Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Management & Strategy

Majority of U.K. Business Would Hire a Hacker to Address Cyber Security Challenges: Survey

A survey of companies in the U.K. more than half are willing to hire a hacker to help deal with a shortfall of cyber-security professionals.

A survey of companies in the U.K. more than half are willing to hire a hacker to help deal with a shortfall of cyber-security professionals.

The finding comes from a KPMG survey of 300 senior IT and HR professionals in organizations with 500 or more staffers. Some 74 percent said they are facing new challenges in cyber-security, and 70 percent admit their organization “lacks data protection and privacy expertise.” In addition, the majority said they are wary of their organization’s ability to assess incoming threats.

Even though 60 percent said they have a strategy for dealing with any skills gaps, 57 percent agree it has become more difficult to retain staff in specialized cyber skills in the past two years. In addition, 60 percent said they are worried about finding cyber experts who can effectively communicate with the corporate-side of the business and not just the IT department.

But the most interesting stat may be this – 53 percent of respondents say they would consider using a hacker to bring inside information to their security teams. Roughly the same number (52 percent) said they would also consider recruiting an expert even if they had a previous criminal record.

“The increasing awareness of the cyber threat means the majority of U.K. companies are clear on their strategy for dealing with any skills gaps,” said Serena Gonsalves-Fersch, head of KPMG’s Cyber Security Academy, in a statement. “However, they wouldn’t hire pickpockets to be security guards, so the fact that companies are considering former hackers as recruits clearly shows how desperate they are to stay ahead of the game.  With such an unwise choice on the menu, it’s encouraging to see other options on the table.”

“Rather than relying on hackers to share their secrets, or throwing money at off the shelf programs that quickly become out of date, U.K. companies need to take stock of their cyber defense capabilities and act on the gaps that are specific to their own security needs,” she added. “It is important to have the technical expertise, but it is just as important to translate that into the business environment in a language the senior management can understand and respond to.”

Written By

Marketing professional with a background in journalism and a focus on IT security.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

More People On The Move

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

CISO Strategy

SecurityWeek spoke with more than 300 cybersecurity experts to see what is bubbling beneath the surface, and examine how those evolving threats will present...

CISO Conversations

Joanna Burkey, CISO at HP, and Kevin Cross, CISO at Dell, discuss how the role of a CISO is different for a multinational corporation...

CISO Conversations

In this issue of CISO Conversations we talk to two CISOs about solving the CISO/CIO conflict by combining the roles under one person.

CISO Strategy

Security professionals understand the need for resilience in their company’s security posture, but often fail to build their own psychological resilience to stress.

Management & Strategy

SecurityWeek examines how a layoff-induced influx of experienced professionals into the job seeker market is affecting or might affect, the skills gap and recruitment...

Cybersecurity Funding

2022 Cybersecurity Year in Review: Top news headlines and trends that impacted the security ecosystem