Why the digital skills shortage poses a security risk for banks

The digital skills shortage has hit a crisis point and the effects are being felt firmly across the UK. Millions of workers lack the vital digital workplace skills necessary to do their job according to a report part-commissioned by Lloyds Banking Group. Not only is this causing a slow down in digital transformation initiatives, but we’re now also at a point where our banks are facing grave security risks and increasingly sophisticated cyber-attacks as a result of both their unskilled workforces and an industry-wide lack of job-ready talent.
Since 2020, enterprises have experienced what McKinsey has labelled a ‘quantum leap’ in digital adoption and digital transformation, but many organisations – particularly those in the financial sector, such as banks – have been left playing catch up due to a lack of digital-savvy staff.
The situation is getting worse too, with additional factors such as the Great Resignation causing banks severe security issues due to a forced reliance on outdated, legacy infrastructure that is increasingly vulnerable to sophisticated cyber-attacks. While the growth of cloud-based banking is undoubtedly the solution due to the built-in security preventions of modern technology, banks are struggling to undergo these digital transformations due to a lack of internal digital expertise.
While we are seeing record levels of investment in cybersecurity (the UK Government reported aggregate revenue of more than £10 billion for the sector last year), the ongoing challenge for banks remains their pregnable legacy infrastructure. Many financial services organisations are still reliant on systems that have been iteratively updated and built upon over years of operation. As a result, it can be a real financial and logistical challenge to maintain and rebuild these systems, especially when coupled with a lack of job-ready digital talent, with the necessary cloud development and cybersecurity skills, within an organisation.
Eliminating legacy architectures and replacing them with new, cloud-based technologies is undoubtedly the way forward, especially for financial services organisations. But banks without up-to-date technology are those most susceptible to security risks, owing to the simple fact that older and more internally convoluted systems tend to be easiest to breach.
Security holes tend to appear when manufacturers stop offering support for older access control systems or when fewer IT professionals have the knowledge and skills required to navigate older architecture. In addition, contemporary cloud-based security solutions, such as zero-trust methods that go beyond classic perimeter security approaches can be complex to set up when data is tied up in older systems. Where the integration of new and old technologies is difficult, data silos can be created, leading to added cybersecurity spending and access frustration.
In a world shifting increasingly to cloud technologies and zero-trust security systems, legacy systems leave banks unable to either compete or effectively mitigate risk, which makes finding a solution for their lack of internal digital expertise a primary concern in a bid to remain compliant.

