Q1. What were some of the main takeaways from Immersive Labs' Cyber Workforce Benchmark report? What surprised you the most?
Our Cyber Workforce Benchmark report answers some of the industry’s burning questions about human cyber capabilities. We analyzed data from over 2,100 organizations, 500,000 exercises and simulations, and 1,500 incidents in order to provide data-driven insights into organizational cyber resilience.
Perhaps most surprising was just how long cybersecurity teams inside large organizations take to develop the skills necessary to defend against breaking threats (96 days, on average!) In just one example, a critical, actively exploited vulnerability in popular mail transfer agent Exim took over six months for security teams to master.
At the same time, four of the five fastest developed skills in 2021 were linked to Log4j, which was an especially high-profile vulnerability. These findings suggest that organizations prioritize the cyberattacks hitting headlines over others which could still be just as impactful. This also highlights the need for organizations to continually assess, exercise, and build their security capabilities in a structured and deliberate way that prioritizes measurable outcomes over activity.
In addition, we found that across all sectors, security professionals are much more interested in improving their skills on the left side of the MITRE ATT&CK framework, with 31% of all exercises focusing on Initial Access, Execution, and Persistence. By examining the time it took for certain labs to be completed, we discovered that security professionals found the high-profile compromise and initial access skills the most difficult and time-consuming to master.
Q2. What does Cyber Workforce Optimization mean? What does it take to get there?
Organizations of all types have found that tools and technology are not enough to ensure operational resilience and that cybersecurity capabilities of their workforce are just as critical to reducing risk. People deserve as rigorous an approach to evaluation and testing as technology and tools.
Immersive Labs is solving the world’s cybersecurity “People” problem by pioneering an entirely new approach to measuring, building, and proving cyber readiness and resilience in order to effectively respond to the latest cyber threats. We call this Cyber Workforce Optimization (CWO).
Cyber Workforce Optimization requires more than a renewed emphasis on improving cybersecurity capabilities. It demands a fundamental mindset shift when it comes to the human element of cybersecurity. Customers tell us that they want to stop thinking about training, certifications, and learning as “check the box” activities without tangible results. We believe that cybersecurity capabilities should be continuously measured, compared with benchmarks, and improved using real-world scenarios and realistic simulations.
Gaps must be identified, invested in, closed, and re-tested. Individuals and teams should have the opportunity to continuously exercise their skills to ensure they are prepared to respond to the latest threats. As organizations adopt this data-driven approach, they are better able to up-level their cybersecurity programs to achieve their business goals around risk reduction and cyber resilience.
In order to work towards true Cyber Workforce Optimization, organizations must follow a few steps, ensuring that measurement and evidence are at the heart of each:
- Exercise. Provide teams and individuals with the opportunity to practice and demonstrate capabilities. Rather than unengaging, unrealistic tests and paper exercises, this requires realistic simulations that evaluate hands-on skills.
- Measure. Analyze data on both individual and team capabilities and their impact on risk exposure. Benchmark current knowledge, skills, and judgment against industry peers.
- Upskill. Plug any gaps the exercises expose. Armed with granular data, organizations can target specific business risks as well as individual needs. This will optimize the impact of exercises, providing much greater results than applying a blanket approach across the business.
- Prove. Use individual and team performance data to provide evidence of cybersecurity capabilities and resilience. This can be used to demonstrate risk reduction and compliance to the Board of Directors, insurance companies, and other third-parties.
Cyber Workforce Optimization is never truly “achieved”. It is a goal to continuously strive towards with a relentless focus on measurement and improvement.
Q3. What do you expect customers will want to hear from Immersive Labs at Black Hat USA 2022? What do you expect will be top of mind issues for them?
In 2022, organizations are looking to do more with less and efficiently build their cybersecurity capabilities to measurably reduce risk and improve resilience. Given economic headwinds, CISOs are looking to focus their resources on areas that will generate results that they can prove to their CEOs and Board of Directors. Cyber security professionals want to bolster their capabilities so they can quickly and efficiently manage real-world threats when product resources may be limited.
Top of mind for our customers is their need to understand their human cyber capabilities and how they compare to industry benchmarks in order to identify gaps and areas of strength. They need to build their capabilities to improve their incident decision-making and response times. And they need to hire, build, and retain skilled cybersecurity talent while facing an industry-wide skills gap. According to Cybersecurity Ventures, the number of unfilled cybersecurity jobs across the globe grew to 3.5 million in 2021. That number will only grow.
While legacy training is unable to guarantee hands-on skills relevant to current threats, everything Immersive Labs does for our customers is measurable and focused on building skills according to the latest threat intelligence. We’re looking forward to talking to organizations at Black Hat USA 2022 about how they can leverage the principles of Cyber Workforce Optimization to efficiently measure, build, and prove cyber readiness and resilience.