BS Cyber Mid-year v3 - Flipbook - Page 5
BARCLAYSIMPSON.COM
5
Key themes in cyber
security recruitment
Top CISO challenges
1
Budgets don’t match expectations
(55% of CISOs)
2
Change management
(37%)
3
Relentless regulations
(33%)
4
Supply chain security
(25%)
CYBER SECURITY & DATA PRIVACY | RECRUITMENT MARKET UPDATE 2024
Source: BSS ‘How CISOs can succeed in a challenging landscape’
High demand for operational resilience
The Digital Operational Resilience Act (DORA) will
come into effect on 16 January 2025.
Many organisations still do not have the right
skills and expertise in place to navigate this new
legislation, so hiring demand within the space has far
outpaced any other area of cyber security and data
privacy recruitment this year.
Employers are finding it challenging to fill these
vacancies. As all companies face the same deadline,
there is widespread demand for candidates with
experience of DORA, but as it is a new regulation,
this skill set is hard to find. Clients have to fight
over the few candidates with experience, and the
problem is exacerbated by candidates working on
DORA projects being reluctant to change jobs in the
middle of a project. Companies are having to look at
operational resilience candidates instead and decide
if they have enough time to train them on DORA
before the deadline.
FTCs on the rise
While the interim market often does well during
periods when the permanent market stutters, this is
not the case at the moment. Demand for contractors
has substantially decreased, and we are instead
seeing an increase in fixed–term contracts (FTCs).
CISO burnout
Our consultants are reporting that the mental health
of cyber security professionals is at an all–time
low, as they battle with under–resourced teams,
elevated expectations and an increasingly complex
threat landscape.
These are generally unpopular with candidates,
who are usually receiving the worst of both worlds.
FTCs do not offer long–term job security, nor do
they pay the premium that typically comes with the
additional risk of contracting.
CISOs are particularly under pressure, given that the
responsibility for security failures typically falls on
their shoulders. Recent research shows that 80% of
CISOs classify themselves as ‘highly stressed’, with
30% saying this has compromised their ability to do
their job. A separate study found that 61% of CISOs
are concerned about personal liability for cyberattacks and breaches at their organisation.
As a result, many interim workers are transitioning
into lower–paying permanent roles as organisations
become reluctant to meet day rates. We expect this
trend to continue while investment in development
and change projects remains suppressed.
Some businesses are outsourcing their SOC
activities at the weekend to relieve stress on their
in–house teams. Sadly, however, many other
CISOs aren’t getting the support they need from
their boards, with 49% claiming there is a lack
of buy–in from C–level executives regarding
information security.