Skip to content
The Cyber Security Place

The work

The security workforce in 2026: the shortage that was a budget

For a decade the story was that the people did not exist. The first year the question was put differently, money came first.

Last reviewed August 29, 2026

In the largest recent workforce study, of roughly 16,000 practitioners,lack of budget replaced lack of qualified talent as the leading cause of staffing shortfalls — the first such reversal since the question has been tracked. Around 65% of teams hold unfilled posts while 38% sit under hiring freezes, 37% face budget cuts and 25% report layoffs, so many vacancies are unfunded rather than unfillable. Meanwhile 48% report exhaustion from keeping current and 47% feel overwhelmed by workload; among CISOs,63% saw or experienced burnout in the past year. People are not leaving the field — 78% intend to stay in it for the rest of their careers — but the intent to stay with the same employer falls from 75% at one year to 66%at two.

Why did the story change in a single year?

It probably did not. What changed is which explanation got recorded. For years the standard survey question invited respondents to explain a staffing shortfall, and the available answer that reflected well on everybody was that qualified people were scarce. It is a comfortable finding: nobody in the organisation is at fault, the remedy lies with universities and training providers, and the shortfall becomes a sector-wide condition rather than a local decision.

Budget as the leading cause is a less comfortable answer, because it names a choice made inside the building. It arrives alongside figures that make it hard to dispute: more than a third of organisations cutting security budgets, a similar share under hiring freezes, and a quarter reporting layoffs in the function. A team can hold vacancies and be forbidden to fill them at the same time, and from outside those two situations are indistinguishable.

The distinction has practical weight for anyone entering the field. Advice built on the shortage story — acquire the certification, the roles are waiting — describes a market where the constraint was supply. In a market where the constraint is funded demand, the same advice produces qualified people competing for a smaller number of posts, and the disappointment is read as a personal failure rather than as a misdescribed market.

One caution about all of these figures, including the ones on this page. They come from professionals answering questions about themselves, which is the only practical way to measure exhaustion and intent to leave, and it means the numbers describe what people report rather than what happens. Self-reporting has known directions of error: distress tends to be understated where an answer might be traced back, and intent to move is a poor predictor of moving. The findings are still the best available and they are worth reading as a description of how the work feels to the people doing it, which is a different claim from a measurement of the labour market.

What the coverage talked about, and what it did not

Across 15,376 entries in this archive,69 describe a shortage of security people. 4 mention the exhaustion of the people already doing the work. The coverage discussed the gap roughly 17 times as often as the condition of those inside it.

0201572016920171820181820198202072021

The hump peaks in 2018 and falls away afterwards, which tracks the attention cycle rather than any labour-market statistic. That is worth stating plainly: a chart of how often something was written about is a record of editorial choice, and it gets read as a record of the world because the coverage was confident and continuous. The earliest instances here — How the cybersecurity industry is coping with a skills shortage fast company business innovation, There isnt a cybersecurity skills gap rik ferguson zdnet, It skills shortage leading to cybersecurity issues research argues cloud tech news — were already treating the shortage as settled fact.

A week has 100 points

What follows is a model rather than a measurement: no survey reports that teams spend a given percentage of their time on triage. What it does illustrate is an arithmetic that any practitioner will recognise. Give each duty the minimum it genuinely needs and the six minimums total 110 against a week of 100. Every possible allocation leaves something below its floor, and the exercise is to find out which one you would starve.

The floors below add up to 110 points of a 100-point week. There are 10 points that do not exist.

Alert triage

30 of 100 · floor 25

Working the queue: deciding which of today's alerts is real.

Below 25: The queue stops being worked and starts being sampled. Nobody decides this; it happens, and the alerts that go unread are indistinguishable from the ones that were never generated.

Keeping current

10 of 100 · floor 12

Reading advisories, tracking what changed, learning the tools the business just bought.

Below 12: Decisions get made from a picture that is a year or two old. It is the first thing cut because nothing visibly breaks that week, and the most expensive to have cut when measured two years later.

Project review

20 of 100 · floor 20

Looking at what the rest of the business is building before it ships.

