1. Key insights into cyber security skills in Latin America

Latin America (LATAM) is not immune to the growing global cyber security challenges. As the region experiences rapid digital transformation and increased connectivity, it becomes more susceptible to cyber threats. The dependence on digital technologies for various aspects of daily life makes individuals and organisations vulnerable to cyber attacks. Furthermore, Latin America is home to valuable assets and critical infrastructure which are potential targets for cyber criminals. Thus, a robust cyber security workforce is crucial to protect the region’s digital assets, maintain stability, and ensure the privacy and security of its citizens.

The COVID-19 pandemic has accelerated society’s reliance on digital technology, with remote work being rapidly adopted to keep businesses, schools, and other services operational during lockdowns. However, the widespread use of remote work has exposed individuals and firms to unprecedented cyber security threats (World Economic Forum, 2022[1]). With a significant portion of the workforce now working remotely or using hybrid arrangements, cyber criminals are better able to exploit weaknesses in digital security measures.

In this context, cyber resilience1 has become a crucial societal and policy goal, indicating the need for both private companies and the public sector to anticipate, recover from, and adapt to present and future cyber threats. The World Economic Forum emphasises that for organisations to be resilient, their cyber security teams must be prepared and equipped to face quickly evolving threats, have sufficient budgets, develop and retain talent with adequate cyber security skills (World Economic Forum, 2022[1]). Similarly, the Inter-American Development Bank (IDB) recognises that governments must be equipped to make decisions based on a rapidly changing technological and threat landscape. This requires comprehensive and sustainable cyber security policies, supported by the allocation of financial resources and the development of skilled human capital (IADB & OAS, 2020[2]). The OECD also recommends raising the level of awareness, skills and empowerment across society to manage digital security risk (OECD, 2022[3]). A skilled workforce is, therefore, a cornerstone of cyber resilience, as it enables countries to effectively protect their citizens, organisations, and critical infrastructures.

Against this backdrop, the world is facing a shortage of skilled workforce that hampers the efforts of different actors to achieve cyber resilience. The International Information System Security Certification Consortium, (ISC)2, estimated a global cyber security workforce gap of 3.4 million people in 2022, an increase of 26% with respect to the 2021 estimation (ISC2, 2022[4]). When turning to Latin America (specifically Mexico and Brazil), (ISC)2 estimates a cyber security workforce gap of nearly 516 000 people in 2022, although the gap in this region decreased by 26% relative to 2021.

The Organization of American States (OAS) identifies the cyber security gap in Latin America as the short-term consequence of a strong increase in the demand for cyber security professionals that is not met with adequate labour market supply. Several years of training are needed to develop the necessary skills and competencies to be able to work in the sector, which means the gap is not likely to be filled quickly, even though the misalignment in demand and supply has led to significant increases in wages and competition among available skilled cyber workers (Organization of American States and CISCO, 2023[5]). The lack of sufficient training programmes specific to cyber security is one of the reasons limiting the region’s ability to build a skilled cyber security workforce (Organization of American States and Global Partners, 2022[6]).

Over the past few years, Chile, Colombia, and Mexico have acknowledged the importance of building capacity to address cyber risk and have implemented cyber security policies (see Box 1.1) including objectives for developing and enhancing skills development in both the private and public sectors (Organization of American States and CISCO, 2023[5]). Recent cyber security policy interventions in these countries have placed them in a relatively good position compared to most countries in the region.

The IADB assesses countries’ cyber security readiness against five key dimensions.2 policy and strategy; cyberculture and society; education, training and skills; regulatory frameworks and standards; and organisations and technologies (IADB & OAS, 2020[2]). According to this assessment, the three countries analysed in this report fall in the mid-level stage of cyber security capacity development. In particular, when focusing on the education, training and skills dimension, the report indicates that the three countries have established and operationalised various education and professional training frameworks and have established opportunities for people to educate in cyber security both at a graduate and undergraduate level.

