Transcript
the practitioners building and defending modern data environments. Hello, everyone, and welcome to another episode of Zero Downtime. Today we're going to talk about how empty seats leave open doors, why cybersecurity hiring gaps invite an attack. So as teams work to fill jobs, we are leaving the gateway open for attackers, and really want you to think hard about that, and we'll really unpack this with an expert in this area in just a moment. My name is Teresa Miller, I am the Senior Director of Technical Marketing here at Cohesity, and my expert and cybersecurity community guest, Deirdre, can you introduce yourself? Yes. Hi, Teresa and everybody, it's great to be with you. My name is Deidre Diamond, I'm the founder and CEO of CyberSN. We are a 12-year organization focused on workforce intelligence, and that is everything from talent acquisition to talent matching to talent data. Really focused on workforce risk, Teresa, as you know, I'm a geek for that. And I'm also the co-founder of the Day of Security Conference, and I know we've also spent time there together before, which is a conference that's been running 10 years now giving the stage to women. Yeah, it's really exciting what you do, Deirdre, from not only a job perspective, but just from a community perspective. That's where we met, and I just, I'm so excited for you to unravel your experience, you know, share your experiences and unravel what that means for businesses making decisions around hiring and security. Yes. So, you do an annual report, you do a survey of sorts called the CyberSN Jobs Report. And from my research, your report tracks around 140,000 monthly cybersecurity job postings across all different types of cybersecurity roles, and you've been trending on this for some time. You know, just even in the short, like, last year or two, what's a surprising shift that you've seen in the data compared over previous years? Yes, yes. Yes, this jobs report that you're speaking about is every time a job gets posted in the United States, everything other than federal job posting, so state and local government accounts, of course, all corporations, public and private, we automatically take that job and bring it into our platform, and we've been doing this almost five years. The next report's coming out in 30 days from now, so we'll have to get together again, Teresa. I like to look at that data, everybody likes to look at that data. We organize that data per cyber job functional role, and as the founders of the cyber job taxonomy, it's really about what roles are, you know, are doing what, and so in the last couple of years, of course, it's been a lot of downturn in the amount of job postings. I'd say the key takeaway is the roles that have stayed steady over the last few years are product security, which took a significant hit, which really surprised me when it took a significant hit, you know, three, four years ago, we can talk about that, but so product security has stayed steady the last three years, it needed to catch back up, but it stayed steady once it did. Management roles, we started to see real investment in management starting three years ago, and that stayed steady, and the third one is GRC, with just a lot more focus on regulations, as we all know, internationally, mostly driving the United States. So those three roles have stayed steady in the last three years, all roles that were prior to these last three years were going down. Okay, so for people who are looking for jobs, I think that that's good data, right, because it can help them figure out one where they need to refocus, maybe do some more learning, get some more experience to be able to secure those jobs if they want to stay in cybersecurity, but I think, you know, the other thing is, and we'll get to this in a little bit, but I just wonder what the overall long-term impact of that is. So if you have more leadership, for example, is that because we are overseeing more strategic decisions? So if you have any thoughts on that here in the short term, I think that would be great, like why those roles, but those are things that are on my mind when I hear you share that information. Yeah, absolutely. You know, 12 years now, my firm is focused on the cyber talent job market. And for until the last three years, it used to really be a security leader and then everybody else. And there wasn't sort of the definition or that we have different types of teams and we need a manager over those teams. And so that's why that progression is so important is that we do have offensive roles, defensive roles, GRC roles. And so finally getting that, at least the funding to build these teams started. Unfortunately, you know, at the same time, AI started coming at us. And so the need, you know, it was much greater because the attack surface just game changed overnight. The good part of that is jobs are now increasing again because of that. So, you know, we keep playing a little bit of this, you know, we're still playing catch up constantly when nobody is staffed, typically not, I shouldn't say nobody, I'd say more than the majority, you know, 60, 70% of organizations do not have the amount of cyber coverage they need. And the way I look at