Joint Committee on the National Security Strategy
Oral evidence
Cyber Security: Critical National Infrastructure
Monday 21 May 2018
4.25 pm
Watch the meeting
Members present: Margaret Beckett (Chair); Lord Brennan; Lord Campbell of Pittenweem; Mr Dominic Grieve; James Gray; Lord Hamilton of Epsom; Lord Harris of Haringey; Baroness Healy of Primrose Hill; Baroness Henig; Lord King of Bridgwater; Dr Julian Lewis; Lord Powell of Bayswater; Rachel Reeves; Stephen Twigg; Theresa Villiers.
Evidence Session No. 3 Heard in Public Questions 39 – 53
Witnesses
I: Mr Rob Crook, Managing Director of Cyber Security and Intelligence, Raytheon UK; Dr Alastair MacWillson, Chair of Institute of Information Security and Chair of Qufaro at Bletchley Park; Mr Elliot Rose, Digital Trust Cyber and Security, PA Consulting Group; Ms Ruth Davis, Head of Commercial Strategy and Public Policy, BT Security.
Examination of witnesses
Mr Rob Crook, Dr Alastair MacWillson, Mr Elliot Rose and Ms Ruth Davis.
Q39 The Chair: Good afternoon. Thank you very much indeed for coming. I am sorry that we had to keep you waiting a little, but I think you were warned that we would have some other business to transact first. We are not expecting a Division now, I hope, so that should mean that the session will not be interrupted.
I will begin the questioning with a child’s guide to defining our terms, so that we know we are all on the same territory. What do you mean by the phrases “cybersecurity skills” and the “cybersecurity skills gap”?
Mr Rob Crook: I am MD for cyber and intelligence at Raytheon UK. I have a business of 250 cyber experts. We have recruited them over the last three to four years, so I know a bit about the issues of recruiting to the market. Cyber skills are associated with securing information or operational technology and, in the case of industry, are typically delivered directly into government or into critical national infrastructure. That is what we do.
The gap is defined as follows. Vacancies in our cyber business have run at the rate of between 20% and 30% all the way through. To give you an example of how that compares, the rest of the business is an engineering business. We have been in defence and aerospace for 100 years. The vacancy rate is probably about half of that. To recruit good cyber people—the issues we find are right across the board—typically takes a minimum of three months, sometimes six and sometimes more. We have a sense that we are probably running 30% or more below the workforce that we could have if we could get the people.
Unemployment rates in cyber in the UK are running at around zero. Pay rates are probably 15% above other tech. That is what the data shows. Recent reports have shown that 80% of businesses worldwide—this is a worldwide issue, not just a UK issue—say that they are experiencing the sort of hard-core vacancy numbers that we are experiencing. I hope that is a good summary.
Mr Elliot Rose: I am from the PA Consulting Group, which is a technology and innovation consulting business. I head up our cybersecurity work. We have more than 150 people working on cybersecurity, ranging from strategic advice right the way through to detailed security in the actual hardware and software.
One of the things that we see in working with clients is that we talk about cybersecurity in terms of the technical skills that we have, but there is a big gap on the business and psychology side of things. The attacks are evolving with increasing sophistication, and there tends to be a people element to it and a cultural thing. There is a gap in training people not just on the technical side of things but in thinking more broadly about the context of cybersecurity to make sure that the enterprise is safe.
The latest statistics show that ransomware gets a lot of publicity. We all heard about, saw and were worried about WannaCry, but phishing-type email scams deliver four times the revenue of ransomware. While ransomware grabs the headlines, making sure that people are aware and training the business so that it is educated and aware enough to spot things such as phishing is probably where the gap lies, as well as on the technical side. There is no doubt that there is a gap on the technical side, but those broader skills are increasingly where the bigger gap is.
Ms Ruth Davis: I am here representing BT’s security team. We are a practice of 2,600 security practitioners. Our job is to protect BT’s global operations and our customers, as well as to provide managed security services to approximately 1,700 clients, government and large enterprises.
BT security defines its career pathways in terms of seven key security disciplines. We talk about architecture and design—how you design solutions for clients; penetration testing; security governance and compliance, as well as security risk management, both of which are the more strategic pieces that Elliot just spoke about; sales enablement; physical security; and threat intelligence and investigation.
On the question of the gap—the disparity between demand and supply—to my knowledge there is no official strategic quantification of that gap in the UK. The best estimate I have seen is that we have only about one-third of the candidates we need for the jobs posted. That strategic quantification of how big the gap is and what disciplines it is in is missing from current policy.
Mr Alastair MacWillson: I chair the Institute of Information Security Professionals here in the UK. Prior to that, my previous real job was as global head of technology at Accenture, which is a big consulting company with a major cybersecurity arm.
Ruth is absolutely spot on in saying that one of the challenges for government and organisations such as the institute that I run is that people talk about the cyber skills gap or cyber skills in a singular way, as though the cyber problem is across the board, without defining what the profession is and where its boundaries are. What I mean by that is that most employers think of cyber skills as people who operate, manage and observe security from a regulatory perspective, for example. Many UK companies would say that that is where there is a desperate shortage. I argue that that misses a much more significant point, which is that the people who design the tools of security or the security that goes into medical devices or cars are in far shorter supply than people who are more in the management profession. That is one of the challenges: defining what people are talking about before they say there is a skills shortage.
However, there clearly is a skills shortage. As Rob said, it is a global phenomenon. It has become really acute in the past two to five years, and the headlines have grown to the point where everybody is paying attention. Cybersecurity as an occupation has been around for 20 or 30 years and there has always been a skills gap of people with the critical talent that organisations need to manage their security in an increasingly complex world.
Q40 The Chair: Thank you. Elliot talked about the psychological aspects of the work and said that the people who do the design are in the shortest supply. You gave us examples, Ms Davis, of seven or eight different categories. Are there any other particular examples of where the shortage is especially acute? Okay, there is a general shortage, but where is it particularly difficult to get these people?
Ms Ruth Davis: From BT’s perspective, we have particular difficulty in recruiting enough people in cyber operations and analytics, and as technical solution architects—that is the design piece—sales specialists and security consultants. Those are our hardest to recruit areas.
Mr Rob Crook: From Raytheon’s experience, some of the more seasoned and experienced people in our world need to combine technical prowess, knowledge of a particular customer’s needs and some of the behavioural insights that Elliot referred to. All those combined in one individual, as you can imagine, is quite a rare set of skills. Those are hard to find. I am quite sure that I would be right in saying that all of us who employ people with cyber skills need to grow their own. They are simply not available in the market. Raytheon has to have its own professional development programmes—I am sure that other people have theirs—to grow our own.
Mr Elliot Rose: The other thing we are seeing is more demand and understanding of how AI and machine learning will help to combat some of the cyber issues that we face. Attacks are growing in sophistication and in volume. It is difficult to keep on top of that with a lot of the security operation centres that organisations currently run. Companies such as Darktrace, which is one of the fastest-growing SMEs out there, are pushing into the marketplace what has been developed in GCHQ and government and are commercialising it.
