Sites like Monster and CSO.com are predicting a massive wave of new cyber security jobs. Some industry pundits claim there will be up to 3.5 million unfilled cybersecurity positions by 2021. Despite this euphoria. a recent survey by Computer Economics found that security staffing is declining despite security being a top priority for organizations. The research firm’s annual IT Spending and Staffing Benchmarks study found that after two years of increases, IT security personnel have declined as a percentage of total IT staff.
Cyber Security staff members declined
The Computer Economics report found that IT security staff members declined to 2.9% of the total IT staff in 2018. This is on par with the percentage in 2016, It is down slightly from 2017. Previously, the ratio was stable from 2013-2015 at 2.6%.
A net 75% of organizations that responded to the survey are increasing their spending on security. However, the researchers found that increases in spending do not necessarily lead to headcount growth. Improved technology continues to allow IT staff to be more productive.
Technologies reduce IT security staff count
Major growth areas in IT security include using artificial intelligence (PDF) and machine learning to track anomalies before humans can detect them. Other technologies reducing the IT security staff are Software-defined networking, better awareness around application development to ensure better security from the start. The reduction of in-house infrastructure due to software as a service (SaaS) and the public cloud also contributes to staff numbers holding steady.
However, despite these trends, the need for increased and improved security may eventually lead to increases in security staffing, especially as cloud usage decreases the need for other types of in-house IT support personnel.
In the presser announcing their new report, David Wagner, vice president of research at Computer Economics said, “I’d still expect to see slow and steady increases over the next few years, But it is unlikely we will see major jumps. Beyond the efficiency aspects, it is still difficult to find skilled IT security personnel. We’ve seen it before that when a job requires skills that are difficult to find, technology is quickly built to fill in the gaps.”
In the face of these challenges, IT executives must ensure that their IT organizations have the proper skills to respond to the latest security threats. For instance, IT security experts are realizing that intrusion-prevention measures must be complemented by the ability to quickly detect an intrusion, stop it from spreading, and remediate it. Privacy must also be top of mind, in the wake of the European Union enacting the General Data Protection Regulation.
rb-
Based on these findings, it seems likely that the cybersecurity boom just went bust. For those who still want to try o change careers into cybersecurity, take a look at the Cybersecurity Supply/Demand Heat Map from CyberSeek. This tool could help you make some good decisions about how to crack the hiring game. According to CyberSeek data, there is an over 500% over-supply of CompTIA Security+ credential holders in metro Detroit. As one would expect, the CISSP credential has the most demand and has a shortage of holders.
Related articles
Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedIn, Facebook, and Twitter. Email the Bach Seat here.







