Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Monday, 15 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Expert Insight: Outdated Recruitment Methods Are Impeding The Global Cyber Army

James McLaughlin, UK VP of WithYouWithMe, explores the road to inclusive recruitment in cybersecurity

by Guru Writer
April 23, 2024
in The Guru Cyber Allyance
Expert Insight: Outdated Recruitment Methods Are Impeding The Global Cyber Army
Share on FacebookShare on Twitter

Cybersecurity is ‘inclusive’ by nature: no one is exempt from the fallout of the expanding cyber threat landscape. The notion, therefore, that some groups of individuals are offered fewer opportunities to join the cyber industry than others is frankly absurd.

ISC2’s latest Cybersecurity Workforce Study gives us a snapshot into the supply and demand of cybersecurity talent – and it’s not good news. While the cyber workforce has grown by 8.7%, the skills gap has increased by 12.6%, which equates to roughly 4 million empty roles.

From a DE&I perspective, we have seen gradual improvements; ISC2 reveals that gender and ethnic breakdowns of the new workforce have undergone a considerable shift.

But there’s a lot more that needs to be done. There’s a major paradox at play here: the industry needs more people, yet entire groups of individuals are currently being overlooked.

And it all comes down to the hiring process.

The limitations of CV-led hiring practices

CVs have been the key that unlocks new job opportunities for decades. But when you really think about it, it’s such a restrictive approach.

How can someone possibly capture their skills, their work ethic, their true value in one or two A4 pages? The reality is, they can’t, meaning employers are making critical hiring decisions based on a snapshot of the candidates’ capabilities.

The main piece of information that is impossible to grasp from a CV is the candidate’s potential to succeed in the specific role being recruited for. Past experience can only tell an employer so much, and this is ultimately where talented individuals from non-traditional employment backgrounds fly below the radar.

Our own research shows that 62% of organisations still rely solely on reference checks, CVs and cover letters to screen candidates. With cybersecurity skills in high demand, it’s time we encourage the pursuit of non-traditional candidates to drastically expand talent pipelines and plug the global skills gap.

ISC2 research also revealed that employers value experience over education. Much of the industry will see this as a good thing, but what they haven’t yet realised is that this is still the crux of the skills crisis.

Not all good candidates will have a cybersecurity background. For example, people looking to make a career change are unlikely to demonstrate the ‘expected’ experience, but may still have valuable skills to contribute to the sector.

If job advertisements continue to outline rigid ‘must have’ role requirements like educational credentials, past job titles and years of experience, then huge numbers of talented individuals will be excluded.

It’s time to recognise that experience isn’t everything.

The road to inclusive recruitment 

The tech sector’s growing shift towards skills-based hiring prioritises a candidate’s demonstrable ability, considering the skills they’ve already learned, but also the skills they have the potential to acquire.

Implementing a skills-first strategy requires a shift in HR practices and a broader change management programme, but in doing so it allows the previously underserved to unlock new opportunities.

Instead of relying solely on CVs and credentials, skills-first hiring uses data-driven assessments, aptitude tests, and psychometric evaluations to identify a candidate’s relevant skills and suitability for a variety of roles. By focusing on capabilities and potential, a skills-first approach is able to reduce unconscious bias in the hiring process, opening up opportunities to a more diverse pool of candidates, and enabling organisations to find the best fit for each position, then train the technical skills.

Importantly, this approach can open up a whole new world of possibilities for the cybersecurity sector. Traditional recruitment approaches typically disadvantage underrepresented groups including neurodivergent individuals and women. As a result, viable talent is being overlooked.

For example, our research reveals that autistic individuals typically score 10% higher in their digital skills aptitude than those with neurotypical traits, and score higher than the general population in verbal reasoning. Also, almost a third (32%) of neurodivergent individuals score higher in spatial awareness and 10% higher in digit symbol coding.

Cyber is an industry with pressing needs to modernise recruitment practices. Hiring needs to consider more than just experience – it needs to assess potential.

 

 

 

ShareTweet
Previous Post

Mandiant’s M-Trends Report Reveals New Insights from Frontline Cyber Investigations

Next Post

Google’s Core Update is ‘Biggest’ Algorithm Update in History

Recent News

Check Point Expands MSP Platform with AI Security Capabilities and Unified Bundles

From Playbooks to Adaptive Workflows: How MSSPs Are Evolving Security Operations with Agentic AI

June 15, 2026
Nagomi Control Brings CTEM Into Action

2 in 5 Organisations Experienced Cyber Incidents Tied to Suppliers in Past Year

June 12, 2026
Certes Research Warns Legacy Systems Are Biggest Barrier to Quantum Security Readiness

KnowBe4 Expands Gamified Training Library With Launch of “Spot the Vish” Game

June 12, 2026
Swan Song For Infosec’s Most Gripping Awareness Training Series: The Inside Man Goes Out With A Star-Studded Bang

Swan Song For Infosec’s Most Gripping Awareness Training Series: The Inside Man Goes Out With A Star-Studded Bang

June 12, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol