Recommendation
SBA should establish a certification program for “part-time” cybersecurity professionals.
Details
Many small businesses either cannot afford or cannot justify hiring a qualified cybersecurity professional, so they assign cyber responsibilities to an employee who works on them “part time.” Unfortunately, virtually all cybersecurity certification programs are tailored for people who do this as their full-time job. As a result, small business employees who only work on cybersecurity as a small part of their job don’t pursue these credentials and are often under-qualified. To address this problem, SBA should develop a low-cost, vendor-neutral certification program for small business employees who serve as their companies’ designated cybersecurity experts. The curriculum for the certification should be regularly reviewed to ensure it is accurate, comprehensive, and up-to-date. SBA could authorize professional certification organizations to award the certification to those who master the material. This would help small businesses assess whether they have staff qualified to handle cybersecurity and ensure their investments in training are worthwhile.
Keep reading:
▪ Daniel Castro, “Testimony to the U.S. Senate on Preparing Small Business for Cybersecurity Success,” April 25, 2018, https://itif.org/publications/2018/04/25/preparing-small-business-cybersecurity-success.