Closing the Cybersecurity Skills Gap with Fortinet’s Rob Rashotte
Rob Rashotte, vice president of global training and technical field enablement at Fortinet, explains what needs to be done, beyond relying more on artificial intelligence, to narrow the cybersecurity skills gap.
Transcript
This is Textron tv. Hey guys, thanks to the throw. We're here with Rob Che, who's vice president of cybersecurity training for the Fortinet Cybersecurity Institute.
And we're talking about, well, of course, training because we've had issues with finding people in the cybersecurity as as long as anybody can remember. Rob, welcome to show. It's good to be here, Mike.
Alright. And that kinda sets up our first question, what is it that we should be doing? Because I think people with great minds have been trying to solve this issue for as and what are we missing and what should we be doing, and is this a solvable problem?
Yeah, I think it's, it's certainly a solvable problem. I think part of the challenge, of course is, uh, you know, even as we make progress in, you know, filling the jobs, the open jobs that are out there, of course the threat landscape continues to, to grow. So the need, uh, for filling jobs continues to grow.
So it's, so we're always playing catch up. Um, but, you know, I, I think there always has been a problem of that, that gap in the number of jobs that are out there and being able to fill them. Uh, yeah, I think there's, there's kind of two aspects to it.
There's the, you know, finding people to, to fill the open roles that are out there. And I think, uh, there's a really great opportunity here for us to, uh, you know, try to do that by looking at, uh, you know, untapped pools, uh, you know, leveraging our existing internal efforts around diversity, inclusion, you know, looking at, uh, uh, you know, women in tech, looking at veterans, looking at, uh, youth and so on, and trying to go over the go. You, you know, use those untapped pools to try to fill some of those, uh, roles.
I think we're really missing out on a, on a, a huge pool of, of, of talent by not looking at those pools closer and, and just tending to look at our traditional recruiting methods by going to universities, looking for those four year graduates. I think we're really selling our ourselves short by not broadening our horizon. Uh, but, you know, the other part of it too is not just the roles that are open, but making sure that people in existing roles are keeping up to date.
As we all know, you know, the threat landscape is ever evolving, so we've gotta make sure that those folks that are in the existing roles, that they realize they're, they're in a lifelong, uh, learning journey. Mm-Hmm. And to your point, there is a lot of burnout in this field and a lot of turnover, and is that connected in some way to the fact that we don't seem to have a continuous training program so people over time don't have the, the skills and the tools to cope?
Yeah, there's, I, I think I, you know, there's probably three things there. I think there's, part of it is that, you know, we're not providing enough of continuous learning and people keeping people up to date. So for career growth, people are, by default is going in other directions so that they can, can grow their careers and get that additional ongoing training.
So we do need to provide a lot more of that for people that are in those roles. I, I think a second issue is cyber security is a relatively new field when you compare it to something like, you know, accounting, for example, where roles are very well defined, uh, you know, in cybersecurity job roles are still not that well defined. So I think as the industry matures and we have more well-defined job roles within cybersecurity, we'll see a lot more of that career progression and, and people will tend to stay longer.
You know, a good example is, uh, security operations. I think if you go to 10 different companies and ask, ask them for their job roles for security operations, you're probably gonna see 10 very different job roles. So that's a, a second issue.
Then I think the third one, which is a very serious issue, is stress. Uh, particularly in the higher, more responsible areas within cybersecurity, there's a lot of stress involved because of the impact of a breach. You know, we see the, uh, the, the average tenure of a CISO is, is pretty, pretty low.
Uh, and I think a lot of that is due to the stress of, of the job. Mm-Hmm. Of course we do live in the age of AI now, and roles will probably change even more rapidly than they have in the past.
So, um, is the bar for entry into cybersecurity gonna change in the age of ai? Will it get lower and might that attract more people? What's your thought?
Yeah, I, I think it's an interesting question because, you know, I think getting into the field right now, the bar is pretty high, but it's higher than it needs to be. And again, this is going back to my point that from a recruiting perspective, a lot of companies still seem to be very laser focused on that four year or engineering degree as the baseline to get into this field. And we know as the field has evolved and the number of different roles has evolved, we're looking for a lot, uh, different types of roles within cybersecurity.
