News: 1632909607

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Give put-upon infosec bods professional recognition to keep them working for you, says chartered institute

(2021/09/29)


Interview As the UK infosec industry prepares for government initiatives intended to expand the sector, how should existing companies keep skilled professionals from jumping ship? Amanda Finch, CEO of the Chartered Institute of Information Security, tells us a thing or two about what she thinks works.

The institute (CIISec) bills itself as "raising the standard of professionalism in information and cyber security". Previously known as the Institute of Information Security Professionals, the organisation is one of those slightly nebulous bodies whose purpose is to improve certification and training across the industry.

"People tend to stay in roles if they are being developed," Finch tells The Register just after the institute's annual conference. "The main thing is about getting the right qualifications for the right role."

[1]

Qualifications are a minefield, and as information security digs ever more rabbit holes for professionals to fall into, there's an age-old problem: how do skilled people communicate those skills to others, especially potential new employers?

[2]

[3]

The usual answer is certifications, though there's a bewildering array of those on the market today: some are more instantly recognised than others. While Finch says CIISec doesn't endorse any one specific certification or competency framework, she speaks passionately about companies recognising their employees' talents as a tool for staff retention.

"The main thing is, is really to get a job with an organisation that actually cares about career development," she says. "If you're with an organisation that is concerned about developing staff, they'll get you on right courses for you at that particular stage in your [career] development."

[4]

As the industry expands, it's natural enough that skilled practitioners are going to be looking for new jobs and potentially starting their own businesses, or growing existing ventures. This is likely to give management teams a headache as their brightest and best start looking elsewhere – so CIISec's position is that investing in people might help companies retain experienced talent.

On top of that, the institute's work on certifications and recognising skills spreads the public-private sector divide. Digital investigation is one area where the institute thinks there'll be a need for standardisation and mutual recognition of skills through qualifications, and it's hoping to roll that out more broadly over the coming months.

"One of the good things about extending the cyber digital investigator qualifications to the private sector is that it will help law enforcement," says Finch, highlighting how evidence collection "by people that have been accredited" brings benefits to those carrying out initial investigations into breaches which could lead to criminal prosecution.

[5]

For example, National Lottery operator Camelot's initial response to the deployment of black hat tool Sentry MBA against Lottery players' accounts [6]rapidly morphed into a multi-pronged prosecution – and guilty pleas.

"Very often," continues Finch, "law enforcement have to go back to basics and do the investigation from from the start themselves, because they can't trust that the evidence has been put together in a way that will stand up in court. So [the accreditation] is really important in terms of bringing [infosec and the law enforcement] communities together".

[7]Burn baby burn, infosec inferno: Just 21% of security pros haven't considered quitting their current job

[8]Global pandemic was good for business, say UK infosec pros – but we're still burning out

[9]Emails, chat logs, more leaked online from far-right militia linked to US Capitol riot

[10]Two Northern Irish cops face Computer Misuse Act charges over Twitter trolling campaign

Status is important to CIISec too; people who feel the work they're doing is not only valuable but is recognised across society are people who'll stick it out for the long haul. Chartered status, something the institute can grant, may help with that goal. Many reading El Reg will be familiar with the frustration of trying to convey what working in any aspect of IT means to mere end-users and consumers.

"That's really where we need to go as a profession," enthuses Finch, "is that there are routes that take you to this chartered level, so that you are measuring competency as well as education."

It all sounds like a good set of initiatives, anyway. With the infosec sector expanding and [11]new bodies such as the UK Cyber Security Council lurching to their feet in the wake of government announcements about skills and training, there's bound to be more of this sort of thing on the horizon.

Whether all employers will care for staff upskilling and recognition is another question, however. ®

Get our [12]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YVSNzxLWWrKlO1I3RtU12QAAAQ8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YVSNzxLWWrKlO1I3RtU12QAAAQ8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YVSNzxLWWrKlO1I3RtU12QAAAQ8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YVSNzxLWWrKlO1I3RtU12QAAAQ8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YVSNzxLWWrKlO1I3RtU12QAAAQ8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2020/01/10/national_lottery_hacker_anwar_batson_jailed_5_pounds/