Below 20: Security becomes a gate applied at the end rather than advice given at the start, which is the arrangement that makes the function unpopular and ineffective at the same time.

Compliance evidence

20 of 100 · floor 18

Producing what auditors, customers and regulators ask for.

Below 18: Deadlines with external consequences slip, so in practice this one is never starved. It takes its share first and the rest of the list absorbs the shortfall.

Incident response

10 of 100 · floor 15

Handling the things that actually happen.

Below 15: Cannot be under-allocated, only postponed from everything else. An incident does not queue politely behind the audit; it takes the week it needs from whatever was planned.

Making things better

10 of 100 · floor 20

Fixing the causes rather than the instances: automation, defaults, removing decisions.

Below 20: The team stays permanently at its current capacity. This is the only activity that reduces the size of the others, and it is the one with no deadline attached, which is why it is almost always the residual.

The 10-point overdraft is the whole argument. Exhaustion in this line of work is not usually the product of one crisis; it is the standing condition of owing more hours than exist, every week, and choosing which obligation to fail. Adding a person moves the numbers and does not change the structure, because the duties expand with the size of the estate. What changes the structure is removing work — automating a category of decision, retiring a system, declining a demand — and that is the only activity on the list with no external deadline forcing it.

What does burnout cost that a vacancy does not?

A vacancy is visible, budgeted for and understood. Its cost sits in a plan. The departure of an experienced person carries a second cost that no plan holds: the undocumented knowledge of why things are the way they are. Which alert fires spuriously every month-end. Which supplier's integration breaks on renewal. Which exception was granted in 2022 and why. None of that is written down anywhere, because writing it down is improvement work, and improvement work is the residual.

The retention figures locate the problem precisely. Roughly three quarters of practitioners expect to remain with their employer over the coming year, and two thirds over two years — a decline of nearly ten points across a single additional year of horizon, against the 78% who intend to stay in the profession for the rest of their careers. People are not disillusioned with the work. They are making plans about a job.

For an organisation, the useful reading is that this is one of the few problems where the remedy is largely within reach and unglamorous. The conditions that produce the two-year decline are mostly local: the standing overdraft above, the absence of any slack, and the experience of being asked to be accountable for outcomes that funding decisions elsewhere have already determined.

The demand side that nobody budgets for

Staffing arguments are conducted almost entirely on the supply side — how many people, with what qualifications, at what salary. The demand side is treated as given, when in fact it grows continuously and nobody signs off on the increases.

Every system the business adopts arrives with a permanent tail of security work: an access model to understand, logs to collect, a supplier relationship to review, a configuration that drifts. Each is small. None is ever removed. A department that adopted four new services a year for five years is carrying twenty of these tails, and at no point did anyone approve a corresponding increase in capacity, because at no point did any single decision look like it needed one.

Regulation compounds the same way. A new obligation rarely replaces an old one; it layers, bringing its own evidence requirements, its own reporting deadline, and its own auditors asking overlapping questions in incompatible formats. The work of answering them is real, recurring, and almost never counted as a reason the rest of the programme slipped, because compliance deadlines have external consequences and therefore get met.

Growth by acquisition is the sharpest version. An acquired company arrives as an entire second estate, with its own suppliers, its own identity system and its own history of decisions nobody present can explain, and the integration budget typically funds making it work rather than making it safe. The security cost of a merger is real and lands in a function whose headcount was set before anyone mentioned the merger.

None of this argues that teams should be larger, which is a conversation about money. It argues that the demand growing invisibly is the reason a team that was adequately sized three years ago is not adequately sized now, and that the version of the story where the market ran out of people never explained that.

Does outsourcing solve the capacity problem?

It is the structural answer most organisations reach for, and it moves a specific part of the load rather than the whole of it. A managed service takes over the activity with the worst hours and the highest volume — watching the queue overnight and at weekends — and does so with people who are awake anyway. That is a genuine transfer, and for a team of two or three it can be the difference between a sustainable job and an unsustainable one.

