Written submission from (ISC)² (ULM0047)
The Business, Energy and Industrial Strategy Committee
UK LABOUR MARKET INQUIRY
SUBMISSION
Evidence Submitted by
Organisation: (ISC)2
Consent: This submission can be made public and published.
(ISC)² is an international non-profit membership association focused on inspiring a safe and secure cyber world. Best known for the acclaimed Certified Information Systems Security Professional (CISSP®) certification, (ISC)2 offers a portfolio of certifications and continuing professional development that is part of a holistic, programmatic approach to information security. Our membership, more than 168,000 strong, with circa 10,000 members in the UK, consists of certified cybersecurity professionals responsible for securing our governments, economies, critical infrastructure and personal information every day.
(ISC)2 is a proud Founding Member of the UK Cyber Security Council. Our certifications – including the CISSP, CCSP, SSCP, CSSLP and HCISPP – have been accredited against the ANSI (ISO/IEC 17024) standard. CISSP is benchmarked by UK ENIC at RQF Level 7. In the UK, (ISC)2 supports the NCSC’s CyberFirst initiative and (ISC)2 membership via the CISSP certification is recognised by the NCSC Certified Cyber Professional Assured Service[1] . In addition, the UK Government Security Profession Career Framework lists the (ISC)2 CISSP certification as an indicative professional qualification for several roles[2]
(ISC)2 is responding to a selection of questions based on our industry expertise and extensive research into the cybersecurity workforce. We ask the BEIS Select Committee to consider these responses to help address and cultivate solutions to the cyber skills gap, and to create a safer and more secure cyber world for the people of the United Kingdom.
Executive Summary
Do we have enough workers with the right skills in the right places?
What more can the Government do to ensure that employers are able to recruit people with the right skills for the job, including the effective use of apprentices?
What are the skills and training needs of different sectors over the coming months and years? Are there particular case studies that underpin priority policy objectives from the Government (for example, in the energy industry)?
How is the UK’s ageing population exacerbating the labour shortage that can already be felt in some sectors, e.g., hospitality, hair and beauty, social care?
The need for more cybersecurity professionals has never been greater. (ISC)2 estimates that the UK needs at least 33,000 new cybersecurity professionals to fill the nation’s skills gap[3], and demand only continues to rise. The solution to the UK skills gap will come in many forms and requires government and private entities to collaborate on multiple fronts.
(ISC)2 research indicates that a clear first step is encouraging organizations to hire and entry- and junior-level cybersecurity practitioners. UK security teams have the lowest percentage of entry-level security professionals with one year or less of cyber experience on their teams compared to the United States and Canada.[4] The UK apprenticeship programme is an ideal pathway to respond to this challenge, but it is critically under-utilized.
To encourage more employers to bring newcomers to the field, the UK apprenticeship programme must evolve. Organizations also need new resources and guidance to effectively enable an increasingly non-technical population that is entering the field. Nearly half (43%) of all cybersecurity professionals in the UK do not have a background in computer science or engineering technologies,[5] but many are building long-term successful careers and contributing to the UK’s cyber defense. Only 2 in every 10 companies currently take in cybersecurity apprentice workers.[6] Cybersecurity is a field that appeals to people of all backgrounds who can learn on the job and quickly contribute to shrinking our skills gap. By focusing on new entrants to the field – especially those with non-technical backgrounds and experiences – we also will encourage a more diverse and inclusive workforce.
Throughout this submission, we will present data-driven solutions to decrease the skills gap without putting increased burden on employers and already overwhelmed cyber employees.
- No. There are not enough cybersecurity professionals in the UK, and the skills gap is increasing. Despite increased efforts and attention by the UK government to drive additional resources to the cybersecurity profession, approximately 697,000 businesses (51%) have a basic skills gap.[7] This is up from 48% in 2020.[8]
- In our 2021 Cybersecurity Workforce Study, (ISC)2 estimates that the UK needs 33,000 cybersecurity professionals to fill the skills gap[9]. This number differs from information put forth in the DCMS 2022 Cyber Security Skills in the UK Labour Market which increased the annual shortfall in cybersecurity personnel to 14,100[10]. Both, however, show a significant shortfall in cybersecurity professionals that needs to be addressed as the demand for cyber skills continues to increase.