There is huge, rapid adoption, but there is a real gap in the technologies now adopted. This is where we sometimes step in to help organisations understand how machine learning and artificial intelligence can deliver a safe and secure service in cyber defence. That is another growing area where there will be a gap.
Mr Alastair MacWillson: One of the challenges the Government certainly face is not only thinking about where the skills gaps are now but looking at where they will be in the near and immediate future, because the pace of technology innovation is so phenomenal, and is increasingly so, that keeping a skilled workforce up to speed with what is going on in technology—with the internet of things, medical devices automation, automotive, aerospace and so on—is where the real challenge lies.
How do you find the engineers who understand the innovations that are coming along? That is a real challenge because of the timeframe for taking a willing student from school age through the career pathway in cyber and making them fit for business through that process.
Lord Hamilton of Epsom: Can I just answer Mr MacWillson’s question? The answer is that industry gets involved in our schools and starts getting schools to produce the people they want to train up in the skills they need. It is no good just sitting back and saying that government must do something. The onus lies with industry. But that is not my question. Mr Crook mentioned that Raytheon had hired 250 people with these skills. Do they earn any revenue for the company, or are they purely defensive and an overhead?
Mr Rob Crook: I am not sure that I see the distinction. They certainly earn revenue.
Lord Hamilton of Epsom: How do they earn their revenue? Do you sell their skills to other people?
Mr Rob Crook: We do. We have government and critical national infrastructure customers who pay for their services.
Stephen Twigg: Rob, you said that this is a worldwide issue, but do we have a particular problem in this country? How do we compare with, say, France or Germany?
Mr Rob Crook: The data is very interesting. I have looked into this a bit. I am not sure that I am qualified to judge on France and Germany. Some data shows that the gap is more extreme in countries such as the UK and Israel. I suspect—others will be better judges of this than me—that the gap is a little wider here because we have a vibrant industry. We are fortunate in having GCHQ and its sister organisation, the NCSC, at the heart of our world in the UK.
We have a tremendous export opportunity here. In a way, if the data is right and the gap is slightly more extreme in the UK, that might conceal a good story that the demand is very strong here. Of course, the demand will not get satisfied unless we conquer this problem. This problem is the key issue, strategically, for growing our businesses.
Mr Alastair MacWillson: There are two things from a UK perspective that skew some of the statistics. One is our incredibly vibrant banking and financial services community, which frankly soaks up what many would say is an unfair proportion of any skills available out there. Of course, it is willing to pay for them as well—needs must, I guess.
Also, we have such a strong use of cyber professionals in government. There is real awareness of the need in government. That is another soaking point. It is a very similar model to the one you see in the US, with strong financial services and particularly strong government. There are possibly more people in government in the US, with the big cyber city being grown in San Antonio. It varies from country to country. It also varies because we have a healthy consulting approach to security, which many of the other European countries do not necessarily focus on as much as we do.
Stephen Twigg: Are there implications from Brexit for our ability to attract people from other countries to work in this field?
Mr Alastair MacWillson: There might well be. The market for security professionals in the immediate term—over the next three to five years—is such in the UK that I do not think it will disadvantage people in the cyber profession in the UK unless they are working for foreign countries.
Stephen Twigg: I was thinking more the other way round: are we reliant on people coming from other European countries?
Mr Alastair MacWillson: I believe that the last figures I looked at said that most of the cyber workforce in the UK—about 78% of it, although this is a year old—are homegrown UK nationals. Many of the others are foreigners working in foreign companies or banks, such as American banks, so they are over here as expats. A large proportion that we deal with are homegrown.
Ms Ruth Davis: That is what we see at BT, too. The majority of our people working in security in the UK are UK nationals, but we obviously have a global workforce. We have people working all around the world for us. About 67% of our security practice is in the UK. From our perspective, we want to make sure that we have a regime after Brexit whereby we can recruit the individuals we really need into the UK and continue to export the skills that we want to our clients in Europe.
Q41 Lord Powell of Bayswater: You talked a lot and very helpfully about the problems you have in finding enough people and so on. Can you tell us a bit more about the talent pools in which you fish to try to acquire talent? What do you characteristically look for in education, training, experience and so on, so that we get a picture of whether you are casting your nets widely enough, to continue the pool analogy?
Mr Elliot Rose: We need to cast our net much wider for cyber skills. For the problems and challenges that people face, we welcome and recognise other disciplines that people might bring to the party. When we go to recruit we look at traditional university areas for the degrees that people have gone through, but we look at other ways. We are working with some clients to try to recruit people such as reformed hackers, and people who like gaming or are interested in gaming, in problem solving or psychology, because you can train people up in a lot of cyber skills. It is the aptitude we want to look at. We want to get somebody looking at problems and trying to solve them in innovative new ways.
One thing PA is investing in is working with schoolchildren. We are trying to capture people early in their primary schools. We have had something running now for a number of years on Raspberry Pi, which is a programmable device you can use for applications. We have sponsored that in schools. We run a competition every year. We try to incentivise and attract people into it.
The problem we face is that there is too much focus on programming when looking at cyber. In our work on Raspberry Pi, we team up with industry and those children. We set them industry problems. They go away and solve the problems, and then they come back with a solution that they present to industry. Industry then decides on that challenge.
That helps us to identify people’s aptitude so that we can try to pull them through and attract them. We have to start really young with children in school, but, to answer your question, we also need to think about the breadth of the pools that we fish from. We need to think more broadly than we have in the past.
Lord Powell of Bayswater: If you cast your net so widely, it sounds a bit strange that you are not catching more fish.
Mr Elliot Rose: We are trying. We are doing our best, but that is why I link it to my other point about trying to incentivise children through from schools. The stats are still poor on people coming through from degrees or taking cyber-related degrees into industry. There is still a challenge there, especially on the female side of things. It is important to us to have a balanced, diverse workforce, whether that is male and female or another type of diversity, but we are still not seeing that come through. We are still seeing male dominance in the industry.
Mr Alastair MacWillson: On one of the challenges that has not been talked about, you asked about the type of people we need. I link that tightly to the types of qualifications that employers are looking for. One of the problems with this very young profession is that it is only in the last 10 years that we have had dedicated cyber degree programmes.
Of course, all big companies are now saying, “We need to hire people with a degree as a minimum”. That is another skew on the real cyber skills gap concept. There are a lot of people out there with the right talent and capability to be really good cyber specialists, but because they are hired only on academic qualifications that are in themselves rather new, companies are hiring people not necessarily on the basis of their capabilities but on the basis of their qualifications. A lot of people get eliminated from that process because of search engines, because they do not have the necessary foundational qualifications.
Lord Powell of Bayswater: Surely that is just a self-imposed barrier and they need to readjust their thinking to the reality.
