The cybersecurity landscape is a challenging and ever-evolving domain, and a recent report highlights the struggles faced by professionals in this field. Over two-thirds of security experts surveyed revealed that the job has become increasingly difficult, with 68% noting a deterioration over the past two years. This sentiment underscores the growing complexity and demands of cybersecurity roles. The study, titled 'The Life and Times of Cybersecurity Professionals, Volume VIII', was conducted by the ISSA and Omdia, and it sheds light on the myriad challenges faced by these professionals.
One of the primary concerns is the involvement of other departments in cybersecurity decisions. A staggering 79% of respondents mentioned that IT operations and platform engineering are increasingly involved in their domain, often without their input. This not only creates a barrier to security adoption but also highlights the need for better collaboration and communication between these departments. The report further emphasizes the importance of leadership support, with 39% of respondents citing a strong cyber commitment from leadership as a key factor in nurturing job satisfaction.
Work-related stress is another significant issue. A concerning 47% of professionals have considered leaving their roles or the profession due to stress over the past 18 months. The most stressful aspects of the job include an overwhelming workload (24%), keeping up with new security requirements (23%), the fear of making mistakes (22%), constant emergencies and interruptions (20%), and discovering IT initiatives without security oversight (20%). These findings underscore the need for organizations to address the mental health and well-being of their cybersecurity teams.
The report also highlights the need for improvement in cybersecurity programs. Only 29% of respondents rated their organization's cybersecurity culture as advanced, indicating significant room for growth. The top areas for improvement, according to the survey, include increased training for IT and security professionals (42%), investments in the right resources (37%), and enhancements to governance, risk, and compliance (GRC) and cyber hygiene (35%).
Collaboration between IT and security functions is another critical aspect. The study suggests that embedding security staff into functional technology groups (44%) and automating processes requiring collaboration between IT and security (41%) could significantly enhance teamwork. However, the current state of affairs is far from ideal, with 72% of respondents noting that tech decisions are made without the input of cybersecurity professionals, further exacerbating the challenges they face.
In conclusion, the cybersecurity field is fraught with challenges, from the increasing involvement of other departments to the overwhelming workload and stress. The report emphasizes the need for organizations to invest in their cybersecurity professionals, provide adequate training and resources, and foster a collaborative environment. By addressing these issues, the industry can work towards creating a more sustainable and effective cybersecurity workforce, ensuring the protection of digital assets and critical infrastructure.