Skip to content
The Cyber Security Place

People

The year they stopped counting the missing millions

A decade of headlines about millions of unfilled jobs, and then the study that produced the number quietly declined to publish one.

Last reviewed August 30, 2026

The annual workforce study stopped estimating the number of unfilled jobs, and the withdrawal says more than the figure did. What the same research does show is askills problem inside existing teams: about 95% report at least one skill need,59% call the gap critical, and 88% had a security event because of one. The binding constraint is now budget rather than scarcity — around 38% have been through a hiring freeze. And the bottom rung has gone: one analysis of 5,260 openings found 318 genuinely entry-level, about 6%. A profession that cannot find people has almost no doors. The most requested skill is now artificial intelligence, named by around 41% against 34% a year earlier. And buy-or-hire has no single answer: products peak in the first year, people compound in the third.

Buy it or hire it?

4 ordinary needs, two ways to cover each, and every option scored twice — at twelve months and at three years. A model of the shape rather than a measurement, built so the inversion can be checked by adding up.

Nobody reads the alerts

Three products generate more findings each day than anyone opens.

Year one 60 · year three 55

Works immediately and keeps working, and it inherits whatever the underlying products get wrong. The queue gets shorter; the judgement does not improve.

Year one 35 · year three 85

Six months of learning the estate, then the false positives start disappearing at the source. By year three the products themselves are quieter, which no platform achieves.

Nothing is watched at night

Attacks arrive at three in the morning and nobody is awake.

Year one 75 · year three 75

The honest case for buying. Covering the small hours with your own staff needs five or six people, and no organisation of moderate size can justify that or keep them.

Year one 40 · year three 20

It works for a while and then people leave. Night cover built from goodwill degrades in a way that shows up as resignations rather than as an outage.

The developers ship flaws

The same classes of defect keep reaching production.

Year one 55 · year three 40

Finds the obvious cases at once, then becomes noise that teams learn to click past. A control everybody has been trained to ignore is worth less than no control.

Year one 25 · year three 90

Slow, unmeasurable, and the only intervention that changes what gets written in the first place. What is being bought is a habit, and habits take two years.

The questionnaires are drowning us

Every customer sends a different security questionnaire.

Year one 70 · year three 60

Genuinely useful and genuinely limited. It answers faster; it does not make the answers true, and the gap between the two is where an audit eventually lands.

Year one 30 · year three 75

The questionnaires stop being the work and become a by-product of keeping the evidence current, which also happens to be the thing the questionnaires were asking about.

Buying everything scores 260 after twelve months and 230 after three. Hiring for everything scores 130 and 270. The ranking inverts, and an annual budget only ever measures the first column.

Buying everything scores 260 in the first column and 230 in the second. Hiring for everything scores 130 and 270. Nothing about the choices changed between those two lines; only the moment of measurement did. An annual budget cycle reads the first column exclusively, which means the decision is usually settled by the calendar rather than by the argument.

Why withdraw a number everybody quoted?

For roughly a decade the shortage had a figure attached, it grew every year, and it appeared in ministerial speeches, funding applications, university prospectuses and the opening slide of a great many conference talks. Then the study that produced it published without one, which is a quieter and more interesting event than any revision would have been.

The number was always a construction. It came from counting advertised vacancies and applying assumptions about how large a security team ought to be, and both halves were shakier than the confidence with which the total was repeated. Adverts are posted speculatively, left open, duplicated across agencies and used to test a market with no intention of hiring. Assumptions about ideal team size were derived from organisations that had money.

What made it untenable was the divergence between the figure and the experience of the people it described. Graduates with relevant degrees could not find a first job while the same publications reported millions of vacancies, and the contradiction eventually became impossible to present with a straight face. A statistic can survive being imprecise; it cannot survive being contradicted by its own audience.

Withdrawing it was the right call and it leaves a vacuum that something worse may fill. The number was useful to people arguing for funding, training programmes and attention, and those arguments now need a harder case built from skills, incidents and consequences rather than from a single memorable total. That is more honest and considerably less quotable.

