Site navigation

ISACA Report: Cybersecurity Teams Understaffed & Underfunded

Graham Turner

,

Cybersecurity staff shortage
“Without strong, skilled teams, the security resilience of whole ecosystems is at risk – leaving critical infrastructure vulnerable,” said Chris Dimitriadis, chief global strategy officer at ISACA.

Cybersecurity teams are under strain, as 61% of European cybersecurity professionals say that their organisation’s cybersecurity team is understaffed, and over half (52%) believe that their organisation’s cybersecurity budget is underfunded.

That’s according to new research from ISACA, the leading global professional association helping individuals and organisations in their pursuit of digital trust.

Staff and funding struggles are having an impact on wellbeing as 68% feel that their role is more stressful now compared to five years ago, with 79% putting this down to the increasingly complex threat landscape.

Two in five (41%) of respondents say they are experiencing more cyberattacks when compared to a year ago, and 29% think they are experiencing the same amount.

But respondents don’t feel the number of attacks will be slowing down any time soon.

Over half (58%) state it is likely their organisation will experience a cyberattack in the next year. This has increased by 6 percentage points (52%) compared to 2023 so there needs to be more investment in the right staff and skills to prepare and respond to these attacks to limit long term damage.

Chris Dimitriadis, chief global strategy officer at ISACA, said: “In an increasingly complex threat landscape, it is vital that, as an industry, we overcome these hurdles of underfunding and under-staffed teams. Without strong, skilled teams, the security resilience of whole ecosystems is at risk – leaving critical infrastructure vulnerable.”

Despite the need for skilled teams to protect businesses, 19% say that their organisation has unfilled and open entry-level positions available, and 48% have unfilled open positions which require experience, a university degree, or other credentials. These figures have dropped only a few percentage points (from 22% and 53%) since 2023, pointing to an ongoing struggle to fill open positions.


Recommended reading


Fifty-two percent of respondents say that soft skills are lacking the most amongst today’s cybersecurity professionals. Of the soft skills in question, 54% feel that communication skills (e.g. speaking and listening skills) are most important, followed by problem-solving (53%) and critical thinking (48%).

Dimitriadis added: “The cybersecurity industry will massively benefit from a diverse range of people – each with different skills, experiences, and perspectives. This is the key to plugging the skills gap. Once talent enters the industry, businesses can then train and upskill new entrants on the job with cyber certifications and qualifications.”

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data