In this interview with Help Net Security, Daniel Clayton, VP Global Security Services and Support at Bitdefender, talks about the cybersecurity skills shortage gap and the role of automation in improving the work of cybersecurity professionals.
I think the realization is relatively widespread today. High profile attacks over the last five years put cyber on the boardroom agenda and ensured enterprises are paying attention to security and Security Operations Centers (SOCs). This is why services like MDR are growing so fast. If we look at investments in technology driving automation across SOCs, its still a relatively new concept and tends to be bolted on later to solve for scale, so enterprise budget holders are less invested than security teams are.
The teams that are building and delivering security operations or outsourcing MDR, understand the huge role automation plays because they live it every day. Yet, we still see organizations applying a traditional model of building something manual and reliant on research and then plugging in automation as needed. Thats just where we are as an industry and thats how most enterprises with security teams approach the automation process. Teams need to start implementing on top of automation from the start; if you build for automation first, you can build for things that you didnt even know you could automate.
Effective threat hunting and incident response are reliant on informed decision-making about what has happened, what is happening now and what is most likely to happen next. Decision-making is reliant on context and context comes from multiple sources (telemetry, threat intel, knowledge bases etc.) and getting it in front of the analyst fast enough for he/she to make an informed decision. That is what automation can help solve.
We as security teams know were going to be attacked. The nature and scale of looming attacks are out of our control, but what we can control is how readily equipped our security teams are to respond. We can quickly apply the knowledge of the environment (what tech do we have? what tools do we have running?, etc.) our knowledge of the attacker (the way they operate, the tactics, techniques and procedures they use, etc.) and discern what bad actors objectives are, whats their intent, their likely course of action and what are they ultimately trying to achieve. Then we can make an informed decision about response actions that we can take to defeat the attack.
The same goes for the benefits of automation when it comes to threat hunting. Modern security organizations can automate that backend legwork so analysts can spend less time triaging cases and more time honing that experience, expertise and intuition needed to develop relevant hypothesis about potential attacks and deliver hunts that prove or disprove those hypothesis.
The human element is the decision making engine behind what we do and the automation provides the timely delivery of context to quickly and effectively do it well. The value in automation comes when leveraged in tandem with human expertise, not a dilution of one over the other.
What automation does is drive more information and context to the analysts/cybersecurity professionals to augment their work, but its the circumventing of knowledge that the analysts bring to the table that cant be replicated by technology tools. These tools automate enrichment which is provides the analysts with the context of the environment, but does not replace the need for the human intuition that you get when you combine experience and expertise. It is intuition that enables analyst to detect and respond to activity that tools just dont see.
My view of the skill shortage is not that there are a shortage of people, its a problem with a shortage of experienced experts out there that can do the job needed in todays threat landscape. This might not be a popular opinion in the market, but in my experience, theres a wide margin of difference between analysts on paper and analysts that can be productive in a modern security operation.
Automation is not the answer to the cybersecurity professionals shortage gap, but it can deal with much of the lower skilled repeatable work to enable analysts to focus on the tasks set them apart from technology-driven solutions.
Take security out from under the IT organization. If you lump security into the IT organization, then security becomes IT work and thats not what it is. All too often I see organizations that have system administrators that have minimal security experience or ambition, yet they find themselves leading security teams. Dont hire IT professionals only to turn them into security professionals by default. Security needs to be treated as a career path not a job.
Rethink the role of analysts. An analyst traditionally looks at data post-event and makes recommendations about what should be done moving forward to prevent incidents. But thats not the role anymore they are cyberwarfare operators. They work in real time, triaging complex security environments that require analysts to know their field, know their environment and have the confidence to make decisions. As an industry, we need to have a more clear delineation between various analyst roles theres a difference between an analyst that works in a SOC versus a vulnerability or forensic analyst.
Diversity. The conversations taking place around diversity, equity and inclusion are industry agnostic. But, specifically within the cybersecurity field, its an area that needs more attention. As an industry we need to do a better job of appealing to women in cyber and tech roles at large in order to challenge the status quo.
Career management. A frustration I frequently see and hear is around a common misconception that analysts chase money. That may be true sometimes, but mostly if you dont manage your teams career then they will manage their own. If you cant present your team with a clear upward trajectory for their career paths, and confidence that as an organization, youre building career momentum for them within your organization, then they will move on. Oftentimes, the people I hear complain about the career shortage gap arent providing basic fundamentals around career and people management thats expected from an employee base.