Three hundred and eighteen doors

The sharpest figure in this subject is not about shortage at all. An analysis of 5,260 openings found 318 that a person could actually start from — around 6% of the market. Everything else asked for experience that can only be obtained in a job like the one being advertised.

Two ordinary decisions produced it. The tasks that used to constitute a first year in this field — working through alerts, gathering evidence, writing up what happened, checking that a fix was applied — are precisely the tasks that tooling and automation absorbed first, because they are repetitive and well defined. And a team under budget pressure that loses a person replaces them with somebody senior, since one experienced hire covers more than two juniors and needs no supervision.

Each choice is defensible and the aggregate is self-harming. A profession that hires only experienced people is consuming a stock it has stopped replenishing, and the effect appears with a lag of about five years, which is comfortably beyond the horizon of anybody making the decision. Meanwhile the same organisations complain, sincerely, that they cannot find anybody.

The remedy is not charity and it is not a graduate scheme with a brochure. It is deciding that a proportion of the work will be done more slowly by somebody learning, and accepting the cost of that on purpose. Organisations that do it acquire people who understand their estate, which is the scarce commodity the market cannot supply at any price, because it does not exist until somebody has spent two years there.

A decade framed as a shortage

408 entries here concern people, hiring or training. 98 frame it as a shortage of talent, 117 discuss training or qualifications, and 15 mention burnout or retention.

72014342015432016522017732018932019612020402021

The solid portion is the share that frames the subject as a shortage of talent: about 20% across the first half of the period and roughly 25% across the second. Coverage peaks in 2019 with 93. The framing mattered, because a shortage of people implies recruitment and a shortage of skills implies training, and the two lead to entirely different spending. The earliest piece here using that framing, How the cybersecurity industry is coping with a skills shortage fast company business innovation, is already treating it as a supply problem.

The usual caution applies and cuts harder than usual here. This measures what was published, and a shortage is a more publishable proposition than a training budget. Some of what the chart shows is the subject; some of it is which version of the subject a headline could carry.

Why do people leave this work?

The explanations offered are pay, hours and stress, and all three are real and none of them is the distinguishing one, because they describe most demanding jobs. What distinguishes this field is a structural mismatch: responsibility for outcomes determined by decisions somebody else takes.

An analyst who identifies a serious problem, escalates it correctly and watches it be deferred for commercial reasons has done the job perfectly and achieved nothing. Repeat that a dozen times and the rational conclusion is that the work does not matter, which is both false and unarguable from the inside. It is the same complaint the head of the function makes about the board, one level down and with less recourse.

The conditions compound it. Success is invisible by construction — nobody thanks a team for the year in which nothing happened — while failure is public, permanent and frequently personal. The work is unbounded, in that there is always more of it, so the only limit is one the person imposes, and the people who impose it well are the ones the profession describes as unambitious.

What helps is unromantic and mostly free. Write down which decisions the security function may take alone, so that some things actually get done because a person said so. Record deferred risks with a name against them, so that being overruled leaves a trace rather than a grievance. And bound the work explicitly, because a team told that everything matters will either burn out or quietly stop believing you, and the second is worse.

What is the skills gap made of?

The phrase does a lot of work and rarely gets unpacked. In practice it names three different problems that require three different responses, and organisations that treat them as one buy training nobody needed while the actual gap stays open.

The first is a genuine absence of a capability: nobody in the team has ever secured a container platform, or read a piece of malware, or run an investigation across a cloud tenancy. That is the version training fixes, and it is the least common of the three. The second is knowledge of the estate rather than of the discipline — somebody who could do the work in the abstract but does not know where anything is, who owns it, or why the strange exception in the middle of the network exists. No course supplies that and no hire arrives with it.

The third is capacity misdescribed as skill. A team that knows exactly what to do and has no hours in which to do it will report a skills gap, because that is the answer a survey offers and the answer a budget request can use. It is also the version that most consistently produces the incidents attributed to skills shortages, and the reason so many of those incidents involve something everybody knew about.

