August 10, 2022 By Jennifer Gregory 2 min read

A recent survey found that the majority of organizations struggle to retain cybersecurity workers. By focusing on improving retention, businesses can also reduce their digital risk.

Increased retention concerns

As new cybersecurity concerns increase, businesses also face an uphill battle to retain the talent needed to keep their data safe. A recent State of the Cybersecurity Workforce study reported that 43% of organizations saw an increase in attacks in the last year. It’s even more challenging to deal with this when they are constantly filling open positions. That means inexperienced workers or not enough people handling the infrastructure.

A key finding from the report was that 60% of respondents have issues retaining cybersecurity workers. That’s a 7% increase from last year. Plus, 63% of respondents have open positions. The survey included multiple industries, with 25% of respondents in the technology services/consulting industry, 21% in finance and 16% in the government.

The report also found a connection between increased attacks and retention issues. Of respondents who faced more attacks in the past year, 69% report being somewhat or very understaffed. This finding illustrates the critical nature of addressing retention issues as a key part of reducing risk and vulnerabilities. However, the study also found that lower retention rates make it harder to retain employees going forward. 73% of groups who are very understaffed reported challenges retaining workers.

Reasons for retention issues

The survey notes that the lower retention numbers are likely due, at least in part, to the current tensions between employees and leadership throughout all departments and industries. Many workers want to continue the flexibility of remote working, while some employers want their staff at the physical office building. Many companies have made changes to return-to-work mandates in hopes of reducing attrition, but there is not enough data yet to determine if these changes make an impact on cybersecurity retentions.

Other reasons cited by respondents for retention challenges include:

  • Recruited by other companies (59%)
  • Poor financial incentives (48%)
  • Limited promotion and development (47%)
  • High work stress levels (45%)
  • Lack of management support (34%).

Importance of retention will increase in the future

Because the demand for the cybersecurity profession is only going to increase, organizations that have low retention rates will struggle even more. 92% expect the demand for technical cybersecurity workers to increase in the future. Plus, 63% predict an increase in demand for executive-level workers in this field.

The key is to focus not only on reducing cybersecurity risk but on hiring and retaining top talent. By creating a positive work environment that includes competitive benefits, professional development and an upward career path, you can retain cybersecurity workers while improving cyber defenses.

More from News

FYSA – Adobe Cold Fusion Path Traversal Vulnerability

2 min read - Summary Adobe has released a security bulletin (APSB24-107) addressing an arbitrary file system read vulnerability in ColdFusion, a web application server. The vulnerability, identified as CVE-2024-53961, can be exploited to read arbitrary files on the system, potentially leading to unauthorized access and data exposure. Threat Topography Threat Type: Arbitrary File System Read Industries Impacted: Technology, Software, and Web Development Geolocation: Global Environment Impact: Web servers running ColdFusion 2021 and 2023 are vulnerable Overview X-Force Incident Command is monitoring the disclosure…

Research finds 56% increase in active ransomware groups

4 min read - Any good news is welcomed when evaluating cyber crime trends year-over-year. Over the last two years, IBM’s Threat Index Reports have provided some minor reprieve in this area by showing a gradual decline in the prevalence of ransomware attacks — now accounting for only 17% of all cybersecurity incidents compared to 21% in 2021. Unfortunately, it’s too early to know if this trendline will continue. A recent report released by Searchlight Cyber shows that there has been a 56% increase in…

Cyberattack on American Water: A warning to critical infrastructure

3 min read - American Water, the largest publicly traded United States water and wastewater utility, recently experienced a cybersecurity incident that forced the company to disconnect key systems, including its customer billing platform. As the company’s investigation continues, there are growing concerns about the vulnerabilities that persist in the water sector, which has increasingly become a target for cyberattacks. The breach is a stark reminder of the critical infrastructure risks that have long plagued the industry. While the water utility has confirmed that…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today