← Back to list

Why today’s IT infrastructure makes cyber security talent urgent

Intro: Think of your company’s tech like a growing city. Five years ago, you had one main road (the data center). Now there are highways in…

Cube1214 · 2025-11-27 22:52 · 16 claps · 3.9 min read
#identity #cloud-computing #engineering #ai #malware
Open on Medium ↗
Wiki topics: AI · AI · General CR · CRISPR & Gene Editing 🔒 · Cybersecurity

Why today’s IT infrastructure makes cyber security talent urgent

Intro: Think of your company’s tech like a growing city. Five years ago, you had one main road (the data center). Now there are highways in the clouds, side streets through SaaS apps, and scooters (IoT/OT) zipping between buildings. Traffic got faster, but so did carjackers. Without expert traffic cops (cybersecurity experts) and engineers who design safer roads (security engineers), gridlock and accidents are inevitable.

1) Cloud, multi-cloud, and SaaS sprawl multiplied the attack surface

Organizations now run hybrids of on-prem, multi-cloud, and hundreds of SaaS tools. In 2024, Flexera reported security, spend, and expertise as top cloud challenges while multi-cloud became the norm — an architecture that increases misconfiguration and identity risk if not deliberately engineered. (The ITAM Review)

So what? Each cloud and app has different identity, logging, network, and encryption models. Designing guardrails (landing zones, policy-as-code, centralized IAM, and data controls) now demands dedicated security engineers, not just generalist admins.

These shifts explain why companies need people who understand cloud-native controls, shared responsibility, and how to weave detection, response, and compliance across providers — roles squarely in the wheelhouse of cybersecurity experts and engineers.

2) Identity is the new perimeter — and it’s under siege

Verizon’s 2024 DBIR shows credential abuse and phishing among dominant initial access vectors, with rapid exploitation of widely used software (e.g., MOVEit) accelerating incidents. (Verizon) Industry threat reporting in 2025 highlights surges in credential theft and identity-based intrusions — attackers increasingly skip malware and just log in. (Security Boulevard)

So what? Security teams must harden identity systems (SSO/MFA, resistant methods, conditional access), engineer continuous monitoring for token theft and MFA fatigue, and rewrite detection for “malware-free” intrusion patterns — specialist work.

As work stays hybrid and SaaS-first, expertise in identity threat detection and response (ITDR) becomes core. This is not a “set and forget” control; it’s an engineering program.

3) Ransomware/extortion got faster and broader

CISA’s joint guidance underscores ransomware and data-extortion as persistent, enterprise-wide risks, and provides prevention/response checklists aligned to baseline controls. (CISA) Regional reporting for 2025 shows record attack tempos and shrinking dwell time — hours, not weeks — amplified by crime-as-a-service markets. (IT Pro)

So what? You need engineers to implement immutable backups, segmentation, and incident automation — and expert responders to run tabletop exercises and pressure-test recovery RTOs/RPOs.

The speed of modern extortion means “weekend war rooms” are obsolete; engineering resilience up front is what saves the business.

Facts

In recent reports, malware-free or hands-on-keyboard intrusions (using valid credentials and admin tools) are outpacing traditional malware in many incidents — meaning attackers don’t need to “infect” you; they can just act like you. (SecurityWeek)

This single shift explains why identity, logging, and least-privilege engineering deliver outsized risk reduction right now.

4) Supply-chain and zero-day exploitation scale systemically

Verizon flags the rapid exploitation of high-impact vulnerabilities (e.g., MOVEit) and the outsized role of third-party software and services. (Verizon) ENISA’s 2024 landscape similarly tracks availability-impacting attacks and escalating complexity across Europe. (ENISA)

So what? Organizations need experts to stand up SBOM intake, vendor risk programs, and rapid patch orchestration across cloud, containers, and SaaS — plus engineers to automate exposure management.

Because one supplier can cascade risk to thousands, supply-chain security has become an engineering discipline, not paperwork.