So it's, it's not just engineers who we need in the field. So I think, uh, I wouldn't say the bar should be lowered, but I think our view of recruiting needs to be expanded greatly. So there's a lot of other skill sets that are very, very relevant to a lot of cybersecurity roles, uh, you know, uh, threat analysts and, and, and so on and so forth.
It's not just those hard technical, uh, skills that we need, but certainly with ai, I think there's a, a double-edged sword there. ai as we see within, uh, you know, certainly within our own products within Fortinet, we're leveraging machine learning and artificial intelligence to really build some great products. But of course, then the threat actors are leveraging similar technologies to make their, uh, attacks even more sophisticated.
So yeah, I mean, from an AI perspective, the, the creativity and the skill sets within cyber is, is, is gonna broaden for sure. Mm-Hmm. One of the things, to your point about the types of people who are attracted to this work and who might succeed, are there attributes that they have?
I mean, in my mind, a lot of them seem to be good at solving puzzles, and they may be in other fields entirely and might wanna move over to something that might be a little more financially rewarding, but how do you kinda assess somebody for their potential in this field? Yeah, I think, you know, those skills that, that you mentioned, you know, the creativity and the problem solving and so on. The good news is HR recruiters are experts at identifying those sorts of skills and attributes.
So that's, that's good news. I think for the other skills, the more technical skills, uh, you know, obviously there's engineering degrees and so and so forth, but I think industry certifications are extremely valuable, particularly when we're, when we wanna make sure that, uh, people have the, the latest skills, very relevant hands-on skills. I think industry certifications can really help recruiters.
'cause although HR recruiters are great at identifying those soft skills and so on, I think it's the vendors that can provide that benchmark to say yes, uh, whatever vendor it is, you know, they've, they've achieved certification within these product sets, so we're helping the recruiters validate those skills, whether it's us bringing people into Fortinet or for our customers and partners and so on. So those industry certifications, I think are, are critical in that validation. Mm-Hmm.
Some people say we can't win this fight because, well, we keep expanding the attack surfaces and we keep deploying more software in the cloud and at the edge, and we'll never have enough people to kind of fulfill the, the mission as it were. Or, um, is that kind of just the state of the thing? Uh, so no, I, I don't, I don't buy that.
Uh, you know, I, I think, uh, you know, we are in, as I said, an industry that is still relatively new. It might not seem like it cybersecurity's been around for, for quite a while. But again, if you look at other, uh, you know, other professions, uh, that have been around a long, long time, relatively speaking, we're, we're still, uh, pretty new.
What we're really starting to see now, I think is gonna make a huge difference is the collaboration across, uh, uh, public-private partnerships. So we're working, for example, we're working with hundreds of academic institutions around the world. We're working with, uh, world Economic Forum.
They're obviously bringing their influence to bear by, by attracting other, uh, entities and so on, where we're really starting to look at how do we address this problem from a bigger picture perspective? How do we get governments to fund programs? How do we get industry to make sure that they're providing the relevant curriculum to academic institutions and so on?
And I think that's what we really need to see is though that three-way collaboration between government, academia, uh, and industry in those public private partnerships. And I would say over the last two years, uh, I've seen a dramatic increase in the activity from that perspective. And I think we'll see some real payoffs, uh, from that, uh, uh, sooner than later.
But I, I think that's how we win this game is by looking at it from a, a much bigger picture perspective. Do we need to go deeper into the educational ranks? Do we need to start talking to high schoolers about careers in cybersecurity?
Yeah, uh, absolutely. And I think, you know, there was, um, uh, someone who had mentioned on a call that, uh, you know, if we're talking to university graduates who are in engineering programs trying to convince them to get into cybersecurity, we've missed the mark. We need to be having those conversations much earlier on in high school, uh, and even earlier.
And I think there's a good opportunity to do that. 'cause what we're, what we're starting to, to see as well is within the education sector at the very young ages, uh, cybersecurity awareness training, uh, and we, we provide a free service actually to, to high schools and, and elementary schools where we're teaching kids about cyber hygiene and, and, and how to understand what cybersecurity is all about. And I think we can leverage that to peak their curiosity as they get older about, Hey, I wonder about a career in that field.
Uh, so I think that's our, that's our way to start those conversations much earlier on. But I think you're absolutely right. We, we need to go deeper and, and, and start those conversations earlier.