What does not transfer is the part that depends on knowing your organisation. Whether an administrator logging in from an unusual place at an unusual hour is an incident or a person on holiday fixing something is not a question about attack techniques; it is a question about your company, and the provider cannot answer it. So the alerts that survive triage come back, and they arrive with the context stripped out — which is why the volume reaching the internal team falls a great deal less than the volume leaving it.

The arrangement also creates work that did not exist before. Someone has to keep the provider supplied with the context that makes their judgements good, review what they closed, notice when their coverage of a new system quietly never got configured, and manage the relationship at renewal. That is not an argument against the model. It is the reason the internal team rarely shrinks by as much as the business case assumed, and why a service bought as a replacement for headcount tends to disappoint while the same service bought as relief for a specific duty tends to work.

The honest framing is that outsourcing changes which of the six activities the in-house team is short of, not whether it is short. Triage hours come back; the obligation to know your own estate does not go anywhere, and improvement work is still the residual it always was.

Two details decide whether it works in practice, and both are settled before signing rather than afterwards. The first is how an escalation reaches a human on your side at three in the morning, tested rather than described. The second is whether you receive the underlying data or only the provider's conclusions, because a team that cannot look at the original events is unable to investigate anything the service did not flag, and that limitation is discovered during the incident where it matters.

The shape of a career in this work

The shortfall leaders now describe is less about headcount than about particular expertise — securing machine learning systems, cloud identity, the plumbing between services — which changes what a career in the field looks like. For most of the period covered by this archive, the reliable path was breadth: know a bit of everything, because the job was to cover an estate alone. That path still exists at smaller organisations and it is where most people start.

Depth pays where the estate is big enough to need it, and the risk it carries is that the specialism can disappear underneath you. Practitioners who built a decade of expertise around a particular perimeter technology, or a particular platform, have watched the demand for it thin out in a handful of years. The people who handled that well were generally those whose depth sat in something durable — identity, cryptography, incident handling, the ability to reason about a system nobody documented — rather than in a product.

There is also a quieter fork between the technical track and the accountability track, and it is presented as a promotion when it is closer to a change of profession. The senior version of this job is largely persuasion, budgeting and writing, conducted with responsibility for outcomes that other people's spending decisions have already constrained. The burnout figures among CISOs are not surprising in that light, and anybody being offered the step is entitled to see it described accurately first.

For people entering now, the most useful correction to a decade of shortage coverage is this: the qualification gets you read, and what gets you hired is evidence that you have done something. A home lab, a documented investigation, a contribution to a tool — small, real, and yours — outperforms another certificate in a market where funded posts, rather than qualified applicants, are the scarce thing.

What automation is changing about the job

The expertise leaders now report themselves short of is concentrated in newer ground, and securing automated and machine-learning systems sits near the top of that list. This produces an awkward position for a profession already reporting that keeping current is its leading source of exhaustion: the fastest-moving area is the one where the least accumulated knowledge exists, and the time to acquire it comes out of the same fixed week as everything else.

On the defensive side the effect is real and easily overstated. Handing the first pass of triage to a system that summarises and correlates removes a large volume of individually trivial decisions, and that is worth having. It also introduces a category of failure the previous arrangement did not have: a confident summary of an incident that is subtly wrong is harder to catch than a raw alert that is obviously ambiguous, because it arrives already resolved. Reviewing what the automation suppressed becomes a duty, and it is a duty with no deadline attached.

The reasonable position is neither of the two on offer. These systems are not replacing the function and they are not a passing fashion; they are a new class of component that has to be secured, operated and audited, and the teams that will do that well are the ones treating it as ordinary engineering work with unfamiliar failure modes rather than as either a threat to their jobs or a solution to their capacity.

What actually helps?

Deciding explicitly what will not be done is the cheapest intervention available and the least often taken. Every overloaded function already drops work; the difference between a healthy one and an exhausted one is frequently whether the dropping was chosen and recorded, or happened by attrition at eleven at night. A written list of what the team is not covering this quarter converts a private failure into an organisational decision, and it is the only mechanism that reliably surfaces the funding question to the people who can answer it.