Invest in education and training. One of the main areas we focus on during the hiring stage and early career development are: aptitude and ability to think like an analyst. Moreover, can an analyst think from the perspective of a potential attacker? Having that natural aptitude is almost something you cant teach, but with this in mind we invest in education models and build employee training that cater to exactly what we need from them in these roles. Were transparent in expectations and provide this education throughout their entire career.
This is a fast moving, disruptive industry clouds, microservices, etc. all of these technology platforms bring with them risks that can be exploited by bad actors. It is critical that our teams know these platforms as well as the bad guys do and understand the vulnerabilities associated whether inherently or in the way they are deployed across the customers environment. And that wont happen without frequent training in the newest technologies.
Even with a highly skilled team, in just two years time that team will be outdated and no longer applicable to the threat landscape and cybersecurity environment. Making team members better than they were when they arrived, not only makes us better, but drives retention and leaves you with high quality people at a price lower than if you hired from the street, or worse, from another company.
Read more:
- Automation Personnel Services - Temporary Staffing ... [Last Updated On: March 25th, 2016] [Originally Added On: March 25th, 2016]
- Automation | Define Automation at Dictionary.com [Last Updated On: March 25th, 2016] [Originally Added On: March 25th, 2016]
- Automation | Definition of automation by Merriam-Webster [Last Updated On: March 25th, 2016] [Originally Added On: March 25th, 2016]
- Automation | The Car Company Tycoon Game [Last Updated On: March 25th, 2016] [Originally Added On: March 25th, 2016]
- Automation - Wikipedia, the free encyclopedia [Last Updated On: March 25th, 2016] [Originally Added On: March 25th, 2016]
- Automation - Cloud process & workflow automation | Microsoft ... [Last Updated On: June 29th, 2016] [Originally Added On: June 29th, 2016]
- Riverside Automation - Machine Controls [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- Automation: The Car Company Tycoon Game Windows - Mod DB [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- System Integration | Industrial Automation [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- WinAutomation - Smart Macro Recorder, Web Automation ... [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- Automation Solutions - Home [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- The Automation Conference [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- Rohtek Automation [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- JL Automation, LLC | Home Automation, A/V Automation [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- Four fundamentals of workplace automation | McKinsey & Company [Last Updated On: August 27th, 2016] [Originally Added On: August 27th, 2016]
- Leviton Security & Home Automation [Last Updated On: August 27th, 2016] [Originally Added On: August 27th, 2016]
- EVA Automation [Last Updated On: September 6th, 2016] [Originally Added On: September 6th, 2016]
- News | Automation | The Car Company Tycoon Game [Last Updated On: September 6th, 2016] [Originally Added On: September 6th, 2016]
- Automation - The Car Company Tycoon Game on Steam [Last Updated On: September 6th, 2016] [Originally Added On: September 6th, 2016]
- Test automation - Wikipedia, the free encyclopedia [Last Updated On: September 6th, 2016] [Originally Added On: September 6th, 2016]
- Job Seekers - Automation Personnel Services [Last Updated On: October 8th, 2016] [Originally Added On: October 8th, 2016]
- Custom Automation & Machine Design | Automation GT [Last Updated On: October 31st, 2016] [Originally Added On: October 31st, 2016]
- iAutomation [Last Updated On: October 31st, 2016] [Originally Added On: October 31st, 2016]
- Test automation - Wikipedia [Last Updated On: November 16th, 2016] [Originally Added On: November 16th, 2016]
- Automation - Official Site [Last Updated On: November 19th, 2016] [Originally Added On: November 19th, 2016]
- Beckhoff Automation - Wikipedia [Last Updated On: November 21st, 2016] [Originally Added On: November 21st, 2016]
- Automation - Security Hyperstore [Last Updated On: November 21st, 2016] [Originally Added On: November 21st, 2016]
- IT Automation - BMC [Last Updated On: November 29th, 2016] [Originally Added On: November 29th, 2016]
- ID Automation [Last Updated On: November 29th, 2016] [Originally Added On: November 29th, 2016]
- The Best Home Automation Systems of 2016 | Top Ten Reviews [Last Updated On: December 24th, 2016] [Originally Added On: December 24th, 2016]
- What is Home Automation? | Home Automation Systems [Last Updated On: December 24th, 2016] [Originally Added On: December 24th, 2016]
- Beyond Automation - hbr.org [Last Updated On: December 25th, 2016] [Originally Added On: December 25th, 2016]
- Build automation - Wikipedia [Last Updated On: December 26th, 2016] [Originally Added On: December 26th, 2016]
- Home automation - Wikipedia [Last Updated On: January 10th, 2017] [Originally Added On: January 10th, 2017]
- Automation | Food Engineering [Last Updated On: January 13th, 2017] [Originally Added On: January 13th, 2017]
- Home Automation - Enerwave Home Automation [Last Updated On: January 14th, 2017] [Originally Added On: January 14th, 2017]
- Automation - DESHAZO [Last Updated On: January 14th, 2017] [Originally Added On: January 14th, 2017]
- Robots, Automation, EOAT, Grippers, Conveyors, Guarding [Last Updated On: January 26th, 2017] [Originally Added On: January 26th, 2017]
- Werner Electric | Automation [Last Updated On: January 28th, 2017] [Originally Added On: January 28th, 2017]
- Automationtechies | Automation Engineering Recruiting [Last Updated On: January 28th, 2017] [Originally Added On: January 28th, 2017]
- Automation - Mazak Corporation [Last Updated On: January 28th, 2017] [Originally Added On: January 28th, 2017]
- Automation | Technologies | Systems | Integrator ... [Last Updated On: January 28th, 2017] [Originally Added On: January 28th, 2017]
- Test Automation Services for Development of Regression ... [Last Updated On: January 28th, 2017] [Originally Added On: January 28th, 2017]
- Carlo Gavazzi Automation Components [Last Updated On: January 30th, 2017] [Originally Added On: January 30th, 2017]
- UI Automation Overview - msdn.microsoft.com [Last Updated On: February 5th, 2017] [Originally Added On: February 5th, 2017]
- New telecom transformation goals require service automation - TechTarget [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Global Hazardous Waste Handling Automation Market: By Products ... - Business Wire (press release) [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- 2M Automation wins IoT support from Schneider - Electronics EETimes (registration) [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Futures Shaped by Automation and Catastrophe: Peter Frase on Capitalism's Endgame - Truth-Out [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Automation expected to displace insurance underwriters, real estate brokers - CIO Dive [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Automation, robots could replace 250000 public sector workers in the next 15 years - Computer Business Review [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Design Automation Conference - Business Wire (press release) [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- The Perks Of Automation And The Risks: Why To Think Twice About Getting Into That Driverless Uber - Forbes [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Lib Dems Should Embrace Automation of the Workforce - Liberal Democrat Voice [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Voices Reinventing enterprise finance by overhauling AP automation - Accounting Today [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- How Accountants Can Use Automation Their Advantage - Accountingweb.com (blog) [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- DFLabs Launches the First Security Automation and Orchestration Platform based Upon Supervised Active Intelligence - Business Wire (press release) [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- QAD Automation Solutions is Honda Approved - Yahoo Finance [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- VIDEO: Going Big on Automation in a Small Footprint Facility - ENGINEERING.com [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Building a better model of human-automation interaction - Phys.Org [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- AlixPartners examines automation in manufacturing and logistics management - Logistics Management [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Report: Test automation is increasing - SD Times - SDTimes.com [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Automation is the unavoidable future of the economy - The Daily Cougar [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- GM's Cruise Automation Is Testing An App to Order Self-Driving ... - Fortune [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Speeders beware: Legislation would allow automation crackdown ... - SFGate [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Orbita Ingenieria: New Age Terminal Automation - Port Technology International [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- A Sharper Focus on the Edge - Automation World [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Rockwell Automation Surged 10% in January as Growth Picked Up Steam - Motley Fool [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Most people are optimistic about workplace automation, social data suggests - ZDNet [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Improving Behavior Through Automation of Vehicle Systems - School Transportation News (blog) [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- 'We employ insane levels of automation' Kris Canekeratne - Times of India [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- Why Don't We See More Automation in Federal Networks? - Nextgov [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- Technobabble: Automation and the modern worker - CIO Dive [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- Readers Write (Feb. 12): The moose population; jobs, start-ups and automation; diversity in the funny pages - Minneapolis Star Tribune [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Automation Nightmare: Philosopher Warns We Are Creating a World Without Consciousness - Big Think [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Automation can replace bureaucrats and save taxpayers money - Hot Air [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Automation can revitalize the US workforce - Fox News [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- TigerStop hopes to ride automation to new heights - The Columbian [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- Hexadite Unveils Custom Playbooks Following One Millionth Automated Cybersecurity Investigation - Yahoo Finance [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- NEC updates postal automation system for Hongkong Post - ETCIO.com [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]