Mr Alastair MacWillson: Part of it is because cyber, as you might be becoming aware, is an extremely complex subject—albeit with a single focus—with lots of different disciplines. HR departments are not necessarily geared up to understand that complexity. They have a single focus when trying to recruit the best people in cyber. That usually means the add-on of a degree-level or postgraduate-level qualification, which is not necessarily going to solve the skills gap problem.
Ms Ruth Davis: We have quite a different approach in BT in response to the problem that Alastair just set out very succinctly. We hire a lot of people at entry level. We hire grads, but we believe that we are also the biggest private-sector employer of cybersecurity apprentices in the UK. We have about 97 apprentices and we are recruiting another 21 next year. We do not insist on a computer science qualification. We take people from a broad range of disciplines.
We changed our recruitment model to be very strength focused. When I was doing some research for this session I spoke to one of our interviewers, who said that one of our best graduate cryptographers is actually a music graduate. The pattern recognition and structure that comes with music is very transferable. We hired her and she has been doing brilliantly.
Q42 Rachel Reeves: I am interested in the point Elliot made about the diversity of the workforce. I would be interested to know what proportion of the people you have working this field are women. Ruth, you mentioned bringing in 97 apprentices. What proportion of your new recruits, whether graduates or apprentices, are women?
Mr Elliot Rose: The answer is absolutely not enough. We strive to recruit more. We get involved in a number of women in industry and mentoring schemes to try to pull people through. It is a real area that we are missing in terms of that gap.
Rachel Reeves: Is it 5%, 10%?
Mr Alastair MacWillson: It is 7%. I am involved with the World Economic Forum. It did a study with the Peel Institute looking at female participation in the cyber programme in a whole variety of countries. The average was 7%. I have more than 7,500 members in my institute; 4% are women. I know that Ruth is more relevant to talking about this than I am, but in our own survey of the profession we specifically surveyed our women members to ask why this is. It may be a very blinkered view of those in the profession, but it is that capturing schoolchildren to come into the profession has several disadvantages. You are trying to teach a subject that is close to computer science, which, as you may know, has poor female representation at educational level. Also, it is almost a given that, aligned with cybersecurity, you teach STEM subjects at school, which again has weak female representation. We need to address this somehow. I am not sure how, but that is the picture. I am sorry to say 7% when Ruth might dispute that.
Ms Ruth Davis: I was just going to say that 11% was the figure I have. It is pretty dire either way. We are quite a rare species. I do not know the exact proportion of our new recruits, but about 17% of the security workforce overall are women. It is better than the average, but still nowhere near where we want it to be. I definitely agree with Alastair about some of the reasons for that. There has been a very big focus on recruiting from STEM subjects, where we have traditionally had less female participation. The focus on broadening those hiring criteria is really important. That is one reason why we have done that: to make sure that we have the diversity we need in the workforce because it makes us a much stronger team.
The other thing is increasing the number of women interested in studying STEM subjects. BT is involved in Step into STEM, which we launched with a bunch of other telecommunications companies. I think it is in its third year now. We work with girls in London schools at A-level age who are interested in a career in STEM. The programme has reached about 130 girls so far, 70% of whom have gone on to study STEM subjects at university. There are lots of programmes such as that that companies run. We also deliver Cyber Discovery in partnership with the UK Government. It has a very strong focus on getting about 30% involvement from girls and female students. I think we are pretty close to hitting the target.
Mr Rob Crook: To offer another ray of hope, another very good initiative from the NCSC is CyberFirst, which a number of us are sponsoring. It is determinedly about attracting girls into getting involved in development courses and competitions, and the data shows 40% to 50% participation, at quite young ages, because it has been explicit about asking girls to join in the cyber world. It points the way to an initiative that we might all back with government and other stakeholders, including industry, to work together to change the game when it comes to the output of girls from STEM subjects.
Lord Powell of Bayswater: In thinking about that, perhaps I am being naive, but are not quite a lot of the roles in this area capable of being performed from home?
Ms Ruth Davis: Yes. I work from home several days a week.
Lord Powell of Bayswater: Does that not improve the gender diversity balance, or do you think it might?
The Chair: Perhaps it would be even worse otherwise.
Mr Elliot Rose: We run programmes of flexible working to try to encourage people. I agree that a lot of our roles and activity can be done this way. A lot of our work is done off-site and in our offices, and equally can be done at home as long as you have the right security protections in place.
Ms Ruth Davis: A big part of the problem is not necessarily where people are working from, because, as you rightly say, there is a lot of flexibility for home working and working from a series of locations around the country or the world. One of the problems is that, because it is quite a new industry, people do not understand what a career in cybersecurity is or what they need to do to get there in the same way in which someone at secondary school will understand what the career path is to become a doctor or a lawyer. The popular cultural image that we have of cybersecurity is nearly always teenage boys, because they always are in soaps or films, hacking away in some sort of intrigue. That does not really appeal to a particularly diverse audience.
One of the key things we need to do is focus on articulating the different career paths in cybersecurity, because they are very broad. You can have very technical careers, but again there is a huge breadth within that. You can have much more strategic careers, as mine is, based on policy and strategy. We need to focus on that. I know that the Government are launching a consultation in May on setting up a professional body or professional council for cybersecurity and trying to achieve royal charter status. That is one of the commitments that they made in the cybersecurity strategy. That is something that Rob, Raytheon and I and many people in the industry have put our support behind, because we think it will go a long way towards achieving what we need.
Q43 Lord Harris of Haringey: Mr Rose said almost in passing that one of the groups you might look to recruit is reformed hackers. How do you know that they are reformed?
Ms Ruth Davis: That is a good question.
Mr Alastair MacWillson: It is a fingers crossed thing.
Mr Rob Crook: You are on your own on this one, Elliot.
Mr Elliot Rose: Obviously there has been a history here for people with those skill sets. It needs to be linked to criminal justice reform and how people are reformed. You have to put safeguards in place, but it is interesting to look and learn from people who have reformed and who want to reform to see what motivated them and why they did what they did.
We need to think about some of the systemic reasons why people hack and how we can turn people away, just as we have with knife crime and things like that. How do we get to children in schools to convince them to turn away from hacking to being on the positive side of things?
Lord Harris of Haringey: Could we distinguish between putting people on a path to being white hats rather than black hats, which might be at an earlier stage of developing the skill, and those who clearly have done some very naughty things? How do you actually know that they have come back?
Mr Elliot Rose: It is difficult. You have to go through the justice system: they have served their time and declared that they want to do good. Again, you have to put the safeguards in place if you want to embrace them and do that.
Lord Harris of Haringey: Does that mean that you put in extra monitoring of what they do?
Mr Alastair MacWillson: Yes, and due diligence. You have raised a couple of interesting points. One is the diligence aspect. Whether it is a hacker or security professional in any form, companies go to great lengths to do due diligence on individuals who are looking after the Crown jewels. If they do not, they are deficient in that regard.
On the point that Elliot was making, the institute that I chair is involved with the Cyber Security Challenge.