However, further actions are necessary to deliver tailored training programmes and awareness campaigns to develop cyber security capacity in Chile, Colombia and Mexico. The United Nations Economic Commission for Latin America and the Caribbean (ECLAC) recognises the need for Latin American countries to provide improved training activities and awareness campaigns targeted to SMEs – as this group of enterprises are typically at a disadvantage when facing cyber security challenges (ECLAC, 2022[7]). Additionally, experts have called for greater collaboration between academia, the private sector and national cyber security agencies. By enhancing co-ordination among these key stakeholders in the cyber security sector, it becomes possible to align education, training, and research initiatives with the specific needs and strategic objectives of each country in the evolving cyber security landscape (Ruiz Tagle-Vial and Álvarez-Valenzuela, 2020[8]). Such collaborative efforts will enable the development of a skilled cyber security workforce capable of effectively addressing emerging threats and safeguarding critical digital assets in the region.

The first crucial step towards addressing the cyber security skills shortage is to grasp what is happening on the supply and demand sides of the labour market. Such knowledge allows businesses and governments to pinpoint their areas of highest weakness and where they need more resources. Job postings serve as valuable data, shedding light on the trending demand for cyber security experts and determining the currently crucial skills to build a sufficiently secure digital organisation. Additionally, examining the offerings of cyber security education and training programmes provides insights into the ongoing development of this specific labour force.

This report marks the second phase of a comprehensive project designed to enhance the understanding of the cyber security workforce and the associated education and training programmes across various regions and countries (see Box 1.2). Each report is divided into two parts, one dedicated to the demand for cyber security professionals and the other to the landscape of cyber security education and training programmes:

  • The demand-side analysis leverages big data to scrutinise job postings for cyber security professionals, revealing trends and aspects of employer demand through an examination of both the volume and content of these postings. This second report focuses on the demand for cyber security professionals in three LATAM countries: Chile, Colombia, and Mexico.

  • The supply-side analysis focuses on cyber security education and training programmes and the policies and strategies designed to broaden and diversify the cyber security workforce. Each report zooms in on one specific country for this supply-side analysis. For this report, Colombia is the selected country.

Therefore, the goal of this report is to offer a comparative analysis of demand in the three selected countries, providing insights about the development and characteristics of the cyber security profession in the Latin American context. Through the Colombian case study, it provides a deep dive into the kinds of education and training programmes that equip workers for cyber security roles, and the policies that could help to make the profession more appealing and diverse.

Online job postings have become instrumental in tracking labour market developments, playing a pivotal role in providing real-time insights into job demand and industry trends. Traditional labour market data can be limited or outdated, and therefore OJPs offer a dynamic and up-to-date complementary source of information. The increasing reliance on big data in labour market research enables a more nuanced understanding of recent trends and provides insights at a more detailed level compared to traditional data sources. In order to conduct a timely and comprehensive analysis of the demand for cyber security professionals, this report utilises data extracted from nearly 14 million online job advertisements sourced from three selected countries: Chile, Colombia and Mexico.3

Specifically, this report uses this dataset to examine the primary trends in the demand for cyber security professionals during 2021 and 2022. To achieve this, it employs text mining and data science techniques to classify job postings within the cyber security domain and extract relevant information from their texts. OJPs enable the analysis of job requirements, such as desired roles and skills, providing valuable insights into the evolving needs of employers in the region. By leveraging the vast amount of data available through online job postings, this report aims to monitor labour market dynamics and identify emerging trends, which can contribute to tailoring policies and training programmes to address the evolving needs of the cyber security workforce in Latin America.

In Latin America, however, informal employment is a challenge for collecting and extracting information from OJPs, as a significant proportion of jobs are not advertised on online employment platforms or though formal labour market channels. Informal employment represents approximately 55-60% of total employment in Colombia and Mexico, while in Chile it is nearly 30% (see Box 1.3). Moreover, even jobs in the formal sector are not always picked up by the OJP data, and this is especially the case for jobs that require low levels of qualifications – which represent a large portion of the labour market in many LATAM countries- as these are more likely to be advertised through other channels (Cammeraat and Squicciarini, 2021[13]). While this can create distortions in the analyses using OJPs, these limitations are likely to be only partly relevant in the current study, as cyber security jobs are more likely to be found in the formal sector and advertised online. Nonetheless, when interpreting data on OJPs for cyber security professionals relative to other parts of the labour market, one should keep these limitations in mind.