it is cyber capability coverage. So it doesn't have to be an FTE. We've got to look at our workforce as our full-time employees, our contractors, even our managed service providers, our consultants, like we got to be thinking about our cyber capability coverage. And when we do that, we say most people are not, most organizations, excuse me, do not have the coverage they need. So it's not as simple as a seat or a couple of hires. It's really much more strategic today. Okay. So one of the other things I recall in your report is that, and you've been touching on this, you talked about the GRC, but some of the renewed demand in the cyber talent is regulatory, evolving workforce strategies, and growing emphasis on the governance risk area. So when you consider a long-term impact, which of these forces are going to have the biggest effect on hiring for the long-term? Yes. I'm going to go with regulation. I've gotten to cyber in the early 2000s as the first vice president of sales at Rapid7. This was before PCI started and was fining. And nobody was doing anything. I'm talking even our public sector, water plants, energy plants, nobody was doing anything. And we were selling to those folks. And really, truly until there were fines, nobody did anything. As soon as PCI started fining, as soon as HIPAA started, and then now here we are, how many years later, we still didn't make much progress until we started to see regulations from other countries push us over here. So really, unfortunately, it's the stick that gets us funded versus the carrot of we're not funded to truly protect ourselves enough. Now, we all know that regulation without understanding is bad for organizations. And there's many that are struggling today with, well, we're doing it because it says it there, and yet not understanding the context. And does it really apply to you? And what is it really meant with those words? Is it cut and dry? It's like, no, it's not. So I think people are struggling with interpretations. At least they're thinking about what they need. We need more. We need more as far as I'm concerned. Yeah. Yeah. It really struck me too, when you kind of clicked into the WaterWorks and the different public utilities. In my local area, just this week, they were already trying to field a potential threat to the water in one of the communities near me. And so it just really validates what you're saying. Like right now, it's here in front of me, but I think it's going to take a lot to get on the other side of that and how critical hiring is, and probably retention even, is to solving that problem and staying ahead of it to keep water safe and utilities safe. Yeah. It's scary. I mean, ignorance is bliss. I've never felt more of that term and understanding it. The more I get my hands on all of this data and not just my hands on the data, I see it. I've been in the community 25 years now, my friend. We've all grown up together almost, our generation anyways. And the level of burnout has always been significant. It's just worse now. And so, yes, when I think of our water, all of our pipelines of anything that's critical for life, it scares the heck out of me. And also note that most public or state and local organizations pay much less for their cyber talent than the marketplace. And that also bothers me. What are we doing? These are the most important roles that we have, these protectors. So I'm really hoping that that change comes. And again, it's only through regulation that I've ever seen the advancement in this entire industry for the last 25 years. Yeah. Interesting. It's sad. Yeah. Because it's so common sense. It's just common sense that we have to protect those things from disaster, not data being more important and those jobs paying more than the ones. So the good news is that I think people are waking up and yet we're way behind. Yeah. Yeah. It's unfortunate. Yeah. Well, let's talk about another topic from your survey about pause periods and pausing forward motions. So from your report, you've talked about how organizations can only pause forward motion for so long as threat complexity keeps evolving. So what does a pause period look from the inside and what finally forces companies to start hiring again? Yeah. Yeah. I've really seen this firsthand right now. So it hasn't been quite two years yet, but the economic climate change is almost at two years. And when it started, it started with the tariffs, right? And then the interest rates, excuse me, started it, then the tariffs. Now we've got a conflict, a military conflict. And so all of those things cause organizations to downsize, to try and protect cash, to do more with less. And that's a pause. Whenever one is already not where they need to be from a security posture. And then the business itself starts to implement those layoffs, those cuts on spend, cuts on training, that halts security too. And really, security shouldn't be thrown in that mix. And it is. And that's what's so shocking. Literally, I never thought I'd see the day. I really thought we were, if you will, recession proof, this business, it's not. And that's the most just gut-wrenching part of learning all of this. So that pause can only last so long before breaches