Connect with us

Hi, what are you looking for?

HEADLINES

McAfee report finds automation, use of gamification as key to winning against cybercriminals

The landscape for cyberthreats is growing, both in complexity and volume. According to the report, 46 percent of respondents believe that in the next year they will either struggle to deal with the increase of cyberthreats or that it will be impossible to defend against them.

McAfee, the device-to-cloud cybersecurity company, released Winning the Game, a new report investigating key challenges facing IT security organizations in terms of threats, technology investment and skills required to win the fight against cyberthreats. The survey revealed that concerted efforts to increase job satisfaction, automation in the Security Operations Center (SOC) and gamification in the workplace are key to beating cybercriminals at their own game.

The landscape for cyberthreats is growing, both in complexity and volume. According to the report, 46 percent of respondents believe that in the next year they will either struggle to deal with the increase of cyberthreats or that it will be impossible to defend against them. Further complicating the dynamics of the competition between security responder and cybercriminal is the cybersecurity skills crisis. Survey respondents believe they need to increase their IT staff by nearly a quarter (24 percent) in order to manage the threats their organizations are currently facing, while 84 percent admit it is difficult to attract talent and 31 percent say they do not actively do anything to attract new talent.

“With cybersecurity breaches being the norm for organizations, we have to create a workplace that empowers cybersecurity responders to do their best work,” said Grant Bourzikas, chief information security officer at McAfee. “Consider that nearly a quarter of  respondents say that to do their job well, they need to increase their teams by a quarter, keeping our workforce engaged, educated and satisfied at work is critical to ensuring organizations do not increase complexity in the already high-stakes game against cybercrime.”

Automation

The growing threat landscape and recruitment and retention challenges facing the cybersecurity workforce demand automation as a key ingredient in the game against cyberattackers. By pairing human intelligence with automated tasks and putting human-machine teaming in practice, automated programs handle basic security protocols while practitioners have their time freed up to proactively address unknown threats.

Advertisement. Scroll to continue reading.
  • Eighty-one percent believe their organization’s cybersecurity would be safer if it implemented greater automation
  • A quarter say that automation frees up time to focus on innovation and value-added work
  • Nearly a third (32 percent) of those not investing in automation say it is due to lack of in-house skills

Gamification

Gamification, the concept of applying elements of game-playing to non-game activities, is growing in importance as a tool to help drive a higher performing cybersecurity organization. Within organizations that hold gamification exercises, hackathons, capture-the-flag, red team-blue team or bug bounty programs are the most common, and almost all (96 percent) of those that use gamification in the workplace report seeing benefits. In fact, respondents who report they are extremely satisfied with their jobs are most likely to work for an organization that runs games or competitions multiple times per year.

  • More than half (57 percent) report that using games increases awareness and IT staff knowledge of how breaches can occur
  • Forty-three percent say gamification enforces a teamwork culture needed for quick and effective cybersecurity
  • Three-quarters (77 percent) of senior managers agree that their organization would be safer if they leveraged more gamification

The Next Generation of Cyberthreat Hunters

To address the shortage skilled cybersecurity workers, the report findings suggest that gamers, those engaged and immersed in online competitions, may be the logical next step to plugging the gap. Nearly all (92 percent) of respondents believe that gaming affords players experience and skills critical to cybersecurity threat hunting: logic, perseverance, an understanding of how to approach adversaries and a fresh outlook compared to traditional cybersecurity hires.

  • Three-quarters of senior managers say they would consider hiring a gamer even if that person had no specific cybersecurity training or experience
  • More than three quarters (78 percent) of respondents say the current generation entering the workforce, who have been raised playing video games, are stronger candidates for cybersecurity roles than traditional hires
  • Seventy-two percent of respondents say hiring experienced video gamers into the IT department seems like a good way to plug the cybersecurity skills gap
Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

This new solution for Sophos XDR and Sophos MDR continuously monitors customer environments for identity risks and misconfigurations and scans the dark web for...

White Papers

As bots get better at bypassing CAPTCHAs, authentication has grown more elaborate – meaning users have become more accustomed to jumping through hoops to...

HEADLINES

Thomas Luu, Country Manager at Viettel Cyber Security: “As the Philippines accelerates towards digitalization faster than ever, the importance of security must not be overlooked....

HEADLINES

The Philippines’ the Cybercrime Investigation and Coordinating Center (CICC) has recently raised alarm over the proliferation of deepfakes, particularly AI-generated pornographic content. The call...

HEADLINES

From identity theft to deepfakes, fraud is evolving fast, leaving businesses struggling to keep up. A fragmented, siloed system creates critical blind spots: when...

White Papers

Despite the Chinese government’s internet restrictions and eCrime crackdown, anonymized marketplaces remain central to cybercrime activity across Asia Pacific and Japan (APJ).

HEADLINES

13% of critical alerts went unnoticed or misclassified, giving attackers an opening to exploit weak points such as identity recovery workflows and lateral movement...

HEADLINES

HP Threat Researchers now warn that the growing use of multiple, often uncommon, binaries in a single campaign is making it even harder to...

Advertisement