The global cybersecurity workforce gap has reached a new high, according to research from non-profit cyber professional organisation ISC2. However, despite the increase, there’s still an estimated shortfall of 4.8 million professionals.
The shift represents a 19% year-on-year increase in the amount of workers needed to effectively secure organisations across the globe.
Despite the growing need for professionals, global workforce growth has slowed for the first time since ISC2 began estimating the workforce size six years ago, holding at an estimated 5.5 million people (a 0.1% year-on-year increase).
This contrasts with last year, when the workforce grew 8.7% year-on-year despite declining economic conditions.
For the first time, participants cited “lack of budget” as the top cause of their staffing shortages, replacing “lack of qualified talent” as the top cause in all previous years.
As organisations continue to face economic instability, the profession is under unprecedented pressure with increasingly limited resources.
While about three quarters (74%) of professionals agree that the 2024 threat landscape is the most challenging it has been in the last five years, budget pressures on the cybersecurity workforce have mounted.
Over a third (37%) have experienced budget cuts, up from 7% in 2023. A quarter reported experiencing layoffs in their cybersecurity team, up by 3% from last year.
Companies appear to be stalling to fix the shortage, with 38% experiencing hiring freezes (up 6% from 2023), and a third (32%) seeing fewer promotions (up 6% from 2023).
The Impact of the Skills Gap
This year, a record 15,852 cybersecurity practitioners and decision-makers participated in the study.
In addition to the workforce gap, 90% of respondents indicated that they face skills shortages at their organizations.
More than half of those surveyed (58%) believe a shortage of skills puts their organisation at significant risk, and 64% say skills gaps present a greater challenge to securing their organisations than staffing shortages.
Professionals said the following are the top five skills gaps at their organisations include AI (34%), cloud computing security (30%), zero-trust implementation (27%), digital forensics and incident response (25%), and application security (24%).
“The ISC2 Cybersecurity Workforce Study highlights a concerning perception among cybersecurity professionals,” said ISC2 executive vice president of corporate affairs Andy Woolnough.
“After two years of declining investment in hiring and professional development opportunities, organizations are now facing significant skills and staffing shortages – an issue that professionals warn is heightening overall risk.
“At a time when global instability and emerging technologies like AI are rapidly increasing the threat landscape, investment in skills development and the next generation of the cyber workforce is more crucial than ever. This will enable cybersecurity professionals to meet these challenges and keep our critical assets secure.”
Recommended reading
- Report: Vulnerability Exploitation Surge Endangers Cybersecurity
- Hiring Practices to Close the 4 Million Worker Gap in Cybersecurity
- ISC2 Study Exposes Gender Disparities in Cybersecurity Workforce
Attracting Entry-Level Talent
Nearly one-third (31%) of participants said their security teams had no entry-level professionals on their teams, and 15% said they had no junior-level (1-3 years of experience) professionals.
Moreover, hiring managers – 62% of which currently had open roles on their teams – are focusing on hiring mid to advanced level roles rather than a broad mix of experience and abilities.
This represents a high proportion of organisations that do not have a pipeline of professionals who can develop their foundational skillset in-house to bolster existing teams and instead are relying solely on hiring pre-qualified talent.
Providing on-the-job training and professional development opportunities for entry-level talent is essential for developing a skilled cybersecurity workforce for the future, as well as offering advancement opportunities for the existing workforce.
Challenges Impacting Job Satisfaction
Job satisfaction among cybersecurity professionals has remained high over the last several years despite prevailing staffing challenges and escalating threats.
However, this year – characterized by mounting security challenges, slow job growth and budget constraints – our study found a 66% favorable job satisfaction rate among professionals, down 4% from 2023.
With mounting pressure on cybersecurity teams, declining job satisfaction can lead to professionals leaving the field and increased burnout, further exacerbating the workforce shortage.
This year’s research reveals three areas of action for organizations to address the global shortage of cybersecurity jobs growth, to encourage new individuals into the profession and to address the skills gap.
This includes addressing job creation and hiring priorities, prioritizing in-house professional development and setting realistic and clear job role expectations.





