

What can we learn from three recent reports into the state of privacy and cyber security from the most influential privacy and cyber security member organisations: the IAPP, ISACA and (ISC)2?
Earlier this year we covered the IAPP Privacy Governance Report 2024, providing an analysis and key takeaways from an Australian perspective. The two other surveys that are also worth considering:
Both these reports are discussed in more detail below.
Although all three reports have very different focuses and approaches, there are some common threads that run through them, and it is not great news for privacy professionals:
For this report, ISACA surveyed 1600 global privacy professionals.
Key findings include:
Experience continues as the key skills looked for – including experience with different types of technologies and/or applications (61%), experience with frameworks and/or controls (49%), and technical expertise (48%). Despite the experience requirement, the top strategy to address the privacy skills gap is training to allow non-privacy staff who are interested to move into privacy roles (48%).
The top three obstacles respondents indicated were:
Meanwhile, the most common privacy failures were:
The survey found a growing use of AI for privacy-related work this year than last year, and fewer respondents said they have no plans to use AI for privacy than they did last year. The use of AI for privacy-related tasks is higher in organizations that are not purely compliance-driven.
In terms of stress, 63% percent of respondents shared that their privacy roles are more stressful now than five years ago. Reasons for this included technology’s rapid evolution (63%) and how enterprises have rushed to adopt new tech, such as generative AI, without adequate consideration of the associated privacy risks. Compliance challenges are another top reason for the increase in stress (61%).
Download the report here.
For this report, ISC2 surveyed a record 15,852 international practitioners and decision-makers. These cybersecurity professionals span the globe from North America to Asia, Latin America, Europe, the Middle East and Africa.
Overall, it found that organisations impacted by a marked increase in risk and disruption in 2024. Economic pressures, exacerbated by geopolitical uncertainties, have led to budget and workforce reductions, while cybersecurity threats and data security incidents have continued to grow. Alongside these issues, organizations and professionals have had to keep pace with rapidly advancing technology innovations such as artificial intelligence (AI). While the offer of transformative potential has fuelled adoption, such technologies also introduce additional risks and exposure to regulation.
What this led to was a year where resources are strained, while cybersecurity teams have to respond to new technologies, particularly AI, and protect against the nuanced threats they pose to their organizations.
The report itself is broken down into the following areas:
A lack of skills was the most challenging aspect of respondents’ jobs over the past 12 months. Although respondents believe changed conditions required more people to secure organisations – organisations are cutting back both on hiring and the professional development of their cyber security teams. 67% of respondents indicated they had a staffing shortage this year, with lack of budget being the main cause for talent shortages and skills gaps (followed by lack of time). 60% of respondents believe that the skills gap significantly impact their ability to secure their organisation.
Entry pathways to the cybersecurity workforce are changing, as are their priorities – however 70% of entrants continue to come from IT. Entrants continue to trend older (35% of entrants were 39- to 49-year-olds) although tenure within careers varied. While IT is the traditional path into cybersecurity, more and more entrants come from different backgrounds or verticals, with these diverse pathways providing equally valuable to success in cybersecurity. Once in, cybersecurity professionals are still focused on higher education and professional development but increasingly prioritise work-life balance (the top-ranked method of deriving meaning from their careers) – because they don’t expect promotions or wage growth.
AI will likely replace some of the technical skills needed in cybersecurity. While study participants speculated on what skills may be automated or streamlined, they cannot yet predict what activities, if any, AI will replace. As a result of this uncertainty, hiring managers aren’t rushing to hire more specialized workers. Instead, they are prioritizing nontechnical skills like problem-solving, teamwork, collaboration, curiosity and communication that will be transferable through the increased use of AI. These skills ranked higher than technical skills like cloud computing security, risk assessment, analysis and management and AI.
Cyber professionals are generally excited about the potential of AI, with 54% saying it will be helpful to cybersecurity. 45% of cybersecurity teams have implemented Gen AI into their teams’ tools to help bridge skills gaps and improve threat detection (among other things). However, they don’t believe that AI will replace their entire role.
In comparison, 64% of respondent organizations have implemented Gen AI in other departments, causing more work for cyber professionals. Over half have already faced data privacy and security concerns due to organizational adoption of Gen AI.
In terms of the way forward:
Download the report: (ISC)2 – Global Cybersecurity Workforce Prepares for an AI-Driven World (2024)
More information here: 2024 ISC2 Cybersecurity Workforce Study
"*" indicates required fields
"*" indicates required fields
Privacy 108 collects your name and email to send you our newsletter. If you do not provide this information, we will be unable to send it to you. We may use third-party service providers (such as email marketing platforms) to distribute our communications. Some providers may store information overseas, including in the United States. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au. You can unsubscribe at any time using the link in our emails or by contacting hello@privacy108.com.au.