Security staff shortages, new tech raising risk of breaches

A shortage of information security professionals is having an adverse impact on healthcare and other industries, even as growth in mobile devices and social media are increasing vulnerabilities.

The sixth Global Information Security Workforce Study, conducted by (ISC)² in partnership with Booz Allen Hamilton and Frost & Sullivan, examined security practices across many industries. More than two-thirds of chief information security officers say they're short-staffed, leading to an increased threat of expensive breaches.

"Now, more than ever before, we’re seeing an economic ripple effect occurring across the globe as a result of the dire shortage of qualified information security professionals we’ve been experiencing in recent years," said W. Hord Tipton, executive director of (ISC)² in a statement.

"More and more enterprises are being breached. We must focus on building a skilled and qualified security workforce that is equipped to handle today’s and tomorrow’s most sophisticated cyber threats."

The study indicated big shortages of software development professionals trained in security, and finds that application security vulnerabilities still rank highest among security concerns, across all industries.

Threats from malware and mobile devices are at the top of the list; cloud security, bring your own device and social networking are all also reported as major concerns in terms of newer security threats on the horizon.


The study's other findings included the following:

  • Information security professionals are enjoying stable employment. More than 80 percent of respondents reported no change in employer or employment in the last year, and 58 percent reported receiving a raise in the last year.
  • New skills, deepening knowledge and a wider range of technologies are needed, however, according to (ISC)². Addressing the risks in BYOD and cloud computing, requires a new security approach. More than three-quarters (78 percent) of respondents said BYOD technology is a significant security risk, and 74 percent reported that new security skills are required to meet the BYOD challenge. More than two-thirds (68 percent) reported social media is a security concern, with content filtering being the chief security measure used.
  • Application vulnerabilities rank the highest among security concerns, yet most organizations are not prioritizing secure software development, according to the report. Nearly half of security organizations are not involved in software development, and security is not among the most important factors when considering an outsourcing provider for software development, yet 69 percent reported application vulnerabilities as their top concern.
  • Security priorities vary depending on the industry. While most banking, insurance and finance companies feared damage to their organizations’ reputations, in healthcare most respondents said patient privacy violations were their top concern.
  • Security incident preparedness is showing signs of strain, with just 28 percent of respondents reporting that their organizations can remediate from a targeted attack within a day. More than 40 percent said addressing damage could take up to a week.

"Security is an organization-wide responsibility, with information security professionals serving as the beacon of knowledge and security stewardship," said Frost & Sullivan researcher Michael Suby, author of the report.

Around the web

The American College of Cardiology has shared its perspective on new CMS payment policies, highlighting revenue concerns while providing key details for cardiologists and other cardiology professionals. 

As debate simmers over how best to regulate AI, experts continue to offer guidance on where to start, how to proceed and what to emphasize. A new resource models its recommendations on what its authors call the “SETO Loop.”

FDA Commissioner Robert Califf, MD, said the clinical community needs to combat health misinformation at a grassroots level. He warned that patients are immersed in a "sea of misinformation without a compass."

Trimed Popup
Trimed Popup