- Almost half (49%) of all organizations have faced or are currently facing issues with technical cybersecurity skills gaps among existing staff and/or job applicants. 19% say that job applicants having these skills gaps has prevented them from achieving business goals.[11] This data indicates that employers are aware of the inherent risks and are being impacted by not having enough trained cybersecurity professionals.
- Objective 5 within the Government Cybersecurity Strategy 2022-2030 delves into addressing the cyber skills gap by recruiting from a multitude of skill sets — both technical and non-technical — ensuring the workforce is inclusive and diverse. The continued creation of leading learning opportunities will further develop the profession and its ability to compete worldwide.[12] (ISC)2 supports this, and we strongly contend that encouraging employers to recruit and develop entry- and junior-level staff can help us accomplish this goal.
- UK security teams have the lowest percentage (22%) of entry-level security professionals with one year or less of cyber experience, 4% lower than the United States[13].
- To assist employers in identifying candidates for these roles, in 2022, we introduced the (ISC)2 Certified in Cybersecurity entry-level certification.[14] This certification helps those with little to no cybersecurity experience demonstrate a fundamental understanding of cybersecurity concepts to pursue employment in the field and provide employers with greater confidence when recruiting these newcomers. (ISC)2 Certified in Cybersecurity supports the desire expressed by more than half (51%) of UK hiring managers that it is critical for entry- and junior-level candidates to hold IT or Security certifications.[15]
- To help strengthen the UK’s cyber workforce even further, (ISC)² is offering the (ISC)2 Certified in Cybersecurity certification education and exam to 100,000 individuals in the UK FREE. The programme is open to all UK residents who do not hold an (ISC)² cybersecurity certification. Recent graduates, career changers and IT professionals looking to move into cybersecurity are encouraged to apply[16].
- Our research also finds that entry- and junior-level employees bring fresh ideas and perspectives, a desire to learn, new technologies, critical thinking and more to their organisations. (ISC)2 found for most organisations, the cost of developing junior talent is relatively low, ranging from £470 to £4,076.[17] Further, it doesn’t take long for entry- and junior-level practitioners to be “up to speed.” 37% of hiring managers we spoke to said entry- and junior-level hires are ready to handle assignments independently within six months or less on the job.[18] This leads (ISC)2 to contend that effective programmes to encourage more entry- and junior-level practitioners to enter the field can have a meaningful impact on the cyber skills gap much quicker than other good-faith initiatives, including investment in primary and secondary education.
- 68% of employers have attempted to recruit for cyber roles within the last three years. These same employers report one-third of their vacancies as being hard to fill[19] despite approximately 7,500 new cyber professionals entering the UK workforce each year and 4,000 UK university graduates entering cyber roles. Even with around 11,500 people joining the profession each year across recent graduates, career changers and other sources, there are only about 1,000 coming in via the apprenticeship route. [20] This relatively low number highlights the need and opportunity to grow this pathway.
- To ensure more people are attracted and recruited into the industry, (ISC)2 strongly encourages the effective use of apprenticeships. It is crucial to build awareness of the cybersecurity field by providing increased access to cyber education, providing subsidized training options to individuals looking to change careers, making apprenticeships more easily accessible to employers, increasing the number of apprenticeships and increasing funding to those apprenticeships.
- Currently in the UK, only 14% of cyber-sector firms have staff with cyber apprenticeship training. [21] Increasing the number of apprenticeships and easing the burden for employers will create a more reliable pathway into cybersecurity. This is one way government can have a near-term impact increasing the number of people gaining the experience necessary to help mitigate the UK cyber skills gap.
- Additionally, government incentives and programmes designed to increase awareness of the cybersecurity industry in academia beyond computer sciences studies are also crucial to bridging the skills gap and improving diversity in the field.
