Security1 publisher2 min readPublished
57% of security executives tell SkillBit a new hire needs six months to deliver value
SkillBit's survey of 200 security executives found 57% say a new hire takes six months to deliver value. A team that loses an analyst therefore stays short-staffed for months after the replacement starts, whatever its patch deadlines.
The Watch · Security desk
What happened
- Seventy percent of the organizations surveyed say they have few roles open to candidates with under two years of experience.
- 84% sponsor certification training for staff, even though 71% of the managers said they prefer 20-minute weekly upskilling sessions to annual training.
- 30% of leaders would accept interactive lab formats in place of credentials, and another 49.5% would if shown convincing evidence that labs work.
- ThreatLocker CTO Michael Jenkins said his team hires early-career staff, including people straight out of high school, and grows them into advanced roles.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint A budget case built on shrinking patch windows cannot cite this survey as support. Its data covers hiring and training, and the patch link comes from the write-up.
- decision With 79.5% of respondents at least open to lab tests, the two-year experience filter is open to negotiation. Whoever can show that labs predict job performance will settle it.
- cost At least 55% of respondents pay for certification courses while preferring short weekly sessions. The course hours come out of teams the write-up says can barely keep up.
SC Media's write-up ties the six-month figure to "the compressed timeline for managing patches in the AI era" [7]. The results it reports cover hiring and training. None of them measure patch windows or exploit timing, so the link between onboarding and patching is the publication's framing, and the numbers do not test it [7].
SkillBit released the study on September 29 [1]. On a base of 200, the six-month group is about 114 executives [4]. The article gives the sample size but not how respondents were chosen [1].
The training figures overlap heavily. If the 71% and the 84% share that base, at least 55% of respondents both prefer short weekly sessions to annual training and pay for certification courses [3]. According to SC Media, certification training "often takes a large amount of time to complete, at a time when most security teams can barely keep up" [6].
Respondents are more flexible on the experience requirement. Leaders said they are open to changing the strict two-year rule if a candidate can show subject knowledge [8]. Counting the conditional group, 79.5% would at least consider interactive labs as a credential substitute [1]. Most of that is conditional: 49.5% want convincing evidence of effectiveness first [10]. The remaining 20.5% fall outside both groups [2].
"We can't keep asking for experienced cybersecurity professionals without giving people a chance to gain that experience," said Michael Jenkins, chief technology officer at ThreatLocker [11]. "AI can help with some tasks, but it cannot replace human judgement, and that needs to be learned through experience," he said [12]. On the six-month figure, Jenkins said every job has a learning curve. What matters, he said, is whether new staff get the chance to contribute and grow during that training time [15].
His method is review. "Every code commit is reviewed by multiple people, and significant actions get a second look, even when a senior employee is involved," Jenkins said [14].
Ram Varadarajan, chief executive officer at Acalvio, said that a few years ago cybersecurity training was viewed as discretionary spending [17]. "To overcome training-time and onboarding challenges, organizations should treat learning as a business requirement with protected time and measurable goals," he said [16]. Diana Kelley, chief information security officer at Noma Security, said employers are still looking for experience and proof of capability, even at entry level [18].
What to watch
- Publication of SkillBit's full questionnaire and respondent profile, which would show whether the 71% and 84% figures share a base and who was surveyed.
- Any data linking onboarding time to patch or remediation times, which would test the patch-window framing the write-up attaches to the six-month figure.
- Outcome data on hiring through interactive labs, the evidence 49.5% of respondents say they need before accepting labs in place of credentials.