skip to main content
10.1145/3465481.3469186acmotherconferencesArticle/Chapter ViewAbstractPublication PagesaresConference Proceedingsconference-collections
research-article

The Matter of Cybersecurity Expert Workforce Scarcity in the Czech Republic and Its Alleviation Through the Proposed Qualifications Framework

Published: 17 August 2021 Publication History

Abstract

This paper is focused on challenges connected with the persisting imbalance between the supply and demand of the cybersecurity expert workforce. We analyse the current situation in the Czech Republic, finding that although the shortage of experts affects the private and public sectors both, the public sector is constrained by a massive financial undervaluation of cybersecurity experts and other legal and systematic deficiencies and obstacles and therefore has a much lower chance of attracting talents in this field. The inability of public institutions to find relevant workforce causes, among other things, problems with formulating public procurements, assessing offers and communicating their requirements to the supply-side of the labour market. One of the solutions to this crisis might be in the systematic support of education programmes. However, the cybersecurity field is so dynamic and fragmented that the alignment of the education programme with the market needs presents a significant challenge. There, a unified qualifications framework could serve as a basis for finding common ground. We focus on the benefits of creating such a framework, especially the benefits that a united taxonomy can bring to the cybersecurity labour market by bolstering cybersecurity higher education. Finally, we summarise the key features of the cyber-qualifications framework that is being developed under our current project and highlight its potential use for labour market optimisation and efficient development of new cybersecurity study programs and further education.

