Upskilling Cybersecurity Teams – Kevin Hanes, Cybrary
Cybrary CEO Kevin Hanes explains why organizations during uncertain economic times need to focus on upskilling the skills of the cybersecurity teams they already have.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with Kevin Haynes. Who's CEO for cybery, and we're talking about cybersecurity training in the lack thereof, Kevin. Welcome the show.
Thank you so much, Michael. We focus so much on the shortage of Cyrus security Personnel, but I have to wonder if we're not paying enough attention to the folks we have and we're kind of just assume that they are magically gonna be able to keep Pace with changes in technology and cybersecurity itself. So are we doing a good job on training these days or is there something kind of broken in our system?
Well Michael, I think it's a good question. You know, I was reading something the other day said roughly half of cyber security Executives feel like they're the Cyber skill shortage is affecting them and they're organization. So that that's definitely top of mind and you're right to ask about what about the people that are in the program and what are we doing to retain upskill those?
And you know, I think about that a lot. You know it. At the end of the day, we're probably asking those people to do more right into into cover more things.
If they're If there really are those shortages in the openings and and in the lack of ability to fill them then we're asking those individuals to do not only more but to do broader different, you know take on different things. So I think upskilling training retaining really needs to be top of mind. It seems like it has you know, those things are a little more top of mind, but they can certainly be, you know, be more so I think is the pace of innovation outstripping their ability of cybersecurity folks to keep Pace.
I mean not only do we have more platforms to secure at the edge than ever, but we're seeing things like Cloud native applications and all kinds of new animals in the proverbial itzu that need to be secured and can they keep Pace with the rate of change? Yeah, I mean I it's a great question. There's certainly been you know tons of Technology investment into cybersecurity in the last decade a lot of that a lot of that technology is really trying to bring better visibility to you know, detect prevent and respond to threats and at the end of the day, I think we all know that that There's so much that the that's for the computers or the technology can do itself and and there's a there's there's a residual or a leftover of what has to go to individuals.
Like people humans to make to make choices, right and oftentimes at least in my experience some of the hardest things the the most Probably risky things actually end up going to a human right in that process. And so yeah, I think it at the end of the day. What are we doing to make sure those things that are going to the people that are handling those things are the best best equipped what have we've done to invest in their their ability to handle that and and know how to make the best decisions so often that comes to to training right and how we're Preparing People for you know, onboarding into those roles but also continuous because you're also right that the Innovation is not just innovation technology but innovation in threat actor tactics, you know how they're how they're sort of running their, you know, running their campaigns, you know, how they're running their, you know, they're playbooks, right?
They're gonna they're gonna shift and so this is a area where you can't be done with learning like it's just never it's never gonna stop. You gotta be always learning. I think the other thing is I think about this.
We just did this report with omdia research report and it's talking about one of the stats. I found incredible was 79% of the participants in this research said that they rank training cyber security training of their professionals as a four out of five an important as it relates to the ability of their organization to stop a breach. Hmm, that's you.
I mean that that's that's jumped off the page to me because that is incredible. So if if it's four out of five importance coming down to the humans and their training that we definitely need to be putting an emphasis on that. To your point is a year sense that the bad guys have some pretty efficient training programs of Their Own It seems like they have no shortage of people these days.
So how does that compare to what the good guys are doing? Yeah, it's hard to say right what what the bad guys are doing. I think it's it's you know, it's probably it's it's probably right to think that they have, you know playbooks and they they train to those playbooks and there's not only one sort of bad guy, right?
There's there's different types of organizations that probably have different types of you know, the way they think about this but at the end of the day If you also think about the number of times that a Defender has to be right to the number of times that you know, somebody on offense, you know, sort of needs to be right. It's not a balance, right? So we as Defenders, I think yes absolutely have to be always Vigilant and training and and you know, the other thing too is I think about this is And I've learned this a lot just by working at library and you know and gotten really insights into.
Strong organizations that that train and that I think the best ones don't make it feel like just more work being dumped on, you know, sort of the individuals that are already stressed out and you know maxed out and and working really hard they do things clever things to make it to make it fun and to give people space and time to train so like they'll do things like, hey, let's carve out, you know an hour an hour and 15 minutes on a Friday right and do something as a team. That's that that's got an element of fun and in gamesmanship and everybody sort of learning something they'll do things where You know, they they will have somebody who goes in and maybe takes a certain, you know skill course and and then get everybody else to take that skill course, but the person that went through it first is maybe maybe an influencer and they do kind of brown bag, you know lunch sessions, you know with the team over a couple of weeks as they as the teams going through it can learn and then ask questions of you know, somebody, you know in house so to speak that's already done it so they find clever ways to make it just not not more work but integrated integrated into sort of the the daily sort of work life, you know of their of their programs. Do you think we are leaning too heavily on Automation and hopes or AI to compensate for the training issue and maybe we got too much emphasis on one side and not enough on the other.
Yeah, I don't know I would say that we have too much on on sort of automation technology and you know machine learning artificial intelligence those things. I think they're very very necessary because if you just look at this, you know, like the signal to noise, you know, and if you you know, there's not enough human beings in the world to deal with all the sort of the alerts that are out there, you know, when you kind of looking at okay this you know that might be just you know, it's suspicious, you know, is it malicious or not? I don't know, you know technology is pretty good at cutting through a lot of that noise and getting in getting to better signal and that's that is really important because there's just not enough human beings in the world to handle all that.
