A quick search on the term skills gap will show that a lot of people have varying opinions on the subject. This is because different people mean different things when they use the term ” but one thing is certain: skills in our day and age are hard to measure and manage, because rapid rates of technological advancement demand new skills that schools aren’t teaching yet and which aren’t supplied by labor markets.
As an example, James Bessen, writing for the Harvard Business Review, uses graphic design to illustrate’ his point:
Until recently, almost all graphic designers designed for print. Then came the Internet and demand grew for web designers. Then came smartphones and demand grew for mobile designers. Designers had to keep up with new technologies and new standards that are still changing rapidly ¦ graphic arts schools have had difficulty keeping up. Much of what they teach becomes obsolete quickly and most are still oriented to print design in any case. Instead, designers have to learn on the job, so experience matters ¦ [as such] the labor market for web and mobile designers faces a kind of Catch-22: without certified standard skills, learning on the job matters but employers have a hard time knowing whom to hire and whose experience is valuable; and employees have limited incentives to put time and effort into learning on the job if they are uncertain about the future prospects of the particular version of technology their employer uses ¦ Under these conditions, employers do have a hard time finding workers with the latest design skills.
Taken that way, the idea of the skills gap becomes more tangible, especially in relation to Big Data analytics and Cyber Security, two industries that are affected most by the proliferation of technology in the modern world.
The Data Analytics Talent Gap
Villanova University’s online resources indicate that up to 78 percent of businesses have experienced challenges filling open data-analytics positions over the last 12 months.
In addition, 59 percent of organizations expect the number of positions requiring analytics skills to increase significantly over the next five years, they write. It is worth noting that the number of data scientists who reported a shortage of qualified candidates in their field rose from 79 percent in 2015 to 83 percent in 2016.
International Data Corporation (IDC) predicts that by 2018, there will be a need for 181,000 people with deep analytical skills, and a requirement five times that number for jobs with the need for data management and interpretation skills, as reported by business.com.
So what are the skills that Data Analysts need that are so elusive? Referring once more to Villanova’s online resources:
- 69 percent of data scientists perform exploratory data-analytics tasks, which in turn form the basis for more in-depth querying.
- 61 percent perform analytics with the aim of answering specific questions
- 58 percent are expected to deliver actionable insights to decision-makers
- 53 percent undertake data cleaning
- 49 percent are tasked with creating data visualizations
- 47 percent leverage data wrangling to identify problems that can be resolved via data-driven processes
- 43 percent perform feature extraction
- 43 percent have the responsibility of developing data-based prototype models
- data scientists say they spend up to 60 percent of their time cleaning and aggregating data
When you take into account the programming languages that data scientists need to know, the situation gets even more complex:
- 56 percent of job listings for data scientists include in-depth understanding of SQL
- 49 percent of job listings listed Hadoop
- 39 percent listed Python
- 36 percent listed Java
- 32 percent listed R
While the basic descriptions of these skills stays the same, the understanding of the actual minutiae that it takes to execute these skills is changing constantly. Cybersecurity experts face a similar dilemma.
The Cybersecurity Skills Shortage
The major problem with cybersecurity nowadays is that it’s becoming harder to employ serious talent within the cybersec realm, while at the same exact time, cybercrime is cheaper and more accessible than ever. Criminals who have never tried their hand at cybercrime before are able to purchase ready-to-deploy malware and even hacking-as-a-service (HaaS). On the other hand, cyber professionals need to keep their skills up to date so that they will be able to, according to ECPI University:
- Install or maintain hardware and software infrastructure that deters hackers
- Analyze, identify and patch system vulnerabilities
- Implement solutions aimed at defusing zero-hour attacks in real time.
- Recover from partially or fully successful cyber attacks
Not only are these skills dependent on keeping up with every inch and corner of your cyber-infrastructure, which is always changing, but it’s up to the cybersecurity professional to keep up with all of the different types of malware and tactics cybercriminals employ.
Jeff Kauflin, writing for Forbes, calls cyber security the fast-growing job with a huge skills gap. In his article, he interviews Bill Bonifacic, who leads the cyber security practice at recruiting firm blueStone Recruiting. Bonificac says that the position of security analyst is in high demand.
Security analysts work to prevent and mitigate breaches on the ground, writes Kauflin. In 2012 there were 72,670 security analyst jobs in the U.S., with median earnings of $86,170. Three years later, there were 88,880 such analysts making $90,120.
Maryville University’s online cybersecurity resources further show that there are staff shortages in the industry. They report that:
Enterprises looking to fill infosec positions bore out that 59 percent of respondents received five applicants for every open position “ but according to 37 percent of these business leaders, less than 25 percent of them are qualified ¦ Furthermore, it often takes companies a long time to fill open cyber security jobs. While 45 percent of respondents to the… report stated that it took two or three months to bring in new talent for these positions “ with 30 percent of that 45 saying three months “ 26 percent said it took 6 months, and 6 percent haven’t been able to make these hires at all.
Without workers skilled enough to fill these positions, there could be major repercussions for companies in need of data analytics and cybersecurity measures. Fortunately, new technology can help shoulder some of the burden of these skills shortages.
AI and Enterprise Immune Systems
The beauty of AI and automation is that rote tasks requiring repetition and/or attention to minutiae can be automated, leaving human minds to focus on big-picture ideas. The problem with the rapid pace of technological advancement our species has adopted is that we haven’t adopted a rate of learning to match it. To compensate, we’ve begun to place our faith in automation and machine learning.
In the above section, it’s mentioned that data scientists say they spend up to 60 percent of their time cleaning and aggregating data. This is because the amount of data for one person to first look through and then try to extract meaning from are staggering, and they are growing every day. Not only that, but human minds often miss correlations and casualties that a machine might catch, even if the machine has never seen an example of it before. Case in point comes from the way that cyber security analysts are now approaching AI deployment in their industry.
They’re calling this an Enterprise Immune System (EIS). As Scott Rosenberg, writing for Wired explains, the cybersecurity industry has always had a fortress mentality: Firewall the perimeter! Harden the system! But that mindset has failed… bad actors are going to get past your heavily guarded gate, into your network ¦ That’s why some in the industry are beginning to focus less on sealing borders from outside threats and more on sensing bad behavior inside as it happens ”when it can be stopped. They’re shifting from military metaphors to the language of biology; they’re designing immune systems rather than barricades.
Darktrace is a cybersecurity program that uses machine learning to define what normal looks like on a network, and then reports on any deviation from this norm as it happens in real time. Rosenberg interviewed Darktrace CEO Nicole Eagan in the same Wired Article.
The big challenge that the whole security industry and the chief security officers have right now is that they’re always chasing yesterday’s attack… It’s flawed, because the attackers keep changing the attack vector, says Eagan. Yet companies have spent so much money on tools predicated on that false premise. Our approach is fundamentally different: This is just learning in real time what’s going on, and using AI to recommend actions to take, even if the attack’s never been seen before.
With automation and AI able to pick up the jobs that humans need them to, the ever-changing fringe-mechanics, the rote tasks, data analytics and cybersecurity both might find it is less difficult to hire employees with the proper skill sets. A practitioner in a field would need to know the overarching ideas in that field, and let the AI fill in for any gaps in knowledge. Some might disagree that this is a positive thing, let alone a possibility ” but only time will tell. Until then, Darktrace is content proving the notion possible through practice:
They recently won Enterprise Security and Cloud Security Awards at Computing’s Security Excellence Awards in London.