Although the two teams are often intertwined, the scope of work is different. IT teams manage and plan networks, hardware, data storage and processing as well as developing strategies to meet the needs of management with an eye at the assigned budget. Security teams focus on the protection of the organization information system infrastructure, the resiliency to internal or external threats and the defense of the confidentiality, integrity and availability of the greatest asset: data. As we can see, the roles are different. While IT personnel have the skills and knowledge to build the system infrastructure in order to manage, store and transmit data, the security team is tasked with ensuring the safety of the substructure by creating the conditions to safeguard information. This includes not only technical solutions and vulnerability monitoring but also programs designed to target what is considered one of the greatest vulnerabilities in the cybersecurity chain: the user.  Security professionals, in their effort to mitigate risks for the organization, are also asked to foster a culture of cyber awareness to increase the responsiveness of staff.

Building a security team

Can IT and security professionals coincide? In a smaller organization, possibly. It is also possible to outsource the task to professional companies external to the organization.  But when building an internal team, especially in medium or large organizations, what can management consider? The task is to create a group that is focused on the discovery of threats and the understanding of possible vulnerabilities, and which is able to help staff become cyber-savvy. This cannot be the job of systems administrators or architects, who are already tasked with managing the infrastructure and do not necessarily have the specific knowledge to tackle cybersecurity.  However, finding the right talent in the IT group ready to move into security roles is definitely possible and a great opportunity for most companies. According to ISACA’s State of Cybersecurity 2020 research, 62% of surveyed professionals stated their company’s cybersecurity team is understaffed and 57% actually have unfilled positions on their team. Training personnel from within can be a winning move, as long as no shortcuts are taken and the right training and knowledge is acquired prior to being entrusted in a safeguarding role.

Why is it a good idea to staff security teams with IT team personnel?

There are a number of reasons why a company should first look within its available staff. First of all, these professionals might already be the right talents for the job. Managers can survey interest in the newly-created group as well as canvass the background and interests of employees to see if anyone has already the proper knowledge. While combing the staff for possible options, it is important for the company to conduct a skills gap analysis. This undertaking can get insight into the IT teams’ current capabilities in terms of security and identify the best options for cyber-related training. An accurate skills assessment provides visibility of the deficiencies in the team at both an individual and group level. What’s more, this could verify which members are more fit for specific tasks or roles that might match their experience. Turning part of the IT team into a security team has also the benefit of including professionals that are already part of the workforce which have already proved their IT competence, their worth and support to the organization’s goals. A number of transferable skills and knowledge can make this option a winning one, and security teams can be enriched by including professionals with a different background and a fresh perspective. In fact, these employees would already know the organization, its values and practices as well as understanding its vulnerabilities, capabilities and data to be protected.  Security personnel might not manage the company networks but do need an in-depth understanding of its setup and the many requirements the systems are asked to meet. For example, they would already know all the required software the company needs to operate and can better evaluate the possible vulnerabilities. This knowledge in current employees is invaluable. Security personnel may have already worked with and in the IT team, which puts them ahead of the game. Collaboration skills are essential and these employees have probably already proved themselves able to work not only in a team but, to a great extent, for that particular ad hoc group. They may have already been exposed to discussing and presenting reports to management.  What’s more, they’ll also have the pulse of the staff computer literacy and their cyber readiness. This would be essential in being able to address possible issues and create awareness programs that better fit the staff needs and capabilities. Of course, looking within onboarded players first is a great way to show appreciation to the current staff and possibly a way to offer professional development and promotion opportunities that build loyalty and boost morale. On-the-job training programs can further security education and coaching is a great way to increase security performance, but a comprehensive certification program can build on the IT knowledge the employees already have.  The IT team, in fact, probably already has related university degrees and possibly already general, comprehensive certifications to cover system administration competencies.  These skills can easily be augmented by creating a certification program that helps staff to achieve the security credentials needed for mid/advanced levels and that can help boost their competences. Certifications like the GIAC®️ Global Industry Cyber Security Professional (GICSP) and (ISC)² CISSP, for example, can be part of an efficient continuing education program.

Conclusion

With new threats emerging every day and cyberattacks on the rise, many organizations have opted to turn to members of their IT team to form a specialized security group able to lead the workplace and deploy the technologies available today to boost cybersecurity. Having a proper IT security team helps better manage risks, resolve vulnerabilities and reduce the time needed to detect issues and problems as they arise and decrease the time to recover from attacks.  Although outsourcing this function and hiring from the public are great options, investing in security education for members of the current IT team has many benefits and it is a viable option for many organizations.  

Sources

State of Cybersecurity 2020, ISACA Why Cybersecurity Awareness Is Important for Every Employee, BizLibrary How to conduct a skills gap analysis, Workable Technology Limited