Site navigation

Survey Reveals Critical Cybersecurity Skills Shortages

Graham Turner

,

AI security skills gap
New report emphasises the importance of continuous learning and comprehensive employee training to mitigate ongoing threats like phishing, network intrusion, and ransomware.

O’Reilly, the technology and business learning platform, today released its 2024 State of Security Survey report, uncovering a stark disconnect between rapidly evolving threats and the readiness of security teams to combat them.

The study identifies emerging threats, and assesses how organisations are adapting their security strategies and workforce development to meet these challenges.

Among the notable findings is a critical AI security skills gap: 33.9% of tech professionals report a shortage of AI security skills, particularly around emerging vulnerabilities like prompt injection.

Cloud security expertise also emerges as a significant concern. Despite cloud computing’s two-decade presence, 38.9% of respondents identified cloud security as the most significant skills shortage, revealing a lag in expertise as organisations continue their cloud migration journeys.

Looking ahead, AI-enabled security tools rank as the top priority for the coming year (34.4%), with security automation following closely behind (28.2%), signaling a strong push toward automation in cybersecurity defenses.

Beyond this, the survey found that phishing remains the top cyber-threat, with 55.4% of respondents citing it as their primary security concern, despite the rise in sophisticated cyber-attacks. This is followed by network intrusion (39.9%) and ransomware (35.1%).

The continued prevalence of phishing, a relatively low-tech threat, underscores the urgent need for comprehensive employee training to recognise and mitigate these attacks. To address these threats, many organisations have implemented key security measures: 88.1% of tech professionals have adopted multifactor authentication, 60.1% have introduced endpoint security, and 49.2% have adopted a zero-trust model.

However, a notable certification gap exists within security teams.

While 51.3% of companies require certifications for hiring, 40.8% of security professionals remain uncertified, particularly incident responders, 70% of whom lack certification.

This gap is less pronounced among CISOs, where only 33.3% are uncertified. Continuous learning is essential, with 80.7% of employers mandating ongoing education for security professionals and 32.2% requiring over 41 hours of training annually.

The survey also found that better security awareness training for all employees (40.1%) was identified as the most crucial step in improving an organisation’s security posture, outranking additional staffing and better security tools.


Recommended reading


“Our global survey underscores a security landscape in flux, with critical skills gaps emerging in AI and cloud security,” said Laura Baldwin, president of O’Reilly.

“As cyber-threats become increasingly sophisticated, it’s clear that continuous, high-quality training is no longer optional; it’s essential for safeguarding our digital future. Organisations must prioritise ongoing upskilling to stay ahead of evolving risks and build robust defenses.

“While certifications like CISSP remain crucial, we’re seeing critical skills gaps in cloud and AI security. To truly safeguard our digital future, we need high-quality, continuous learning that goes beyond exam preparation and empowers every employee to be a frontline defender against evolving threats.”

Graham Turner

Sub Editor

Latest News

Awards Finance Fintech

Scottish Financial Technology Award 2026 Winners Revealed

Cybersecurity

Hackers Message Asos Users in Alleged Data Breach

Funding

Scottish BioTech MiAlgae Secures £2.5m for Grangemouth Expansion

Social Media

Ofcom Investigates Meta’s Instagram Instants Over Online Safety