OPSWAT’s Irfan Shakeel on Cybersecurity Skills Development
Irfan Shakeel discusses OPSWAT’s $10 million scholarship program, how it contributes to closing the cybersecurity skills gap, and how it aligns with government initiatives focused on enhancing cybersecurity measures.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with ear fan Shaquille, who's vice president of training and certifications for ops swat, and we're talking about a new scholarship program that they've created to help close the gap in cybersecurity skills, which, uh, despite the rise of AI remains persistent.
So, welcome to the show. Thanks for having me, Mike. So, how much are you guys allocating to this, uh, program and, and, and who's eligible for this scholarship?
Well, um, uh, you know, under op Sort Academy Umbrella, HOR is investing $10 million into the scholarship program. And as far as the eligi eligibility is concerned, the program is available, uh, globally, meaning that, um, you know, no matter where you are based in, uh, if you are eligible, and if you fulfill, uh, you know, certain criteria. So number one is the age requirement.
You should be at least, uh, 18 or older in order to, you know, get into the pro, uh, into, into this program. Secondly, we deliver our course material, uh, in English language. So English proficiency is required, or although if you are based in Asia, Africa, if you speak fluent English, if you understand, if you can comprehend, then you are qualified for this.
However, now there are certain other requirements. Uh, number A is, um, either you are working already working the cybersecurity domain, um, or B, you are a student or pursuing a relevant degree such as cybersecurity, bachelor's, or master, or master's in cybersecurity or, or related degrees such as cyber, physical system, information security, or even computer science with the intent to pursue a career in cybersecurity. So if you have one of these, uh, you know, if you fulfill one of these criteria, then you are eligible to, uh, get into the scholarship program.
One more. Very important, uh, I must not, I must not say a requirement, but I say commitment is the applicants or participants. Uh, they must, you know, commit to, uh, completing the course package provided by the, uh, scholarship within six months of gaining access.
And this basically demonstrates a dedication to advancing their cybersecurity knowledge and skills. So, where did the course come from? Who created that and what went into the development of it?
Well, ops sort has, you know, has over a decade of experience in, um, you know, uh, in the cybersecurity domain, particularly focusing on the SIP industry, which is the critical infrastructure protection industry, and ops sort run, uh, a training platform called Ops sort. Academy. Ops Sort Academy is, is one of a unique cyber security training platform, I must say, because unlike other trade training platform, OP Academy focuses on, uh, creating, uh, cybersecurity best practices or certifications focusing, uh, on the SIP industry.
So all the critical infrastructure out there, you know, whether it's nuclear energy, oil and gas, chemical healthcare sector. So, offshore Academy focuses on these, those industries. Uh, and as far as who creates those courses is our internal team.
So we have the, you know, uh, expertise, uh, since we, we are a company, we focus on developing cybersecurity products, solutions and education as well. So we have expertise, we have our engineers, so we create those courses. And in some of the, you know, some of the courses we, uh, take, um, you know, help from the industry's experts as well.
There's a lot of conversation these days about how we're not reaching out far enough beyond the typical cybersecurity pool to bring people into the sector. So this program seems to be more focused on, uh, rewarding fo folks who already have some exposure to cybersecurity. But what are you guys thinking about doing as far as expanding kind of this effort and, you know, are you looking at beyond the typical college graduate with a four year degree who might be entering the space and somebody who's totally new to it?
Well, as I said, uh, officer academic courses, unlike the traditional IT security, our courses, we focus on a particular niche that's, that's this, you know, SIP industry. Although we have, we do have, we do our courses do talk about the general cybersecurity concepts that are applicable to IT security, however, we bridge the gap between IT and OT security. So some of our courses, uh, ex explicitly, you know, mentioned the problem, uh, we are facing as far as the industrial segments are concerned, like iic s environment or OT environment.
So, um, so the co you know, the students, you know, coming out, uh, from, you know, uh, going out or co you know, coming from a traditional cybersecurity education after four year college degree, they'll be exposed to a very particular set of a skillset knowledge, which are very, uh, I must say, industry ready. And, um, uh, you know, hands-on, uh, uh, you know, uh, you know, consists of hands-on experiences or skillset. What is your sense of, um, is it gonna get worse in terms of our inability to find people to fill these jobs?
Or is it gonna get better in the age of AI because we'll be able to automate more tasks? I mean, we've been dealing with this chronic shortage for a decade or more, but, you know, what's your sense of the outlook? Well, it, uh, you know, certainly it depends.
