chief ICT security officertocybersecurity risk manager
A chief ICT security officer already meets 75% of what the cybersecurity risk manager role asks for. The move turns on 2 required skills not yet in the profile.
75%
36.6/ 100
1 Share of the cybersecurity risk manager role’s weighted skill requirement already met by the chief ICT security officer profile. Required skills count in full, supplementary skills at 0.35. Directional: the figure for the reverse move differs. 2 Combines what is missing with how specialised it is, so a gap of general skills scores easier than the same number of narrow ones.
Why this move works
A cybersecurity risk manager role treats 20 of its required skills as things a chief ICT security officer already does. These are the ones it depends on most.
- ICT network security risks
- ICT safety
- ICT security standards
- advice on security risk management
- assessment of risks and threats
- attack vectors
What stands in the way is 2 required skills the profile does not yet cover. Table 3 groups them; Table 4 says which to take first.
Table 2 · What you already bring
Of the 47 skills that carry over, these are the ones fewest other occupations ask for. A cybersecurity risk manager role needs them, and most people applying for one will not have them already. This is the part of a chief ICT security officer background worth leading with.
- already held establish an Information Security Management System assisting and caring
- already held establish an ICT security prevention plan management skills
- already held advice on security risk management information skills
- already held computer forensics information and communication technologies (icts)
- already held engage with stakeholders communication, collaboration and creativity
- already held lead disaster recovery exercises management skills
All 47 carried skills, including the 20 the cybersecurity risk manager role treats as required.
Table 3 · What you would need to learn
The 25 missing skills fall into 6 areas of the ESCO skill hierarchy, numbered below in the order worth working in: the areas carrying the most required skills come first, and inside each one the required skills sit above the supplementary ones.
- required, not held ICT performance analysis methods required
- optional, not held ICT problem management techniques optional
- optional, not held Open source model optional
- optional, not held Outsourcing model optional
- optional, not held domain name service optional
- optional, not held hybrid model optional
- optional, not held levels of software testing optional
- optional, not held mobile device management optional
- optional, not held service-oriented modelling optional
- optional, not held tools for ICT test automation optional
- optional, not held systems development life-cycle optional
- required, not held security threats required
- optional, not held develop with cloud services optional
- optional, not held implement spam protection optional
- optional, not held use an application-specific interface optional
- optional, not held remove computer virus or malware from a computer optional
- optional, not held solve ICT system problems optional
- optional, not held use ICT ticketing system optional
- optional, not held use back-up and recovery tools optional
- optional, not held ICT quality policy optional
- optional, not held investment analysis optional
- optional, not held legal requirements of ICT products optional
- optional, not held define security policies optional
- optional, not held define technology strategy optional
- optional, not held design for organisational complexity optional
Table 4 · Where to start
The 2 entries a cybersecurity risk manager role is least likely to hire without. The ordering is computed from the skill data, not from what pays.
- 01 ICT performance analysis methods knowledge · sector specific
- 02 security threats knowledge · cross sector
Each entry opens a course search for that skill. Career Overlap earns nothing from these links.