Lord Harris of Haringey: I should make it clear that I am a board member.
Mr Alastair MacWillson: You will know, then, that that is a way of identifying people with innate talent so that they can go through a competition process to win work or a scholarship placement. That is a very good way of identifying whether they have the technical capability, but it does not decide which side of the line they might go on.
The intention of government and organisations such as ours is that we capture them at an early enough stage so that we can, hopefully, steer them down the right path and use the talent that many of them have. That has been a successful programme, as you know, for several years now.
Q44 Lord King of Bridgwater: Can I ask a question about age? We went through this some years ago. We were looking for younger people who might leave school at 16 and might not have many qualifications, a lot of whom missed out a bit and for whom hacking became a great obsession. They are the ideal people to recruit, are they not—people who are already interested in the subject?
Mr Alastair MacWillson: That is what the Cyber Security Challenge does, and a few other initiatives, such as Hacker House, which takes disadvantaged people or people who have had a troubled childhood and tries to teach them the good aspects of ethical hacking. However, there are no guarantees. That is true of any form of employment.
Lord King of Bridgwater: Are you taking on those aged 16 or 17? Are you recruiting about that age?
Mr Alastair MacWillson: Yes, and younger in some programmes.
Lord King of Bridgwater: A lot of people previously went on perhaps not terribly valuable university degrees. They would stop going there and have a much more worthwhile and financially rewarding activity in the hacking world.
Mr Alastair MacWillson: It is not just the hacking world, but you are right. For youngsters, hacking is a cool thing to do. Elliot mentioned that one of the talents we look for in really good hackers is gaming capability—people who can play computer games—because that gives them an understanding of logic, dexterity, mental dexterity and so on. We are identifying people at 13 and 14 years of age.
Lord King of Bridgwater: How satisfied are you that schools and the education system are educating them properly in hacking?
Mr Alastair MacWillson: I would not like to say whether I am satisfied or unsatisfied. I am quite keen on the CyberFirst programme. There are a couple of other programmes that have mostly been initiated by the Government, but also by bodies such as ours. We have a Train the Teacher programme, because unless you teach teachers the fundamentals of cyber from a safety perspective, as well as from the perspective of a viable career, you will have a real problem with close contact and extending that knowledge and enthusiasm to their students. That is really important.
There are a number of programmes. They might not be too joined up yet, but they are becoming increasingly joined up as they become more sophisticated and better understood.
Mr Rob Crook: School output is critical. The recent NAO report estimated that we have a general shortage in STEM of 1.5 million in this country. Looking at the data for computer science, my understanding is that for every boy who chooses to take on a computer science degree, 10 will take biology, and for every girl who chooses to go after a computer science degree, 100 will do biology. I understand that 0.5% of girls choose to do a computer science A-level; I think it is 4.5% for boys. Whatever we have done thus far in schools seems to be turning people off.
We are incredibly innovative at taking people from outside computing into cyber. As I said earlier, we have our own professional development programmes to facilitate that. But until we unblock the pipe of people who are prepared to have a go at this from a technical point of view and do some sort of computer-related qualification at some level in schools, colleges or universities, we will continue to talk about the skills gap. That is my assessment.
Lord King of Bridgwater: One last point. You talk about getting that qualification, but what worries me is that, as you have already said, this scene is changing so fast; new developments are coming in so fast. Somebody is proud to set up—“I’ve now got a degree in this”—but it is probably out of date in certain respects by the time they have it. Is that right? That is why you need to get the young people in and keep getting them in. They are the ones who can pick up the new waves as they come through.
Mr Alastair MacWillson: You are right in principle, but cyber is not the only profession that is moving at a hell of a rate. There is a really good analogy with medicine. We are now talking about gene splicing as though it is a common or garden technique and there are professionals who are trained in it. There are not, and there is no professional discipline in that area. But medicine has to adapt and constantly evolve. It is amoeba-like. There are immense similarities between the cyber profession and medicine, although one is very immature and the other is quite mature. New things happen and you have to adapt.
However, you cannot deal with that evolution in medicine either, so you have to train and educate people with a foundational set of skills—technology skills, engineering skills, management skills or software skills, for example. Then they can grow into a job in a particular area or genre of cybersecurity that is of interest, usually coached by an employer.
Mr Elliot Rose: A consultation on professionalising cyber is under way with DCMS, which is looking at the profession as a whole.
The one point I would emphasise is that, with cyber consulting skills or with cyber generally, you have to have continuing professional development, just as engineers or doctors do. We ought not to get caught up in thinking about qualifications, whether they come from traditional pools or a different pool. We ought to think about life-long learning. How are we going to accredit that? How are we going to make sure that those skills are up to date and relevant?
We have to look at the education system. We work with the Open University on the FutureLearn platform, which is all about modular-based learning and learning new skills and new techniques. The NCSC plays a really important role in education awareness among industry bodies, such as those for the financial services. We need to think about the regulators’ position in those sectors and about professional development in cybersecurity as a whole.
Q45 Lord Powell of Bayswater: I have one last question on this sector. Particularly in the light of Mr Crook’s slightly pessimistic summary, do all four of you generally think that the cyber skills gap is going to get worse, or are you beginning to make ground on it?
Mr Elliot Rose: We are making ground on it. There is still a lot of work to be done. We are in the fourth industrial revolution, and with digital skills and advances in machine learning and AI we will see much more automation coming forward. We need to anticipate that and think about how our skills grow and evolve. They will become much more specialised.
The gap is in the volume. We are trying to deal with that volume and the complexity, and we are starting to see a revolution in automation around some of this stuff.
Mr Alastair MacWillson: I go back to one of the early questions: what is the cyber skills gap? It is not avoiding the answer that you seek to say that we have to determine the shape of the profession and where the skills gaps are before we can say that we are confident, or at least I can say I am confident, that the right measures are being taken to fill it. A lot is being done, that is for sure, but is it adequate?
I mention that, because one of the things that has not been discussed is the demographics of the people in the profession now. Thirty-nine per cent, according to our institute’s stats, are aged over 45. It does not take a maths genius to work out that you have to work very hard to replace people who are within 10 or 15 years of retirement—the vast bulk of the senior workforce. That is the challenge that everybody faces, looking at it gloomily.
Q46 Mr Dominic Grieve: We have discussed gender, but we have not discussed disability. I am interested in hearing about that, because there is quite a lot of evidence to suggest that some of those who may have the skills necessary to help you might have disabilities, particularly autism spectrum disorder. I wondered what was being done in your organisations to provide appropriate support so that you can maximise what they have to offer.
Mr Rob Crook: That is a good point. GCHQ and the NCSC are taking a lead in this subject, and they have said very strongly that one of the advantages that we have in cyber is that we can offer a terrific career to people who are commonly referred to as being in the neurodiversity area. We will follow their lead. It is another area of innovation that industry and other stakeholders and employers will follow, and I think we will see some real improvements in that area. It is a very good point, and it is a great opportunity for us.