Protecting the two activities with no deadline comes next. Keeping current and making things better are the first casualties precisely because nothing breaks that week, and they are respectively the leading named source of exhaustion and the only category that shrinks the others. A standing allocation that is not raided for incidents — even a small one, even a single day a fortnight — is worth more than its size suggests, because it is the only part of the week that compounds.

Lastly, measuring the right shortfall. A team that reports vacancies is describing a symptom; a team that reports which duties fell below their minimum, and what followed, is describing the problem in terms a budget holder can act on. The first framing invites the answer that qualified people are scarce. The second does not allow it.

What a budget holder can act on is narrower than what a security team usually presents. Three lines cover most of it: the duties that fell below their minimum this quarter, the named consequence of each, and what it would cost to lift them. That is a proposal with a price on it rather than a complaint with a chart attached, and it converts the conversation from one about whether security matters — which nobody will say it does not, to no effect — into one about a specific sum against a specific exposure. It also has the useful property of being answerable with a no, which at least records that the decision was made deliberately and by whom.

Common questions

Is there a cyber security skills shortage?

Less than a decade of coverage implied. In the most recent large workforce study, lack of budget replaced lack of qualified talent as the leading cause of staffing shortfalls for the first time since the question has been tracked. Around 65% of teams report unfilled positions while 38% are under hiring freezes, which means a substantial share of those vacancies are unfunded rather than unfillable.

How common is burnout in security work?

Around 48% of professionals report exhaustion from keeping up with threats and technology, and 47% say they are often overwhelmed by their workload. Among CISOs, 63% experienced or witnessed burnout in the past year. These are self-reported figures from a survey of roughly 16,000 practitioners.

Do people leave the security profession?

They leave employers rather than the field. About 78% intend to stay in security for the rest of their careers, but the share expecting to remain with their current organisation falls from roughly 75% over twelve months to 66% over two years. The retention problem is local, not sectoral.

Will more training courses close the gap?

Only the part of it that is genuinely about skills. Where the constraint is budget, a larger pool of qualified candidates does not create a funded post. Where it is skills, the shortfall reported by leaders is increasingly about specific expertise — securing AI systems, cloud identity — rather than about headcount in general.

Why do security teams struggle to keep up with technology?

Because keeping current is the only major activity with no deadline attached, which makes it the residual. Nothing visibly breaks in the week it is skipped, and the cost appears two years later as decisions made from an out-of-date picture. Nearly half of practitioners name it as a source of exhaustion.

What is the most common cause of unfilled security roles now?

Money. That is a reversal: for years the reported cause was a lack of qualified people, and the shift to budget as the leading constraint happened alongside 37% of organisations facing cuts, 38% freezing hiring and 25% reporting security layoffs.

How many people should a security team have?

There is no defensible ratio, and published ones vary by an order of magnitude because they average across industries with completely different obligations. A more useful exercise is to list what the team is expected to do, estimate the minimum time each activity needs, and see whether the total fits inside the hours available.

Does automation reduce the workload?

It changes its shape. Automating triage reduces the volume of individual decisions and adds a standing obligation to maintain the automation, review what it suppressed, and notice when it silently stops working. The net effect is usually positive and it is never zero-cost.

Is a security certification worth having?

For getting past recruitment filters, frequently. As evidence of capability, it certifies familiarity with a body of knowledge at a point in time, which is a narrower claim than it is usually read as. Neither observation is an argument against holding one.

How should a small team decide what not to do?

Explicitly and in writing, because the alternative is deciding implicitly by running out of week. An activity nobody chose to drop still gets dropped, and the difference between the two is whether anyone above the team knows it happened.

What is the first sign a security function is overloaded?

Alert queues stop being worked and start being sampled, usually without anyone deciding to make that change. The second sign is that improvement work — the only category that reduces the size of the others — has not moved in two quarters.

Does hiring a CISO fix the problem?

It creates someone accountable, which is not the same as creating capacity. Where the constraint is budget or headcount, a senior appointment concentrates responsibility for an unchanged shortfall, and the burnout figures among CISOs suggest how that arrangement tends to resolve.

Long-form pieces in the archive

80 contributed articles, newest first. Median length 727 words against 47 elsewhere in the archive.