CLOSE

Specials

I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

Skip to: Curated Story Group 1
Life Sciences Review
US
EUROPE
APAC
CANADA

About Us

Conference

Partner With Us

  • US
    • EUROPE
    • APAC
    • CANADA
    • LATAM
  • Drug Discovery
    Antibodies
    BioTech
    Cell and Gene Therapy
    Clinical Trial
    Drug Discovery and Development
    Life Science AI
    Regenerative Medicine
    Therapeutics
  • Biomanufacturing
    Biomanufacturing
    Bioprocessing
    Blood Bank
    CDMO
    Clinical Laboratory
    CRO
    Life Science Testing
    Skin Care
    Supplements
  • Business Services
    Life Science Consulting
    Life Science Facility Service
    Life Science Financial Services
    Life Science Marketing
    Life Science Recruitment Firms
    Pharma Wholesale and Distribution
    Pharmacy Management
    Regulatory and Compliance
    Regulatory Services
  • Leadership Perspectives
  • Innovation Insights
  • Research
  • News
  • Magazines
  • CXO Awards
×
#

Life Science Review Weekly Brief

Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from Life Science Review

Subscribe

loading

Thank you for Subscribing to Life Science Review Weekly Brief

A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by our Life Sciences Review Advisory Board.

Regeneron Pharmaceuticals

Mark Leary, Global Chief Information Security Officer

A Ciso Challenge: Cybersecurity Talent Shortage

Mark Leary

Mark Leary

With the year-over-year increase of cybersecurity incidents, the demand for cybersecurity professionals has equally increased. A recent survey of over 1,200 IT leaders found that 60 percent struggled to recruit cybersecurity talent and 67 percent identified the lack of qualified candidates created greater risk to the company. In fact, 80 percent indicated that at least one data breach was attributable to the cybersecurity skill gap. There are simply not enough cybersecurity professionals and will require cybersecurity leaders to develop several strategies to address demand.


Reduce dependence on staff performing transactional tasks by using AI/ML and automation


One effective strategy associated with the cybersecurity talent shortage is to rely less on staff and more on intelligent automation. Cybersecurity staff personnel, mainly operators, spend an incredible amount of time pouring over logs and alerts, manually hunting for and remediating threats. As an alternative, Artificial Intelligence/ Machine Learning (AI/ML) powered threat identification, detection, and response – which learns and continually improves – can reduce analytical effort and improve situational awareness.


Cybersecurity staff, analysts and operators alike, also desire to be liberated from time-consuming, routine, transitional tasks so they can focus on more important work. Complementary to AI/ML, Security Orchestration, Automation, and Response (SOAR) solutions and tools that allow organizations to optimize cybersecurity operations in threat and vulnerability management, incident response, and cyber operations automation. SOAR solutions can save operational cycle-time, reduce manual errors, and allow cybersecurity staff to focus on important activities. In both cases, the investments can save both time and effort while potentially improving retention through more challenging and rewarding activities than deary and mundane tasks.


At Regeneron, we made the investment in applying SOAR-like automation technology in a novel manner. Our centralized security monitoring and alerting platform provides alert feeds to our security incident response case management tool that, in turn, creates security tickets based on predefined rules. Using Robotic Process Automation, we use orchestrators and bots to monitor their assigned ticket queues to perform standardized procedures, such as blocking spam or cleaning malware from devices, to free up our human staff to deal with the more complex security incidents.


Supplement retained staff with staff augmentation and managed security services providers


Many cybersecurity leaders have overcome staffing shortages through a mix of staff augmentation and managed security service providers (MSSPs). Staff augmentation can include arrangements with service providers or by contracting with independent contractors to provide technical assistance or subject matter expertise. As a strategy, this approach has several advantages to address the shortage of cybersecurity professionals. Under the staff augmentation model, contracting for temporary requirements and disengaging once those requirements have been met is significantly faster than the time to identify, recruit and hire staff. Staff augmentation requires minimal contracting effort, can scale up or down quickly, and has minimal impact on the existing operating model of a cybersecurity organization.


The MSSP model differs from staff augmentation. An MSSP offers a set of defined security services based on measured outcomes at a flat fee. A managed security service is typically comprised of their technology deployed and tuned to the customer on-premises and/or Cloud environments. With an MSSP, a dedicated  team keeps up with current threats and instrument their technology to protect their customers around the clock. The MSSP market has matured over the past years and become a reliable, stable source of cybersecurity services at a known quality for CISOs to pull from.


However, there are some disadvantages in both cases. The cybersecurity team will eventually lose their subject matter expertise with little choice in the matter. Temporary individual contractors or consultants, who have intimate knowledge of the company’s 


cybersecurity needs, will be required to leave over time or face significant tax consequences. Likewise, with the MSSP, companies have very little leverage over MSSP staff retention or the vetting of qualified replacements.