Mr Alastair MacWillson: I mentioned the Cyber Security Challenge a moment ago. One of the really interesting statistics that came out of the build-up to the Cyber Security Challenge was the level of neural diversity among the candidates who applied to go through the challenge. It is amazingly high in comparison with other professions. You would expect a high level of neural diversity with musical or mathematical talent, but it seems to be even higher in cyber, and the belief is that that is because of the gaming or the logical theory. Those with neural diversity seem to have a real talent for logic. That has shown up throughout history, from the early days of Bletchley Park, for example, which I am also involved in.
Ms Ruth Davis: It is certainly something that we are focused on at BT. We are in the process of adapting our recruitment process so that neurologically diverse individuals can feel at home in our selection sessions and showcase the best of their abilities.
We are also making sure that we raise awareness among our workforce and that we offer environments that they are comfortable working in. We are working quite closely with the National Autistic Society to develop an employers’ handbook dealing with the attraction, recruitment and retention of neuro-diverse candidates.
Q47 The Chair: In this inquiry, we have focused in particular on critical national infrastructure. So far, we have been talking across the piece. Are there any specific aspects of what you have been saying to us that are particularly different and difficult—more challenging in some way—for CNI sectors?
Mr Rob Crook: From my point of view, I do not think so. Many businesses are seeking to serve government and critical national infrastructure. The two go together quite well. If you can do one well there is a good chance that you can do the other quite well. Therefore, my observation is that, on the whole, the skills issues are the same whether you are serving government directly or the critical national infrastructure. I see no distinction, at least in respect of the skills gap.
It is possible that with automation, machine learning and so forth, any efforts that are made to make us more productive in our products and services may serve CNI customers more effectively for a range of reasons, including the fact that their demands are probably slightly more straightforward to satisfy—easier to productionise, if you like. So to that extent I suspect we may see an improvement in productivity in that regard. That might take some of the heat out of the skills gap, but at the moment that is probably speculation.
Mr Elliot Rose: One of the things that we are seeing in relation to critical national infrastructure is the digital age coming in. You tend to find a lot of CNI organisations with a whole legacy of operational systems. Obviously with the digital age coming in, we are seeing a clash with the two coming together. There is a certain challenge to that. That legacy infrastructure being connected to the internet and much more exposed to it is another area of concern, and we are providing more and more skills to help organisations through those challenges.
There is a whole change in the air sector, for example, at the moment. There are already remote control towers in place. Instead of control towers at airfields, they are remotely located somewhere else, and they need to interface into all the legacy systems at the airport.
We are certainly seeing a lot of examples like that, and there are real challenges in thinking about it. It comes back to my original point: the technical things with operational security are pretty much there in the traditional ways of protecting it, but there is also a need to think about all the new ways in which people can exploit or create vulnerabilities in those types of systems or new ways of working.
Ms Ruth Davis: Of course, at BT, certain very important aspects of our business are part of the critical national infrastructure here in the UK. Our team that protects our business also protects our customers, so we see no difference in skills there.
The Chair: You have made it clear that these are good job opportunities and highly rewarded. Is there any difficulty in some of the CNI sectors matching what is available elsewhere?
Mr Alastair MacWillson: Rob, Elliot and Ruth have mentioned that CNI does not represent a particular challenge. I am not so sure. Most of the critical national infrastructure is utility-based—the water companies, the electricity companies, telcos—which have to compete in a commercial market with the likes of the banking industry, which is also a critical infrastructure.
In my experience it is more difficult for, say, a water company to hire a top cyber team than it is for a bank because of the difference in margins. There is that industry challenge.
I agree with everything else that was said.
Mr Elliot Rose: The only thing to add is the regulation that has just come out. We have all been preoccupied with GDPR, as I am sure a lot of people are around the table. By stealth, at the same time, the NIS directive has come out and is being enacted. That places significant fines on CNI players if they get it wrong in meeting those requirements from a cybersecurity point of view. That will play out more and more once we get over the GDPR, but that has grabbed the headlines so far.
Lord Hamilton of Epsom: May I just take up something that Ms Davis said about it being very difficult for HR departments to identify people with these skill sets? Surely one could get round that with some form of exam or intelligence test. Do they not do that?
Ms Ruth Davis: I agree. It was not me who made that point. We certainly do. We have moved to a strength-based model where candidates are assessed on things such as problem solving, situational awareness and understanding our business, seeing security in context. That enables us to recruit candidates with strong aptitude who do not necessarily have, say, a computer science qualification.
Q48 Lord Hamilton of Epsom: My question is about retraining current employees. From what has been said so far, it seems that recruiting people with the right aptitude is rather a young man’s business. If I find that the skills that I have in a business have become completely redundant, it sounds to me as though I am rather bad raw material to be retrained. Is that not the case?
Mr Alastair MacWillson: I do not know you enough to respond to that. I will stick to the general.
From a general perspective, that is not a correct statement. Israel is a good example. It has an extremely good retraining programme of conscripts in the army. It has a fertile source of individuals coming out of the army either building cyber businesses or going into the cyber profession.
I am not saying that we should do that, but we in the institute have been trying to recruit from the Armed Forces here at whatever age they retire, because they have all the disciplinary-type skills that employers are often looking for. Many of them work in areas such as Armed Forces communications that are complementary to the cyber foundational requirements that you have to go into the cybersecurity industry. It is not impossible.
The Government have a cyber boot camp for such individuals of any age. It is quite an effective programme. Some 5,000 people are going through that reskilling programme at the moment. They are mostly ex-Armed Forces but not wholly so. Some are teachers, but it could be people from any other profession.
Lord Hamilton of Epsom: Israel has conscription, so a lot of those ex-military will be very young men and women.
Mr Alastair MacWillson: Indeed. It is the same in Norway, Estonia and various other countries. That programme works, but it will not work here, so the Government have had to do something else to encourage people to move.
Mr Elliot Rose: We recruit a lot of ex-armed services personnel for the reasons that Alastair gave. They have good problem-solving skills and good discipline. We find it is easier to give them the cyber skills rather than teaching inherent skills or behaviours. That is important.
It is also important to reflect that in industry we see that a lot of people who are very good at cyber or are chief information and security officers—CISOs—who have come from the business and have learned the technical side of things and the technical skills. It is coming from the younger generation. Bear in mind that there is a time lag in what we do today. It will be a number of years before that starts to filter through. We should recognise the talent that we have already. In our experience, that has been very successful.
Lord Hamilton of Epsom: Are you saying that it makes no difference whether someone is aged 18 or 45?
Mr Elliot Rose: No. If they have those core behaviours, you can train the other cybersecurity disciplines around them.
Mr Alastair MacWillson: It will be one piece that might help to solve the skills gap, but it will not solve it in its own right. No way.
Mr Rob Crook: In answer to your question, I am sure you would make an ideal candidate. I will give you a business card before we break to see whether we can prove it.