Uh, sometimes, see the AI definitely helps cybersecurity all the industry, but particularly cybersecurity industry. So we have more automated tools available, uh, meaning that we are not, uh, now relying on human skills or manual skills, I must say, human skills, of course, there to operate those AI based tools, but not the manual approaches. However, the drawback is, um, is, is, you know, if something, uh, you know, uh, goes wrong, if something goes in a wrong direction, then being able, you know, being, uh, able to use the AI tool all, all you all year long, the, that particular individual cannot troubleshoot the problem, and they need to call the company, Hey, this thing is broken.
They cannot find a box they cannot fix. They cannot troubleshoot on their own. That's number one problem.
Secondly, ai, just like AI is solving several cybersecurity challenges, AI al also introducing some cybersecurity challenges, because not only the good guys are utilizing ai, the bad guys are also using ai. Now they're using AI to create a malware program, which are, uh, you know, so sophisticated that are traditional IT security solutions cannot detect them. So AI will have, uh, impact on both, both sides, like on the good side and the bad side.
And as far as this, uh, cybersecurity skills, uh, pool is concerned. Uh, the, the pool is growing, the pool is growing, and, and the, uh, in the, in the foreseeable future, I, I believe that it's gonna grow further, specifically, uh, uh, you know, the industry wise, because as far as the IT security is concerned, we have tons of security, uh, courses out there in the market. Uh, and universities are now focusing on education degree out there.
However, for OT or ISIS environment, which is the blend of all industrial processes and IT security, we haven't, we, I don't see a lot of training out there in the market which focus on this domain. So if I, if, if I talk about the talent gap or skill shortage for the OT environment, it, it is there and it's growing. Do you think AI will flatten, uh, the silos that exist in our IT environments?
And I'm asking the question because, um, today we're trying to deputize the, um, IT people and the application development people to handle more security functions. And conversely, we want the security people to know more about the environments that they're trying to secure and maybe even apply a patch without breaking anything. So are we on the cusp of some sort of, uh, great leap forward?
I mean, it's, it's, it's like, you know, that's, that's one of the problem because organization nowadays not, and not just nowadays, I mean, the organiz is used to, they ask it security people to fix bugs in an application. That's not their job. They do not understand it.
That's typically it's a developer job to ensure that the program they are developing, uh, you know, by using the security best practices and then, uh, it's EC or application security, personal, personal job to make sure that the applic application is secure. Now, as far as the ai, AI is concerned, yeah, there are several AI model, uh, you know, models out there or techniques out there, which definitely can help in, uh, finding those bugs either during the, you know, software development, you know, development life cycle or maybe in the, in, in, in the testing phase. However, the real, uh, you know, uh, solution to this problem is to not expect IT security guide to understand the, the software level bugs or fix that software level bug, or even to not just rely on the, on, on the AI solution to find and report that software level bug, because that can easily, easily be bypassed.
What it, what needs to be done is to make sure that these, uh, you know, software, secure software development, uh, approaches, organizations should adopt the, you know, the secure, you know, development procedures. And they also use AppSec level, uh, you know, expertise to test their softwares before the deployment and even after the deployment, they should be able to fix the problem and fix it. Again, this is AppSec job, not the IT security job or, or, or, or, or network labor security job.
Secondly, AI can help in this domain, but AI can only find the problem which, uh, which, which, you know, which, uh, they, which that particular AI has been trained, trained for. They cannot see the zero data box. They cannot see the logical errors.
AI can AI or, or a, you know, AI level software can find a typical problem like SQ injection, uh, cross scripting, all these bugs on the software. However, the logical problem, logical bugs AI cannot find that. For that we need to rely on the manual security testing.
A lot of folks have what can only be described as a love-hate relationship with certifications. They don't really like taking the test and studying for that, but they kind of appreciate it when, uh, someone in HR decides to pay them more because they have a certification. So, um, what is your sense of, uh, the value of certifications these days?
Do we fully appreciate that and are enough people getting them? Well, that's, that's true. You know, some people, and I must say a lot of technical people, and I personally know them, they do not like to be tested.
They get, uh, you know, they get offended. You know, when if, if you suggest them, Hey, you are, you, you, you are, you have all these skill sets, why don't you simply go and appear the test and get a certification? They say, Hey, we don't need the certificate.
Uh, we know our things. You know, that's true. However, the problem is hr, they need some sort of, uh, an assessment tool to judge either you have a particular skill set or not.
Uh, so HR cannot just rely, they do not know you personally. So if, if, if, uh, you know, whenever hr, you know, publish a job online, they check or validate, uh, an individual skillset based on certain criteria. One, you know, number one is, is the educational degree your college or master's degree.
Secondly, the certifications. And apart from the, the, you know, this basic, uh, uh, you know, screening, you can show your skills while talking to the hiring manager. But in order to bypass or pass the HR screening, you must show the, uh, required certifications.
