{"id":560,"date":"2017-08-24T15:48:47","date_gmt":"2017-08-24T15:48:47","guid":{"rendered":"http:\/\/securitycurve.com\/?p=560"},"modified":"2017-08-24T15:48:47","modified_gmt":"2017-08-24T15:48:47","slug":"skills-gap-or-pyramid-scheme","status":"publish","type":"post","link":"https:\/\/securitycurve.com\/?p=560","title":{"rendered":"Skills gap?  Or pyramid scheme?"},"content":{"rendered":"<p><img decoding=\"async\" class=\"alignright size-medium lazyload\" data-src=\"http:\/\/3.bp.blogspot.com\/-HDu_jG_grKk\/Ua4dt4vKQsI\/AAAAAAAALJI\/EBOthNIeCFQ\/s640\/1348342187652_5957990.png\" width=\"420\" height=\"294\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 420px; --smush-placeholder-aspect-ratio: 420\/294;\" \/>So you&#8217;ve probably heard that security (cybersecurity if you must) has a skills gap, right? \u00a0Today&#8217;s headlines, for example, have no fewer than three separate articles about it (the best of which is <a href=\"https:\/\/www.theregister.co.uk\/2017\/08\/24\/chronic_shortage_qualified_cybersecurity_bods\/\">this one<\/a> over at The Register).<\/p>\n<p>I&#8217;ve heard this too. In fact, I&#8217;ve been one of the folks actively reporting on it: both in the trade media and also at my (ahem) &#8220;day job.&#8221; \u00a0I&#8217;ve done studies about it, wrote reports and articles about it, blogged and spoken about it, and otherwise been discussing it ad nauseum. \u00a0 But I&#8217;ve started to question the premise a little bit &#8211; or maybe not the premise but the implications? \u00a0I&#8217;m questioning something.<\/p>\n<p>Now, I get it that what I&#8217;m about to say is not &#8220;the traditional wisdom.&#8221; \u00a0So I&#8217;m sure people will come out of the woodwork to fight me on it. \u00a0But let me walk you through my musings and you can draw your own conclusions. \u00a0First, from the get-go, let me be clear that I&#8217;m not disputing that the data says what it says. \u00a0There is absolute a challenge filling positions &#8211; we know that from the data. \u00a0There are also open positions out there: they are increasing, there are more of them, and organizations aren&#8217;t getting what they need skill-wise. \u00a0Truth &#8211; I know because data.<\/p>\n<p>I think that the conclusions that folks draw from these points are a little skewed though. \u00a0Here&#8217;s what I mean. \u00a0When looking at the data points above, most people tend to picture in their minds something like this:<\/p>\n<p><a href=\"https:\/\/securitycurve.com\/wp-content\/uploads\/2017\/08\/job_growth.jpg\"><img decoding=\"async\" class=\"alignnone wp-image-562 size-large lazyload\" data-src=\"https:\/\/securitycurve.com\/wp-content\/uploads\/2017\/08\/job_growth-1024x352.jpg\" alt=\"\" width=\"1024\" height=\"352\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/352;\" \/><\/a><\/p>\n<p>The size of the circle represents, as you might imagine, the number of open positions. \u00a0People tend to assume a universal distribution of jobs across all experience levels. \u00a0For simplicity&#8217;s sake, let say the market is broken down into two groups of jobs: &#8220;experienced people jobs&#8221; and &#8220;entry level&#8221; jobs. \u00a0The natural assumption leads people to think that the &#8220;skills gap&#8221; and &#8220;resource shortage&#8221; mean that both the demand for experienced people and the demand for entry level would increase near equivalently.<\/p>\n<p>This is the part that I&#8217;m starting to think isn&#8217;t true. \u00a0 Instead, I think what we&#8217;re seeing is something like this:<\/p>\n<p><a href=\"https:\/\/securitycurve.com\/wp-content\/uploads\/2017\/08\/triangles.jpg\"><img decoding=\"async\" class=\"alignnone wp-image-563 size-large lazyload\" data-src=\"https:\/\/securitycurve.com\/wp-content\/uploads\/2017\/08\/triangles-1024x241.jpg\" alt=\"\" width=\"1024\" height=\"241\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/241;\" \/><\/a><\/p>\n<p>In this, the overall size of the position &#8220;inventory&#8221; is increasing, but it is not happening homogeneously across all areas. \u00a0Instead, it&#8217;s happening at a certain place: the bottom of the triangle. \u00a0Say the market is striated in such a way that you have bands like:<\/p>\n<ul>\n<li>Industry leaders &#8211; people who lead the industry beyond their particular organization<\/li>\n<li>Organizational leaders &#8211; people who lead a particular organization<\/li>\n<li>Managers &#8211; people who manage other people<\/li>\n<li>Experienced contributors &#8211; experienced, high-value individual contributors<\/li>\n<li>Technical staff &#8211; somewhat experienced individual contributors<\/li>\n<li>Entry level &#8211; folks just starting out<\/li>\n<\/ul>\n<p>I get it that there are probably huge nuances that I&#8217;m not accounting for in