In today’s digital age, cybersecurity has become a top priority for businesses and organizations around the world. However, there is a growing concern about the shortage of skilled cybersecurity professionals to meet the demand.
This has resulted in a highly competitive market for cybersecurity talent, with businesses struggling to find the right candidates for the job.
In this article, we explore some of the strategies used by businesses to close the cybersecurity talent gap.
We speak to Jeremy Hughes, Technical Services Manager at Acora, who shares his insights on what businesses should look for in potential candidates, how to find talent, and the biggest mistakes to avoid when seeking cybersecurity talent.
What’s the best way to find skilled cybersecurity talent in a tight market?
When interviewing a potential candidate, I focus on the applicant’s previous experience to get them through the door, seeing what they can evidence and how well they can talk around the subject they are discussing. Does it sound like they are reading from a textbook? Do they have a full understanding of why and what they are recommending? Are they able to answer questions and apply thought to scenarios, or are they in the ‘textbook’ stage?
With our clients – it’s never one size fits all. We must consider their risk profile/market they are in/what budgets they have for cyber, therefore an applicant must understand that every client’s scenario is different, and we cannot speak to each client in the same way or have the same solution for everyone. In an interview, they must be able to demonstrate agility to jump from customer to customer and support their needs no matter how custom they may be.
What are the key qualifications to look for in applicants?
We are fairly qualification agnostic. I’ve hired people without degrees, but it is a fact that 95% of the workforce does have a degree. We have an affiliation with Bournemouth university, and we know the Cyber Security Management course works well with their role in our company.
There doesn’t necessarily have to be a list of qualifications to get them in the door, as they become part of Acora, we put everyone through certifications and vendor programmes to get them up to speed. The cybersecurity space is always changing, so we must always keep learning.
During the probationary period of 3/6 months, there is a lot to take in. Potential employees must learn to be product agnostic and learn the core solution of how you can drive that one specific product. It’s about having a broad understanding and asking the right questions during that probationary period to learn the ropes.
What’s an “out of the box” way to find talent?
It’s been really helpful to find placement students from Bournemouth University, then we send them off to complete the final year of their course, and then offer them full-time employment once they’ve finished university.
We also undergo a simple practical test during the interview, where I show the applicant one of our products or services, then explain why we are doing it in this way, and then ask them what they think of it and how they think it’s an improvement of what other companies are doing. This demonstrates a high level of understanding from the applicant and allows us to determine if they are a good fit and will have ideas for us to improve in the future.
What’s the biggest mistake organisations make when seeking cybersecurity talent?
The biggest mistake is narrowing your port of applicants, by scaring people off from even applying due to the qualification requirements. Many listed job roles require more experience or more qualifications than is necessary for the role. For example, any job ad over 40k requires CISP, which is a course that takes around 6-12 months, with an 8-hour exam on everything you could possibly need to know about cybersecurity – it’s vast and occasionally unnecessary for a lot of roles.
Is there anything else you would like to add?
Since integration, Acora has found that there is a real desire within the business for employees to learn more across the two functions – cyber and IT. Cyber is integral in our business, so the cyber team are preparing Acora with training guides so that we can up-skill across the business.