The Chair: You made the point earlier that it is about getting the right mix of skills and so on; it is not just about technical expertise in cyber. Is that area sometimes useful for reskilling existing employees? Is there a range of maturity and experience and so on that can be relevant?
Mr Rob Crook: That is right.
Mr Alastair MacWillson: That is right. In fact, you do not have to look back very far—maybe 10 or 15 years—when nearly everybody in what is now being called the cybersecurity profession came from somewhere else, as I did. I was at the Foreign Office. There are lawyers, project managers, technologists and so on. That was the norm.
The Government and industry are trying to move away from that in a way, because there are now graduates coming out of university, apprentices and others who are interested in going through things such as the Cyber Security Challenge. We need to capture those, as well as the older people like me who moved in and hijacked an interesting area of life.
Mr Elliot Rose: We talk about the cybersecurity career pathway, but we find, and industry has to recognise this, that there is much more churn in the cybersecurity market than you might expect. It is all about career experience, rather than the overall destination or journey. We need to think about how we engage and employ cybersecurity professionals and realise that there is quite a churn. It is quite a good thing in cybersecurity to have that degree of churn, because people bring new experiences from different sectors and areas.
Ms Ruth Davis: The public policy debate probably has not focused enough on that. We have talked a lot about building a pipeline of future talent, which is understandable because that takes time to filter through, but that is an area that we should move on to. We certainly see good results from it at BT. We retrain our network engineers. Some 136 of them, I think, joined the security team last year.
Q49 Dr Julian Lewis: Moving on to the question about the Government’s efforts to develop cybersecurity skills, you have already made some remarks about government initiatives. Do you believe that the Government are succeeding in addressing the various gaps in cybersecurity skills? How easy is it for businesses and schools to navigate the Government’s initiatives in trying to recruit for this field? Are they any particular initiatives that you find to be especially beneficial?
Mr Rob Crook: That is a really good question. I must have sounded a bit gloomy earlier, but I applaud the Government’s initiatives arising out of the cyber strategy. I mentioned CyberFirst, which points the way. I would be much less gloomy if that initiative was scaled up. Looking at the numbers involved in CyberFirst, by the end of this financial year some 500 bursaries will have been offered to undergraduates and some 1,300 or up to 2,000 younger schoolchildren will have been through the programme. I think it is intended that 5,700 will have been through the Cyber Discovery programme by 2021.
Those are great programmes. Industry is falling in behind them. We are sponsoring them, as are other stakeholders and employers. Perhaps for the next phase of the strategy they are well worth reinvesting in and scaling up. This really is now a game of scaling up. You will have heard from other members of the panel—I will echo them if I may—that the launch of a cyber profession will provide a focal point that will answer one of your specific questions, which is, to borrow a phrase from the NAO report on STEM skills, the bewildering array of routes into cyber.
That we have diverse routes into the profession is a strength in a way, but by God it must be confusing for schoolchildren, parents and teachers. Therefore, anything the Committee can do to get behind DCMS’s initiative to launch a profession so that we achieve royal charter status for the cyber profession in 2020 will go a long way towards regularising the way we set the profession out to those who want to enter it, from whatever walk of life, and to allow us to scale up what we are doing.
Those two sets of initiatives—getting into the schools and getting these very low take-up rates to start to come up but at a much greater scale than at the moment and, secondly, combining that with DCMS’s initiative associated with a cyber profession—are reasons for much optimism.
Ms Ruth Davis: I agree. The Government have started a fantastic array of initiatives. They have been very creative and forward-thinking when you look at what is happening on the international scene. Of course, this raises the problem that it is quite difficult, if you are coming in from outside the sector, to have a clear idea of where to engage. I certainly agree with Rob about the need for a professional body and for greater visibility and clarity in the sector.
The other area I encourage a focus on is the more strategic approach to skills, looking at how risk is quantified and managed in cybersecurity, for example. We have a considerable skills shortage in that area, and most of the initiative so far has focused on technical skills rather than the strategic and policy side.
Mr Alastair MacWillson: Everybody—business and government—has been taken aback and very surprised by the scale and growth of the threat.
In parallel with that is dealing with the skills deficit. That is a challenge in any circumstances. It is not just unique to the UK; it is a global problem. I believe that the Government have been caught a little. They might have been able to foresee the scale of the challenge, but, as I say, they were surprised. Therefore, putting in place a programme that, by its nature in the learning pathway that Elliot mentioned, takes a 12-year slice out of anybody’s life will be a real challenge for anybody to design something that can predict what the problem will be in a very unpredictable future. They can only anticipate, which is exactly what they have been doing quite effectively, particularly at school level.
Dr Julian Lewis: Are there any other challenges, if you were to imagine yourself in the shoes of the Government, that you would find particularly onerous and hard to deal with? If you can identify such further challenges, do you have any recommendations as to how they might be surmounted?
Mr Rob Crook: I would love to grab the first question so that someone else gets the second. I am no expert on this, but the initiative to introduce coding into primary schools, which we welcomed in principle, might have run into some problems in practice. For one, it is not obvious that that initiative has included cybersecurity as part of its curriculum. Secondly, I am not sure that it is inspiring young people into the profession. When I say “not sure”, I mean that literally, but that might be a problematic area. Is it inspiring children? Others on the panel may know more about it than I do. I would certainly invite further comment on that.
Mr Elliot Rose: We talked about the Raspberry Pi initiative, which is aimed at digital skills and capturing people in primary school. More should be done on that from the government point of view, but industry should play a part in it. We have been involved in the WePROTECT initiative, which is quite interesting. It is all about protecting children, right the way from primary school upwards, from child exploitation online.
Again, we worked with a number of the large players in industry to come together to work with the Government to understand how to deal with those challenges. It was led by Baroness Shields, who was appointed to pick that up. There is a need to make sure that we capture people early enough, educate them, make them safe online and think about cybersecurity issues and challenges, and that we start to sow the seeds in the very early generations that this is something that a number of them would be interested in following.
Ms Ruth Davis: There is probably a need to empower parents and teachers as well. A lot of them do not feel confident teaching or talking about cybersecurity, whether that is staying safe online or cybersecurity as a profession.
I agree that industry has a responsibility to look at what we can do there. At BT we have worked quite hard on this issue in computer science, with the Barefoot Computing programme in primary schools helping teachers to become more confident in teaching computing in an interesting and engaging way for that age group. There is probably more for industry to do there to apply it to cybersecurity.
Q50 Dr Julian Lewis: Seeing as a couple of you have touched on this, we have been focusing mainly on hacking and cyberattacks, but two of you mentioned safety online for young people. Is this an area to which you have been giving attention in this context?
Mr Elliot Rose: We certainly have through the WePROTECT initiative. There is a cyber element to that, so we have been involved in it. We are keen to help and develop that further for cybersecurity.
Ms Ruth Davis: We were the first CSP to block images of child sexual abuse online many years ago. We work with a large number of charities and educational organisations to try to improve awareness on that.
