Skip to main Content
Article

The benefits of cybersecurity certification

Tony Deslandes
  • Date: 25 February, 2021

For those looking to enter the cybersecurity industry, the world of certifications can be a confusing one. What value do you get from the hard slog of achieving a certification and is it really worth it?

The latest Cybersecurity Workforce Study from (ISC)² looks at the various challenges faced by cybersecurity professionals and, in particular, at the benefits of certification. It also provides an insight into the skills that cybersecurity professionals are especially keen to acquire.

(ISC)² is an international, non-profit membership association for information security leaders, with more than 150,000 members. The survey in question collected data from 3,790 security professionals at all levels, drawn from small, medium and large organisations throughout North America, Europe, Latin America and the Asia-Pacific region, so there is undoubtedly a high degree of authority in the findings.

One overarching finding certainly underlined the prominence of certification within the cybersecurity industry. The survey revealed that almost two thirds (63%) of cybersecurity professionals are currently pursuing, or planning to pursue, some sort of security-related certification within the next year. These certificates are seen as critical for their professional and career growth, with many cybersecurity professionals earning multiple certifications throughout their careers. 

A certification demonstrates the depth of the holder’s cybersecurity knowledge and expertise, which has been independently validated by the certification body. This is important from an employability perspective, as it means that any organisation seeking to recruit a cybersecurity professional can hire a certified professional in the full confidence that the person is skilled, experienced and will perform their tasks ethically.

The types of certifications that employers require are either vendor-specific certifications (e.g. Cisco, Microsoft, etc.) or vendor-neutral certifications (e.g. CCSP, CISM, etc.). 

The study also found that within organisations, senior managers and other employees valued certified cybersecurity professionals for a number of reasons:

For senior managers:

  • Stronger skills in key cybersecurity areas
  • Greater confidence in the ability to meet security challenges
  • Current knowledge of security and privacy trends 

For employees: 

  • Greater confidence in security strategy and practices 
  • Confidence and validation of staff expertise 
  • Greater confidence among customers and clients 

Other benefits of certification cited generally by employers included reducing the impact of a security breach, knowing that technology and best practices are up-to-date, and enhancing the organisation’s reputation within its given industry. 

One particularly interesting point to emerge from the study was the fact that cybersecurity professionals not only find value in holding certifications themselves, but also in knowing that their colleagues and managers have gained the same kind of knowledge that these credentials certify. It is for this reason that security competence is increasingly seen as vital not just for specialist cybersecurity staff, but increasingly for managers and even senior executives within the organisation.

 

In-demand skills

Another reason that certifications are important, and why cybersecurity professionals seek them out, is to demonstrate their expertise as technology changes and new industry trends emerge. For example, while the cloud is not new, cloud services remain a challenge to secure. It’s no surprise that 40% of the cybersecurity professionals surveyed across roles, age brackets and company sizes named cloud security as the skill they most needed to develop in the next two years, and no doubt an area in which they would seek to demonstrate their knowledge through certifications.

The full list of skills that cybersecurity professionals are planning to acquire over the next two years, according to the report, include:

  • Cloud computing security (40%)
  • Risk assessment, analysis and management (28%) 
  • Security analysis (28%)
  • Governance, risk management and compliance (26%)
  • Threat intelligence analysis (26%)
  • Application security (25%)
  • Security engineering (24%)
  • Security administration (23%)
  • Data management protection (22%)
  • Penetration testing (22%)

So, going back to our original question – is certification really worth it?  Well, in a profession with so many entry points, certifications can help demonstrate and validate skills and experience. Furthermore, many employers undoubtedly place a high value on certifications, so possessing one can be a major differentiator for those looking to move jobs. And increasingly, training and certification are viewed as critical to addressing the skills shortages that are currently prevalent in the cybersecurity world.

Browse Related Topics:

Tony Deslandes

Senior Portfolio Manager

Tony Deslandes joined Global Knowledge in 2012 and now works as a Solutions Architect and Portfolio Manager across a diverse range of Portfolios, including cybersecurity, Best Practice, DevOps and Leadership & Business Skills, working with vendors and accreditation bodies to define the Go To Market Strategy for GK UK. He has a passion for business, technology and training. He also collects watches and is fascinated by time – use yours wisely