Half of polled infosec pros say their degree was less than useful for real-world work
- Reference: 1707337876
- News link: https://www.theregister.co.uk/2024/02/07/kaspersky_infosec_cso/
- Source link:
The Moscow-headquartered multinational revealed those figures today in the [1]first part of a multi-stage report based on a survey of 1,012 infosec professionals across 29 countries.
About a quarter of those probed said their higher education was "not at all useful" for their working life in cybersecurity; 12 percent said it was "slightly useful;" and 14 percent described it as "somewhat useful," adding up to 50 percent for the negatives. On the flip side, 29 percent said their education was "extremely" useful, and 21 percent said "very" useful.
[2]
Here's what Kaspersky had to say about that:
The lack of teaching personnel with real-world experience in the cybersecurity might be one of the biggest reasons explaining traditional education’s detachment from the industry and respondents hesitating to call their formal studies useful.
Or it might be that they took the wrong course, or didn't pay attention, but that's just our opinion. And we should include this part from Kaspersky's report to give you more context:
Of the infosec professionals with two to five years’ experience, just 19 percent feel their formal education was extremely useful or very useful in their day-to-day work, while three-quarters of these young professionals say the theoretical knowledge they got was not useful in helping them fulfil their responsibilities. However, this trend is skewed towards mid and senior level professionals.
If you were wondering what subjects these industry professionals studied – for instance, it's no surprise that someone taking physics found that less than useful for IT security – we pondered that, too. Kaspersky said 36 percent of those polled said the highest-level of education they got was in engineering, 21 percent said information technology, 15 percent said computer science, 13 percent said business management, 10 percent said science, and three percent said mathematics or something else.
We're told 43 percent of the polled cybersecurity professionals actually studied information security as part of their official curriculum. Which perhaps better explains the above 50-50 split on usefulness.
Keep up
There is another possible angle here. Security technology — and tech in general — moves fast and becomes "legacy" in one or two years, it's believed.
"If you are studying for a bachelor's degree in cybersecurity, for instance, you are preparing for a four-year course," said one survey respondent who works as a bank CIO in Brazil. "But in those four years the tech has advanced so much that the knowledge you acquired in the first or second year is already outdated in your third or fourth years of study."
[3]
[4]
As mentioned above, an overall skills gap in the IT security industry may have caused or is fueling a shortage of qualified instructors who have practical industry experience as opposed to theoretical knowledge. Without those educators, graduates may feel the knowledge they gained is less than useful in the real world.
Almost 40 percent of the polled infosec professionals worldwide said they "somewhat disagree," "disagree," or "strongly disagree" that their college or university professors had real-world experience. Breaking that down: 32 percent of North American respondents said they disagreed their tutors had real-life experience; 35 percent for Europe; and 37 percent for the Asia-Pacific region.
[5]Wait, security courses aren't a requirement to graduate with a computer science degree?
[6]Infosec pros can secure IT, but have harder time securing job satisfaction
[7]Ransomware attacks hospitalizing security pros, as one admits suicidal feelings
[8]Infosec still (mostly) a boys club
The regions with the smallest number of academic instructors with industry experience are in Russia (42 percent of respondents in that region disagreed their tutors had outside experience) and the Middle East, Turkey and Africa (48 percent).
Latin America seemed to have the highest report with only 20 percent of people surveyed disagreeing that their professors had practical experience in the field.
[9]
Overall, half of the respondents rated the availability of infosec courses in higher education institutions as poor (27 percent) or very poor (23 percent), and this number jumped to 83 percent for professionals with between two and five work experience under their belt.
According to one professional from the US: "There was no such thing as handling real-life situations, it was simulating real security incidents and learning to respond effectively. So this was missing from the educational programs. Handling actual security incidents requires a different set of skills than theoretical knowledge alone." ®
Get our [10]Tech Resources
[1] https://www.kaspersky.com/blog/portrait-of-infosec-professional-report-2024/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZcQLl0-sXZ8HhC9tuKC-6gAAAYo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZcQLl0-sXZ8HhC9tuKC-6gAAAYo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZcQLl0-sXZ8HhC9tuKC-6gAAAYo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2024/01/26/security_courses_requirements/
[6] https://www.theregister.com/2023/11/02/infosec_pros_burnout/
[7] https://www.theregister.com/2024/01/18/ransomware_attacks_hospitalize_security_pros/
[8] https://www.theregister.com/2022/10/15/infosec_boys_club/
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZcQLl0-sXZ8HhC9tuKC-6gAAAYo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://whitepapers.theregister.com/
"Security technology — and tech in general — moves fast and becomes "legacy" in one or two years"
Maybe in detail, but two things are durable -- first principles of both technologies and their management and the essential human elements of infosec (neither of which features to any great extent if at all even in dedicated infosec degree courses).
We have a culture that views infosec almost exclusively as a technology discipline and considers 'users' to be stupid (as opposed to just uninformed), whereas in reality probably the majority of successful attacks are down to sloppy management on the victim side. Examples include 'policies' that don't work because they're not backed up by training and resourcing or they assign to front line staff responsibilities they can't fulfil rather than employing technical fixes to eliminate the hazard; incident response plans that are never tested and which often only address a limited list of predicted incidents rather than allowing for the unexpected; blame cultures that fail to learn from experience, and many more.
Some years ago I was invited to deliver a masters module on infosec policy management, but I was deeply disappointed to find almost all the students were utterly uninterested in the underlying principles that contribute to effective policies -- they just wanted to be fed and regurgitiate standard template policies without consideration of whether they were any good.
Re: "Security technology — and tech in general — moves fast and becomes "legacy"
they just wanted to be fed and regurgitate standard template policies...
There's a whole industry (sub-)segment out there catering for exactly that market. And, occasionally, I'm called in after some "consultant" left a template mess behind to bring in some workable structure (which is another market). And, probably, after me some true infosec professional is hired to get things actually done.
Not surprised...
might have got better numbers if the whole circus had enrolled in RADA (UK) rather than wasting places in engineering and science courses.
If the concept of "transitive closure" (of relations or graphs) were ever internalized a fair bit of nonsense could be avoided.
Safety concepts - eg knowing the difference between hazard and risk would help.
All really bit of a mess...
I am not an infosec pro, but that is my day job. When I was at uni, there were no security courses. We learned about hacking by recovering from what was left.