Appendix · The rest of the record
All 47 skills that carry over
- already held ICT network security risks knowledge
- already held ICT safety skill
- already held ICT security standards knowledge
- already held advice on security risk management skill
- already held assessment of risks and threats knowledge
- already held attack vectors knowledge
- already held communicate with stakeholders skill
- already held cyber attack counter-measures knowledge
- already held cyber security knowledge
- already held engage with stakeholders skill
- already held ensure adherence to organisational ICT standards skill
- already held establish an ICT security prevention plan skill
- already held establish an Information Security Management System skill
- already held ethical hacking principles knowledge
- already held implement ICT risk management skill
- already held information security strategy knowledge
- already held internal risk management policy knowledge
- already held manage system security skill
- already held risk management knowledge
- already held security engineering knowledge
- already held ICT encryption knowledge
- already held ICT process quality models knowledge
- already held ICT project management knowledge
- already held ICT recovery techniques knowledge
- already held ICT security legislation knowledge
- already held ICT system user requirements knowledge
- already held Internet of Things knowledge
- already held audit techniques knowledge
- already held cloud monitoring and reporting knowledge
- already held cloud security and compliance knowledge
- already held computer forensics knowledge
- already held decision support systems knowledge
- already held develop information security strategy skill
- already held execute ICT audits skill
- already held identify ICT security risks skill
- already held implement ICT security policies skill
- already held implement a firewall skill
- already held implement a virtual private network skill
- already held implement anti-virus software skill
- already held implement cloud security and compliance skill
- already held information confidentiality knowledge
- already held internet governance knowledge
- already held lead disaster recovery exercises skill
- already held manage disaster recovery plans skill
- already held manage keys for data protection skill
- already held organisational resilience knowledge
- already held web application security threats knowledge
23 supplementary skills, helpful but not required
- optional, not held ICT problem management techniques optional
- optional, not held ICT quality policy optional
- optional, not held Open source model optional
- optional, not held Outsourcing model optional
- optional, not held define security policies optional
- optional, not held define technology strategy optional
- optional, not held design for organisational complexity optional
- optional, not held develop with cloud services optional
- optional, not held domain name service optional
- optional, not held hybrid model optional
- optional, not held implement spam protection optional
- optional, not held investment analysis optional
- optional, not held levels of software testing optional
- optional, not held mobile device management optional
- optional, not held service-oriented modelling optional
- optional, not held tools for ICT test automation optional
- optional, not held use an application-specific interface optional
- optional, not held legal requirements of ICT products optional
- optional, not held remove computer virus or malware from a computer optional
- optional, not held solve ICT system problems optional
- optional, not held systems development life-cycle optional
- optional, not held use ICT ticketing system optional
- optional, not held use back-up and recovery tools optional
34 held skills the cybersecurity risk manager role does not ask for
- not needed by the target role ICT communications protocols knowledge
- not needed by the target role ICT infrastructure knowledge
- not needed by the target role ICT project management methodologies knowledge
- not needed by the target role World Wide Web Consortium standards knowledge
- not needed by the target role apply operations for an ITIL-based environment skill
- not needed by the target role assess ICT knowledge skill
- not needed by the target role cloud technologies knowledge
- not needed by the target role comply with legal regulations skill
- not needed by the target role computer programming knowledge
- not needed by the target role conduct impact evaluation of ICT processes on business skill
- not needed by the target role control objectives for information and related technology knowledge
- not needed by the target role coordinate technological activities skill
- not needed by the target role create solutions to problems skill
- not needed by the target role data protection knowledge
- not needed by the target role educate on data confidentiality skill
- not needed by the target role ensure compliance with legal requirements skill
- not needed by the target role ensure cross-department cooperation skill
- not needed by the target role ensure information privacy skill
- not needed by the target role ethics knowledge
- not needed by the target role forecast organisational risks skill
- not needed by the target role identify legal requirements skill
- not needed by the target role implement corporate governance skill
- not needed by the target role maintain plan for continuity of operations skill
- not needed by the target role manage IT security compliances skill
- not needed by the target role manage digital identity skill
- not needed by the target role manage staff skill
- not needed by the target role monitor developments in field of expertise skill
- not needed by the target role monitor technology trends skill
- not needed by the target role optimise choice of ICT solution skill
- not needed by the target role protect personal data and privacy skill
- not needed by the target role software anomalies knowledge
- not needed by the target role train employees skill
- not needed by the target role use different communication channels skill
- not needed by the target role utilise decision support system skill
15 gaps that are knowledge rather than practice
Knowledge gaps usually close through study. Practical skill gaps usually need something you can point at.
- required, not held ICT performance analysis methods required
- required, not held security threats required
- optional, not held ICT problem management techniques optional
- optional, not held ICT quality policy optional
- optional, not held Open source model optional
- optional, not held Outsourcing model optional
- optional, not held domain name service optional
- optional, not held hybrid model optional
- optional, not held investment analysis optional
- optional, not held levels of software testing optional
- optional, not held mobile device management optional
- optional, not held service-oriented modelling optional
- optional, not held tools for ICT test automation optional
- optional, not held legal requirements of ICT products optional
- optional, not held systems development life-cycle optional
Other moves recorded from chief ICT security officer
How this record was compiled
Both occupations are taken from ESCO, which lists the skills and knowledge each occupation is expected to have and marks every one required or optional. Nothing here is a prediction about hiring, and nothing here knows that a particular employer wants a particular certificate. Treat Table 3 as a starting point for your own research rather than a syllabus. The full method states what these figures can and cannot tell you.