The Problem
This headline stopped me:
"The cybersecurity talent shortage narrative is wrong."
That came from SANS. Their 2026 Cybersecurity Workforce Report. The industry has spent years operating on the assumption that we do not have enough people. SANS has challenged this assumption at the root. And the data behind it was worth my time taking a read.
The Facts
The SANS 2026 Cybersecurity Workforce Report found:
- 60% of organizations say their teams lack the skills to handle current threats
- 95% report at least one significant skill gap on their team
- 88% tied a major security event directly to that gap
The ISC2 2025 Cybersecurity Workforce Study adds: 31% of security teams have zero entry-level professionals. No pipeline. No one coming up through the ranks building fundamentals before they are handed real responsibility. The same study notes that economic challenges, skills shortages, and rapid workplace changes are affecting the morale of professionals already in the field. After two years of declining job satisfaction, warning signs remain: stagnant wages, increased workload, and limited advancement opportunities.
The Fortinet 2026 Skills Gap Report finds the same pattern: the skills deficit is contributing directly to security incidents, not just operational friction.
Three things worth sitting with:
We have a development problem, not a hiring problem.
When 60% of organizations say their teams lack the skills to handle current threats, the instinct is to hire. But hiring does not close a skills gap. It relocates it. If the fundamentals were not built before the role, they do not appear after the offer letter. The shortage narrative made the solution feel external. The data does not support that frame.
Skills gap risk is a leadership conversation, not just a workforce planning conversation.
If the development problem starts at the team level, it lands on leadership's desk as a risk number and not a headcount number. 88% of organizations in the SANS study reported a significant security event tied directly to a skills deficiency. The data draws a direct line between capability and exposure. Whether that line is showing up in leadership conversations is a different question.
At the industry level, the compounding cost is already here.
Underdeveloped teams and leadership blind spots around skills risk are now colliding with a third reality: the professionals currently holding organizations together are under pressure. Stagnant wages, increased workload, and limited advancement opportunities are pushing experienced practitioners toward the exit. With 31% of teams having no entry-level presence, there is no one coming up behind them. When senior people leave and the pipeline is empty, organizations do not just lose a role; they lose the institutional knowledge, the judgment, and the informal mentorship no job posting replaces.
Closing Thoughts
The SANS finding does not mean the talent conversation is over. It means the framing needs to shift from how many to how ready. That distinction changes what organizations prioritize, what hiring looks like, and what professional development is actually supposed to accomplish.
I am curious what this looks like from where you sit.
What skill gap shows up most often on your team or in the candidates you interview? And do you think the shortage narrative has shaped how your organization approaches development? Drop your take in the comments.
This post is part of a six-week series on the cybersecurity skills gap. Each week surfaces research findings and practitioner observations on what the data is actually telling us.