- Women are under-represented at all levels of cyber. Only 18% of cyber professionals identify as female in the UK, while 77% identify as male. Ethnic minority candidates are less successful in getting roles at leadership levels in the industry. 79% of the UK cyber workforce is White/Caucasian/European, while only 7% are South Asian, 4% are Black or African descent, 2% East or South-East Asian and 1% are Hispanic or Latino.[22]
- There is a general perception that the bar for new cyber candidates is set at such a high level of educational background and professional certification attainment that it often rewards only the candidate profiles of those already in the field. This discourages new and diverse talent. Often, younger, entry-level practitioners, who can perform a variety of technical tasks that don’t necessarily require professional certification, are overlooked in favor of individuals who hold certifications. This is a missed opportunity as these individuals frequently possess skills applicable for areas such as risk management, analytics or communications that can be just as important to a security team.[23] Additionally, certifications can be achieved over time allowing flexibility for the practitioners seeking them.
- In the 2022 Cyber Skills in the UK Labour Market study, a survey of 205 cyber sector businesses found only 14% of staff qualified through a cyber or other apprenticeship role, while 30% had a background or a general computer science or IT degree that led them to a career in cyber and 33% held a specialist degree in cybersecurity. 46% of cyber professionals held some other form of technical credential.[24]
- Providing better exposure to the opportunities offered by cyber careers at the entry- and junior – level and in a wide variety of disciplines will help bolster long-term, sustained interest in the sector from areas such as business, marketing and finance and would also help to increase DEI in the industry as it provides greater exposure to more demographics.
- (ISC)2 asked UK cyber professionals which areas they would want to further develop or improve on over the next two years. They cited the following as the top areas for development:[25]
- Cloud Security – 37%
- Artificial Intelligence and Machine Learning – 27%
- Risk Management – 23%
- DevSecOps – 23%
- Threat Intelligence Analysis – 23%
- Governance, Risk and Compliance – 22%
- Cyber professionals are eager to build on their knowledge and expertise. This can be accomplished through investing in education programmes as well as incentives for cyber professionals to seek additional certifications. As indicated in the Government Cybersecurity Strategy 2022-2030, achieving sustainable change can be accomplished by shifting the cyber culture to one that encourages and empowers people to learn and continuously improve.[26]
- Data suggests that cyber may not be as affected by an ageing workforce as other professions. The (ISC)2 Cybersecurity Workforce Study showed only 15% of the profession is over age of 55. 29% is between 45-54; 34% between 34-44; and 19% under the age of 34. More than half of the workforce is below the age of 45.[27] This creates a unique opportunity for cybersecurity in that older workers may represent yet another opportunity to bridge the skills gap.
- There is a clear need to bring more younger professionals into the industry to address the skills gap and ensure an efficient transfer of skills and knowledge to the next workforce generation. Nonetheless, we must not discount the immense value that older people bring to the workforce, while also being aware of the difficulties they face in securing employment.
- From December 2020 to February 2021, older workers were more likely to be long-term unemployed (for 12 months or more) than younger age groups. Of the 4.7 million furloughed employees in February 2021, 1.3 million (27.9%) were workers aged 50 years and over. [28] This provides a unique opportunity to re-skill an educated and eager population.
- One in five older employees believe they are seen as less capable due to their age. Nearly half said that their age disadvantage them in applying for a job. The key to attracting diversity is to openly recruit for it and encourage a wide variety of players to enter the ring. [29] By providing every employee, regardless of their age, with the tools they need to succeed, it benefits the employer, the employee, and the cyber sector.[30]
- Older workers should be viewed as an opportunity not as a concern. We need to embrace everyone and the strengths they bring to the table. It takes a variety of skills, interests, experiences and talents to work and thrive in cybersecurity. Striving to bridge the skills gap and diversify the workforce includes incorporating all age groups. Cyber threats come from diverse backgrounds and demographics. To effectively contend with diverse threats, it is crucial to employ a diverse workforce.
