Skip to main Content
Article

A cybersecurity round-up as businesses face cyber skills shortages

Matt Barclay
  • Date: 19 October, 2020

The increased demand for remote working is resulting in a scramble for cyber skills, but it’s not all doom and gloom. 

There’s good news for AWS customers using Amazon Elastic Kubernetes Service (EKS), as they can now utilise EC2 security groups to secure applications with varying network security requirements on shared cluster compute resources, making it easier to achieve network security compliance in clusters that are shared across multiple teams and applications.

There are many things to consider when it comes to running a secure Kubernetes cluster. Every organisation has specific security and compliance policies and often some are tightly coupled to security groups.

While Identity and Access Management (IAM) roles for service accounts solve the pod level security challenge at the authentication layer, many organisations’ compliance requirements also mandate network segmentation as an additional level of defence. Kubernetes network policies provide an option for controlling network traffic within the cluster, but do not support controlling access to AWS resources outside the cluster. For example, containerised applications frequently require access to other services running within the cluster, as well as external AWS services such as Amazon Relational Database Service (Amazon RDS) or Amazon ElastiCach.

Network security, however, rules that span pod to pod and pod to external AWS service traffic can now be defined in a single place with EC2 security groups, then applied to individual pods and applications with Kubernetes native APIs. This makes it easy to achieve network security compliance in clusters that are shared across multiple teams and applications.

And with the growing adoption of home working, this will be beneficial for many, not least remote technical teams who need on-demand access to infrastructure environments in order to develop, test and deploy their applications.

It is also good news for security professionals as it will make it easier to achieve network security compliance by running applications with varying network security requirements on shared computer resources. And any tool that enables security professionals to be more productive is welcome news, especially given the growing demand for cybersecurity skills as evidenced by recent research.

For example, a study by global non-profit body (ISC)2, the largest association of certified cybersecurity professionals, found that whilst there are approximately 2.8 million security professionals working worldwide, another 4 million trained professionals are still needed to close the cybersecurity skills gap. That’s a whopping increase of 145%.

The global pandemic has undoubtedly forced businesses to adopt home working in increasing numbers and exacerbated the shortage of IT professionals with appropriate cyber skills.

A report from recruitment firm Robert Walters and data provider Vacancysoft found that half of UK businesses do not have adequate cybersecurity provision to allow for complete remote working. Looking at Europe as a whole, the problem grows even larger, with 70% of companies claiming not to have a sufficient cyber security team. In total, Europe lacks some 140,000 cybersecurity workers!

“The move to remote working, cloud-based file sharing, as well as the rise in video calls and cashless transactions have highlighted to all businesses the importance of adequate IT security to allow for business continuity and protection from online breaches,” said Darius Goodarzi, Principal - Information Security and IT Risk at Robert Walters.

The pandemic has also unleashed more pressure on the security professionals tasked with trying to ensure that the growing numbers of employees working from home are able to do so efficiently and safely outside the confines of the traditional corporate IT network.

This pressure is heightened by concerns over adequate training in many quarters. The annual global study of cybersecurity professionals by the Information Systems Security Association (ISSA) and independent industry analyst firm Enterprise Strategy Group (ESG) reported that many organisations are not providing the right levels of cybersecurity training.

The study found that 36% of respondents believed their organisations should provide a bit more cybersecurity training, while 29% felt their organisations should provide significantly more training. Furthermore, 28% claimed there was not enough cybersecurity training provided for non-technical employees.

The study, now in its fourth year, concludes that training has been a perpetual shortcoming during that period and, worryingly, there seem to be no plans for improvement within many organisations...

Browse Related Brands:
Browse Related Topics:

Matt Barclay

Product Director for Cloud

Matt Barclay is Product Director for Cloud at Global Knowledge UK&I. He has many years of industry experience, with a focus on Cloud and Software Development. He works closely with our key vendors such as AWS and Microsoft to help drive success, address our customers' challenges and ensures our offerings are in line with current trends.