Now, as far as these value is concerned there in the IT security, there are tons of security vendors out there. Some, they, uh, they do carry value. So some they do, you know, talk about the real stuff, and some certifications are just for the sake of certification.
Although they are very famous because they have been there in the wa you know, in the market for so long. However, they are not updating or upgrading. So, uh, in, in my opinion, one should take, uh, uh, you know, a certification courses and get certified in order to, uh, grow in their career, because that's a very good assessment tool.
Do not just get offend, Hey, the, you know, that a certificate, how, how, how a certificate can test your knowledge. That's a certificate cannot test your knowledge. But this is one way of testing.
Either you are eligible enough to get a job, a particular job. So however, uh, my opinion is, if even if you are going for a certification, make sure that select the appropriate certificate, go through, you know, the curriculum and see the kind of value you will get after attending that particular course and training. Do you think the vendors could do a better job on working together to manage these certifications?
'cause you talked to some folks and they were kind of like, you know, I just studied for this certification, and then I studied for the other one, and they were at least half the content was the same. Yeah, to some extent, vendors, uh, you know, they can collaborate, but they, you know, they have their own, uh, problems. Uh, because at the end of the day, they are competing in the market.
Uh, so I, I believe it's in an ideal world, they should collaborate and they should come up with a unified, uh, training, you know, uh, certification. However, uh, let's face the reality, it's not going to happen. So the, the burden is on the, uh, participant shoulder.
So, uh, if, if I, if I am to take a certificate, I will judge, uh, uh, you know, I'm going, uh, I'm going to go through the, you know, curriculum. I will go and talk, talk with the relevant people, uh, who are already working in the industry. I will meet people in a seminar and conferences.
I will ask their opinion, Hey, what should do, uh, you know, what should I do? These two certificate, they look alike. They have more or less the same sort of curriculum and outline, and most of them, they carry the similar sort of value in the industry.
So what I will do, I will check, I will, you know, talk to people, I'll see their opinion, I'll see, uh, what carries the most, uh, weight and what's not, because yeah, that's true. You know, there are several vendors out there and they are competing, um, you know, to each, you know, with each other and their certification. They, uh, give the same sort of education, but that, that they're slightly difference maybe I must say.
So let me give you, you one my opinions for the beginners. Let's say if you are coming out of college, you should get one beginner level certification and then go out from the theoretical concepts, get some hands-on experience by participating in the CTF challenges online or going to the seminar and participate there. So what ultimately is your best advice to people who are going for certifications or as they say, you know, what's the pro tip that you wish people were more conscious of as they went for these things?
And, um, you know, a lot of folks are worried that they'll fail. So, um, you know, how, what, what, what's the co what's the teacher's best advice? Well, um, you know, first of all, you need to decide, so what do you want to do?
Because cyber security is, uh, is, is, is, is a broad domain. You know, we have network security, application security, cloud security, and let's talk about blockchain. Now, let's talk about this critical infrastructure.
So we have this, you know, critical infrastructure, protection, security. So first thing, first you need to decide what do you want to do in your life? You cannot say that, Hey, I want application security certification, and then I want blockchain security as well.
And then cloud security as well. It's good if you can invest into your education, because learning is always good. However, you must first, you know, first step is to decide what do you want to do?
And then let's say if you want to pursue a career in, in the SIP industry or, or in the critical infrastructure security, then find out the top, you know, uh, security, uh, certification vendors out there. And as I said, most of the security, security vendors, they offer, you know, more or less similar sort of, you know, curriculum or courses. So judge, uh, what, what, you know, what, what is going to give you the most value of, of your buck, you know?
So, and based on that, you can definitely join the courses. And apart from taking the courses, the most important thing is a hands-on experience. So whenever you go to a particular vendor, see what sort of hands-on training or practical experience, the lab environment, whether it's a cloud-based lab, or they teach you to set up your home, home lab, what sort of hands-on experience or the train, uh, or, or the, you know, skills you are getting.
So that's very important. So number one, you should take a basic course. Either you are going in a cloud security, blockchain, security, AppSec and SIP industry.
Take one basic course, which is the theoretical concept, the fundamental, and then the rest of your courses should, depends on the practical or hands-on experience. So for example, in SIP industry, offshore academy, uh, uh, you know, the, uh, it starts with ICIP, which is the introduction to the SIP industry. And then it goes and talks about, uh, you know, data security, uh, cloud security, the bridge between IT and ot, the conversions and how to particular, how to solve the particular problems that, um, arise due to this bridge.
So this is how it goes. All right, folks, you heard it here. It's age old advice.
Decide what you want to be when you grow up and work backwards. Hey, different, thanks for being on the show. Thanks for having me, Mike.
All right, and back to you guys in the studio.