Security Staffing’s Problem Is Skills, and 60% Agree

For years, one number defined the security staffing conversation: a global headcount gap in the millions. In 2025, ISC2, the organization behind that number, stopped leading with it. Two major surveys, a record year for breach costs, and Europe’s own regulator all point at the same reframe: the problem was never how many people you have. It’s whether they have the right skills, right now.

Stats band showing four key figures the piece is built on: SANS 2026 finding 60% of organizations now cite skills gaps over headcount, IBM 2026 recording a $4.99M average breach cost, ISACA 2025 finding 65% of organizations have unfilled cybersecurity positions, and ENISA 2025 finding 45% cite skills as the top hiring barrier.

For years, one number has defined every security staffing conversation: a global headcount gap running into the millions. It’s the figure behind a thousand conference keynotes and just as many vendor pitches, repeated so often that it has become shorthand for the entire problem, and repeated just as often inside board decks used to justify a security staffing budget request. In 2025, ISC2, the organization that has published that number annually for over a decade, made a quiet but telling change: it stopped leading with it.

That’s not a minor editorial choice. It’s an admission that the number everyone quotes was measuring the wrong thing, and that most security staffing conversations built on top of it have been solving for the wrong variable. Six signals point at the same reframe, drawn from two major workforce surveys, a record year for data breach costs, Europe’s own cybersecurity agency, and the World Economic Forum: security staffing was never really a counting problem.

It’s a question of whether the people already on a team, or the people a team can actually reach, have the specific skills a given threat requires, right now, not in a hiring cycle that runs three to six months. Every figure below is drawn directly from the organizations that published it, not from a summary of a summary, which matters when the whole point is that the widely repeated version of this story has been wrong.

The organization that owns the headcount number backed off it

Card showing 60% of organizations now cite skills gaps over headcount shortages per SANS's 2026 report, alongside ISC2's own quote that resilience depends less on headcount and more on capability

If any single source has the authority to say the security staffing conversation has been framed wrong, it’s the one that built the framing in the first place. Two more sources reach the same conclusion independently, from different data and different years.

SANS found skills gaps had overtaken headcount as the top complaint

SANS’s 2026 workforce report, its third annual edition and unveiled at RSAC 2026, surveyed roughly 1,000 respondents across six regions and found that 60% of organizations now identify skills gaps as their bigger security staffing problem, against 40% citing headcount shortages. A year earlier, that split had been a four-point gap.

The swing to twenty points in a single year is the kind of shift that does not happen by coincidence, and it lines up with a second, much larger finding in the same report: entry-level roles, the ones a pure headcount strategy is built to fill, are being cut fastest of all, with SOC analyst and threat intelligence analyst positions down 32% and 26% respectively as AI absorbs the work those roles used to do.

ISC2 itself stopped leading with the gap number

ISC2’s 2025 Cybersecurity Workforce Study, based on responses from 16,029 cybersecurity practitioners collected in May and June 2025, states plainly that the study has historically “led with global and regional estimates on the overall workforce size” and the associated gap figure, but that “cybersecurity resilience… depends less on headcount and more on agility, capability and continual skill development.” Eighty-eight percent of respondents said they had experienced a real, specific consequence from a skills shortage, not a hypothetical risk.

Fifty-nine percent reported critical or significant skill needs, up 15 points from the year before, one of the largest single-year swings the study has recorded. Security staffing, by the organization’s own read of its largest dataset to date, is a skills question wearing a headcount costume, and the costume has started to slip in the data itself, which is exactly why the security staffing number everyone still quotes no longer tells the full story.

A record year for breach costs, with a name attached to the cause

Card showing IBM's 2026 record global average breach cost of $4.99 million, converted to €4.35 million at today's exchange rate, alongside SANS findings that 27% of breaches trace to a capability gap and 74% say AI is reshaping team structure

Abstract security staffing survey findings are easy to set aside as an HR problem rather than a security one. A bill is harder to ignore, and 2026 delivered a large one.

The global average just hit a record high

IBM’s 2026 Cost of a Data Breach Report puts the global average cost of a breach at $4.99 million, a 12% increase over the prior year and a new record, driven in large part by higher detection, escalation and lost-business costs. That increase landed in the same year two major workforce studies independently concluded that security staffing gaps had shifted from a headcount problem to a skills one, which is not a coincidence worth ignoring. A breach that takes longer to detect and contain because nobody on the team recognized the specific pattern is a security staffing failure with a dollar figure attached to it, even when the organization involved was never short of open seats to begin with.

