75% of companies 'lack enough security staff'
Most firms struggle to fend off cyber attacks due to few skilled workers


Three-quarters of companies do not have enough skilled security workers to protect against cyber attacks, a new study suggests.
Security company Tripwire's research revealed that out of 500 IT security employees surveyed, only 25% felt that their companies' IT departments had enough people with enough skills to combat a major cyber security breach.
This lack of trained professionals is putting organisations at risk, and 66% of respondents reported that it was actively increasing security risks in their organisation.
Almost 70% have tried to plug the skills gap in their organisation with security but that's not enough, according to Tripwire's senior director of IT security and risk strategy, Tim Erlin.
"Having the right tools is only part of the solution," he said. "A lack of cybersecurity skills not only degrades an organisation's ability to respond to incidents, it also inhibits organisations from developing and deploying effective prevention."
This survey, along with many similar ones, reveals that there simply aren't enough people working in the cybersecurity field, but it also gives a clue as to why. The industry currently has a huge problem when it comes to the recruitment and development of new infosec professionals.
When questioned, over 70% of respondents admitted that they or their organisation found it difficult to hire cybersecurity experts, and almost 80% said that they had no facilities for increasing the expertise of existing security staff, and over half reported experiencing problems with staff retention.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Hiring, training, and retaining security personnel is clearly a problem for many companies, but while almost 30% admitted that their existing programmes were ineffective, a full half of respondents stated that they had no such programmes at all.
"Cybersecurity is a growth industry for employees," Erlin said, "and supply is falling far short of demand. Smart organisations need to establish effective programs for educating and developing employee skills around information protection."
Adam Shepherd has been a technology journalist since 2015, covering everything from cloud storage and security, to smartphones and servers. Over the course of his career, he’s seen the spread of 5G, the growing ubiquity of wireless devices, and the start of the connected revolution. He’s also been to more trade shows and technology conferences than he cares to count.
Adam is an avid follower of the latest hardware innovations, and he is never happier than when tinkering with complex network configurations, or exploring a new Linux distro. He was also previously a co-host on the ITPro Podcast, where he was often found ranting about his love of strange gadgets, his disdain for Windows Mobile, and everything in between.
You can find Adam tweeting about enterprise technology (or more often bad jokes) @AdamShepherUK.
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
Symantec snaps up LifeLock for $2.3 billion
News Security company acquires identity theft protection firm
By Rene Millman Published
-
Legal experts predict 600% surge in data protection disputes
News Disputes could rocket by six times in next five years
By Rene Millman Published
-
AdultFriendFinder hack 'exposes 412 million users'
News Account details were reportedly stored in plaintext
By Jane McCallion Published
-
Experts say UK must keep pace with cyber threats
In-depth Industry welcomes £1.9bn investment, but highlights skills shortage
By Rene Millman Published
-
EU has "serious concerns" over WhatsApp data sharing
News The European Commission has delivered a letter to WhatsApp demanding greater clarity
By Dale Walker Published
-
Was Mirai malware behind Dyn DDoS attack?
News IoT-powered malware may have caused Twitter, Spotify & Reddit outage
By Jane McCallion Published
-
UK's National Crime Agency joins fight against ransomware
News No More Ransom hopes to publish new decryption tools with 13 new members
By Joe Curtis Published
-
How to handle personal data (without getting hacked)
In-depth The IT Pro Panel asks how you can handle personal data safely
By Joe Curtis Published