4 ms·
Schneier is on the money again and it's painfully true. Elsewhere I've said why cybersecurity is a losing battle and a significant part of the problem is the e
by nonrandomstring 3y ago
Schneier is on the money again and it's painfully true.
Elsewhere I've said why cybersecurity is a losing battle and a
significant part of the problem is the educational and HR side of
things [0].
There's a motivation and engagement problem. Generally, people have no
idea what cybersecurity is. It scares them, and they either don't
want to talk about it or will let any random "expert" assuage or
distract them. That's made fertile ground for a flourishing
certificate and compliance racket of clueless gatekeepers who only
make things worse, because the field is so deep and dynamic this stuff
is ossified before the ink is dry.
I also see that it's an entirely reactive affair. People and companies
will spend zero attention and money on cybersecurity until they get
hacked, then run around spending their fortune like there's no
tomorrow of stupid things. This attracts opportunists who are often
as bad as the ransom-ware gangs that preyed on them in the first place.
Unpleasant as it is to say, it's the fault of the companies who do not
value the deep and hard won knowledge of those who could help
them... a cohort who are growing older and giving up caring.
And frankly, universities are fucked, to put it as politely as I
can. At least in Britain, nobody who can do this stuff wants to be
within a clear country mile of these crumbling institutions with their
awful pay and working conditions and total lack of vision.
Elsewhere we have military and intelligence groups playing at 1980s
"cyberwars", completely missing that the real war is going on within
our culture.
So what we're left with is a technologically over-extended society
that cannot meet the maintenance needs of its structure.
As educators, sadly we might set many young people up for failure and
struggle since the expectations and demands of "the industry" don't
match what they can deliver. Consequently the high churn leads to even
more disaffection and panic in the industry.
Worse still is the fate of women in cybersecurity. Again and again
I've seen equally qualified candidates go into a firm on the same pay
grade, the guy gets out on "pen-testing" and the woman gets put on
front line support (read: stress and abuse hell). The women are almost
universally demeaned and given "agreeable" public facing work, while
the men are streamed into "technical" roles. The tragedy is, it's
usually the females who seem to understand the higher-level strategic
and operational wisdom that is so desperately missing.
[0] https://www.linuxtoday.com/developer/why-we-cant-teach-cybersecurity/ https://www.linuxtoday.com/developer/why-we-cant-teach-cyber...
- 0xbadc0de5 3y agoI agree with almost all of this. Well said! My only disagreement is with the culture aspect and treatment of women. I'm just not seeing what you're describing. Our industry is so starved for talent that anyone who shows interest and competence is immediately welcomed and allowed to choose the path that most interests them. Not to say bad apples don't exist, but they're the exception, not the rule.
- nonrandomstring 3y agoI didn't see it myself until I got much more interested in the outcomes and employment journeys of students. And I can only attest to the microcosm of reality I see with my own limited eyes. For what it's worth, 10 years ago I wouldn't have seen gender disparity because we simply wouldn't have had those women on the programme in the first place - so progress of course, but in small steps. I suppose it's also amplified by being in an area where we're so desperate to grow good people that it feels galling and frustrating to see anyone left by the wayside in such times. Maybe I am not noticing the young lads who are similarly sidelined, but are less vocal.