The severity of the Log4j crisis highlights the real-world consequences of the Cybersecurity Workforce Gap
(ISC)² – the world’s largest nonprofit association of certified cybersecurity professionals – today published the results of an online poll examining the Log4j vulnerability and the human impact of the efforts to remediate it. Cybersecurity professionals from around the globe shared their experiences and opinions, revealing the severity and long-term consequences of the Log4j attack for both security teams and the organizations they protect.
Key findings from the poll include:
- Industry professionals across the globe responded swiftly following the December 2021 disclosure of Log4j; nearly half (48%) of cybersecurity teams gave up holiday time and weekends to assist with remediation
- 52% of respondents said their team collectively spent weeks or more than a month remediating Log4j
- 64% of cybersecurity professionals believe their peers are taking the zero-day seriously
- 23% noted that they are now behind on 2022 security priorities as a result of the change in focus
- More than one in four (27%) professionals believe their organization was less secure while remediating the vulnerability
“The main takeaway from the Log4j crisis and this data is that dedicated cybersecurity professionals are spread thin and need more support to effectively remediate zero-day exploits while still maintaining overall security operations,” said Clar Rosso, CEO, (ISC)². “Log4j is one critical vulnerability of many and it’s only a matter of time before the next novel attack occurs. To avoid burnout—the consequences of which can lead to catastrophic breaches—organizations must support their cybersecurity teams by expanding their recruiting efforts, providing more resources and investing in the development and retention of their existing staff.”
Cybersecurity Professionals Defending Multiple Fronts at Once
There haven’t been any major breaches attributed to Log4j to date, in large part due to the hard work and dedication of the cybersecurity community. According to the poll, as a result of the reallocation of resources and the sudden shift in focus that was required, security teams reported that many organizations were less secure during remediation and fell behind on their 2022 security priorities.
This landscape of unsteadiness is what the Cybersecurity Workforce Gap looks like in practice. According to the (ISC)² 2021 Cybersecurity Workforce Study, the gap stands at 2.72 million professionals globally, with 60% of respondents reporting that the workforce shortage is placing their organizations at risk.
When a cybersecurity team is staffed appropriately, the disclosure of severe vulnerabilities doesn’t become a “fire drill” as the team has the resources to investigate and remediate in a timely manner. Investing in the development of existing staff is one of the many factors that contribute to higher retention. Retaining staff means the organization spends less time and resources on continuously hiring and training new staff members, which, in cybersecurity, has a positive impact on the overall cybersecurity posture. Additionally, well-trained cybersecurity personnel with institutional knowledge are more prepared to tackle Log4j-like threats.
Visit AITechPark for cutting-edge Tech Trends around AI, ML, Cybersecurity, along with AITech News, and timely updates from industry professionals!