5) GenAI and AI-assisted attacks raise the floor for adversaries

Microsoft’s 2024 Digital Defense Report and subsequent reporting show nation-states and e-crime using AI to enhance phishing, deepfakes, and operational speed. (Microsoft) Netskope’s 2024 analysis of AI apps in the enterprise shows rising data-loss risk from unsanctioned GenAI tools, prompting DLP and user-coaching controls. (Netskope)

So what? You need security experts to govern AI usage (policies, model/security reviews) and engineers to implement privacy-preserving data pipelines, DLP, and guardrails in apps and MLOps.

As both defenders and attackers adopt AI, the gap will widen between firms that engineer controls into their workflows and those that rely on banners and hope.

6) Costs, board pressure, and talent gaps make proactive security non-optional

IBM’s data-breach research reported the global average breach cost near US$4.88M, the largest annual jump since the pandemic; coverage highlighted staff shortages compounding impact. (Table Media) WEF’s 2024 outlook calls out the growing cyber skills deficit and the need for executive-level resilience. (World Economic Forum)

So what? Boards increasingly expect credible risk reduction, metrics, and tested recovery. That requires professionals who can translate business risk into architecture and operations — not just tools.

In practice, that means funding security engineering roadmaps (identity, data, resilience) and hiring experts who can brief leadership with risk-based outcomes.

What this means for hiring (practical takeaways)

  • Cybersecurity Expert (strategy + governance): Builds risk registers, selects frameworks, runs supplier risk, leads incident readiness, and reports outcomes to leadership using credible metrics tied to business impact. (See WEF/IBM for business drivers.) (World Economic Forum)
  • Cybersecurity Engineer (implementation): Ships landing zones, IAM policies, logging pipelines, EDR/XDR integrations, DLP, segmentation, backup immutability, and automated patch/exposure workflows aligned with CISA’s playbooks. (CISA)

Modern risk comes from interconnection — clouds, vendors, identities, and AI systems. Strategy without engineering doesn’t reduce risk; engineering without strategy chases tools. You need both roles.

References

  • CISA. (2025). #StopRansomware Guide. Cybersecurity and Infrastructure Security Agency. (CISA)
  • CrowdStrike. (2025). Global Threat Report. CrowdStrike, Inc. (SecurityWeek)
  • ENISA. (2024). ENISA Threat Landscape 2024. European Union Agency for Cybersecurity. (ENISA)
  • Flexera. (2024). State of the Cloud Report. Flexera Software LLC. (The ITAM Review)
  • IBM & Ponemon Institute. (2024). Cost of a Data Breach Report 2024. IBM Security. (Table Media)
  • Microsoft. (2024). Microsoft Digital Defense Report. Microsoft Corporation. (Microsoft)
  • Netskope Threat Labs. (2024). Cloud and Threat Report: AI Apps in the Enterprise. Netskope, Inc. (Netskope)
  • Verizon. (2024). Data Breach Investigations Report (DBIR). Verizon. (Verizon)
  • World Economic Forum & Accenture. (2024). Global Cybersecurity Outlook 2024. World Economic Forum. (World Economic Forum)
  • AP News. (2025, Oct.). Microsoft: Russia, China increasingly using AI to escalate cyberattacks on the US. Associated Press. (AP News)
  • Axios. (2024, Jul. 30). Data breach recovery has gotten more expensive. Axios Media. (Axios)

메타데이터
post_id
a632feb7017e
slug
why-todays-it-infrastructure-makes-cyber-security-talent-urgent-a632feb7017e
url
https://medium.com/@cube1214/why-todays-it-infrastructure-makes-cyber-security-talent-urgent-a632feb7017e
canonical_url
https://medium.com/@cube1214/why-todays-it-infrastructure-makes-cyber-security-talent-urgent-a632feb7017e
author_url
https://medium.com/@cube1214
status
ok
fetched_at
2026-06-26 21:52:29