Dr Julian Lewis: Some of us find it very difficult to understand why, despite all the concern, it is so easy for people to access atrocity material, for example, but it does not seem so easy to block it. Are you working in that field?
Ms Ruth Davis: We do block it and we have for many years.
Dr Julian Lewis: Successfully?
Ms Ruth Davis: Yes.
Dr Julian Lewis: Any other comments on the success with which that is achieved?
Mr Rob Crook: All I would say is that part of every encounter that our STEM ambassadors have in schools colleges and universities associated with bringing cybersecurity to the attention of pupils and students is about being safe online. That is a great advantage that this profession brings.
Mr Alastair MacWillson: Early findings in the UK are that one good way of attracting future cyber professionals is to give them an initial grounding in cyber as a safety set of instructions for students, because if they come from a technical or gaming background they are fascinated by the whys and the how this can happen, which leads them on to more detailed interests.
Lord Campbell of Pittenweem: Forgive my late arrival.
I find this fascinating. I am on a very steep learning curve here, and you have helped me considerably. There is one initiative that I do not think has been mentioned. Why do we not work out exactly how our opponents came to achieve the standard that they have achieved, whether they use education or financial inducement or whether people with the proper qualities are compelled to go into it? By what means have our opponents achieved the levels of competence that we now have to meet?
Mr Elliot Rose: Some of our opponents have certain levels of conscription, which have been used as a focal point for developing skills and having the manpower to pose the threat to us that they pose.
Lord Campbell of Pittenweem: Big financial rewards in societies where financial rewards are not necessarily as great or as comfortable as we enjoy?
Mr Elliot Rose: Exactly.
Ms Ruth Davis: For criminal gangs, it is also a pretty low-risk activity, especially if you are operating in part of the globe that does not pursue cybercrime as diligently as we would in the UK, and the rewards from it are pretty high.
Mr Alastair MacWillson: People refer to it as the asymmetry of attack and defence. In cyber circumstances that means that it is much easier for any individual to attack an organisation or another individual than it is to defend them. A CISO in a bank or a business has to defend against thousands of possibilities, whereas an attacker only has to try certain techniques or certain tools. I am not saying that they are not as talented—they are often very talented—but criminals have an easier time of it than someone who is responsible for protecting an organisation. There is no like for like comparison.
Your question is a very good one. I am not aware of any body that has done research into why cybercrime, cybercriminal gangs in particular, is incredibly well funded. They use tools and techniques that are equal to many of the best tools that businesses buy, and they go through similar education processes in many cases. As I say, it is easier to attack than to defend.
Lord Campbell of Pittenweem: It is a variation of the terrorist only having to succeed once, whereas the Army has to succeed all the time.
Mr Alastair MacWillson: Exactly.
Lord Campbell of Pittenweem: Perhaps we have sparked an interest.
The other thing, of course, is to persuade people to come over to us. I know this is treading into rather delicate intelligence areas, but that would be a possibility: identifying very good people on the other side and turning them.
Mr Alastair MacWillson: Yes. That certainly happens in the commercial sense. Organisations are very good at what they do, but they do it for money, and people might not necessarily be paid by good organisations all the time. There is that borderline of security organisations that might well drift to the wrong side of the line.
Lord Hamilton of Epsom: I think I am right in saying that the technology we are dealing with here doubles every two years. So although people say that our schools should be on top of all this, is it not almost inevitable that they will be behind the curve? If I am a wildly intelligent teacher who understands cyber, am I not likely to be working for double the money for you than I would be in a school?
I do not think you can rely on our schools to do anything other than basic training on this. The inspiration, as Ms Davis said, has to come from the industry.
Ms Ruth Davis: Yes. It needs to be a partnership. We mentioned the context of university degrees earlier. Industry cannot expect to get the talented individuals with the breadth of experience they are looking for if they do not get involved in helping universities to keep their courses up to date and focused on what they are looking for.
The same applies to schools, which is why we work closely with schools and a big array of universities: to make sure that we have that dialogue and that partnership.
Mr Elliot Rose: It is that inspirational thing. Industry needs to work with schools. We support the Teach First programme, for example, which mentors teachers. It is really important to keep skills up to date, but it is also important for industry to set role models. It is really important for children to see first-hand the art of the possible and what the career development opportunities can be.
Mr Alastair MacWillson: A sub-point that has not been raised yet is that there is a revolving door because of the skills gap. Your comment about teachers being trained up to do cyber and then jumping ship and ceasing to be a teacher and moving into industry or government is very valid. That happens across the profession, and it is an endemic problem for many organisations in that they lose people as fast as they can hire them because it is a roundabout of he or she who pays the most.
Lord Hamilton of Epsom: Presumably the traffic is one way and they never go back into teaching.
Mr Alastair MacWillson: I imagine that is right, but it is like many other professions that teachers move into.
Mr Rob Crook: I think most of us would settle for your model, which is that if we can scale up the basics coming out of the education system, the rest of us will provide the customising and the up-to-date training. That is a perfectly okay model, but we need to scale up what is coming out of schools.
Q51 Lord Harris of Haringey: Dr Lewis’s series of questions were about the Government’s role. I want to go back to my earlier preoccupation about black hats and white hats.
You mentioned the importance of due diligence. Do the Government have a role in supporting you in that due diligence when determining whether a hacker has genuinely reformed or whether some of your recruits are more interested in black hatting than white hatting?
Mr Alastair MacWillson: Several of the panellists have mentioned the Government’s professionalisation initiative, which is part of the national cybersecurity strategy. Part of that professionalisation is to put standards, ethics and guidelines in place for institutions such as my institute or other stakeholders involved in the professionalisation process so that there are codes of practice for security practitioners, whatever the discipline they are in.
You may be familiar with an organisation call CREST, which accredits ethical hackers—penetration testers—across the UK and in some other countries. They have strong ethical and good-practice standards, which they have implemented when employing people. They do peer reviews, so they can look up and consider the background of any individual applying to be a member of that institution.
That links to employers, who say, “I only want to hire pen testers who have gone through some form of accreditation. Therefore they must be members of CREST, for example”. That is exactly what the Government want to do on a wider scale, but the Government want to harmonise those standards across a variety of organisations that might accredit or award levels of skills and experience status.
That starts the due diligence process, but as with anything else, particularly in the security profession, whether it is physical security or cybersecurity, the employers are the last resort, I guess, for doing that level of due diligence on the individuals, and there is much sensitivity around that.
Lord Harris of Haringey: I want to clarify something. You are saying that the Government are taking the initiative and trying to bring together the different bodies that purport to represent the cybersecurity world—
Mr Alastair MacWillson: Yes, like an engineering council.
Lord Harris of Haringey: —which is all well and good—and then leaving it to them to set the standards.
