic business role dealing with risk management and cross-organisational collaborations. Today’s CISOs must understand business operations and be able to articulate the importance of digital resilience to the broader organisation. They need to work closely with other executives, such as the chief information officer and the chief risk officer, to develop comprehensive security strategies that align with the company’s overall goals.
At a more fundamental level, tech teams within organisations still tend to work in silos. Infrastructure, cloud and application teams typically have their own sets of objectives and focus, which makes it hard for cybersecurity teams to monitor the entire company for threats.
Teamwork is crucial in modern cybersecurity and allows for true organisational resilience. A good example of collaboration is the convergence of various security and IT functions to create a unified platform for all teams to work together seamlessly. It helps companies increase efficiency by detecting anomalies more quickly, eliminating redundancies and reducing incident response time. The convergence also enhances productivity and cost-saving measures while contributing to an improved cybersecurity posture.
Embracing analytics and automation tools increases cyber resilience
Beyond integrating the various teams of a company, another form of integration also warrants scrutiny – that of data analytics and automated tools. These technologies, backed by AI and machine learning, can help cybersecurity professionals increase efficiency while reducing the risk of burnout. They do so by automating routine operational tasks, freeing up time for more strategic work. It also improves a company’s ability to respond to threats and protect its systems.
Globally, IT leaders are starting to realise these benefits, with two-thirds of those polled in Splunk’s report having deployed technologies designed for security analytics and operations automation and orchestration.
Respondents are using analytics across the entire attack life-cycle. This deployment of technologies designed for security analytics and operations automation allows organisations to improve threat detection, identify cyber risks, accelerate investigations and automate remediation.
In fact, IT leaders have shared that the top tasks targeted for automation are integrating security tools with IT operations systems, integrating external threat intelligence with internal security data, and automating basic remediation tasks (such as updating endpoint security controls) with their automation and orchestration initiatives.
Don’t get stuck in reactive mode
The cybersecurity and tech talent shortage is here to stay – at least in the short term. However, a smaller availability of talent should not translate to lower spend on cybersecurity, which seems to be the case in Singapore. IT leaders in the city-state are projected to invest at a lower rate than their global peers – just 27 per cent say their organisation will increase spending significantly in the next one to two years, compared with 59 per cent across the rest of the world.
Singapore teams currently do not report a higher incidence of ransomware or supply chains, but their notably lower cyber focus and funding is concerning, and elevates future risk as data consumption continues to skyrocket and technology like AI and ChatGPT open up new forms of risk. Most security teams get stuck in reactive mode. There is a sense of urgency for business and IT leaders to modernise their teams and tools to be effectively proactive and ensure mission-critical operations stay safe.
The writer is vice-president, security, Asia-Pacific, at Splunk.
TRENDING NOW
UOB found ‘grossly negligent’ over Stamford Land rights issue advice, to pay S$1.9 million
MAS allocates S$1.45 billion to five asset managers in third EQDP batch: Chee Hong Tat
He built the Vingroup empire. Now South-east Asia’s richest man is handing some key roles to his sons
NoMad Singapore marks brand’s arrival in Asia