digital forensics experttocybersecurity risk manager
A digital forensics expert already meets 33% of what the cybersecurity risk manager role asks for. The move turns on 13 required skills not yet in the profile.
33%
75.4/ 100
1 Share of the cybersecurity risk manager role’s weighted skill requirement already met by the digital forensics expert profile. Required skills count in full, supplementary skills at 0.35. Directional: the figure for the reverse move differs. 2 Combines what is missing with how specialised it is, so a gap of general skills scores easier than the same number of narrow ones.
Why this move works
A cybersecurity risk manager role treats 9 of its required skills as things a digital forensics expert already does. These are the ones it depends on most.
- ICT network security risks
- ICT security standards
- attack vectors
- cyber attack counter-measures
- cyber security
- establish an ICT security prevention plan
What stands in the way is 13 required skills the profile does not yet cover. Table 3 groups them; Table 4 says which to take first.
Table 2 · What you already bring
Of the 20 skills that carry over, these are the ones fewest other occupations ask for. A cybersecurity risk manager role needs them, and most people applying for one will not have them already. This is the part of a digital forensics expert background worth leading with.
- already held establish an ICT security prevention plan management skills
- already held computer forensics information and communication technologies (icts)
- already held develop information security strategy assisting and caring
- already held cyber attack counter-measures services
- already held ICT encryption information and communication technologies (icts)
- already held identify ICT security risks information skills
All 20 carried skills, including the 9 the cybersecurity risk manager role treats as required.
Table 3 · What you would need to learn
The 52 missing skills fall into 7 areas of the ESCO skill hierarchy, numbered below in the order worth working in: the areas carrying the most required skills come first, and inside each one the required skills sit above the supplementary ones.
- required, not held ICT performance analysis methods required
- required, not held ethical hacking principles required
- required, not held assessment of risks and threats required
- optional, not held ICT problem management techniques optional
- optional, not held ICT process quality models optional
- optional, not held ICT recovery techniques optional
- optional, not held ICT system user requirements optional
- optional, not held Internet of Things optional
- optional, not held Open source model optional
- optional, not held Outsourcing model optional
- optional, not held cloud monitoring and reporting optional
- optional, not held cloud security and compliance optional
- optional, not held decision support systems optional
- optional, not held domain name service optional
- optional, not held hybrid model optional
- optional, not held internet governance optional
- optional, not held mobile device management optional
- optional, not held service-oriented modelling optional
- optional, not held web application security threats optional
- optional, not held systems development life-cycle optional
- required, not held ICT safety required
- required, not held manage system security required
- optional, not held develop with cloud services optional
- optional, not held implement a firewall optional
- optional, not held implement a virtual private network optional
- optional, not held implement anti-virus software optional
- optional, not held implement spam protection optional
- optional, not held manage keys for data protection optional
- optional, not held use an application-specific interface optional
- optional, not held remove computer virus or malware from a computer optional
- optional, not held solve ICT system problems optional
- optional, not held use ICT ticketing system optional
- optional, not held use back-up and recovery tools optional
- required, not held internal risk management policy required
- required, not held risk management required
- optional, not held ICT project management optional
- optional, not held ICT quality policy optional
- optional, not held investment analysis optional
- optional, not held organisational resilience optional
- required, not held advice on security risk management required
- required, not held implement ICT risk management required
- optional, not held execute ICT audits optional
- optional, not held implement cloud security and compliance optional
- required, not held communicate with stakeholders required
- required, not held engage with stakeholders required
- optional, not held design for organisational complexity optional
- required, not held ensure adherence to organisational ICT standards required
- required, not held establish an Information Security Management System required
1 further area in the appendix
Table 4 · Where to start
The 3 entries a cybersecurity risk manager role is least likely to hire without. The ordering is computed from the skill data, not from what pays.
- 01 ICT performance analysis methods knowledge · sector specific
- 02 ICT safety skill · unknown
- 03 advice on security risk management skill · sector specific
Each entry opens a course search for that skill. Career Overlap earns nothing from these links.