are not just one, but plentiful. And then the other thing that can only last so long is that the people that are doing the work, for the people that are no longer there, or the services that are no longer there, or for the roles that were open that then got put on hold, they can only do that for so long before they burn out to a level where they're either performing less effectively or they're leaving because somebody pitched them a better place to be. And there are places that have it together. It's not a large amount at all. It's literally maybe half the marketplace or a little less because this economic climate has caused everybody to act not as wise as they should in thinking about cutting costs. Yeah. As you were sharing your thoughts on being recession proof in the security space, I was literally sitting here thinking the same thing. It's like, why would those jobs be in the chopping block at all? Unless you have the wrong resource, it really is baffling to me. It actually feeds really well into just the next question I wanted to talk to you about today, and that is the gaps, right? So security hiring becomes important to be able to fill cybersecurity gaps that leave enterprises at risk. So you do a pause. Okay, now we're leaving the environment at risk when there's already risk inherently because cyber attacks are changing and evolving constantly. So which technology focused on security risks are the most relevant today, Deirdre? And are we leaving gaps for hackers to infiltrate and attack our businesses when we're not hiring correctly? Oh my gosh. So the last three and a half years, my full-time work is on the workforce intelligence side of cyber SN. And that view is about working with organizations to document their cyber capabilities in a way that shows those gaps. And there isn't anybody that doesn't have a gap to a capability that they need to have, whether it be their business line or regulation. And it's really hard to see those gaps when we have traditionally been running our businesses and our departments with titles and job descriptions. It doesn't give that insight of cyber capabilities. And so partially this is about how fast this industry has changed and grown and the attack surface. So it's not fair to really put blame to security leaders by any means, particularly since the people that hire them really don't want to give them the budgets that they need. Part of that's the inability to sell up. Part of that's also just that what we said, this is not a recession proof business. This is business to most organizations and it is not agnostic from the spend. So these gaps are also being caused. So let's just say that you're an organization that has all the gaps covered, which many are now in particular, because with AI, sink or swim at this point, with METOS and everything else we know about coming at us, it's sink or swim. So even if I'm an organization that has all my cyber capabilities covered, I'm going to have a gap in a week or a month or a day because we're talking about humans that can get sick. We talk about humans that for unforeseen reasons are no longer employed or that are going out on maternity or paternity or how about our managed service providers where we don't even know what's happening on the other side of those and when people are coming and going and all of that or our contractors because same thing. And so the workforce definition needs to be that vast and now it needs to have AI agents such that if something breaks or isn't available or can't work, that gap needs to be surfaced immediately, which is what we do. And because otherwise one moment we think we're covered, but truth is we're not in a day or a week or a month. And that's what leaders haven't been able to keep up with because how do you keep up with that? If you've got a team of any size, probably past 20, not just FTEs, contractors, FTEs, consultants, the person at the top who's making all these decisions, who's taking on risks that they feel are worth taking on or pushing back on, if they don't have that ability to see that, they're making poor decisions. And this is what we've been dealing with. It's so complex. It's not as simple as it used to be in terms of how to think of the workforce. Yeah, I'm just sitting here actually completely baffled by the risk that enterprises are taking on when they are literally just looking to cut costs instead of thinking the risk exposure coming from hiring gaps in cybersecurity. So and you made a good point that I had not considered is the AI agents. It's just, I'm again, just- You should have seen me the day I called my product team and I said, so we need to add AI agents to the definition of workforce and we need to adjust all our services to include the intake process for AI agents, just like we do FTEs, managed service providers, contractors. It's no different. My soul that day just felt really yucky. And of course, I have a love-hate relationship with AI today and still it's here and it is also going to cover capabilities for cybersecurity and it's going to have its own problems just like humans have, which is why the rate of change is so significant. Now, so that, and then how do you project the future is the next