[1] National Cyber Security Centre. (2018). Certified Cyber Professional (CCP) Assured Service. Available at: https://www.ncsc.gov.uk/information/certified-cyber-professional-assured-service. (Accessed: 22, February 2022).
[2]https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/864752/Government_Security_Profession_career_framework.pdf. (Accessed: 22, February 2022).
[3] (ISC)2 Cybersecurity Workforce Study 2021, A resilient Cybersecurity Profession Charts the Path Forward. (ISC)2. 2021. https://www.isc2.org//-/media/ISC2/Research/2021/ISC2-Cybersecurity-Workforce-Study-2021.ashx p.26.
[4] (ISC)2 Cybersecurity Workforce Study 2021, A resilient Cybersecurity Profession Charts the Path Forward. (ISC)2. 2021 p.26. https://www.isc2.org//-/media/ISC2/Research/2021/ISC2-Cybersecurity-Workforce-Study-2021.ashx p.5.
[5] (ISC)2 Cybersecurity Workforce Study 2021, A resilient Cybersecurity Profession Charts the Path Forward. (ISC)2. 2021. https://www.isc2.org//-/media/ISC2/Research/2021/ISC2-Cybersecurity-Workforce-Study-2021.ashx *
[6] Cybersecurity Skills in the UK Labour Market 2022. Department for Digital, Culture Media and Sport. 2022. https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/1072767/Cyber_security_skills_in_the_UK_labour_market_2022_-_findings_report.pdf p. 20.
[7] Cybersecurity Skills in the UK Labour Market 2022 Findings Report - IPSOS. Department for Digital Culture Media and Sport, 2022https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/1072767/Cyber_security_skills_in_the_UK_labour_market_2022_-_findings_report.pdf p. 24
[8] Cyber Security Skills in the UK Labour Market 2020. Gov. UK. 2020. https://www.gov.uk/government/publications/cyber-security-skills-in-the-uk-labour-market-2020/cyber-security-skills-in-the-uk-labour-market-2020
[9] (ISC)2 Cybersecurity Workforce Study 2021, A resilient Cybersecurity Profession Charts the Path Forward. (ISC)2. 2021 p.26. https://www.isc2.org//-/media/ISC2/Research/2021/ISC2-Cybersecurity-Workforce-Study-2021.ashx
[10] Cyber Security Skills in the UK Labour Market 2022 Findings Report - IPSOS. Department for Digital Culture Media and Sport, 2022https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/1072767/Cyber_security_skills_in_the_UK_labour_market_2022_-_findings_report.pdf p. 92.
[11] Cyber security skills in the UK labour market 2022 - Ipsos|: findings report 2 21-016089-01: Department for Digital, Culture, Media and Sport 2022 https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/1072767/Cyber_security_skills_in_the_UK_labour_market_2022_-_findings_report.pdf p.5.
[12] Government Cyber Security Strategy. Building a Cyber Resilient Public Sector. HM Government. 2022. https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/1049825/government-cyber-security-strategy.pdf -.59
[13] (ISC)2 Cybersecurity Workforce Study 2021, A resilient Cybersecurity Profession Charts the Path Forward. (ISC)2. 2021 p.26. https://www.isc2.org//-/media/ISC2/Research/2021/ISC2-Cybersecurity-Workforce-Study-2021.ashx p.5.
