{"id":636,"date":"2017-10-25T13:30:44","date_gmt":"2017-10-25T13:30:44","guid":{"rendered":"https:\/\/securitycurve.com\/?p=636"},"modified":"2017-10-25T13:30:44","modified_gmt":"2017-10-25T13:30:44","slug":"skills-gap-redux","status":"publish","type":"post","link":"https:\/\/securitycurve.com\/?p=636","title":{"rendered":"Skills Gap Redux"},"content":{"rendered":"<p><a href=\"https:\/\/securitycurve.com\/wp-content\/uploads\/2017\/05\/6b4c8b6f5849da03ffe4122ddf4468e6.jpg\"><img decoding=\"async\" class=\"alignright wp-image-154 size-full lazyload\" data-src=\"https:\/\/securitycurve.com\/wp-content\/uploads\/2017\/05\/6b4c8b6f5849da03ffe4122ddf4468e6.jpg\" alt=\"\" width=\"371\" height=\"375\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 371px; --smush-placeholder-aspect-ratio: 371\/375;\" \/><\/a>Today is a slow news day.\u00a0 Yes, I know about <a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/10\/badrabbit-ransomware-strikes-eastern-europe\/\">BadRabbit<\/a>&#8230;\u00a0 I make this statement anyway because it seems to me like BadRabbit is boring.\u00a0 I&#8217;m sure it&#8217;s not boring to you if you&#8217;re impacted by it, but for the unimpacted news reader, it&#8217;s neither\u00a0<a href=\"https:\/\/blog.malwarebytes.com\/threat-analysis\/2017\/10\/badrabbit-closer-look-new-version-petyanotpetya\/\">technically interesting<\/a>\u00a0nor necessarily noteworthy from a tradecraft perspective.\u00a0 It uses human intervention to elevate privileges and lays down some dropper malware to encrypt files for Bitcoin.\u00a0 The primary implication I guess is that the <a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/hh278941.aspx\">first immutable law of security still applies.<\/a>\u00a0 Murf.\u00a0 In fact,\u00a0the primary reason I&#8217;d be interested in BadRabbit is attribution&#8230; which, other than analysis suggesting it&#8217;s probably the same people as NotPetya, is still up in the air.\u00a0 So maybe it&#8217;ll become more interesting if we learn more about it down the road, but right now I give it a &#8220;meh&#8221;.\u00a0 Potentially a &#8220;meh plus&#8221; because of the attribution angle, but it&#8217;s on the cusp.<\/p>\n<p>Anyway, because I&#8217;m not super interested in that, I&#8217;ll continue an exploration <a href=\"https:\/\/securitycurve.com\/skills-gap-or-pyramid-scheme\/\">I started a while back<\/a> about the security &#8220;skills gap.&#8221;\u00a0 Why?\u00a0 Because <a href=\"https:\/\/www.comptia.org\/resources\/evaluating-it-workforce-needs\">I came across the research from CompTIA that has implications for this<\/a>.<\/p>\n<p>But first, a few full disclosure statements and caveats: 1) be advised that my &#8220;day job&#8221; is with ISACA, an organization that (depending on your point of view) is a direct competitor to CompTIA.\u00a0 I&#8217;d argue it really isn&#8217;t, but not everyone sees it the same way I do.\u00a0 2) I have, in the past, highlighted data about &#8211; and posited analysis that supports &#8211; a security skills gap.\u00a0 I&#8217;ve written reports, for example, that conclude that it exists and that it&#8217;s an important thing to pay attention to.\u00a0 That either supports or detracts from my credibility on this matter depending on your point of view.<\/p>\n<p>That out of the way, about the CompTIA study.\u00a0 The thing I found most interesting is this (from <a href=\"http:\/\/www.hrdive.com\/news\/good-news-on-the-skills-gap-it-pros-are-interested-in-cyber-security\/507996\/\">HRDive coverage of the press release<\/a>):\u00a0<em>&#8220;The report also found that some professionals worry their skills will soon be obsolete; many, however, said they were interested in careers in cybersecurity (51%) and cutting-edge areas such as the Internet of Things (30%) and artificial intelligence or machine learning (20%).&#8221;<\/em>\u00a0 Note that I did my level best to find this data point in the <a href=\"https:\/\/www.comptia.org\/resources\/evaluating-it-workforce-needs\">materials released by CompTIA<\/a>, but I can&#8217;t find it in there &#8212; my suspicion is that this data point made it to the press release but didn&#8217;t make it into the report summary up on the site.\u00a0 Since I can&#8217;t find the full report or the data (the &#8220;Access&#8221; button points to an executive summary &#8211; at least as of now), I&#8217;m running with this one.<\/p>\n<p>The reason this is interesting to me is that it demonstrates that cybersecurity is increasing in interest for those in the job market.\u00a0 So this is an interesting data point to me for a few reasons.\u00a0 First, it&#8217;s maybe unsurprising as there has been quite a bit of attention out there on why cybersecurity is a &#8220;hot&#8221; area, how there&#8217;s a skills gap (the implication being that it&#8217;s super easymode to find a job and that there&#8217;s tons of mobility and job security), etc.\u00a0 It also suggests to me that the narrative of the skills gap is gaining traction into broader IT.