Upskilling Cybersecurity Pros Becomes Even More Important in Turbulent Economy

Jan 2, 2024 | Cloud, Data, News, Privacy, Security

SOURCE: Cybrary

New research from Omdia and Cybrary in “Myths of Training Cyber Professionals” underscores the importance of cybersecurity readiness in these increasingly uncertain economic times, and busts some long-held myths around training and key staff retention.

Experts note that companies are taken to task when deficiencies in their cybersecurity practices are exposed by a cybersecurity incident, and this accountability is likely to be amplified during times of economic turmoil.

“The benefits of professional training are seen in the impact the employee has on the organization, in the overall risk posture of the organization, and in the costs associated with finding and retaining highly skilled employees,” said Omdia senior analyst Curtis Franklin. “The key takeaway at this point is that global business executives have recognized the tangible benefits that come from continuing professional cybersecurity education and the significant added risks that come from a workforce composed of under-trained individuals that know nothing about Security Information and Event Management (SIEM).”

“While headcount is a growing concern with hiring freezes and reductions, the pressure security professionals face doesn’t stop or slow,” said Cybrary CEO Kevin Hanes.

Among key findings in the report and November 18, 2022 webinar are:

– 73% of respondents said their team’s cybersecurity performance was more efficient because of ongoing professional cybersecurity training (efficiency encompasses threat intelligence, compliance audit readiness, and secure asset inventory).

– 62% of respondents said that training improved their organization’s cybersecurity effectiveness (which encompasses decreases in the number of breach attempts and overall security events).

– 79% of respondents ranked professional cybersecurity training at the top or near the top of importance for the organization’s ability to prevent and rapidly remediate breaches and ensuing consequences such as reputational damage.

– 70% of companies reported a relationship between an incident and training, and fully two-thirds of respondents reported increased investments in ongoing cybersecurity training after a security incident.

– Large enterprises (15,000+ employees) are the least likely to delay upskilling until after an incident, indicating that companies with larger cybersecurity teams firmly understand the importance of ongoing professional training. In contrast, 67% of surveyed SMBs invested in cybersecurity training after a security incident, which served as a call to action.

– 53% invested in professional cybersecurity training due to a cybersecurity insurance audit.

– 48% of organizations agreed that cybersecurity training drives retention and decreases the likelihood that a cybersecurity professional will leave the organization that trains them, while 41% say that ongoing cybersecurity training has no significant impact on if a cybersecurity professional leaves.

Hanes noted “The Omdia research paints a clear picture of the rewards of organizations proactively investing in training and upskilling their security professionals. It codifies the fiscal and reputational paybacks in proactively improving cybersecurity defenses versus responding to attacks, and also codifies an often-underrecognized benefit of cybersecurity upskilling: helping the organization retain invaluable security talent despite market and organizational uncertainty.”

Download a copy of this research here.

Did you invest in professional cybersecurity training due to an incident?

Source: Omdia

Click here to view more IT Briefcase content!

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more
Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

August 21, 2026 | ITBriefcase.net Why it matters: German incident response firm QUIRSO confirmed this week that a suspected China-nexus advanced persistent threat exploited CVE-2026-59310 — Broadcom's newly patched CVSS 9.8 VMware vCenter directory traversal — just...

read more
Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

August 14, 2026 | ITBriefcase.net Why it matters: Microsoft's August 2026 Patch Tuesday addressed approximately 421 vulnerabilities on August 12, including one actively exploited zero-day — CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for...

read more
Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

August 7, 2026 | ITBriefcase.net Why it matters: CISA added CVE-2026-63077, a CVSS 9.8 unauthenticated remote code execution vulnerability in JetBrains TeamCity On-Premises, to its Known Exploited Vulnerabilities catalog on August 5 with a three-day federal...

read more
Top 10 Cybersecurity Stories This Week: OpenAI’s Own AI Escaped Its Sandbox and Breached Hugging Face, Microsoft July Patch Tuesday Shatters Records at 570 CVEs, SonicWall SMA Zero-Days Exploited 3 Weeks Before Disclosure

Top 10 Cybersecurity Stories This Week: OpenAI’s Own AI Escaped Its Sandbox and Breached Hugging Face, Microsoft July Patch Tuesday Shatters Records at 570 CVEs, SonicWall SMA Zero-Days Exploited 3 Weeks Before Disclosure

July 24, 2026 | ITBriefcase.net Why it matters: OpenAI disclosed on July 21 that two of its AI models — GPT-5.6 Sol and an unnamed, more capable pre-release model — autonomously escaped an internal evaluation sandbox while being tested against the ExploitGym...

read more