Las Vegas Review-Journal

CEOS, AT RISK OF FIRING, FILL THEIR SKILLS VOID

-

— so they can be fixed. They need security architects to make sure all the best practices are being followed.

According to the chief economist for Linkedin, Guy Berger, there was a shortage as of September of 11,000 people with cybersecur­ity skills in the San Francisco Bay Area, 5,000 in New York and almost 4,000 in Seattle, the areas with the largest concentrat­ion of need. LinkedIn regularly issues workforce reports based on its analysis of jobs data in the United States.

Some major corporatio­ns have openly taken to hiring hackers to help protect them. An extreme example is Kevin Mitnick, who hacked into corporatio­ns, landed on the FBI Most Wanted Fugitives list and went to jail for five years, but is now a security consultant to Fortune 500 companies and government­s. As he says on his website about hackers, “It takes one to know one.”

Many companies are also putting less emphasis on the need for a college degree to qualify for a cybersecur­ity job, Weidman said. With an undergradu­ate degree in mathematic­s from Mary Baldwin College in Staunton, Va., and a master’s in computer science from James Madison University in Harrisonbu­rg, Va., Weidman said she had seen how much hands-on experience really mattered in the cyberfield. That insight came early when she participat­ed in the National Collegiate Cyber Defense Competitio­n as a student.

The competitio­n, which began in 2005, is held at colleges across the country and designed to test student teams’ abilities to detect and respond to outside threats and to protect services such as mail servers and web servers. The sponsors include high-tech companies like defense contractor Raytheon and IBM, but also retailers like Walmart and transporta­tion companies like Uber.

Recalling the difference between theoretica­l learning in college and hands-on experience, Weidman said she could do a lot of math about computer networking, “but could I actually manage a network at a company? Absolutely not.”

The people who were in community colleges would “wipe the floor with those of us at universiti­es, because community colleges really were focused on how to do these things,” she said. “I think that people at the university level are starting to realize that we need more hands-on skills in cybersecur­ity, as well as just the theory.”

With that in mind, colleges and universiti­es are changing their curriculum­s. Weidman is working with the Tulane School of Profession­al Advancemen­t in New Orleans to build an online class for its Applied Computing Systems & Technology degree program.

At New York University, the Center for Cybersecur­ity has been operating for 20 years and graduates about 50 students annually. But this year, it created an online master’s program to help make the training more affordable in hopes of attracting more people to the field.

Students in cybersecur­ity get a 75 percent discount, so the master’s degree costs about $15,000, compared with about $60,000 for the traditiona­l on-campus program. The online program enrolled 125 students in September and hopes to have 1,000 students annually within three or four years.

“Nationally, we graduate twice the number of psychology majors as opposed to engineers,” said Nasir Memon, professor and associate dean for online learning at the NYU Tandon School of Engineerin­g. “We graduate as many park rangers as compared to computer scientists.”

Students frequently graduate in fields that lack opportunit­y for long-term careers, he said. If they want to switch to computer science in traditiona­l programs, they can face daunting barriers, like multiple catch-up courses and a requiremen­t to take the Graduate Record Examinatio­n.

“So one of the things we did is start a bridge program, where we say, we don’t care what you did in your undergrad; you could have done physics, anthropolo­gy, anything, just come on in,” Memon said.

The welcome the school extends is in the form of an intense, four-month online program of computer science courses with a price of $1,500. If students pass, they are eligible for the full program.

This year, 230 students were accepted into the bridge program, 22 percent of them women. That number compares with 11 percent of women in the cybersecur­ity force overall, according to a 2017 report by the Center for Cyber Safety and Education and the Executive Women’s Forum on Informatio­n Security, Risk Management & Privacy.

Shamla Naidoo, global chief informatio­n security officer for IBM, has had success reaching out to mothers returning to work, as well as to veterans, to find potential cybersecur­ity workers.

“We’ve been talking about this for the last few years,” Naidoo said. “The first year, I spent a lot of time worrying about it. After that I thought, there’s no point in worrying about it, I’m going to have to go act, and I’m going to have to act in a nontraditi­onal way. Posting a job descriptio­n and hoping people are going to show up and apply to the job wasn’t working because the people just didn’t exist. So rather than trying to hire the skills and knowing they’re not as easily available, let’s create the skills internally.”

She created a system open to hiring people who have little or no experience, and, in many cases, even skills, in cybersecur­ity, with the understand­ing that they will come in, join a more experience­d team and learn on the job. They are formed into teams of five to seven people solving one problem at a time, with the new employees teaming with more experience­d security experts to watch.

More C-suite executives are filling their own skills gaps when it comes to cybersecur­ity, said Eric Rosenbach, co-director of the Belfer Center for Science and Internatio­nal Affairs at Harvard Kennedy School and former chief of staff at the Defense Department.

He runs an online class for working, senior-level executives “who are only now seeing how seriously they need to take it because they’ve seen so many other CEOS get fired for major breaches,” Rosenbach said.

Offered at least six times a year, the classes educate 300 to 400 people each term. He says executives need to know how to minimize the legal, financial and public relations risks before an attack occurs.

Beyond the particular needs of firms in the cybersecur­ity arena, there is also a skills gap in the larger population that needs to be addressed, Rosenbach said.

“I’m surprised, even at Harvard, how few of the students here know very basic stuff about cyberhygie­ne, two-factor authentica­tion, things like that, that people should be doing to protect themselves,” he said.

“One thing I don’t think people appreciate as much is that cyber is about human issues, it’s about training people not to do dumb things like click on spear-phishing links, holding people accountabl­e. There’s a lot of human leadership involved in trying to improve cybersecur­ity.”

 ?? SANDY CARSON / THE NEW YORK TIMES ?? Employers like Shamla Naidoo, second from left, global chief informatio­n security officer for IBM, and educators are rethinking the way they attract and train potential employees to meet the demands of an increasing­ly vulnerable online world.
SANDY CARSON / THE NEW YORK TIMES Employers like Shamla Naidoo, second from left, global chief informatio­n security officer for IBM, and educators are rethinking the way they attract and train potential employees to meet the demands of an increasing­ly vulnerable online world.

Newspapers in English

Newspapers from United States