There has also been a year-on-year increase in the number of respondents whose organisations are trying to offer a more interesting and creative environment for their subject matter experts. A greater emphasis on recruitment of graduates was subsequently reflected in the respondents’ answers to a question mapping the average length of relevant cybersecurity work experience (see Graph 11). Respondents listed the following positions as the top five most difficult to fill: cybersecurity architects, network infrastructure administrators, SIEM security oversight positions, server infrastructure administrators, and cybersecurity auditors. 50% 40% 30% 20% 10% 0% 47 46 27 6 1 2020 41 22 21 2021 19 21 18 9 6 0-1 year 2022 1-5 years 15 years and more 5-15 years 4 11 Do not know Graph 11: Average  Relevant Experience of Cybersecurity Staff in Respondents‘ Organizations (in % of Respondents) People as Users: Majority of Organizations Trains and Tests its Staff Since a large percentage of cyber incidents are caused by user error or carelessness, education and testing for staff members constitutes an integral part of ensuring cybersecurity. The good news in this regard is that only less than 5% of respondents reported a complete absence of any cybersecurity training for employees. More than half of the interviewed organizations train their staff at least once a year, with nearly a tenth of organizations actively training more than once every six months (see Graph 12). More than half of the surveyed organizations test all their staff at the same time, most often through simulated phishing campaigns. To strengthen their cybersecurity, some organizations also use penetration testing techniques or participate in technical and non-technical exercises (see Graph 13). 60% 57 40% 20% 0% 4 More often than every 6 months 10 8 Every 6 months Annually Every 2 years 13 Once during employment 8 Never Graph 12: Frequency of Cybersecurity Trainings in Organizations in 2022 (in % of Respondents) 13

Select target paragraph3