Appendix · The rest of the record
All 20 skills that carry over
- already held ICT network security risks knowledge
- already held ICT security standards knowledge
- already held attack vectors knowledge
- already held cyber attack counter-measures knowledge
- already held cyber security knowledge
- already held establish an ICT security prevention plan skill
- already held information security strategy knowledge
- already held security engineering knowledge
- already held security threats knowledge
- already held ICT encryption knowledge
- already held ICT security legislation knowledge
- already held audit techniques knowledge
- already held computer forensics knowledge
- already held develop information security strategy skill
- already held identify ICT security risks skill
- already held implement ICT security policies skill
- already held information confidentiality knowledge
- already held legal requirements of ICT products knowledge
- already held levels of software testing knowledge
- already held tools for ICT test automation knowledge
The 1 learning area not shown above
- optional, not held define security policies optional
- optional, not held define technology strategy optional
- optional, not held lead disaster recovery exercises optional
- optional, not held manage disaster recovery plans optional
39 supplementary skills, helpful but not required
- optional, not held ICT problem management techniques optional
- optional, not held ICT process quality models optional
- optional, not held ICT project management optional
- optional, not held ICT quality policy optional
- optional, not held ICT recovery techniques optional
- optional, not held ICT system user requirements optional
- optional, not held Internet of Things optional
- optional, not held Open source model optional
- optional, not held Outsourcing model optional
- optional, not held cloud monitoring and reporting optional
- optional, not held cloud security and compliance optional
- optional, not held decision support systems optional
- optional, not held define security policies optional
- optional, not held define technology strategy optional
- optional, not held design for organisational complexity optional
- optional, not held develop with cloud services optional
- optional, not held domain name service optional
- optional, not held execute ICT audits optional
- optional, not held hybrid model optional
- optional, not held implement a firewall optional
- optional, not held implement a virtual private network optional
- optional, not held implement anti-virus software optional
- optional, not held implement cloud security and compliance optional
- optional, not held implement spam protection optional
- optional, not held internet governance optional
- optional, not held investment analysis optional
- optional, not held lead disaster recovery exercises optional
- optional, not held manage keys for data protection optional
- optional, not held mobile device management optional
- optional, not held organisational resilience optional
- optional, not held service-oriented modelling optional
- optional, not held use an application-specific interface optional
- optional, not held web application security threats optional
- optional, not held manage disaster recovery plans optional
- optional, not held remove computer virus or malware from a computer optional
- optional, not held solve ICT system problems optional
- optional, not held systems development life-cycle optional
- optional, not held use ICT ticketing system optional
- optional, not held use back-up and recovery tools optional
57 held skills the cybersecurity risk manager role does not ask for
- not needed by the target role Aircrack (penetration testing tool) knowledge
- not needed by the target role Backbox (penetration testing tool) knowledge
- not needed by the target role BlackArch knowledge
- not needed by the target role Cain and Abel (penetration testing tool) knowledge
- not needed by the target role GDPR knowledge
- not needed by the target role ICT infrastructure knowledge
- not needed by the target role John The Ripper (penetration testing tool) knowledge
- not needed by the target role Kali Linux knowledge
- not needed by the target role LDAP knowledge
- not needed by the target role LINQ knowledge
- not needed by the target role MDX knowledge
- not needed by the target role Maltego knowledge
- not needed by the target role Metasploit knowledge
- not needed by the target role N1QL knowledge
- not needed by the target role Nessus knowledge
- not needed by the target role Nexpose knowledge
- not needed by the target role OWASP ZAP knowledge
- not needed by the target role Parrot Security OS knowledge
- not needed by the target role SPARQL knowledge
- not needed by the target role Samurai Web Testing Framework knowledge
- not needed by the target role THC Hydra knowledge
- not needed by the target role WhiteHat Sentinel knowledge
- not needed by the target role Wireshark knowledge
- not needed by the target role XQuery knowledge
- not needed by the target role analyse network configuration and performance skill
- not needed by the target role apply reverse engineering skill
- not needed by the target role check methods knowledge
- not needed by the target role cloud technologies knowledge
- not needed by the target role collect cyber defence data skill
- not needed by the target role data storage knowledge
- not needed by the target role design computer network skill
- not needed by the target role digital data processing skill
- not needed by the target role educate on data confidentiality skill
- not needed by the target role forensic intelligence knowledge
- not needed by the target role gather data for forensic purposes skill
- not needed by the target role hardware architectures knowledge
- not needed by the target role hardware platforms knowledge
- not needed by the target role identify ICT system weaknesses skill
- not needed by the target role implement ICT network diagnostic tools skill
- not needed by the target role information architecture knowledge
17 further entries not listed here
26 gaps that are knowledge rather than practice
Knowledge gaps usually close through study. Practical skill gaps usually need something you can point at.
- required, not held ICT performance analysis methods required
- required, not held ethical hacking principles required
- required, not held internal risk management policy required
- required, not held assessment of risks and threats required
- required, not held risk management required
- optional, not held ICT problem management techniques optional
- optional, not held ICT process quality models optional
- optional, not held ICT project management optional
- optional, not held ICT quality policy optional
- optional, not held ICT recovery techniques optional
- optional, not held ICT system user requirements optional
- optional, not held Internet of Things optional
- optional, not held Open source model optional
- optional, not held Outsourcing model optional
- optional, not held cloud monitoring and reporting optional
- optional, not held cloud security and compliance optional
- optional, not held decision support systems optional
- optional, not held domain name service optional
- optional, not held hybrid model optional
- optional, not held internet governance optional
- optional, not held investment analysis optional
- optional, not held mobile device management optional
- optional, not held organisational resilience optional
- optional, not held service-oriented modelling optional
- optional, not held web application security threats optional
- optional, not held systems development life-cycle optional
Other moves recorded from digital forensics expert
How this record was compiled
Both occupations are taken from ESCO, which lists the skills and knowledge each occupation is expected to have and marks every one required or optional. Nothing here is a prediction about hiring, and nothing here knows that a particular employer wants a particular certificate. Treat Table 3 as a starting point for your own research rather than a syllabus. The full method states what these figures can and cannot tell you.