References

[1]
Vojtěch Blažek. 2016. Státu chybí IT experti a právníci. Nabízí jim ale jen 20 tisíc měsíčně. Právní rádce (2016). https://pravniradce.ihned.cz/c1-65285160-statu-chybi-it-experti-a-pravnici-nabizi-jim-ale-jen-20-tisic-mesicne
[2]
Center for Strategic and and International Studies, McAfee. 2017. Hacking the Skills Shortage: A study of the international shortage in cybersecurity skills. (2017). https://www.mcafee.com/content/dam/enterprise/en-us/assets/reports/rp-hacking-skills-shortage.pdf
[3]
European Commission European Commission. 2017. State of the Union 2017 - Cybersecurity: Commission scales up EU’s response to cyber-attacks. https://ec.europa.eu/commission/presscorner/detail/en/IP_17_3193
[4]
CONCORDIA. [n.d.]. CONCORDIA Service - Cybersecurity Skills. https://www.concordia-h2020.eu/concordia-service-cybersecurity-skills/
[5]
Cyber Security for Europe. 2020. Addressing the Shortage of Cybersecurity Skills in Europe. https://cybersec4europe.eu/addressing-the-shortage-of-cybersecurity-skills-in-europe/
[6]
CyBOK. 2020. About. https://www.cybok.org/about/
[7]
Tommaso De Zan and Fabio Di Franco. 2019. Cybersecurity Skills Development in the EU: The certification of cybersecurity degrees and ENISA’s Higher Education Database. https://www.enisa.europa.eu/publications/the-status-of-cyber-security-education-in-the-european-union/at_download/fullReport
[8]
ENISA. 2020. Cybersecurity Skills Development in the EU. https://www.enisa.europa.eu/publications/the-status-of-cyber-security-education-in-the-european-union
[9]
ENISA. 2020. Launch of New Ad-hoc Working Group on European Cybersecurity Skills Framework. https://www.enisa.europa.eu/news/enisa-news/launch-of-new-ad-hoc-working-group-on-european-cybersecurity-skills-framework
[10]
Abdul Hameed and Aamer Waheed. 2011. Employee Development and Its Affect on Employee Performance: A Conceptual Framework. International Journal of Business and Social Science 2, 13 (2011), 224–229.
[11]
HAYS. 2021. Mzdový průzkum 2021. https://cloud.email.hays.com/mzdovy-pruzkum-2021
[12]
Hlídač státu, Rekonstrukce státu, and Frank Bold. 2021. [Ne]digitální Česko: Zpráva o plnění vládních slibů v oblasti digitalizace. https://www.rekonstrukcestatu.cz/download/3nQoIg/nedigitalni_cesko.pdf
[13]
INTERPOL. 2020. INTERPOL report shows alarming rate of cyberattacks during COVID-19. https://www.interpol.int/en/News-and-Events/News/2020/INTERPOL-report-shows-alarming-rate-of-cyberattacks-during-COVID-19
[14]
Petr Král. 2020. Odborníků na IT a kybernetickou bezpečnost je ve zdravotnictví naprostý nedostatek, říká Martin Zeman. Český rozhlas: Radiožurnál (June 2020). https://radiozurnal.rozhlas.cz/odborniku-na-it-a-kybernetickou-bezpecnost-je-ve-zdravotnictvi-naprosty-8235789 Section: Domácí.
[15]
Jana Magdoňová. 2019. Kyberúřadu chybí IT specialisté a technici. Plánoval jich přijmout 48, ale povolení dostal jen na osm. iROZHLAS (2019). https://www.irozhlas.cz/zpravy-domov/skrty-mista-urednici-schillerova-narodni-kyberneticky-urad_1907030657_kno
[16]
Andreas Marazis. 2021. Addressing Cyber Security Threats from Russia in the EU. In Principled Pragmatism in Practice, Fabienne Bossuyt and Peter van Elsuwege (Eds.). Brill | Nijhoff, 234–254. https://doi.org/10.1163/9789004453715_014
[17]
Ministerstvo práce a sociálních věcí. 2020. Strategický rámec politiky zaměstnanosti do roku 2030. https://www.mpsv.cz/strategicky-ramec-politiky-zamestnanosti-do-roku-2030
[18]
NIST. 2020. CVE-2020-10148 - National Vulnerability Database. https://nvd.nist.gov/vuln/detail/CVE-2020-10148
[19]
NIST. 2020. Workforce Framework for Cybersecurity (NICE Framework). https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-181r1.pdf
[20]
NÚKIB. 2020. Report on the state of cyber security in the Czech Republic in 2019. https://www.nukib.cz/download/publikace/zpravy_o_stavu/report-czech-cyber-security-2019-en.pdf
[21]
Jakub Onderka. 2021. Proč Česko nedokáže svým občanům nabízet IT služby v požadované kvalitě? Odpověď je jednodušší, než se může zdát. Deník N (Jan. 2021). https://denikn.cz/541330/proc-cesko-nedokaze-svym-obcanum-nabizet-it-sluzby-v-pozadovane-kvalite-odpoved-je-jednodussi-nez-se-muze-zdat/ Section: Audio.
[22]
Charlie Osborne. 2021. Everything you need to know about the Microsoft Exchange Server hack. ZDNet (2021). https://www.zdnet.com/article/everything-you-need-to-know-about-microsoft-exchange-server-hack/
[23]
Markéta Pištorová. 2020. Být ICT odborníkem se vyplácí. Statistika&My (2020). https://www.statistikaamy.cz/2020/08/20/byt-ict-odbornikem-se-vyplaci
[24]
Martina Poskočilová. 2018. „Ajťáci“ chybějí dvěma třetinám firem. Statistika&My (2018). https://www.statistikaamy.cz/2018/10/17/ajtaci-chybeji-dvema-tretinam-firem/
[25]
Lukáš Prchal. 2020. Brněnská nemocnice po kyberútoku ruší operace, testování koronaviru ohrožené není. Deník N (March 2020). https://denikn.cz/314303/brnenska-nemocnice-po-kyberutoku-rusi-operace-testovani-koronaviru-ohrozene-neni/ Section: Česko.
[26]
Lukáš Prchal. 2021. Hackeři napadli České dráhy a Správu železnic. Bezpečnost dopravy není ohrožená, tvrdí vedení. Deník N (March 2021). https://denikn.cz/587281/hackeri-napadli-spravu-zeleznic-bezpecnost-dopravy-neni-ohrozena-tvrdi-vedeni/?cst=7539be9ce0de4d9dd6f5b9b92951f96172050269 Section: Česko.
[27]
Lukáš Prchal. 2021. Hackeři poliklinikám zašifrovali data o pacientech a nechali vzkaz. Na odpověď nereagovali. Deník N (March 2021). https://denikn.cz/585878/hackeri-poliklinikam-ukradli-data-o-pacientech-a-nechali-vzkaz-na-odpoved-nereagovali/?cst=b2b169071e2fbc7cc52c121fa582984536512ec4 Section: Česko.
[28]
Jay Ryerse. 2020. The importance of a cybersecurity framework. Security Magazine (2020). https://www.securitymagazine.com/articles/93509-the-importance-of-a-cybersecurity-framework
[29]
Alex Scroxton. 2020. EU sanctions China and Russia over cyber attacks. ComputerWeekly (2020). https://www.computerweekly.com/news/252486952/EU-sanctions-China-and-Russia-over-cyber-attacks
[30]
SECURE. 2020. Future of Secure Remote Work Report. https://www.cisco.com/c/dam/en/us/products/collateral/security/secure-remote-worker-solution/future-of-secure-remote-work-report.pdf
[31]
David Slížek. 2021. Rezervační systém pro očkování proti COVIDu odstartoval, měl problém s posíláním SMS [AKTUALIZOVÁNO]. Lupa.cz (2021). https://www.lupa.cz/aktuality/rezervacni-system-pro-ockovani-proti-covidu-odstartoval-v-prvnich-minutach-se-hlasilo-75-tisic-lidi/ ISSN: 1213-0702.
[32]
SPARTA. [n.d.]. SPARTA. https://www.sparta.eu/
[33]
SPARTA. 2020. D9.1 Cybersecurity skills framework. https://www.sparta.eu/assets/deliverables/SPARTA-D9.1-Cybersecurity-skills-framework-PU-M12.pdf
[34]
Adam Váchal. 2021. Místo zjednodušení přinesla problémy. Kvůli nové dálniční známce přicházejí řidiči o peníze. Hospodářské noviny (Jan. 2021). https://ihned.cz/c1-66867850-misto-zjednoduseni-prinesla-problemy-kvuli-nove-dalnicni-znamce-prichazeji-ridici-o-penize Section: HN.
[35]
Úřad práce ČR. 2021. Zpráva o situaci na krajském trhu práce, o realizaci APZ v roce 2020 a strategie APZ pro rok 2021. https://www.uradprace.cz/documents/37855/914384/Rocni_ABK_2020.pdf/7dcbc6bb-1f6d-7479-83d3-6d2af71387eb
[36]
Český statistický úřad. 2019. Odměňování zdravotnických pracovníků. https://www.czso.cz/documents/10180/112643651/260024-19.pdf/bf124e97-fd37-4823-a9a5-0cb824f309a4?version=1.0
[37]
ČTK. 2021. Kyberútoků na nemocnice je za dva měsíce skoro o polovinu víc, využívá se stavu nouze. Aktuálně.cz (Jan. 2021). https://zpravy.aktualne.cz/zahranici/pocet-kyberutoku-na-nemocnice-vzrostl-za-dva-mesice-o-45-pct/r~f48b24ec53fb11eb9d470cc47ab5f122/ Section: Zahraničí.
[38]
ČTK. 2021. Sčítání odstartovalo s ostudou. Systém 8 hodin nešel a problémy trvají. (2021). https://www.seznamzpravy.cz/clanek/zacalo-scitani-lidu-online-dotaznik-ale-nefunguje-148630

