惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

罗磊的独立博客
U
Unit 42
N
Netflix TechBlog - Medium
人人都是产品经理
人人都是产品经理
Hugging Face - Blog
Hugging Face - Blog
腾讯CDC
小众软件
小众软件
V
Visual Studio Blog
T
Tailwind CSS Blog
Engineering at Meta
Engineering at Meta
博客园 - 叶小钗
GbyAI
GbyAI
爱范儿
爱范儿
雷峰网
雷峰网
Microsoft Azure Blog
Microsoft Azure Blog
D
DataBreaches.Net
博客园_首页
D
Docker
A
About on SuperTechFans
G
Google Developers Blog
I
InfoQ
T
The Blog of Author Tim Ferriss
V
V2EX
博客园 - Franky

Enterprise – Silicon Republic

Recovery readiness a missing link in cyber resilience, finds report EU finally gets its hands on Anthropic’s Mythos New Irish dispute body to tackle illegal online content launched Rhysida leaks 5.7TB of sensitive Berlin state data in major hack ‘Keeping OT security up to date is more than patching systems’ HSE fined €645,000 for storing records in decrepit conditions Boston Scientific cyberattack: Cork staff asked to work remotely Report: Only sectors aiding AI adoption sure to grow from it Why connectivity and cybersecurity can't be treated separately French authorities investigating hack of national tax authority Levi Strauss corporate data stolen in cyberattack Levi Strauss corporate data stolen in cyberattack How might a system ‘leak secrets’ without being hacked? What is a side-channel attack in cybersecurity? OpenAI agents breach Modal client system after Hugging Face hack OpenAI agents breach Modal client system after Hugging Face hack Report: EMEA businesses not reaping benefits from their AI spend Report: EMEA businesses not reaping benefits from their AI spend Transport for London hackers jailed for five and a half years Transport for London hackers jailed for five and a half years Commission refers Ireland to CJEU for failing to enact cyber rules Commission refers Ireland to CJEU for failing to enact cyber rules Cloudflare to block AI crawlers from ad-supported webpages by default Cloudflare to block AI crawlers from ad-supported webpages by default Google ordered to pay Klarna nearly $2bn in abuse-of-power row Google ordered to pay Klarna nearly $2bn in abuse-of-power row Upcoming iPhone 18 model leaked in Tata Electronics hack New iPhone 18 models reportedly leaked in Tata Electronics hack Data breaches going unreported – Irish compliance survey Data breaches going unreported, says Irish compliance survey
Why employee retention is at the heart of the cyber skill...
silicon · 2026-08-12 · via Enterprise – Silicon Republic

‘The bucket is leaking, and the industry keeps blaming the tap,’ writes Nahla Davies discussing the cybersecurity talent shortage.

For a decade, the cybersecurity industry has told itself one story about its staffing crisis: there aren’t enough people. Train more, certify more, run more bootcamps, and the 4.8 million global workforce gap will close. It’s a comforting story, because it makes the problem someone else’s job: the schools’, the government’s, the pipeline’s.

There’s just one difficulty. The people who own the most-cited version of that gap statistic, ISC2, also explained why it grew, and the reason has nothing to do with a shortage of talent.

The year the pipeline delivered and the gap grew anyway

In ISC2’s 2024 study, the global cybersecurity workforce grew by just 0.1pc, effectively flat after years of expansion, while the workforce gap widened by 19pc. If this were a supply problem, those two numbers would move together.

Instead, the study named the actual cause: budget was the top factor, cited by 39pc, ahead of any talent shortage, with 37pc of organisations reporting budget cuts, 38pc hiring freezes and a quarter making layoffs.

Read plainly, that means the gap grew in a year when supply held steady and demand for hiring was cut. The bucket is leaking, and the industry keeps blaming the tap.

The paradox sharpens at entry level. A third of organisations reported no entry-level staff at all, while ISC2’s hiring research found 38pc of managers demanding a CISA certification and 34pc a CISSP for junior roles, credentials that themselves require around five years of experience.

