Jamal Elmellas: Resilient recruitment: The need for a risk-based approach

-

A big part of the problem associated with the cyber skills shortage is that it threatens the security of the business. There is now a deficit of 14,000 entrants every year so businesses are going to need to adjust how they go about recruiting and need to do so in a way that protects the business and its assets, argues Jamal Elmellas.

Today some of the hardest positions to fill are in middle management and the C-suite with hirers looking for between three plus years’ experience, according to a DCMS report. This is because many organisations subscribe to the belief that they need to create a solid security team starting at the top of the hierarchy. But is this really true? According to a report from Verizon, the average time a CISO will stay in the job is just 26 months so while leadership is key it certainly doesn’t have the destabilising effect many envisage.

Roles based on risk

One idea advocated by McKinsey is not to prioritise hiring based on seniority but on risk. It suggests that rather than using a top-down approach that fills most senior roles first before filling roles further down, organisations should first identify where the riskiest roles are. Often these will be dotted throughout the business with some in the top, middle and bottom of the organisational hierarchy.

It is possible to identify and prioritise role filling by calculating what it calls a ‘Talent-to-Value’ (TtV) strategy which identifies those posts that expose the business to the most risk. The formula is not a one size fits all proposition, however, and will need to be adapted depending on how mature the business is and other factors such as business transformation which can of course create more risk.

HRreview Logo

Get our essential weekday HR news and updates.

This field is for validation purposes and should be left unchanged.
Keep up with the latest in HR...
This field is hidden when viewing the form
This field is hidden when viewing the form
Optin_date
This field is hidden when viewing the form

 

The business can use its understanding of risk to determine what can be done to reduce it and who can make that happen. Some risk frameworks can be used to analyse knowledge and identify skills gaps such as NIST’s NICE (National Initiative for Cybersecurity Education).

It needs to decide which of those risks and by association roles are the most pressing and will lead to the greatest reduction in risk. Perhaps investing in Cloud Security Architects would counter the risks posed more effectively than, say, a Cloud Security Manager.

Specific job descriptions should be built in concert with the security team that are determined by the tasks and skills and the HR team can then explore whether there is an opportunity to upskill in-house or if they need to recruit or outsource.

The benefits of TtV

McKinsey claims adopting a TtV can result in up to 50 percent less new hires, saving the business time and money and focusing recruitment drives to create a more adaptable workforce. But there is of course the problem of covering the interim period while people get up to speed. However, recent research would seem to suggest this isn’t necessarily a problem.

Whether upskilling or recruiting, new entrants into the profession can add significant value and they do not take as long to get up to speed as you might expect. According to the ISC(2), over a third of hiring managers said it took just six months or less for entry and junior-level hires to be able to work independently and that the roles they performed took significant pressure off those higher up in the business, alleviating stress which in turn is likely to boost the retention rates of those professionals.

Fundamental to the success of such a strategy, however, is a clear outline of career progression and succession planning so that those that have been brought in to fill these roles can see they have a future in the business. Employers and their HR Teams can often underestimate how important these aspects are, with some neglecting to mention training opportunities, for example.

Forging a path

Another development that promises to make this less opaque is the Career Pathways Framework which is being devised by the UK Cyber Security Council. This sets out the certifications and experience required to progress within specialist fields but, until this is published, employers can make use of its Careers Route Map. The Chartered Institute of Information Security (CIISec) newly announced cyber-skills framework is also relevant and is geared towards helping organisations develop recruit and retain talent.

In many ways, both the TtV strategy and Career Pathways could significantly reform how we recruit in cybersecurity. Today, the TtV has at its heart the tasks and skillsets required to mitigate a particular risk which then helps determine the role that needs to be filled.

However, as more formal structures such as the Career Pathways become established, we can expect it to become easier to identify what those roles are.

What this also means is we’re less likely to see the current criticisms levied against hirers regarding job descriptions. The same DCMS report found that “job specifications were often unrealistic in their demands, tried to recruit multiple roles in one, or were not reflective of the actual requirements for the role on offer” with hirers sometimes using other adverts as templates. One recruiter got around this by speaking with the hirer and drafting the spec themselves, which shows just how much of a problem this is at present.

If job specifications are more task-based and recruiting is more risk-led we can expect to see clearer, more targeted recruiting. This will see the diminishing talent we have applied much more wisely and help to ensure more cybersecurity staff remain in the profession. Not only will this help to ensure the business is then better protected but it will also make the HR team’s job that much easier.

Amelia Brand is the Editor for HRreview, and host of the HR in Review podcast series. With a Master’s degree in Legal and Political Theory, her particular interests within HR include employment law, DE&I, and wellbeing within the workplace. Prior to working with HRreview, Amelia was Sub-Editor of a magazine, and Editor of the Environmental Justice Project at University College London, writing and overseeing articles into UCL’s weekly newsletter. Her previous academic work has focused on philosophy, politics and law, with a special focus on how artificial intelligence will feature in the future.

Latest news

Govt unveils visa support scheme to help scale-ups hire global talent

Fast-growing firms will receive visa fee support and recruitment assistance under plans designed to help businesses attract international talent and expand.

Employment tribunal roundup: Disability testing, discrimination evidence, procedural fairness and training access

Recent EAT rulings examine disability discrimination, religion and belief claims, procedural fairness and access to workplace training opportunities.

Half of grieving workers handle ‘death admin’ during work hours, study finds

Many bereaved employees are managing probate, pensions and financial paperwork during working hours, with four in five saying it affects their ability to work.

Lauren Webb: Empowering women to lead the way in analytics and AI

Women remain wildly underrepresented in technical and digital leadership, making up just 22% of the UK’s AI talent. It’s jarring.
- Advertisement -

Employers urged to balance flexibility and fairness as England’s World Cup campaign begins

Employment lawyers are advising organisations to plan ahead for leave requests and workplace flexibility as the 2026 FIFA World Cup gets under way.

Amy Coleman on uncertainty and pressure at work

“Many of you shared feelings of uncertainty and pressure as the work evolves.”

Must read

From ‘sick note’ to ‘fit note’

The Government intends to launch a new ‘fit note’...

Catherine Trombley: teamwork, the truth about teams

If you’ve had your performance review lately, you have...
- Advertisement -

You might also likeRELATED
Recommended to you