- 88% of cyber professionals report operational issues due to staffing shortages.
- 74% of CISOs lack cloud security expertise in their teams.
- 59% of organizations face high staffing costs related to SIEM tools.
- Upskilling through adjacent roles in IT and networking can help bridge the cyber skills gap.
As cyber threats continue to rise, Chief Information Security Officers (CISOs) are grappling with an alarming challenge: finding qualified talent to protect their organizations. In fact, 88% of cybersecurity professionals report operational issues stemming from staffing shortages. The cyber skills gap is not only putting businesses at risk, but it's also driving up costs for security platforms and their training—keeping CISOs up at night.
The Impact of Cyber Staffing Shortages on CISOs
Cybersecurity staffing shortages are a growing pain point for businesses worldwide. In 2024, the gap between the demand for skilled professionals and available talent has only widened. CISOs are feeling the pressure, as threats grow in both complexity and volume. With fewer hands on deck, teams are forced to work overtime, leading to burnout, security gaps, and overall decreased effectiveness.
Moreover, the cyber skills shortage is not just about finding bodies to fill seats; it’s about finding the right skills. The report from Command Zero highlighted that many CISOs are struggling to find professionals with the advanced expertise necessary to navigate today’s sophisticated cyber landscapes, particularly in cyber defense, cloud security, and incident response.
The Skills Gap: Where Are the Cybersecurity Experts?
According to the Skill Shortage List in New Zealand and Australia, cybersecurity professionals are in high demand, but the pool of qualified candidates is shrinking. Cyber roles often require a mix of expertise in networking, systems administration, and software development, making them hard to fill. The average cyber investigator must be a subject matter expert in analytics and hold administrator-level knowledge of data sources. Such high requirements narrow the talent pool drastically, leaving many organizations struggling to meet their security needs. In addition, 74% of CISOs reported a lack of sufficient public cloud skills in their teams, crucial for conducting high-quality investigations.
The High Cost of Security Platforms & Training
Cybersecurity tools, while essential, are a significant burden on both budgets and staff. EDR/XDR, SIEM, and SOAR systems are among the most common security operations tools used today. However, they come with limitations and heavy costs—especially when scaling them across cloud environments.
- 59% of CISOs reported high staffing costs associated with SIEM tools.
- 75% of teams face challenges integrating data sources into SIEM and SOAR systems, often relying on third-party services to keep them operational.
Training for these tools is another costly endeavor. Hiring professionals with cross-disciplinary knowledge is already difficult, and providing ongoing training further drains resources.
SecOps Tools: A Double-Edged Sword
While tools like EDR/XDR, SIEM, and SOAR are critical to Security Operations (SecOps), they come with their own set of challenges. EDR/XDR, for instance, struggles with correlating network and cloud telemetry, which leaves gaps in visibility and requires more specialized skills to operate effectively. Moreover, SIEM systems are expensive, not just in deployment but also in the costs associated with staffing and maintaining them. This often leads organizations to invest in third-party services, further inflating the budget while still not achieving full coverage of IT systems.
Staffing Shortage vs. Job Openings: The Disconnect
Despite the constant talk of cyber staffing shortages, many wonder if companies are actually hiring. The answer is yes, but the bar is high. Most cyber roles require deep cross-disciplinary skills in IT, networking, and systems administration, making it a competitive and difficult job market to break into. Command Zero’s research indicates that to land a role in cybersecurity, professionals should aim for adjacent positions such as networking or systems engineering, before moving into cyber roles. And once in the industry, continuous learning is key.
Conclusion
The cybersecurity industry is facing a double crisis: a shortage of skilled professionals and the high cost of maintaining and securing platforms. While tools like EDR, SIEM, and SOAR provide necessary defense layers, they are only as good as the talent using them. To stay ahead, organizations need to invest in both technology and people, focusing on reducing turnover, enhancing job satisfaction, and upskilling their workforce.
At Fortray, we specialize in closing the cybersecurity skills gap. With comprehensive programs in cyber defense, cloud security, and incident response, we help professionals acquire the expertise needed to excel in this competitive field. Explore our cybersecurity traineeship program today and ensure your team is prepared to face the challenges ahead.
FAQ
Yes, cybersecurity jobs are highly in demand in the UK due to rising cyber threats.
Absolutely, the UK offers excellent opportunities, training, and a supportive framework for cybersecurity careers.
It can be challenging but is accessible with the right training and dedication.