Cited By

View all
  • (2023)The Curation Mechanism for the Czech National Qualifications Framework in CybersecurityProceedings of the 18th International Conference on Availability, Reliability and Security10.1145/3600160.3605001(1-6)Online publication date: 29-Aug-2023
  • (2022)The Platform for Czech National Qualifications Framework in CybersecurityProceedings of the 17th International Conference on Availability, Reliability and Security10.1145/3538969.3543800(1-6)Online publication date: 23-Aug-2022
  • (2022)Empirical Study on the State of Practice of Information Security Management in Local GovernmentHuman Centred Intelligent Systems10.1007/978-981-19-3455-1_2(13-25)Online publication date: 16-Jun-2022

Recommendations

Comments

Information & Contributors

Information

Published In

cover image ACM Other conferences
ARES '21: Proceedings of the 16th International Conference on Availability, Reliability and Security
August 2021
1447 pages
ISBN:9781450390514
DOI:10.1145/3465481
Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than the author(s) must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected].

Publisher

Association for Computing Machinery

New York, NY, United States

Publication History

Published: 17 August 2021

Permissions

Request permissions for this article.

Check for updates

Author Tags

  1. Cybersecurity
  2. labour market
  3. qualifications framework
  4. workforce

Qualifiers

  • Research-article
  • Research
  • Refereed limited

Funding Sources

Conference

ARES 2021

Acceptance Rates

Overall Acceptance Rate 228 of 451 submissions, 51%

Contributors

Other Metrics

Bibliometrics & Citations

Bibliometrics

Article Metrics

  • Downloads (Last 12 months)15
  • Downloads (Last 6 weeks)2
Reflects downloads up to 25 Feb 2025

Other Metrics

Citations

Cited By

View all
  • (2023)The Curation Mechanism for the Czech National Qualifications Framework in CybersecurityProceedings of the 18th International Conference on Availability, Reliability and Security10.1145/3600160.3605001(1-6)Online publication date: 29-Aug-2023
  • (2022)The Platform for Czech National Qualifications Framework in CybersecurityProceedings of the 17th International Conference on Availability, Reliability and Security10.1145/3538969.3543800(1-6)Online publication date: 23-Aug-2022
  • (2022)Empirical Study on the State of Practice of Information Security Management in Local GovernmentHuman Centred Intelligent Systems10.1007/978-981-19-3455-1_2(13-25)Online publication date: 16-Jun-2022

View Options

Login options

View options

PDF

View or Download as a PDF file.

PDF

eReader

View online with eReader.

eReader

HTML Format

View this article in HTML Format.

HTML Format

Figures

Tables

Media

Share

Share

Share this Publication link

Share on social media