[14] (ISC)2 Entry-Level Certification. 2022. https://www.isc2.org/Certifications/entry-level-certification-pilot
[15] (ISC)2 Cybersecurity Hiring Managers Guide. Best Practices for Hiring and Developing Entry-Level and Junior-level Cybersecurity Practitioners. 2022. https://www.isc2.org//-/media/ISC2/Research/2022/ISC2-Cybersecurity-Hiring-Managers-Guide.ashx *
[16] (ISC)2 100K in the UK. https://www.isc2.org/News-and-Events/Press-Room/Posts/2022/05/17/ISC2-Unveils-100K-in-the-UK-Scheme-to-Expand-the-UK-Cybersecurity-Workforce
[17] (ISC)2 Cybersecurity Hiring Managers Guide. Best Practices for Hiring and Developing Entry-Level and Junior-level Cybersecurity Practitioners. 2022. https://www.isc2.org//-/media/ISC2/Research/2022/ISC2-Cybersecurity-Hiring-Managers-Guide.ashx p.2
[18] (ISC)2 Cybersecurity Hiring Managers Guide. Best Practices for Hiring and Developing Entry and Junior-Level Cybersecurity Practitioners. 2022. https://www.isc2.org//-/media/ISC2/Research/2022/ISC2-Cybersecurity-Hiring-Managers-Guide.ashx *
[19]
Cyber Security Skills in the UK Labour Market 2020. Gov.UK. Department for Digital, Culture, Media and Sport. 2020. https://www.gov.uk/government/publications/cyber-security-skills-in-the-uk-labour-market-2020/cyber-security-skills-in-the-uk-labour-market-2020.
Summary.
[20] Understanding the Cyber Security Recruitment Pool. Research Report for the Department for Digital, Culture, Media and Sport. 2021. https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/973914/Ipsos_MORI_Cyber_Recruitment_Report_v1.pdf p.4
[21] (ISC)2 Cybersecurity Hiring Managers Guide. Best Practices for Hiring and Developing Entry-and Junior Level Cybersecurity Practitioners. 2022. https://www.isc2.org//-/media/ISC2/Research/2022/ISC2-Cybersecurity-Hiring-Managers-Guide.ashx *
[22] (ISC)2 Cybersecurity Workforce Study 2021, A resilient Cybersecurity Profession Charts the Path Forward. (ISC)2. 2021 p.26. https://www.isc2.org//-/media/ISC2/Research/2021/ISC2-Cybersecurity-Workforce-Study-2021.ashx *
[23] In Their Own Words. Women and People of Color Detail Experiences Working in Cybersecurity. (ISC)2. 2021. https://www.isc2.org/-/media/ISC2/DEI/DEI-Market-Research-2021.ashx?la=en&hash=705FD79E771BE65AEA205B153AA3A51AF7D5EBB0 p.6.
[24] Cybersecurity Skills in the UK Labour Market 2022. Department for Digital, Culture Media and Sport. 2022. P. 21 https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/1072767/Cyber_security_skills_in_the_UK_labour_market_2022_-_findings_report.pdf
[25] (ISC)2 Cybersecurity Workforce Study 2021, A resilient Cybersecurity Profession Charts the Path Forward. (ISC)2. 2021 p.26. https://www.isc2.org//-/media/ISC2/Research/2021/ISC2-Cybersecurity-Workforce-Study-2021.ashx *
[26] Government Cybersecurity Strategy. Building a Cyber Resilient Public Sector. HM Government. 2022. https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/1049825/government-cyber-security-strategy.pdf p. 60.
[27] (ISC)2 Cybersecurity Workforce Study 2021, A resilient Cybersecurity Profession Charts the Path Forward. (ISC)2. 2021 p.26. https://www.isc2.org//-/media/ISC2/Research/2021/ISC2-Cybersecurity-Workforce-Study-2021.ashx *
[28] Living Longer: Older Workers During the Coronavirus (COVID-19) Pandemic. Office for National Statistics. 2021. https://www.ons.gov.uk/peoplepopulationandcommunity/birthsdeathsandmarriages/ageing/articles/livinglongerimpactofworkingfromhomeonolderworkers/2021-08-25
[29] New Report by U.K. NCSC Highlights the Impact of Diversity on the Cybersecurity Workforce. (ISC)2 Blog. 2022. https://blog.isc2.org/isc2_blog/2022/02/impact-of-diversity-on-the-cybersecurity-workforce.html
[30] Becoming An Age Friendly Employer. Centre for Ageing Better. 2018. https://ageing-better.org.uk/sites/default/files/2018-09/Becoming-age-friendly-employer.pdf
- Footnotes indicated with an * have information not readily available in the published version of the document. This specific data is available upon request.