About
Subscribe

Skills needed for SA's IT security

Lebo Mashiloane
By Lebo Mashiloane
Johannesburg, 08 Apr 2014

Although SA's IT infrastructure is well-equipped to address threats posed by emerging technologies, the lack of skills development remains a huge concern for the country's IT security segment.

So says Greg Griessel, consulting systems engineer security solutions at Cisco SA.

Sharing his insights with ITWeb on the recent release of Cisco's annual security report, Griessel said he believes that the emergence of new technologies such as the cloud, social media and bring your own device (), means new security challenges for organisations on the continent who, unlike SA, sit with very limited IT capabilities and infrastructure.

"South Africa is on top of its game with regards to the infrastructure and technologies needed to square up to the new security threats," says Griessel, noting, however, that the major concern for the country is a lack of skills development, with only 5% of the country's schools offering IT at high school level.

There's a demand in the market place for skilled IT professionals in areas of security and , according to Griessler, pointing out that 40 000 to 70 000 jobs are available in the IT industry annually, yet the country is unable to match this demand.

This is further backed by a University of Cape Town study which mentions that, considering the centrality of ICT skills to sustaining the economic growth across different industries, the ICT skills shortage in the country is perturbing.

"The information age means that data is the new value source; even at government level, countries are spying on one another for it. This requires new sets of skills that are relevant to the current scenario instead of playing catch-up to emerging technology trends," Griessel explains.

Social media is one example, he adds, where individuals are now used as entry points when targeting organisations.

"So, through someone's social network profile, hackers are able to determine what their interests are and send malware through a link relevant to these interests. This can then be easily spread to the company's entire network from just one click."

Griessel adds that technology strategies such as BOYD are also inputs for blurring the organisations' network lines.

"The growing smartphone adoption, which has infiltrated the workplace, results in most companies being unaware of what happens inside their networks and skews their ability to determine what's valuable to the company's network," he says. "The threats have become so sophisticated that one single attack's lifespan can take place continuously, with different layers of the company's security breached, over a six-year period without any alerts."

Griessler concludes that if SA is to remain on par with the rest of the world regarding IT security capabilities, the same focus and investment given to the consumer side should be spread across to areas of training, skills uptake and development.

Share