sticky-notes

We Stopped Investing in Fundamentals

From 2015 to 2019, I was entrusted to oversee the daily operations of a technology training school in Virginia Beach called HyperLearning Technologies.

Every week I had students who wanted to break into IT and cybersecurity: Veterans transitioning out of service; career changers who had been told to get certified; and IT folks who had been on the job for years but never filled in the foundational gaps. We put them through A+, Network+, and Security+ coursework. When they passed their exam, we put their name on a board in the break room and handed them a t-shirt. It was a small thing, but it meant something to them and to us.

I watched people land their first IT jobs and build careers from what they learned in that room. The demand was real. The candidates were there. And though I am not actively in the classroom now, there are many training providers available for developing industry candidates. So why is there a talent shortage?

The Problem

As a member of the industry for over a decade, I have echoed the sentiment that we are short-staffed. Every year a new report confirms the gap. Every year the workforce numbers move, but the conversation stays the same. Nobody asks the harder question: why is the entry point so thin?

The Facts

The ISC2 2025 Cybersecurity Workforce Study puts a number on it that caught my attention. Thirty-one percent. That is the share of security teams that currently have zero entry-level professionals on staff. Not low numbers. Zero. Nearly a third of security teams have no one at the ground floor.

Three things worth sitting with:

When 31% of security teams carry no entry-level staff, the daily weight falls entirely on mid-level and senior practitioners.

They are not just doing their jobs. They are covering the gaps that should have been filled below them. That kind of load does not stay invisible. It shows up in burnout rates, in slower response times, and in teams that run lean until they cannot anymore. The pipeline problem is not abstract. It is sitting inside active security operations right now.

We promoted our way out of our own pipeline.

Leadership gets measured on what they close, not on what they develop. Under that kind of pressure, entry-level investment gets deprioritized. The pathway that used to feed the workforce gets narrower over time, then disappears. The gap that shows up today compounded quietly across a lot of decisions that each made sense in the moment.

When you remove the fundamentals from a workforce pipeline, you do not just create a short-term gap. You fracture the transfer of institutional knowledge.

The people who learned security from the deckplates carry a kind of understanding that does not get passed down through certifications alone. It gets passed down through mentorship, through floor-level experience, through working alongside someone who can explain the why behind the what. When that layer disappears, the whole structure gets more brittle. And AI has added another variable: experienced practitioners who are quietly apprehensive about training someone who might reduce the perceived value of their role. The knowledge transfer that should be happening is getting held back, and the ISC2 data signals what the industry stands to lose.

Closing Thoughts

The candidates are out there. I know because I trained some of them, and because some of the best in this field invested in me. What is missing is not people who want to get in. What is missing is the organizational commitment to bring them in, develop them, give them a real path forward, and refuse to let it be the first thing cut when times get hard.

If your team has no entry-level professionals right now, that is worth sitting with for a moment. Not as a criticism, but as a question. What would it take to change that? What would it mean for your team two years from now if you did?

If you were a HyperLearning Technologies student or trainer, I would love to hear where you landed.

Wayne M. Shelton Sr. is a retired military veteran and cybersecurity practitioner. He holds the CISM, CGRC, CySA+, Security+, and CTT+ certifications and writes about cybersecurity, AI, and ministry technology at waynesheltonsr.com. Contact: [email protected]