\u00a0 Though I don&#8217;t have direct evidence to support it, I also think it is having a broader impact on the job market more generally.\u00a0 It&#8217;s comparatively more appealing to these folks compared to other &#8220;hot&#8221; areas.<\/p>\n<p>Here&#8217;s why I think caution is warranted though. Namely, there are organizations for which there is a direct line between the &#8220;security skills gap&#8221; narrative and their particular agenda (financial or otherwise).\u00a0 Consulting companies, for example.\u00a0 The more difficult it is (or seems to be) to find good security talent, the more appealing their services appear to be.\u00a0 Also, certification bodies and educational institutions.\u00a0 Those who offer &#8220;differentiation vehicles&#8221; (like certifications or degrees) for professionals in the space.\u00a0 Their goals are also directly forwarded by the narrative.\u00a0 \u00a0Technology companies and those who automate security tasks likewise.\u00a0 What I&#8217;m saying I guess is that there is a communal bias and interest in believing the narrative.\u00a0 \u00a0I am\u00a0<strong>NOT\u00a0<\/strong>saying that anyone is doing this purposefully.\u00a0 But as an exercise to the reader, I would ask you to pay attention to the source of information about the skills gap when you hear it: who is the report coming from and whether they are directly or indirectly served in some way by highlighting it.<\/p>\n<p>Do I personally believe a skills gap exists?\u00a0 I do.\u00a0 But am I biased?\u00a0 Unquestionably.<\/p>\n<p>I also happen to think that the implications of it are, long term, potentially problematic for practitioners in the space.\u00a0An influx of personnel into the job market absolutely will have a downward pressure on salaries over the long term and have a long term impact on professional mobility.\u00a0 That&#8217;s the downside.\u00a0 The upside is that, the less competitive the space becomes the more opportunity there is for safeguards against malpractice.\u00a0 I&#8217;ve advocated for professional licensing of security practitioners before.<\/p>\n<p>So, like, if a security pro sucks at their job &#8211; and engage in either deliberate or accidental (but grievous) malpractice &#8211; we can limit the further damage they can do to others by revoking their ability to practice.\u00a0 As it stands now, those in the profession who aren&#8217;t great can continue to be that way until they retire.\u00a0 As long as they can sell how awesome they are to people who don&#8217;t know anything about it&#8230; and having held an equivalent position at organizations that are heavily disincentivized from sharing their negative experiences with that candidate.<\/p>\n<p>I&#8217;ll continue to come back to this topic&#8230;\u00a0 Of all the things that are going on security, I think the long-term economic impacts on the job market are potentially the most significant for individual practitioners.\u00a0 When BadRabbit goes away five minutes from now, there will be something else to take its place.\u00a0 The impacts on the job market from the skills gap though?\u00a0 Both the narrative and the actual underlying phenomenon will still be playing out 5 years from now &#8212; and still be impacting practitioner&#8217;s lives.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Today is a slow news day.\u00a0 Yes, I know about BadRabbit&#8230;\u00a0 I make this statement anyway because it seems to me like BadRabbit is boring.\u00a0 I&#8217;m sure it&#8217;s not boring to you if you&#8217;re impacted by it, but for the unimpacted news reader, it&#8217;s neither\u00a0technically interesting\u00a0nor necessarily noteworthy from a tradecraft perspective.\u00a0 It uses human [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[4],"tags":[110],"class_list":["post-636","post","type-post","status-publish","format-standard","hentry","category-security","tag-skills-gap"],"_links":{"self":[{"href":"https:\/\/securitycurve.com\/index.php?rest_route=\/wp\/v2\/posts\/636","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/securitycurve.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/securitycurve.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/securitycurve.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/securitycurve.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=636"}],"version-history":[{"count":1,"href":"https:\/\/securitycurve.com\/index.php?rest_route=\/wp\/v2\/posts\/636\/revisions"}],"predecessor-version":[{"id":1916,"href":"https:\/\/securitycurve.com\/index.php?rest_route=\/wp\/v2\/posts\/636\/revisions\/1916"}],"wp:attachment":[{"href":"https:\/\/securitycurve.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=636"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/securitycurve.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=636"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/securitycurve.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=636"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}