The sector loudly requests more pipeline, then refuses to hire the pipeline’s output. The famine is partly self-imposed.

Where the people are actually going

If supply isn’t the bottleneck, the exits are. And the data on why experienced people leave is damning, precisely because it rules out the easy explanation.

It isn’t pay. CISO compensation rose 6.7pc in 2025 and salaries across the field remain strong. People are walking away from good money.

It’s the conditions. ISACA’s 2025 research found 55pc of teams understaffed, 50pc struggling to retain talent, and 47pc naming high stress as the leading reason people leave, ahead of pay.

Among SOC analysts specifically, Tines found more than half likely to change employer within a year, with manual, repetitive work and alert fatigue topping the list of frustrations.

Gartner saw this coming. Back in 2023, it predicted that nearly half of cybersecurity leaders would change jobs by 2025, a quarter leaving the field entirely due to work-related stress, with the analyst noting bluntly that burnout and attrition are outcomes of poor culture. From the vantage point of mid-2026, that prediction reads less like a forecast and more like a description.

Then there’s the newest accelerant, aimed squarely at the top of the experience curve: personal liability. Since the prosecution of Uber’s former security chief and the SEC’s action against SolarWinds, 66pc of CISOs report concern about personal liability, and a separate survey found 70pc saying liability stories had soured their view of the role. You cannot train your way around senior people concluding the top job is a legal risk not worth taking.

The gap is seniority-shaped

This is why the pipeline framing fails on its own terms. The shortage isn’t of bodies; it’s of experience, and experience is the one thing a bootcamp cannot manufacture on demand.

Kaspersky found 48pc of organisations take six months or more to fill a cybersecurity role, and 36pc take close to a year for senior positions. Most open roles sit at mid to advanced level. Every burned-out senior analyst who leaves creates a vacancy no graduate can fill, and takes institutional knowledge out the door with them, while the industry poaches the same shrinking pool of experienced people from itself in a zero-sum loop that inflates salaries without adding a single net defender.

Ireland’s maths depends on the leak

For Ireland, the stakes are concrete.

The All-Island Cybersecurity Sector Report 2025 counted 632 firms, 10,600 professionals and €3.2bn in revenue, and Cyber Ireland’s earlier labour-market work set a target of 17,000 cyber jobs by 2030, needing more than a thousand hires a year.

That target is usually discussed as a recruitment challenge. It is really a retention challenge wearing a recruitment costume, because if half of organisations can’t keep the people they already have, the pipeline has to first refill the leak before it adds anyone net new.

Ireland’s 2030 ambition quietly assumes a retention rate the sector is not currently achieving, and the wider European picture is no kinder, with an EU Eurobarometer finding over half of companies struggling to recruit cyber staff.

What a retention-first industry would do

The fixes are known, cheaper than perpetual re-hiring, and almost entirely within an employer’s control. Automate the toil, because when SOC analysts name manual work as their top frustration, the 64pc of their time lost to it is a resignation letter being drafted in real time.

Build a blameless culture, since Gartner’s own diagnosis put culture, not headcount, at the root. Hire and train juniors, given that ISC2 found entry-level hires productive within a year at modest cost, yet transition-training programmes are being cut rather than expanded. And de-risk the senior roles with proper liability cover and documented governance, so the experience you have is not frightened out of the profession.

One honest caveat – none of this means the pipeline is irrelevant. Long term, the field genuinely needs more entrants and Ireland’s education investment matters.

But pouring water into a leaking bucket faster is not a plan, and calling the leak a supply shortage is the industry’s most expensive act of denial. The gap statistic everyone quotes to demand more training is, on ISC2’s own reading, substantially a measure of churn and cut budgets, laundered into the language of a talent famine.

The people exist. The question the industry keeps refusing to ask is why so many of them are leaving.

By Nahla Davies

Nahla Davies is a software developer and tech writer. Before devoting her work full time to technical writing, she managed – among other intriguing things – to serve as a lead programmer at an Inc 5,000 experiential branding organisation, where clients include Samsung, Time Warner, Netflix and Sony.

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.