I think one of the challenges organizations face is, um, keeping people engaged once they decide. 'cause some folks will say, yeah, I'll be involved and I'll take some training, but, um, sometimes they get frustrated early and they leave. So how do we kinda, you know, once they're in, keep 'em in.
Yeah, it, it's, again, I think it goes to making sure that we have, uh, career progression is, is number one. I mean, people that come into this field are, are usually, uh, you know, very driven. And if they're not going to have, uh, paths to develop their careers, we're gonna lose them.
So making sure we have those, those career paths, which means we need to also have the, the job roles well defined. And then of course, a, a key component of that is providing the ongoing training, uh, and certification, uh, that these folks are gonna need to grow their careers and to stay relevant as the technology continues, uh, to change. And as the threat landscape continues to evolve.
I think part of the issue is that we kinda, at least in tech, we've gotten used to the idea that there'll be more candidates than there are positions, but cybersecurity being the opposite. Um, I wonder if there's a lot of people out there that, um, one might be interested or have the skills, but they don't know how to engage, they don't know how to reach out, they don't know who to talk to. They can be, uh, minorities, they could be women working at home, they could be veterans, but how do we get to these folks and kinda say, Hey, there's a thing here for you.
Yeah, so there's, there's lots of organizations that I think we can work with. And this was definitely a, you know, a a a lesson that we learned at Fortinet. Uh, if I go back five years ago, if I use our veterans program as an example, you know, we, we were trying to, you know, leverage that, uh, untapped tool.
You know, veterans have a particular skill set as very, very relevant to cybersecurity. But what we were trying to do is we were trying to build a program ourselves and go after those folks directly. And what we found was, um, that really wasn't our, our, uh, forte.
So we, we went out and we started to partner with organizations who represent those veterans. And, you know, we, we looked at that and said, okay, you guys, you guys know how to make the connections, you know how to, uh, do the career development with those folks. What we can bring to the table is training, education, connection with our network of partners who are out there.
So it was really a learning for us that we, we need to, we need to partner, uh, to be able to reach these untapped goals. 'cause they definitely are out there. And again, veterans are only one example.
Uh, there's all sorts of women in tech groups around the world that we started to partner with as well. Uh, you know, we go to an annual conference now of, of women in cybersecurity where there's, there's 3000 women in attendance, uh, and a lot of them are students. And, uh, it's really great to see that.
Uh, and you know, again, those are just examples of these different interest groups, uh, community groups that are out there that we need to leverage rather than trying to go after these, these groups directly. Uh, looking at these organizations that already have those connections, I think is, uh, a much more efficient way to go about it. Alright, so if I happen to be a CISO and I'm looking to tap you to help me train some folks, or conversely, if I'm somewhere and who's not in the field and I'm trying to find my way into this field, where do I reach out to Fortinet?
What's the, what's the handle as they say? com. com that's open to anyone.
And in fact, what we did is during the pandemic was we made a strategic decision here at Fortinet that, uh, we were gonna take our entire training and catalog, which represents about 900 hours worth of training and make it free to everyone. And, uh, uh, you know, that's, we haven't changed that. Uh, we, we've continued, that's our new strategy now, is that we wanna remove all the barriers that we can.
com can create an account and have access to our entire training catalog. And for those folks that prefer instructor led training, of course we have a network of authorized training partners around the world that provide classroom training. But, uh, you know, we've really tried to remove all the barriers that we can.
And in doing that, we've actually, we, we've set a, a target for ourselves at Fortinet. Uh, over a five year period, we wanna train a million people in cybersecurity. And, uh, you know, pleased to say that we back in June, we hit the halfway point on the calendar for that, and we're, we're past the halfway goal.
Uh, so we're making good progress and we're quite confident that, uh, at the end of a five year period, we, we will training that million people. All right folks, you heard it here. Hey, the thing of it is, is the bad guys still outnumber the good guys by a wide margin.
And there's really, really a thin line of folks that are, uh, protecting us from what could have become total chaos as opposed to what we see today, which I might call partial chaos. And if you're interested, by all means, we can use the help. Hey Rob, thanks for being on the show.
Great. Thanks a lot, Mike. All right.
And back to you guys in student.