IT lumped with 'arrogant, ignorant' grads

IT lumped with 'arrogant, ignorant' grads

Summary: Industry experts at a Cisco discussion panel held in Sydney today have painted a bleak picture of the future information security workforce, stating that university graduates are ill prepared and lack basic, necessary skills.

TOPICS: Security

Industry experts at a Cisco discussion panel held in Sydney today have painted a bleak picture of the future information security workforce, stating that university graduates are ill prepared and lack basic, necessary skills.

(Lecture theatre image by Seedcamp Photos, CC BY-SA 2.0)

Telstra chief information officer Glenn Chisholm said that one of the greatest problems facing the information security industry is arrogance of ignorance.

"The number of people that believe they understand security, but don't, far exceed the number of people that do," he said. "The ability to access well-trained personnel at that tertiary level is almost non-existent," he said.

Cisco vice president and chief security officer John Stewart agreed.

"The generation of people that we're hiring out of college don't even understand the OSI layer," he said, adding that structured tertiary education has, in a way, robbed students of the lessons they could have naturally learned.

"The concept of buffer overflow is just not even in their mindset, because they've been learning in an environment where that wasn't even possible.

"The nature of that education is removing some of the very elements of what this industry needs for the experience that you have to have on the job."

Head of Edith Cowan University's School of Computer and Security Science professor Craig Valli said that the university has recognised these pitfalls, and is going back to basics in terms of training students.

"Students are learning assembly again. It had been taken out. They're going to have a C programming unit, they're having a scripting unit, all of these basics in computer science that they're going to need when they get out there," he said, adding that he is also pushing for students to be educated in current concepts like IPv6 in addition to IPv4.

However, Valli revealed that only one fifth of students studying cybersecurity actually grasp these basics.

"We've got the biggest program in Australia, but I would say that out of the 500-odd bodies we have doing cybersecurity units, about 20 per cent 'get it'."

Chisholm did admit that students have a much tougher learning curve than those who enter the industry earlier and learn along the way.

"The legislative frameworks and the concepts that exist now didn't exist then. You've had 15 years to learn what we asking someone to learn in one. That's not a reasonable proposition. In effect, that's what a tertiary education is designed to do."

He said that it is still possible for organisations to be prepared if they play their recruiting cards right.

"It's not that there are no staff; it's that the pool of staff is not sufficient. There are organisations in Australia that have excellent information and cybersecurity capability, but those are not the norm."

Yet Stewart warned that time is running out, and that the situation is only going to get worse if nothing is done.

"We're getting to the point where there's a certain generation that's going to retire out. When we take the institutional experience and transfer it to the next group of people, we're going to frankly face significantly bigger problems. Demand is exceeding supply, and then transference into the training of that supply isn't going quickly enough."

Updated at 9:37, 9 November 2011: clarified that Chisholm had said arrogance of ignorance as opposed to arrogance and ignorance.

Topic: Security

Michael Lee

About Michael Lee

A Sydney, Australia-based journalist, Michael Lee covers a gamut of news in the technology space including information security, state Government initiatives, and local startups.

Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.


Log in or register to join the discussion
  • I have a saying "know all, know nothing" as they have no knowledge of the real world or a real working production environment. Added with "managers" who them selves learnt it from a course or a book which makes a great working environment ! just ask the major sources how well things are going.
  • It's funny that our national skill shortage crisis has reached our universities and their systems....
    Could it be more than a skill shortage?
  • God what a negative article. I work in the consulting space and our company hires a lot of grads out of IT degrees. Are they ignorant? Sure, they are just getting started. Arrogant? Not so much. You get the occasional one but we don't hire them.

    We give our grads good training and mentoring and I'm constantly amazed at how quickly they fit into the organisation. That said, each generation require a slightly different training/mentoring approach to motivate.

    My advice to Cisco would be to take a hard look at your hiring, training and retention strategies before slagging off about a generation of potential employees.
  • 250 years ago, 80% of people were on the land. After the Industrial Revolution, 80% were in factories. Mid 20th century, 80% were in offices. Probably now, 80% are in service industries.

    However, as a species, technological competance is very, very young, and not very widespread. So one should not expect more than a couple of percent of people to understand any one sophisticated technology to much depth at all.
  • This is pathetic. Up to 5 years ago, I was studying IT at TAFE. It was practical work, and they tried to simulate "real-world" situations as best they could, up to and including server failure and disaster recovery. I got nowhere, instead being brushed aside by university guys who, in one place I've heard tell, spend most of their day playing Call of Duty or similar games when they should be working.

    I don't know what it is, but when some people make their place in the IT world, they stop caring. Back then, I would have loved to work as a desktop support person. Now, I'd be lucky to get a job in a computer shop.

    mwil19: is this company based in Sydney? Can you supply the website?
  • I've delt with developers daily for 2 decades and I am astounded at the arrogance that new grads possess, combined in no fundamentals and of course lack of project experience. The fact that they actually believe that they can speak with authority is the most unbelievable behavior.