Cyber security education and training programmes take many forms and their content and structure depend on labour market needs and the learners’ profiles. Policies and initiatives to expand the supply of cyber security professionals and make the field more accessible also play a major role in shaping the landscape of learning opportunities. To provide insights into how education and training for cyber security roles can be developed, delivered and promoted, this report focuses on one particular country – Colombia. The purpose of presenting a dedicated case study is to provide a detailed description of programmes, policies and initiatives that could serve as inspiration for other countries developing their cyber security education and training sector.

The Colombian case looks at the landscape of cyber security programmes, focusing on professionally-oriented formal education programmes at the undergraduate level or below (e.g. technical professional and technologist programmes) and non-formal programmes (e.g. diploma certificates or diplomados). The case study also looks into the efforts put in place to create a strong framework for the provision of cyber security programmes, including national strategies for cyber security skills, and efforts to diversify the provision within higher education and to tackle teacher shortages. Special attention is dedicated to policies that contribute to better access and inclusion, describing challenges and initiatives designed to promote participation in cyber security learning, including among female learners and those from disadvantaged backgrounds. The case study analysis builds on national data and literature, as well as insights gathered from interviews with various key stakeholders in the Colombian education and training sector and cyber security field.

Chile, Colombia and Mexico have increased their focus on cyber security over the last decade. These countries have designated national cyber security policies and strategies. These formulate goals that, amongst others, aim to improve citizens’ ability to safely operate in cyberspace and to boost the cyber security sector in each respective country. In accordance with the rising importance of cyber security in Latin America, the demand for cyber security professionals (approximated by the number of online job postings, OJPs) has increased sharply between 2021 and 2022, with the growth rates for cyber security OJPs significantly outpacing those for other occupations, particularly in Chile and Mexico (Figure 1.3).

Most of the OJPs in the cyber security job market are for jobs in main metropolitan cities where major enterprises and government headquarters are found. The share of cyber security roles posted in metropolitan cities is far larger than the share of the Chilean, Colombian and Mexican populations that live in these areas. What contributes to this finding is that certain industries, such as finance, technology, and professional services, tend to have a higher presence in metropolitan areas due to the availability of skilled labour, infrastructure, and market demand. This boosts the demand for high-skilled positions such as cyber security roles.

Results also show that the demand for cyber security professionals is heterogeneous. Among different job roles, cyber security architects and engineers (those in charge of designing and modelling security solutions) stand at the core of the demand for cyber security professionals, recording the highest share of cyber security OJPs in Chile and Mexico in the period analysed. Cyber security analysts, which provide insights to support planning, operations and maintenance of systems security, represent the largest share of OJPs in the cyber security landscape in Colombia. Furthermore, Colombia experienced a significant increase in demand for cyber security auditors and advisors, indicating a growing recognition of the importance of assessing the efficiency and compliance of security solutions.

In the three LATAM countries under exam in this report, vacancies for cyber security roles frequently specify the need for candidates to possess familiarity with cyber security frameworks or standards, and to have obtained specific certifications. Typically, certifications serve as a standardised measure of candidates’ expertise and aptitude in highly specialised areas including, for instance, cyber security. Particularly in Latin America, where the cyber security industry is still developing and rapidly evolving, the signalling function of these certifications is important as employers use them to select qualified candidates, while job seekers employ them to signal their skills.

However, it is worth noting that the certifications which are most sought after in Mexico and Colombia are primarily aimed at experienced professionals, as they necessitate a minimum of five years of relevant work experience but, simultaneously, many employers require them in vacancies for entry-level positions. This disparity between job level and certification requirements hampers efficient talent matching in the region’s cyber security workforce. Potential employees with the necessary skills may be deterred by these certification needs, while employers struggle to find suitable candidates, resulting in prolonged job vacancies and talent shortages. Consequently, there exists a misalignment between the skill requirements of the labour market and the available job opportunities.

Results also show other important bottlenecks in the ability of the available workforce to match the current demand. For instance, proficiency in English is among the most in demand skill requirements across OJPs for cyber security professionals in the region, but the workforce in LATAM traditionally struggles in this area.

