‘The bucket is leaking, and the industry keeps blaming the tap,’ writes Nahla Davies discussing the cybersecurity talent shortage.
For a decade, the cybersecurity industry has told itself one story about its staffing crisis: there aren’t enough people. Train more, certify more, run more bootcamps, and the 4.8 million global workforce gap will close. It’s a comforting story, because it makes the problem someone else’s job: the schools’, the government’s, the pipeline’s.
There’s just one difficulty. The people who own the most-cited version of that gap statistic, ISC2, also explained why it grew, and the reason has nothing to do with a shortage of talent.
The year the pipeline delivered and the gap grew anyway
In ISC2’s 2024 study, the global cybersecurity workforce grew by just 0.1pc, effectively flat after years of expansion, while the workforce gap widened by 19pc. If this were a supply problem, those two numbers would move together.
Instead, the study named the actual cause: budget was the top factor, cited by 39pc, ahead of any talent shortage, with 37pc of organisations reporting budget cuts, 38pc hiring freezes and a quarter making layoffs.
Read plainly, that means the gap grew in a year when supply held steady and demand for hiring was cut. The bucket is leaking, and the industry keeps blaming the tap.
The paradox sharpens at entry level. A third of organisations reported no entry-level staff at all, while ISC2’s hiring research found 38pc of managers demanding a CISA certification and 34pc a CISSP for junior roles, credentials that themselves require around five years of experience.
The sector loudly requests more pipeline, then refuses to hire the pipeline’s output. The famine is partly self-imposed.
Where the people are actually going
If supply isn’t the bottleneck, the exits are. And the data on why experienced people leave is damning, precisely because it rules out the easy explanation.
It isn’t pay. CISO compensation rose 6.7pc in 2025 and salaries across the field remain strong. People are walking away from good money.
It’s the conditions. ISACA’s 2025 research found 55pc of teams understaffed, 50pc struggling to retain talent, and 47pc naming high stress as the leading reason people leave, ahead of pay.
Among SOC analysts specifically, Tines found more than half likely to change employer within a year, with manual, repetitive work and alert fatigue topping the list of frustrations.
Gartner saw this coming. Back in 2023, it predicted that nearly half of cybersecurity leaders would change jobs by 2025, a quarter leaving the field entirely due to work-related stress, with the analyst noting bluntly that burnout and attrition are outcomes of poor culture. From the vantage point of mid-2026, that prediction reads less like a forecast and more like a description.
Then there’s the newest accelerant, aimed squarely at the top of the experience curve: personal liability. Since the prosecution of Uber’s former security chief and the SEC’s action against SolarWinds, 66pc of CISOs report concern about personal liability, and a separate survey found 70pc saying liability stories had soured their view of the role. You cannot train your way around senior people concluding the top job is a legal risk not worth taking.
The gap is seniority-shaped
This is why the pipeline framing fails on its own terms. The shortage isn’t of bodies; it’s of experience, and experience is the one thing a bootcamp cannot manufacture on demand.
Kaspersky found 48pc of organisations take six months or more to fill a cybersecurity role, and 36pc take close to a year for senior positions. Most open roles sit at mid to advanced level. Every burned-out senior analyst who leaves creates a vacancy no graduate can fill, and takes institutional knowledge out the door with them, while the industry poaches the same shrinking pool of experienced people from itself in a zero-sum loop that inflates salaries without adding a single net defender.
Ireland’s maths depends on the leak
For Ireland, the stakes are concrete.
The All-Island Cybersecurity Sector Report 2025 counted 632 firms, 10,600 professionals and €3.2bn in revenue, and Cyber Ireland’s earlier labour-market work set a target of 17,000 cyber jobs by 2030, needing more than a thousand hires a year.
That target is usually discussed as a recruitment challenge. It is really a retention challenge wearing a recruitment costume, because if half of organisations can’t keep the people they already have, the pipeline has to first refill the leak before it adds anyone net new.
Ireland’s 2030 ambition quietly assumes a retention rate the sector is not currently achieving, and the wider European picture is no kinder, with an EU Eurobarometer finding over half of companies struggling to recruit cyber staff.
What a retention-first industry would do
The fixes are known, cheaper than perpetual re-hiring, and almost entirely within an employer’s control. Automate the toil, because when SOC analysts name manual work as their top frustration, the 64pc of their time lost to it is a resignation letter being drafted in real time.
Build a blameless culture, since Gartner’s own diagnosis put culture, not headcount, at the root. Hire and train juniors, given that ISC2 found entry-level hires productive within a year at modest cost, yet transition-training programmes are being cut rather than expanded. And de-risk the senior roles with proper liability cover and documented governance, so the experience you have is not frightened out of the profession.
One honest caveat – none of this means the pipeline is irrelevant. Long term, the field genuinely needs more entrants and Ireland’s education investment matters.
But pouring water into a leaking bucket faster is not a plan, and calling the leak a supply shortage is the industry’s most expensive act of denial. The gap statistic everyone quotes to demand more training is, on ISC2’s own reading, substantially a measure of churn and cut budgets, laundered into the language of a talent famine.
The people exist. The question the industry keeps refusing to ask is why so many of them are leaving.
By Nahla Davies
Nahla Davies is a software developer and tech writer. Before devoting her work full time to technical writing, she managed – among other intriguing things – to serve as a lead programmer at an Inc 5,000 experiential branding organisation, where clients include Samsung, Time Warner, Netflix and Sony.
Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.
You must be logged in to post a comment Login