[7] https://www.theregister.com/2020/07/14/infosec_job_change/

[8] https://www.theregister.com/2021/09/08/ciisec_state_uk_infosec_report/

[9] https://www.theregister.com/2021/09/28/in_brief_security/

[10] https://www.theregister.com/2021/09/23/northern_ireland_psni_computer_misuse/

[11] https://www.theregister.com/2021/04/06/uk_cybersecurity_council_domain_fail_launch/

[12] https://whitepapers.theregister.com/



Certifications

Eclectic Man

I was an Associate member of the IISP, and a CLAS consultant (now retired). The issue with certifications and examinations is that there was some confusion over what was actually done, and the breadth of experience instead of just knowledge required to gain, for example full membership of the IISP. You not only had to know quite a bit about several different aspects of InfoSec, such as fighting virus infections in networks, business continuity, ISO27001, but have had, and maintained experience of doing it for real over a period of time.

I failed my full membership of the IISP interview because I had never had to actually deal with a virus as a lead consultant, managed to ensure backups were taken so never had to invoke the full BCP / DR plan etc. Oh, and although I had passed the ISO27000 Lead Auditor course, I hadn't conducted a major audit running a team in the past 3 years.

Contrast this with public examinations for, say 'A'-levels or degrees, and there is either specific coursework or a formal examination to assess the candidates. When CLAS went to a two tier hierarchy (just before CESG was transmogrified into the NCSC) looking at my job responsibilities, there was no way I could claim the experience required to get the upper tier, and just maintaining the lower tier would be difficult.

So go for certifications if you must, but there a re a lot of intelligent and able information security consultants out there who will struggle to get them if they have to actually have experience of doing the fire-fighting, DR / BCP, auditing every two years, because they will be working on bids, managing firewalls or other such things as their main jobs and their employers, however keen on staff development, will keep them there because they are good at it.

Keeps on giving

elsergiovolador

"People tend to stay in roles if they are being developed,"

One of the effects of IR35 is that specialists running their own business no longer have funding for training, as a consequence of being taxed on revenue. Despite being their own employer and paying employer taxes, they no longer get benefits of being one.

Since they cannot train themselves, their business will eventually decline and they'll go back to the pool of employees and they will no longer be able to decide what's best for them to learn.

Inevitably, the employers will have to spend more money on training - but here is the catch - if employee learns a new skill that is valuable on the market, they are more likely to jump the ship and go to an employer who pays more, so the statement above is not entirely true.

The employers will try to protect themselves by various means, which effectively means further enslavement of engineers - if they want to develop their skills.

IR35 has busted the Security profession

Anonymous Coward

When I was an employee; I was deskilling myself, so I had to book days off to attend seminars. I would also pay for my own training, as the company would not support new technology development. So I jumped to contracting, less stress and bullying, less ass kissing and more self development and money.

Currently, Inside IR35, no way to offset the cost of training / development, no travel costs. But I pay as much as I can self-sacrifice into pension. I will then take Xmas > March off and claim the tax back, through my limited company (still keeping it going from the war chest). I will then use the time off to re-qualify for my certs and live on the tax I get back. I don't know if I can ask for the Employer NI back that the Umbrella company "stiffed" me on?

If the Outside market picks up, I will start applying for roles. Or if I get an offer, I will just jump ship, I only got to give 5 days notice. Not even working days and no handover or knowledge transfer in my contract.

Re: IR35 has busted the Security profession

elsergiovolador

Just wait when they catch up that some contractors in scope only work 6 months in a year to avoid getting much over the higher tax bracket. I wonder how they solve it... 12 month minimum contracts?

Anonymous Coward

I worked with plenty of people who have loads of certifications, but are basically useless in the real world.

I've also worked with some brilliant techies who are too busy solving technical problems to spend time going on certification courses.

And if you want good people to keep working for you, treat them right and pay them well. It's not rocket science.

Anonymous Coward

It will come to a point where sec pros do everyting because everything has a security element.

I know I'm not the only one that gets hit with any problem that has "security" or "risk" in the title

Defining Break/fix, policy, standards, governance and security problems and allocating appropriately would help

A neighbor came to Nasrudin, asking to borrow his donkey. "It is out on
loan," the teacher replied. At that moment, the donkey brayed loudly inside
the stable. "But I can hear it bray, over there." "Whom do you believe,"
asked Nasrudin, "me or a donkey?"