On the supply side, the case study for Colombia shows that there can be various educational and training pathways into cyber security roles, with opportunities for progression (see Figure 1.4). The Colombian higher education system provides multiple cyber security training programmes that lead to formal qualifications recognised by the National Ministry of Education (MEN), including vocational and undergraduate programmes. The former include professional technical and technologist courses focused on practice-oriented training, preparing learners for careers in cyber security operations and management. These programmes take between two and three years to complete. Undergraduate programmes delve deeper into the theoretical foundations and advanced concepts of cyber security, emphasising research, innovation, and critical thinking. Learners can also develop basic cyber security skills at lower levels of education, including through cyber security modules integrated into technical upper-secondary education.

In addition to these formal cyber security qualifications, young people and adults in Colombia have the opportunity to engage in non-formal training. This type of training, often shorter and more adaptable than programmes within the formal education system, is frequently embodied in the form of diploma certificates. These are predominantly offered by public and private higher education institutions or training providers in the cyber security field. Such flexible courses typically take between three to 12 months to complete, incorporating practical training, case studies, and group discussions. The content of cyber security diploma certificates can vary, both in terms of difficulty and specialisation. Diploma certificates that cover more general concepts furnish students with foundational technical knowledge in cyber security and computer security management. Others address more advanced and complex topics, with some even aligning with competency certifications or industry-required standards.

Colombia has enacted various policies and strategies to broaden learning opportunities and diversify the workforce in the cyber security sector. The country has focused on developing national strategies that strengthen the response to cyber threats and enhance cyber security capabilities, which have been translated into expanding learning opportunities in the field. Increasing flexibility, particularly within higher education institutions, has been one avenue for effectively and rapidly responding to the evolving skill needs in the sector and catering to a diverse group of learners. Training providers have also implemented innovative strategies to address teacher shortages in ICT. To diversify the workforce of cyber security professionals, the country has emphasised the development of basic digital skills across the wider population in an effort to raise cyber security awareness and foster interest among potential learners in pursuing training in this field. Additionally, multiple policies have been implemented to eliminate barriers that might deter interested individuals from exploring these learning opportunities such as providing financial support to engage with basic technical cyber security training. Box 1.4 provides examples of relevant practices in Colombia, which are further documented in Chapter 3.

The insights derived from the analysis of the demand for cyber security professionals in Chile, Colombia and Mexico and the detailed analysis of the cyber security education and training in Colombia underscore diverse opportunities for Latin American countries to tackle labour and skills shortages in the sector. This section signals some of them.

  • The cyber security profession is in constant redefinition, which poses challenges to employers, education and training providers, and learners to understand the different cyber security roles and associated skill requirements. This challenge calls for joint efforts from different actors to develop a structured and comprehensive characterisation of the profession. The adoption of cyber security skills strategies can facilitate the understanding of the cyber security profession in Colombia, as well as in the rest of LATAM, and establish a common taxonomy that contributes to understanding and analysing labour market dynamics in the field. Developing cyber security skills strategies also enhances the design and implementation of policies to overcome labour shortage in the field by providing a roadmap on how to expand the supply of learning opportunities and make training more responsive to employers’ needs.

  • While knowledge of specific cyber security frameworks is currently in high demand (e.g. ISO/IEC 27000 and ITIL), it is crucial to understand that the field is dynamic and continually evolving, necessitating targeted training efforts to respond to the most recent needs. Assessing and anticipating skills needs through timely and granular data analysis allows countries to generate information about the current and future needs of the cyber security sector (OECD, 2016[19]). These skills assessment and anticipation exercises are vital to stay abreast of emerging trends and to adjust training systems accordingly.

  • It is necessary to raise awareness among stakeholders about the importance of a qualified cyber security workforce to respond to cyber risk. Adherence to cyber security frameworks/standards provides essential guidance, best practices, and a common language for organisations and professionals. These tools enable them to establish comprehensive cyber security strategies, mitigate digital security risk, and enhance overall cyber security resilience.

  • Higher education institutions offer a wide range of formal programmes (e.g. technical professionals, technologists and undergraduates) that lead to entry-level job opportunities in cyber security. Some education institutions also have articulation arrangements (i.e. propaedeutic cycle) which play a crucial role in smoothing the transition from general ICT technical programmes to technologists and undergraduate programmes in cyber security. This approach is designed to prepare students for more specialised studies in their chosen field, building on the solid foundation in core ICT concepts and principles they already acquired.

