Menu

Call us on 03450 21 21 51

Why a CISO is the hardest role to recruit for
The SRM Blog

Why a CISO is the hardest role to recruit for

Tim Deakin

Written by Tim Deakin

27th January 2021

Share this article

CISO recruitment

The importance of a competent Chief Information Security Officer to an organisation is only growing. But with few senior professionals in the marketplace holding the relevant skills and experience, CISO vacancies can be a headache to fill.

The rise of ransomware, phishing attempts, GDPR challenges and cybersecurity breaches have put businesses in a precarious position. Companies across all industries are under constant threat from cyberattacks, yet finding the right personnel to shape a more secure future is easier said than done. In particular, mature businesses in need of a seasoned Chief Information Security Officer can often find themselves short of credible candidates.

As the market rapidly evolves, job specifications are struggling to keep up – not least because those hiring senior cyber personnel often don’t have the expertise to identify the appropriate criteria themselves. In fact, the question is: without a background in cyber, how is a CEO, CTO or COO expected to differentiate between a stellar candidate and one whose skills lie more in a well-worded CV?

Then there’s the issue of salary. Good CISOs don’t come cheap and for a non fee-earning role within a business, it can be all too easy for brands to go cheap and cheerful rather than invest in someone with the right qualities but knows their true value.

 

Most companies still aren’t investing enough in cybersecurity

Despite a growing awareness of cybersecurity threats, many companies continue to underinvest in effective protection. In tumultuous times, companies look for ways to tighten budgets, and all too often cybersecurity is seen as a luxury rather than an essential. Even as our understanding of cybersecurity grows, many companies are still settling for basic training, a robust firewall and a template business continuity plan.

Yet the fast-changing threat landscape suggests that a shift in mindset is needed now. According to Verizon, the number of phishing email messages that are being opened in error has risen from 23 percent to 30 percent, and the gap between the time to compromise and the time to discovery has risen from 62 percent to 84 percent – a statistic that is inevitably getting worse as a result of the new remote working model implemented by many organisations.

But while businesses continue to tighten their purse strings in a tough economic climate, this makes the likelihood of finding a suitable CISO significantly harder.

Look beyond an in-house team member and tap into the expertise of an embedded consultant

For those organisations that understand the need for a highly qualified and experienced cyber security professional but don’t perhaps have the resources to bring in a full-time CISO, one appealing alternative is to employ an embedded consultant. Entrusting security responsibilities to a consultant gives businesses a chance to retain freedom and flexibility, while seeing cybersecurity needs met.

At SRM, our VirtualCISO™s have worked with businesses across a broad range of sectors to provide all the benefits of an in-house team member without some of the potential drawbacks often associated with a permanent member of staff.

A VirtualCISO™ isn’t simply an arms-length consultant; it’s an experienced professional able to integrate fully with an organisation’s teams to help shape the future of policies, processes, systems and procedures. And because our VirtualCISO™s are part of the broader SRM team, we always have the capacity to scale up resources quickly as a client’s business grows.

Click here to find out about the Virtual CISO™ and Virtual ISM™ services available from SRM and put your business security in safe hands.