thing, meaning I have tons of clients who have been on top of workforce intelligence and working with us for the last three years. And now the request is, okay, so we do all this, we've been doing all this planning for all these years, because it's not just about where we are today. It's like, how do we get better and better and tighter and take people with us and train them and develop them? But now we're at the place where it's like, okay, so how do we know what AI is going to be doing in the future versus people, like answering those questions also is a gut in my stomach, and yet they have to be answered. We have to really figure this out. And so there's a lot to workforce is my point. And I think we just make it about the few FTEs that we may have, even before AI agents, and now AI agents are, because most people have lots of managed service support. I mean, that's people. Those are people behind the technology that we don't even manage and retain or anything. So, and then I'll also say this, like insider threat, up through the roof. I don't have a client that hasn't said to me insider threat isn't up significantly. And the amount of calls we're getting to higher insider threat SMEs is significant. And this is because we have done wrong by our people. Insider threat comes from how we treat each other. So I'm not surprised. I called it out long ago before this started happening. Like there's no way we can treat people the way we've been treating them, burning them out, then saying, we know your burnout, we know your burnout. And then, but we're going to burn you out more. Like, that's what we just did. That's what just happened. You know? So, so insider threat now is also a massive worry, which is massive risk. Yeah. I mean, how much easier is it to cause problems when you're an insider versus an outsider? That's so true. It's crazy. And it's literally, to me, it's business 101. Like what are we, what to do? And so this is where money meets morality. Sure. And it's, it's, it's, it's definitely a, you know, labor laws are also out there being attacked. And we hardly have any projections in the U S compared to other countries for labor. So this is a topic that's just going to get more and more attention because it's, it's weighing significantly and such that the risk is hitting companies. And so this is where I think we're going to see a lot more from this topic, insider threat. Yeah, it is. It is. My whole business is heavy. It always has been, which is why I really come out of how can I, you know, provide knowledge for change joining these types of podcasts and everything else. It's, it's the ignorance is bliss. There's no question to see at scale, our workforce system for our protectors. Nevermind. Think if this is what's happening to security professionals, what's happening to, you know, the average person that's got a job. So then, and, you know, let's, let's not, let's recognize that layoffs or, or, or cutting is only one piece of this for, you know, interaction. There's also the cultures themselves that in these environments, the people that are still working, they're worse than they've ever been. Because of the pressure and the change and the movement of leadership, we've seen more change in leadership at the top. And I'm not talking CISO, those roles move every eight to 12 to 18 months, pretty much for since I've been in the business. I'm talking CTO, CIO, CEO, CFO, those are usually 10 year roles, you know, minimum five. And we're, we're, we've been seeing massive movement in that. So that also slows everything down until those seats are full. Yeah, I could see it slowing things down. But beyond that, if, if you're continually adopting new mindsets, that could be good. But it could also be very negative, because you're starting all over when it comes to securing the environment. And so, you know, I think it could go either way. But this has been such an interesting topic, Deirdre, just real quick, what are just some of your key takeaways for the team or the the audience here today? The team that's coming in? Yeah, you know, being a subject matter expertise is, you know, find your domain, become a subject matter expertise in that domain, there's 45 different cyber job categories. Of course, not just adopting AI, understanding it, staying on top of it, it's critical, there's just no way around that. And really, this concept of managing up, like we call it Pwn Your Career, you know, all of this together, we call it Pwn Your Career, the idea of managing up, meaning get what you need, the ability to speak up, the emotional intelligence skills of communication, get yourself training, get yourself the art of communication as a strong skill, because everything's going to come down to how we all talk to each other, as this, you know, musical chairs continues. Yeah, well, thank you. Thank you so much, Deirdre, that was was really enlightening. I now have a different perspective on on this whole topic, just by talking with you today. So thank you. You're welcome. I appreciate you taking the time to make sure this information gets out. Yeah, absolutely. And thank you to our audience for joining in today. And that wraps up another episode of Zero Downtime.