  • Education institutions are increasingly aware of the need to provide programmes and courses that meet the diverse needs of learners, while addressing labour market needs. Diversifying the cyber security offer in higher education to include non-formal training programmes contributes to meeting skills demand more swiftly. It is also essential to facilitate the creation of flexible training programmes that provide sufficient opportunities for cyber security training aligned with labour market needs, that are quality assured and easily accessible, especially for more disadvantaged learners such as those facing financial barriers and digital illiteracy. Such non-formal programmes should ideally lead to certificates that are easily recognised by employers.

  • Partnerships between higher education institutions and private sector companies or specialised international training providers are key to expand the provision of cyber security training. In Colombia, this collaboration has led to an expansion of customised short training programmes, such as diploma certificates. This responds to particular skill needs, while typically also being part of learning pathways or building blocks for developing more advanced and specialised skills. Some are even linked to industry certifications which are in high demand in the cyber security sector.

  • Teacher shortages affect the provision of cyber security education and training in countries like Colombia. Educational institutions need strategies to attract and retain instructors and professors in ICT fields in a context of significant shortages of cyber-related professionals. Strengthening relationships with companies to provide training to ICT teachers, allowing professionals in industry to dedicate some time to teaching and improving teachers’ English proficiency can contribute to reducing shortages.

  • Participation in cyber security education and training requires individuals to possess solid basic digital skills. Digital illiteracy is common in Latin America, especially among individuals from disadvantaged backgrounds. In Colombia, for instance, the provision of training programmes covering key fundamentals ICT subjects has been crucial to equip learners with basic concepts for digital navigation and facilitate progression to advanced training. Additionally, developing such skills from a young age can contribute to generating interest in ICT professions, such as in cyber security.

  • Enhancing English language proficiency is crucial in mitigating the workforce cyber security gap in LATAM. The English proficiency gap creates significant obstacles to cultivating cyber security skills, as most of the training resources are not available in Spanish. Potential solutions could include offering cyber security training in local languages or providing translation services. Nonetheless, strategies should also focus on improving English proficiency levels in the region to ensure that individuals can access cyber security opportunities offered in English.

  • Gender stereotypes can hinder participation in cyber security education and training. Even though countries like Colombia have experienced reductions in the performance gap between boys and girls in mathematics and sciences, the proportion of female professionals in ICT remains low. Latin American countries need initiatives to encourage women to engage in education and training in STEM fields and specifically in ICT and cyber security topics. Platforms and spaces for women to connect, learn and share their experiences in these fields are valuable initiatives towards promoting interest in the profession.


← 1. The World Economic Forum defines cyber resilience in the Global Cyber Security Outlook 2022 as “the ability of an organisation to transcend (anticipate, withstand, recover from, and adapt to) any stresses, failures, hazards and threats to its cyber resources within the organisation and its ecosystem, such that the organisation can confidently pursue its mission, enable its culture and maintain its desired way of operating” (World Economic Forum, 2022[1]).

← 2. The IADB and OAS study uses the Cyber security Capacity Maturity Model for Nation (CMM) developed by the Global Cyber Security Capacity Centre of the University of Oxford to assess the maturity of the countries’ cyber security capacity (IADB & OAS, 2020[2]).

← 3. Data is provided by Lightcast.io.

← 4. In this report, informal employment “…refers to working arrangements that are de facto or de jure not subject to national labour legislation, income taxation or entitlement to social protection or certain other employment benefits (advance notice of dismissal, severance pay, paid annual or sick leave, etc.).” (OECD/ILO, 2019[26]).

← 5. This figure follows the International Labour Organization (ILO) definition of employment and labour informality: “Employment comprises all persons of working age who, during a specified brief period, were either in paid employment (whether at work or with a job but not at work) or in self-employment (whether at work or with an enterprise but not at work). Informal employment comprises persons who in their main or secondary jobs were: (a) own-account workers, employers and members of producers´ co-operatives employed in their own informal sector enterprises; (b) own-account workers engaged in the production of goods exclusively for own final use by their household (e.g. subsistence farming); (c) contributing family workers, regardless of whether they work in formal or informal sector enterprises; or (d) employees holding informal jobs, whether employed by formal sector enterprises, informal sector enterprises, or as paid domestic workers by households” (ILOSTAT, 2023[15]).