More than a quarter of breaches trace to a capability gap, not an empty seat

SANS’s same 2026 report found that 27% of organizations that experienced a breach traced it directly to a capability gap on their security team, not a vacancy. Meanwhile, 74% of organizations said AI is already reshaping their security team’s structure, and only 21% have a comprehensive AI security framework in place to manage that shift. A team can be fully staffed on paper and still miss the specific, current expertise a modern breach actually requires. That is precisely the failure mode a headcount-first security staffing plan is structurally blind to, because it counts seats filled rather than asking whether the person in the seat has ever handled the specific pattern the breach turned out to be.

The hiring cycle itself is the bottleneck

Timeline showing 65% of organizations currently have unfilled cybersecurity positions per ISACA, with non-entry roles taking three to six months to fill

Even where the will and the budget exist, security staffing runs into a much more mundane obstacle than skills scarcity alone: how long it actually takes to fill a seat once a real opening exists. That timeline, not the size of the gap itself, is what makes a purely headcount-based security staffing plan so brittle against a threat landscape that changes faster than any hiring process can.

Two in three organizations have unfilled positions right now

ISACA’s State of Cybersecurity 2025 report, its eleventh annual global survey, found that 65% of organizations currently have unfilled cybersecurity positions. This is not a niche problem affecting a handful of specialist roles. It is the ordinary condition of most security teams, most of the time, and it means most security staffing plans are being built and re-built around a gap that never fully closes before the next one opens.

Even non-entry roles take three to six months to fill

The same ISACA report found that 39% of organizations need three to six months to fill a non-entry-level security role, and 38% report the same timeline for entry-level roles. A security staffing gap identified today, addressed through a standard hire, is realistically a gap that persists through the next two fiscal quarters. Against SANS’s finding that AI is reshaping team structure inside a single year, a six-month hiring cycle is not fast enough to keep pace with what a team actually needs.

Europe’s version of the same problem has its own numbers

Card showing ENISA's EU cybersecurity shortage figures: 299,000 estimated EU shortage, 76% struggling to attract talent, 71% struggling to retain it, and 45% citing skills as the leading hiring barrier

None of this is a uniquely American pattern. Europe’s own cybersecurity agency measured the same dynamic independently, with figures specific to the EU, and its security staffing findings line up with SANS and ISC2’s almost exactly despite drawing on a completely separate respondent pool.

The EU-specific numbers back up the global pattern

ENISA’s NIS Investments 2025 report, based on responses from 1,080 organizations, found that 76% of EU organizations struggle to attract cybersecurity professionals and 71% struggle to retain the ones they already have. The estimated shortage within the EU reached 299,000 in 2024, a 9% increase from the year before, with the wider European gap at 424,000 and the global figure ENISA cites, corroborating ISC2’s own number, at 4.8 million. Critically, ENISA names the actual root cause directly rather than leaving it to inference: the leading barrier to hiring is difficulty finding candidates with the required skills, cited by 45% of organizations, ahead of budget constraints, unattractive compensation, or any other factor security staffing conversations usually reach for first.

Smaller organizations feel the security staffing gap hardest

ENISA’s data shows the gap is not evenly distributed. Ninety-four percent of SMEs report difficulty attracting cybersecurity personnel and 90% report difficulty retaining them, compared with 83% and 80% among large enterprises. Smaller organizations are also less likely to have dedicated security staff or formal risk-management processes at all, according to the same report.

Smaller organizations are the least likely to have a dedicated security staffing budget large enough to compete for scarce, specialized skill on salary alone, which makes the timing mismatch between a hiring cycle and an active threat even more costly for exactly the organizations least equipped to absorb it. A large enterprise stretched thin can often shift an existing generalist onto an urgent problem for a few weeks; a smaller organization frequently has no equivalent slack to borrow from.

The specific skills missing are not generic

Card showing 85% of organizations with insufficient resilience cite missing skills, with the World Economic Forum naming three specific roles: threat intelligence analysts, DevSecOps engineers, and identity and access management specialists

Knowing that security staffing is a skills problem, not a headcount one, only helps if it’s clear which skills are actually the ones in short supply. A generic security staffing plan that just says “hire more people” gives a recruiter nothing to search against.

DevSecOps and identity management are named, specific gaps

The World Economic Forum’s Global Cybersecurity Outlook 2026, its fifth edition, produced with Accenture from 804 respondents across 92 countries including 316 CISOs, found that 85% of organizations reporting insufficient cyber resilience also cited missing critical skills and people as a cause. The report names the three roles facing the most acute security staffing shortages directly, rather than leaving the category vague: threat intelligence analysts, DevSecOps engineers, and identity and access management specialists. 

Two of those three are exactly the areas Fyld’s own DevSecOps guide and Non-Human Identity piece cover in technical depth, not a coincidence given how fast both practices have had to evolve, and a useful reminder that a security staffing gap named at the level of “we need more security people” is rarely specific enough to act on.