The most requested capability today is artificial intelligence, named by around 41% against roughly 34% a year earlier. Some of that is real: teams are being asked to secure systems whose behaviour nobody in the building can fully explain. Some of it is adverts copying each other. Telling the two apart matters, because one implies a hiring strategy and the other implies a fashion.

What a certificate is actually for

Practitioners argue about certifications with unusual heat, and both positions are correct about different things. They do not predict competence: the correlation between holding one and being good at the work is weak enough that everybody who hires has a story about it. They also open doors that stay shut otherwise, which is not nothing when the alternative is not being read.

The function they perform is filtering by people unqualified to filter. A recruiter with two hundred applications and no way to assess any of them needs a criterion, and a certificate is a criterion that exists. That is a statement about the hiring process rather than about the qualification, and it explains why the same certificate is simultaneously essential for getting interviews and irrelevant once somebody technical is in the room.

The costs land unevenly. Fees, renewals and continuing-education requirements are trivial for an employer paying them and substantial for somebody trying to enter the field from outside, which is precisely the group the profession claims to want. A requirement that costs the applicant a month's wages to satisfy is a barrier described as a standard.

The sensible position is instrumental. Get the one your target employers filter on, treat it as a key rather than an education, and take the actual learning from building things and breaking them. Employers can help by naming which certificate they filter on and admitting that is what they are doing, which is more honest than listing five as required and meaning none of them.

What a very small team should look like

Most organisations that need somebody doing this do not need a security team, and building a small one is the commonest expensive mistake in the field. Three people covering everything a large function covers will do all of it badly, be permanently behind, and leave within two years, and the organisation will conclude that security is impossible rather than that the shape was wrong.

The shape that works is one capable generalist with explicit decision rights, a written list of the handful of things that must never happen, and a budget to buy the two or three capabilities that genuinely require scale — night-time monitoring, threat intelligence, and whatever regulatory evidence-gathering the sector demands. Everything else is done by the people who already own the systems, with that person deciding what good looks like and checking.

The hardest part of that arrangement is refusal. A single practitioner is asked for everything, from a questionnaire to a suspicious email to an opinion on a procurement, and saying no to most of it is the skill that determines whether the role survives. That is much easier when somebody senior has written down what the role is for, which returns the argument to authority rather than headcount.

And it needs an exit plan for the person. A generalist doing this alone acquires enormous knowledge of one estate and very little marketable specialism, which is a trap disguised as job security. Organisations that fund a training budget and let the person spend three weeks a year being taught by somebody else keep them longer, which is a cheaper retention mechanism than the pay rise it substitutes for.

Getting in from outside

Advice to newcomers in this field is abundant, contradictory and mostly written by people who entered when the door was wider. What survives contact with the current market is narrower and less encouraging, and pretending otherwise wastes years of somebody's life.

The most reliable route is sideways rather than in. Support desks, system administration, network operations, software development and audit all produce people who already understand how something real works, and that understanding is the thing employers are actually short of. Somebody who has run a mail server has a better foundation than somebody who has completed four courses about attacking one, and the first group gets hired for roles the second group cannot see.

What demonstrably helps is evidence of having done something. A small piece of infrastructure built and defended, a write-up of a problem investigated properly, a tool that solves a dull task, a contribution to something other people use — each gives an interviewer material to ask about, which is what an interview is for. Certificates get an application read; artefacts get a conversation.

The advice worth resisting is specialisation before entry. A person who has decided to be a malware analyst before holding any job in the field has narrowed their options to a handful of employers, and the specialism that eventually fits is usually one they had not heard of. Breadth first, then depth chosen from experience, is slower to describe and faster in practice.

Two things are worth saying to the people already inside, because they cost nothing and almost nobody does them. Answer the message from the stranger asking how you got in; the ten minutes are trivial and the effect on somebody with no contacts is enormous. And when you interview, tell the candidate what the actual work is — including the tedious majority of it — because the field loses people who arrived expecting one job and found another, and that loss is entirely self-inflicted.