So I think that has that has to continue to get better and better and I believe it will but as I said earlier, there's just there's a there's a certain, you know residual amount. That's that ultimately is gonna go to you know, human beings to decide and and deal with in that we probably are not putting enough emphasis on that. I think we I think we we take it a little bit for for granted that those individuals, you know are trained up and know what to do.
So I think we could do more there. As we go along here. Do you think that there's a high correlation between the amount of stress that cybersecurity professionals feel and the lack of training because maybe it exacerbates things to the point where we are starting to see more turnover that could be traced back to the simple fact that we don't have enough training.
Yeah, I think I think there are many things that can create the stress clearly. You know training helps a few things, right? It helps it helps people with in that report.
I mentioned that I'll be report they talk about 48% of the respondents to that research said that it actually when they when they provide training that it actually keeps people, you know, it helps them retain employees. Not not the other way around, you know kind of the myth is that you know, if I provide training then you know, then people are gonna then, you know, they're gonna get trained they're gonna get this, you know, a certification or whatever and then that they're just gonna go get a higher paying job somewhere else. So leave me in and that was largely rejected.
I mean hugely rejected in the research, which is great to see so I think one it starts with How do I have a team that I invest in so that their cross train so that you know, there's not so many just sort of silos but people can do you know more things more broadly understand how the full program works and and help across the board that's one, you know have having people that have that have been there longer always helps, you know, more tenured individuals can train and bring other people along so it's not as chaotic as just stepping in there's you know, there hasn't been somebody that has been there very long is always problematic. So I think yes training can help those things and it also provides confidence right these these folks are making, you know, critical critical decisions and they're usually having to make them pretty fast and and under sometimes under duress. So, you know, the more that you have a confidence that you've seen these things before you sort of trained on them before then then yes, I think it can bring down the stress levels.
What's your best advice for making training engaging because you know, I think we've all seen the cybersecurity training program. That's about as exciting as traffic school. So can we yeah all the way to kind of make this more compelling.
Yeah, so at Cyber, we're doing a few things. So one is just starting, you know, a lot of a lot of the content and training that's out. There is is his historically been certification oriented and while that's what while that's good because those those are those are those are very worthy Pursuits.
They often they oftentimes can be a bit dry. So we have complimented that at Cyber with a whole plethora of alcohol skills-based training that are really around recent relevant type threats, right? So it's in and we're trying to take them down to you know, kind of like somebody could do it over a lunch time, right?
It's so they could do it over their lunch break. So it's not like a, you know a week long thing, but they could they could they could they could get something done in 45 minutes for example and get a skill and we're always trying to put a little bit of a fun, you know kind of gamification element to it. So those are some of the things we were doing continue to do.
The other thing I think is just by the way you teams think about this the more it feels like an Vigil effort versus a team effort, you know, the more you kind of I think it can be more dry or dull. So I think the best Learning and Development teams that we see that we get an opportunity to work with. They definitely try to get their teams doing something together.
So hey, let's go take this thing on cybery. And let's do it as a team. You know, let's let's schedule out an hour on a Friday and do it as a team and and kind of see you can get there first.
You can solve it first or you know, how do we Mentor the team that maybe can't get there as fast. So I think I think those are some of the tactics that that we can do to make it to make it, you know more approachable. And the other thing is I think just helping people understand that you want you want them to do this and you want and it's okay to take an hour, you know to go to go skill up on something and it doesn't always have to be, you know at 10 pm at night, you know, you can do this you so I think kind of that that can be hard and I understand but to the extent possible or organizations can can free up, you know blocks of time for their for their team to go and invest in themselves.
It's important. Well to that point do too many organizations expect cybersecurity people to maintain their skills on their time and they don't factor that into the You know the the job responsibility which is you know for them to create some opportunity to train those folks or do they think that somehow or other they're all just magically going to go home at night and do that themselves. Yeah.
I don't think it's necessary. I don't believe that it's a sort of a Sort of a negative sort of thought or or like a bias towards not not wanting to invest or train. I think it's just sort of a symptom of the workload doesn't stop or slow down and you know, we I think we can all acknowledge.
There's there's a there's a gap in this, you know, there's a skill Gap out there. So what ends up happening is you have a lot of teams and organizations that have a little you know, they have more to do than they can do it. Right and so the idea of the idea of sort of taking somebody out of the fight, you know, putting them into yeah into this training, you know, and maybe that maybe that's something that they got to go do for a week or something, you know, kind of be out of the loop.
It's hard. It's really hard. So I think we have to understand though that there's and and this report I think really helps us to think around, you know further out and think about the benefits of training not you know, you can't just think about okay the time that you're taking somebody out of the fight, but think about you know, what they're gonna be able to do to help the team with that training in terms of how it will apply to, you know further risk reduce reduction making the overall organ.
Position more efficient and effective and you know and retaining those employees right? Because in what the you know that those those teammates want to be invested and they want to they want to make sure that you know, they're getting better. So I think we have to we have to see it from both sides and and do what's necessary.
And yeah, like I said a side where we're also trying to make sure that the modalities of learning don't always just have to be like, okay, you're gonna go not, you know, you're gonna go off for a week and do something, you know sort of out of the fight but make it more integrated into sort of how people work in their day. And as I said, I think really smart organizations are finding ways to carve out times for like, you know for people to sort of do it together. and and that that helps All right, folks here did here make cybersecurity training fun.
Otherwise people are going to check out otherwise known as gamification in some quarters Hey Kevin. Thanks for being on the show. Thank you, Michael.
All right back to you guys in the studio.