Mr Alastair MacWillson: That is still being debated. There has been a consultation process for 18 months now, which the institute is heavily involved in. Organisations like my institute have quite a high level of maturity in assessing the skills, experience and background of individuals, but there are others at different maturity levels that may use different standards for accrediting and assessing individuals. So the Government want an über-organisation, which is now being talked about as an engineering-type council with a royal charter that in effect charters the other stakeholding organisations such as the institute that I chair so that they can harmonise standards. That is exactly what happened 500 years ago with the medical profession, which I used in an analogy earlier.
Lord Harris of Haringey: That is fine, but the medical profession has had 500 years of clear ethical standards. That did not mean that the General Medical Council could pick out Harold Shipman before he murdered people.
I am trying to get at whether there is a role for the Government and their agencies being engaged in the vetting of people, which you rely on for cybersecurity.
Ms Ruth Davis: Yes, where we are seeking security clearances for individuals to work on particularly sensitive projects, but in normal deployment it is up to us, as it is to any other employer, to vet our own staff and make sure that we are hiring ethical people.
Mr Alastair MacWillson: I believe there would be immense pushback from industry if security practitioners had to go through that formal process. There may be good reason to do it in certain cases, particularly where critical national infrastructure is involved, but there are better methods for vetting than a formal process of DV-ing or SC-clearing every individual who can get access to sensitive data.
Ms Ruth Davis: It would be impossible, because the resources are not there to do that.
Mr Alastair MacWillson: No. Getting our organisations to abstract the appropriate checking, balancing, peer reviewing and accrediting of individuals to other organisations is possibly the fastest way of getting it done, provided that you entrust those organisations.
Q52 Lord King of Bridgwater: I want to ask about what the Government might do in this sense. I was very worried about the figures you gave for how many girls were coming out of schools and into this field—how few there were and how they were not interested in these subjects. Is there an opportunity to advertise role models? In one part of your evidence you said that if you are in this field you might get a salary that was 15% higher, but we know that some people are making absolute fortunes in this field by various deviations. I cannot remember the name of the young man who is a YouTuber, a blogger or whatever and who has made £7 million or £8 million just putting up his ideas, pictures or whatever.
This is a rather muddled question, but is there a way of developing a few role models to show how well you can do if you are good and experienced in this field in order to encourage many more young people to take an interest in it?
Mr Elliot Rose: That is a very valid point. Some of the other disciplines out there do that. Science, for example, has Brian Cox, who is a very public figure. That attracts people into those professions. We need to think about doing something similar in cybersecurity and get away from the perception that it is all teenage boys in their bedrooms. It is a worthy, important thing to do. It is not just financially rewarding; we are protecting critical national infrastructure. It is a really positive thing to do to protect the security of the nation.
Mr Alastair MacWillson: Somebody put it to me that we need a James Dyson for cybersecurity. Perhaps he is not the right choice, but we need a figurehead that would give visibility.
Lord King of Bridgwater: In America, Zuckerberg and onwards all earn a lot. The money that so many of them have made is a huge incentive to young Americans to get into that field.
Mr Alastair MacWillson: Yes. But the challenge in the cyber discipline, I guess, is that it is not as sexy as doing social networking or social websites.
Lord King of Bridgwater: But there are angles of it that are.
Mr Alastair MacWillson: Yes.
Ms Ruth Davis: Sadly for all of us, the average salary even in cybersecurity does not quite match what Mark Zuckerberg takes home.
I agree on the role model point. It is also one of the reasons why we see so few women entering the sector: most of the senior people in it are men because they have been there longer. Women look at the sector and do not really see anybody who looks like them, so why would they think about joining it? I completely agree that having more role models is very important. The work of a professional body in defining the sector and giving it a shape and a voice that people can relate to will be really important.
Mr Alastair MacWillson: We have 50 fellows in the institute, fortunately, but unfortunately they are all as old as me, or older. They might be luminaries, which gets them into the fellowship consideration, but they are not attractive to youngsters in the way they might think they are.
Lord King of Bridgwater: You want a 19 or 20 year-old who has really done well.
Mr Alastair MacWillson: That is a challenge.
Lord Campbell of Pittenweem: I cannot resist suggesting sending them all to Menlo Park for a fortnight. When they see just how much money is made, send them up to San Francisco to find out what the property prices are. If you see the extraordinary nature of the reward, that could be a bigger incentive than anything else.
Mr Alastair MacWillson: Yes. San Antonio is the place for cyber people.
Q53 Baroness Healy of Primrose Hill: We have talked a lot about education. Do you think the school curriculum is adequate to meet future demands for cyber skills? Do you think there should be a fundamental rethink of the way children are taught to think in the first place? I would be interested in your views.
Ms Ruth Davis: Quite a lot has been done, such as introducing cybersecurity to computer science and improving computer science qualifications. The change I would like to see is cybersecurity being woven into a large number of subjects. It is very relevant to business and law, for example. I would like to see it broadened out into other subject areas.
Mr Alastair MacWillson: But that necessitates training the teacher to be confident that they can factor that in. There are two avenues that many schools, particular sixth form schools, are going down. One is being a lot more inquisitive about how they can factor cyber into the current curriculum of whatever the subject matters are, as Ruth just said. The second is that the institute and others have just launched an extended professional qualification, or EPQ, in cyber, which is an A-level equivalent. A new one will be an apprenticeship-equivalent qualification in cybersecurity.
There are two streams because nobody in the Department for Education or any educationalist has decided whether cyber needs to be an integral part of education at sixth-form level or emphasised in a stand-alone, separate way. This is the dilemma for the Government at the moment with these new tech institutes, which are a good way of dealing with the subject. It might well be good standing alone, but it clearly has a lot of merits if it is an embedded part of everything else. “The jury is out”, is probably what we both are saying.
Baroness Healy of Primrose Hill: That is what I was wondering when you talked about empowering children by beginning to understand the role of cyber, not just to see it as a threat. That might also encourage more young girls to get involved. Do you think the Government should rethink the curriculum, or should the industry try to put more pressure on the Government to rethink the curriculum?
Mr Alastair MacWillson: Both things are happening. The Government have gone right back to thinking about national occupational standards with a cyber stream in them. That goes right down to foundational education at GCSE level. So the Government are thinking about how they teach cyber safety, as we talked about, but they are also thinking desperately about how to encourage people to think about cyber as a profession, as well as the security and safety factors.
Industry needs to step into that, because it has the demand and can think long term and maybe influence some of the more foundational thinking that has been going on. That is stripping off some of the more esoteric educational areas. They are trying to simplify the curriculum, rather than complicate it. That is why I say the jury is out on all this, but a healthy debate is going on around it.
Ms Ruth Davis: Partnership will be key. To date, the industry and government have had a very successful partnership. That is certainly something I would emphasise on BT’s part. Although the curriculum is obviously set by government, not industry, a big role for industry will be supporting that and giving teachers the confidence and resources so that they feel they are teaching these subjects in the right way and are engaging children.
The Chair: Thank you very much indeed. This has been a very useful session, even if I suspect you have reinforced our anxieties.