Employers can do one cheap thing as well. Say in the advert which requirements are genuine and which are aspirational, since everybody in hiring knows the list is padded and only the confident apply anyway. The people deterred by a list of nine essential technologies are disproportionately the ones who read carefully and assess themselves accurately, which is not the trait a security function should be filtering out. The same applies to the salary: publishing it costs nothing, saves both sides three conversations, and its absence is read — correctly, most of the time — as a plan to pay whatever the candidate can be persuaded to accept. A profession that spends this much energy complaining it cannot find people could start by being easier to approach.

None of this is charity either, which is worth saying because it tends to be heard that way. An organisation that answers messages, describes the work honestly, publishes what it pays and admits which requirements are optional will fill a role faster and keep the person longer than one that does none of those things and pays slightly more. The behaviours that make a profession easier to enter are the same behaviours that make an employer competitive, and the fact that they are usually argued for on moral grounds is probably why so few finance directors have heard the commercial version.

And the market rewards persistence unfairly. The applicant who is rejected forty times and applies again is not more talented than the one who stops, and does end up employed, which is a statement about hiring rather than about merit. Anybody giving career advice in this field should say that plainly instead of describing the outcome as a meritocracy.

Common questions

How many cybersecurity jobs are unfilled?

Nobody publishes a credible figure any more, and the fact that the main annual study stopped estimating it is more informative than any number it previously gave. The estimates were built from vacancy counts and assumptions about ideal team sizes, and both turned out to measure advertising behaviour rather than need.

So is there a shortage or not?

There is a shortage of specific skills inside existing teams rather than a shortage of bodies. Around 95% report at least one skill need, 59% describe the gap as critical or significant, and 88% attribute a security event in the past year to it. That is a different problem with different remedies.

Why are teams not simply hiring?

Because money, not scarcity, is now the binding constraint. Budget has overtaken talent availability as the leading barrier to hiring, and about 38% have been through a hiring freeze, up roughly 6 points in two years. Vacancies that are advertised and never filled are frequently vacancies that were never funded.

Is it hard to get an entry-level job?

Extraordinarily. One analysis of 5,260 openings found 318 that were genuinely entry-level — about 6%. A profession that says it cannot find people has almost no doors, which is not a paradox so much as an explanation.

Why did the junior roles disappear?

Two forces at once. The tasks that used to fill a first year — triaging alerts, chasing evidence, writing up findings — are the tasks most readily automated, and squeezed budgets favour consolidating two roles into one experienced hire. Neither decision is irrational and their combined effect is to remove the bottom rung.

What skill is most in demand?

Artificial intelligence and machine learning, named by around 41% and rising from about 34%. That demand is partly genuine and partly a shift in what job adverts ask for, and the useful reading is that teams expect to defend systems they do not yet understand.

Do certifications help?

They help you be found, and they do not predict competence. Their real function is as a filter used by people who are not qualified to assess the role, which makes them worth having and worth being sceptical about in equal measure.

Should we hire or buy?

It depends entirely on when you intend to measure. Products deliver most of their value in the first months and then plateau or decay; people deliver very little in the first six months and compound thereafter. An annual budget cycle measures only the first horizon, which is why the answer is usually to buy and usually wrong.

Where is buying clearly right?

Round-the-clock coverage. Watching systems through the night with your own staff needs five or six people to do it sustainably, and organisations that build it from goodwill and a rota discover the cost as resignations rather than as a line in the budget.

Is burnout as bad as people say?

It is structural rather than incidental. The work is unbounded, failure is public and success is invisible, and a substantial part of the job is telling colleagues things they do not want to hear. Those conditions produce attrition independently of how pleasant the employer is.

What actually retains people?

Deciding things. The most consistent reason experienced practitioners give for leaving is not pay or hours but having responsibility without the authority to act on it, which is the same complaint the leadership of the function makes one level up.

How should a small organisation staff this?

Not with a security team. One competent generalist with explicit authority, a short list of things that must never happen, and a budget to buy the two or three services that genuinely need scale will outperform a nominal team of three doing everything badly.

People and skills in the archive

408 entries, peaking in 2019 with 93.