The gap moves faster than most teams can retrain for it

SANS’s finding that AI is reshaping team structure at 74% of organizations, against only 21% with an actual AI security framework, is itself a named skills gap most security staffing plans were not built to anticipate. A team that has never had to review an MCP server’s permissions, for instance, does not close that specific gap by hiring a generalist security engineer on a standard six-month timeline. 

Fyld’s own MCP security piece is a useful test here: if nobody on a given team could have written it, that is itself a signal worth taking seriously, and a much more precise diagnostic than asking whether the team is “fully staffed” in a headcount sense. Most security staffing plans get built around job titles and years of experience, neither of which reliably predicts whether someone has touched this specific, current class of problem before.

Budgets are already moving away from headcount

Quote card from ENISA's NIS Investments 2025 report stating investment is shifting toward technology and outsourcing rather than expanding internal teams, with headcount declining as budgets held steady or grew

None of this is a hypothetical response Fyld is proposing from outside. It is already what the spending data shows organizations doing with their own security staffing budgets, whether or not they would describe it in those terms internally.

ENISA found spending shifting toward technology and outsourcing, not headcount

The same ENISA report opens with exactly this finding as its first insight: EU organizations have held cybersecurity investment roughly level year over year, but that spending is increasingly “directed more toward technology and outsourcing rather than expanding internal cybersecurity teams.” Average in-house cybersecurity headcount actually declined slightly across the 1,080 organizations surveyed, even as overall security budgets held steady or grew. 

The money did not disappear. It moved, and it moved toward exactly the kind of flexible, specialized capacity this piece has been describing throughout, which is a striking thing for a security staffing budget to do only if the underlying constraint is still assumed to be a counting problem rather than a skills one.

That shift is a rational response to a skills problem, not a budget one

Read against everything above, that reallocation makes sense in a way a pure headcount story never could. If the real constraint were money, spending would track headcount more closely than it does, and budgets would simply grow until enough people were hired. 

If the real constraint is finding people with the right, current skills on any reasonable timeline, redirecting budget toward outsourcing and specialized technology is exactly the adjustment a rational organization makes while a standard hire is still three to six months out. Security staffing built around flexible capacity is not a workaround for budget constraints or a sign an organization has given up on building a real team. For a growing share of EU organizations, according to ENISA’s own numbers, it is already the primary strategy, not a fallback position.

What actually closes a skills-shaped gap

Six signals, one consistent shape: the barrier is specific, current expertise, not an empty seat that any qualified candidate could fill. That reframe changes what a sensible security staffing response actually looks like, and it changes what a smart security staffing budget gets spent on first.

ENISA’s own data makes the point precisely: the leading barrier to hiring, at 45%, is not budget or headcount, it’s finding candidates with the required skills. That is a fundamentally different problem than the one a standard three-to-six-month hiring process is built to solve, because a generalist req does not target a specific, current gap the way a scoped engagement can. 

IT Team Expansion and Team as a Service exist for exactly that mismatch: a security staffing model built around bringing in the specific, current expertise a team is missing, even when the  timeline is shorter, even when the verdict isn’t out on who should eventually sit on a security team permanently. 

For organizations whose gap is less about a single skill and more about ongoing coverage, IT Managed Services provides the continuous attention a stretched internal team often cannot sustain on top of everything else already on its plate, which is its own quiet form of security staffing relief even when nobody is technically hired.

It’s worth being direct about what this is not. None of this is a claim that flexible security staffing solves the global 4.8 million person gap on its own, or that it substitutes for building durable, in-house capability over time.

 A security staffing model built entirely around outside capacity, with no plan to eventually own the recurring parts of the work internally, just trades one structural weakness for another. What it addresses is narrower and more honest: the gap between when a specific, current skill becomes necessary and when a standard hiring process could realistically deliver it. 

A security staffing decision made on those terms, rather than on a headcount target, is also easier to defend to a board asking why the team still looks understaffed on paper. Fyld’s own 2026 cybersecurity trends piece covers the broader shape of that widening gap between how fast threats evolve and how slowly most security staffing models are built to respond. Get in touch to talk through where that gap actually sits on your team.

IT Forum

MCP Security

MCP Security: 2 CVEs Your Team Can’t Ignore

The NSA doesn't usually publish design guidance on a protocol that's barely...
Secrets Sprawl

Secrets Sprawl: 6 Patterns to Stop CI/CD Credential Leaks

Secrets sprawl isn't a public-GitHub problem anymore - it lives inside the...
Vendor Risk: 5 Signals Your AI Supply Chain Is Exposed

Vendor Risk: 5 Signals Your AI Supply Chain Is Exposed

Traditional vendor risk management assumes software is static. AI vendors aren't —...
We value your privacy

We use cookies to run this website, measure its performance and show relevant content. Cookies Policy