For a CISO managing the cybersecurity talent shortage, it’s a careful balance of staff augmentation and MSSPs to support a cybersecurity team. One model that has worked in the past is to reserve the management layer and higher-level knowledge worker as retained staff, staff augmentation for technical engineering or projectbased activities, and a MSSP for the highly transitional, routine tasks or specific subject matter expertise. This is not a generic recipe and tailoring is expected; many cybersecurity teams have different needs based on the size, scale, and technology of the company they serve.


 

Artificial Intelligence/Machine Learning (AI/ML) powered threat identification, detection, and response—which learns and continually improves—can reduce analytical effort and improve situational awareness

 


Leverage nontraditional sources of cybersecurity talent


Also due to the cybersecurity talent shortage, cybersecurity leaders are required to get creative in attracting and hiring cybersecurity professionals. Expanding the aperture to underutilized cybersecurity talent pools should include underrepresented groups such as diversity candidates, former veteran or government employees, and other nontraditional sources of candidates.


As an example, Historically Black Colleges and Universities (HBCUs) have played a major role in science, technology, engineering, and math (STEM). HBCUs produce 32 percent of Black bachelor's degree-holders in STEM fields including cybersecurity. HBCUs with leading cybersecurity programs are Grambling State University, Hampton University and Talladega. Cybersecurity leaders should leverage their talent acquisition teams to engage with these institutions.


Neurodiverse individuals with autism spectrum disorder, dyslexia and dyspraxia have also demonstrated to be a great source of cybersecurity talent. These individuals possess strengths in pattern recognition, analytics and are detail-oriented and, combined with focus and integrity, are well positioned for a cybersecurity role. They possess an exceptional aptitude to observe patterns from the “noise” that may be indicators of an attack. This pool is still vastly underleveraged.


The are several public-private partnerships that companies may want to consider partnering with. One example is the Cybersecurity Talent Initiative that allows participants complete a two-year placement with a federal agency, then two years at the partnering private sector company. For military veterans, CyberVET is an initiative dedicated to transitioning veterans, often with no IT background, to develop cybersecurity skills. These programs do require some sponsorship from participating companies but can help establish a pipeline of qualified cybersecurity professionals.


Another strategy to close the gap is by using more capabilities-based job specifications that focus on the abilities workers already have. From there, the company can build upon these innate capabilities with training to grow the individual into the role.IT support staff with technical skills like troubleshooting and repair only need a few key skills like incident response or computer forensics to qualify as a cybersecurity analyst. My best SOC Manager was a gaming enthusiast with a Sociology degree who was originally hired to build high-end desktop workstations.


Searching for cybersecurity recruits with specific cybersecurity degrees and certifications will constrain your talent acquisition team and narrow the candidate pool too much. Investing in automation, balancing the resource mix of retrained staff and outsourcing, and broadening the search to include nontraditional sources of talent will help companies address the critical need for cybersecurity talent.


 


The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.
The Leadership Perspectives forum brings together voices shaping the future of life sciences. It features leaders who are advancing change across the industry through strategic leadership and applied insight.
EDITOR'S CHOICE
  • Willis Towers Watson

    ICON [NASDAQ: ICLR]

    The Significant Increase in Demand for Clinical Research Associates (CRAs)

    Helen Yeardley, Executive Vice President, ICON [NASDAQ: ICLR]

  • Willis Towers Watson

    PacBio [NASDAQ: PACB]

    The Talent - Culture Continuum: How to Manage an Innovation Culture Amid Growth and Change

    Alvin Hom, Head of Global Talent Acquisition, PacBio [NASDAQ: PACB]

  • Willis Towers Watson

    Repligen Corp [NASDAQ: RGEN]

    Gene Therapy-Therapeutic Viral Vectors; Manufacturing, Challenges, and Innovation

    Rachel Legmann, PhD, Senior Director of Technology, Gene Therapy, Repligen Corp

  • Willis Towers Watson

    Ionis Pharmaceuticals [NASDAQ: IONS]

    Bridging the Diversity Divide

    Victoria Sanjurjo, Medical Director, Clinical Development, Ionis Pharmaceuticals, Inc [NASDAQ: IONS]

Life Sciences Review
Follow on LinkedIn

About

  • Home
  • About Us
  • Partner With Us

Stay Connected

  • Subscribe
  • Newsletter
  • Sitemap

Contact Us

  • editor@lifesciencesreview.com
  • sales@lifesciencesreview.com
  • marketing@lifesciencesreview.com

Legal

  • Editorial Policy
  • Privacy Policy
  • Terms of Use

© 2026 Life Sciences Review. All rights reserved. Headquartered in Fort Lauderdale, FL, USA.

This content is copyright protected

However, if you would like to share the information in this article, you may use the link below:

https://biometric-fingerprint.lifesciencesreview.com/leadership-perspective/a-ciso-challenge-cybersecurity-talent-shortage-nwid-2308.html