that, but you get my drift. \u00a0Anyway, expanding the above to reflect the various strata, you get something like this:<\/p>\n<p><a href=\"https:\/\/securitycurve.com\/wp-content\/uploads\/2017\/08\/newtri.jpg\"><img decoding=\"async\" class=\"alignnone size-large wp-image-564 lazyload\" data-src=\"https:\/\/securitycurve.com\/wp-content\/uploads\/2017\/08\/newtri-1024x459.jpg\" alt=\"\" width=\"1024\" height=\"459\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/459;\" \/><\/a><\/p>\n<p>The growth at the bottom of the pyramid is huge (for entry level people), while the growth at the top is there, but percentage-wise is fairly static relative to the growth at the bottom. \u00a0This is akin to what I think is happening in the security job market: huge demand at the lowest part of the pyramid, relatively little change at the top.<\/p>\n<p>The analogy I&#8217;d use is Starbucks. \u00a0Let&#8217;s be real, I have no clue what it takes to staff a Starbucks, but I can probably make some guesses to make the point. \u00a0Say Starbucks opens 100 new shops in the time it takes you to read this sentence. \u00a0How many new baristas do they need now compared to right before you read it? \u00a0Based on the highly unscientific observation that there seem to be about 6-7 baristas at any given time at my local buckies, let&#8217;s assume (given shift requirements) that they need like 20 baristas per shop. \u00a0So, to staff 100 new shops, they need 2000 new people behind the counter. \u00a0Now how many new managers do they need? \u00a0If there are 2 managers per shop (who knows), they need like 200 &#8211; one tenth of the new baristas. \u00a0How many new regional executives or folks at HQ? \u00a01 or 2 maybe (a tenth again)? \u00a0How many additional CEO&#8217;s? \u00a0None.<\/p>\n<p>See? Pyramid.<\/p>\n<p>If that&#8217;s true, what are the implications for the security market? \u00a0For one, good luck to you long term if you&#8217;re anywhere other than entry level. \u00a0I say this including myself in that group. \u00a0Why? \u00a0Because droves of people are coming into the profession. \u00a0The hype is real, and people are responding as you&#8217;d expect them to (i.e. following the money). \u00a0There&#8217;s room for them in the short term of course (because pyramid), but there will be increasing competition as they grow and move up the ladder. \u00a0 Competition will increase at each tier they move through along the way. \u00a0Likewise, the bottom of the pyramid has a shelf life. \u00a0Why? \u00a0Because automation. \u00a0It&#8217;s only a matter of time before we can automate things like log review, SOC operations, intelligence analysis, etc. etc. \u00a0That will increase competitive pressure upwards as well as folks move to reposition as the lower tiers contract. \u00a0With competition comes downward pressure on salaries. \u00a0So, near term boom, but long term demand will be down as will salaries.<\/p>\n<p>All this is, of course, rampant speculation on my part. \u00a0I&#8217;m not basing this on data, but rather on feedback from folks that I know in the field and &#8220;reading between the lines&#8221; of the data. \u00a0But I&#8217;m starting to think that there is some real truth to it. \u00a0More to come on this.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>So you&#8217;ve probably heard that security (cybersecurity if you must) has a skills gap, right? \u00a0Today&#8217;s headlines, for example, have no fewer than three separate articles about it (the best of which is this one over at The Register). I&#8217;ve heard this too. In fact, I&#8217;ve been one of the folks actively reporting on it: [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[4],"tags":[111],"class_list":["post-560","post","type-post","status-publish","format-standard","hentry","category-security","tag-skills-shortage"],"_links":{"self":[{"href":"https:\/\/securitycurve.com\/index.php?rest_route=\/wp\/v2\/posts\/560","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/securitycurve.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/securitycurve.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/securitycurve.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/securitycurve.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=560"}],"version-history":[{"count":0,"href":"https:\/\/securitycurve.com\/index.php?rest_route=\/wp\/v2\/posts\/560\/revisions"}],"wp:attachment":[{"href":"https:\/\/securitycurve.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=560"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/securitycurve.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=560"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/securitycurve.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=560"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}