InfoSec Hiring Practices: Addressing Self-Inflicted Talent Shortages in Cybersecurity
InfoSec Hiring Practices Are Creating the Talent Shortage They Claim to Solve
Cybersecurity organizations across North America are writing job requirements that systematically exclude the entry-level candidates they desperately need — and a new industry report says the problem is largely self-inflicted.
The 2026 SkillBit Micro-Training Survey Report, "The Shift to Continuous Cybersecurity Micro-Training," reveals a troubling paradox at the heart of the industry's workforce crisis. Commissioned by Bellini Capital and CyberBay and guided by micro-training provider SkillBit, the study surveyed 202 North American decision-makers including CIOs, CISOs, and security operations leaders. More than 88% work at organizations with over 1,000 employees and more than 80% spent their entire 2025 training budget. The money exists. The model, the report argues, does not work.
The Hiring Pipeline Is Broken by Design
Seventy percent of organizations have no junior roles — or very few — that can be filled by candidates with less than two years of experience. The report calls this a self-imposed talent shortage. Organizations declare a hiring crisis and then draft job descriptions that make entry impossible. Understanding how flawed technology hiring processes exclude capable candidates is an essential first step toward fixing a pipeline that is structurally misaligned with the industry's own stated needs.
"The long-term risk is a pipeline that runs dry," said Diana Kelley, CISO at Noma Security. "Cut off the early-career pathways and you lose the next generation of defenders."
Kelley advocates for deliberate on-ramps including apprenticeships, AI-amplified junior roles, and academic pipelines tied to real work. Her prescription is direct: "The organizations that thrive will be the ones that figure out how to onboard new employees quickly and use AI to make junior practitioners more capable rather than replace them."
AI uncertainty is making the funnel even narrower. Robb Reck, Chief Information, Trust, and Security Officer at Pax8, notes that many organizations are slowing hiring while waiting to see how AI agents will perform in practice. "The candidates who are getting hired? Those who lead with an AI-first mindset and can articulate how they'll drive transformation — not just use the tools," Reck said.
There are early signs of movement on credentialing. Thirty percent of leaders are already receptive to interactive lab formats as a substitute for traditional credentials, and another 49.5% would consider them with convincing evidence. Testing a candidate in a live environment rather than screening a resume could widen the pipeline without lowering the bar — a meaningful shift in how the industry defines proof of competence.
The broader challenge of sourcing and developing technology talent is not unique to cybersecurity, but the sector's combination of high stakes, fast-moving threats, and rigid credentialing requirements makes the consequences of pipeline failure more acute than in almost any other discipline.
The Hidden Risk Window Between Hiring and Readiness
Once a candidate clears the hiring process, the clock starts running — and it runs long. Sixty-four percent of executives consider three months an acceptable time-to-value for a new cybersecurity hire. Fifty-seven percent report it actually takes six months. The report describes that gap as a "hidden risk" period: months in which a seat is filled on the org chart but not yet in the SOC.
What slows new hires down is revealing. General IT knowledge was cited by 55% of respondents and cybersecurity processes by 50% as the most significant causes of delay. Tool-specific knowledge ranked lower. Organizations may be screening for product familiarity while missing the foundational IT and security knowledge that actually determines readiness.
Skills decay compounds the onboarding problem. Thirty-nine percent of executives cite decay as an active issue on their teams, and the report attributes the acceleration to the pace of AI-driven change. Among organizations with 50,000 or more employees, 60% reported the problem. Among those who identified decay, 44% rated the impact on team readiness at a four or five out of five — ranking it above morale, training costs, and staffing flexibility.
"Cybersecurity training must be ongoing, not occasional," said Shane Barney, CISO at Keeper Security. "AI streamlines detection and efficiency but it still relies on human oversight and sound governance to operate securely."
The implications for workforce planning are significant. A team that cannot maintain current knowledge under operational pressure is not a training problem — it is a structural risk. Leaders who fail to account for decay in their readiness models are measuring a capability that no longer exists. For a deeper look at why this matters beyond the SOC, the relationship between cybersecurity talent retention and business continuity planning illustrates how workforce gaps translate directly into organizational vulnerability.
Certifications, Calendars, and the Case for Continuous Learning
The Certification Paradox
Eighty-four percent of organizations sponsor certification training, with vendor-specific certs, CISSP, CompTIA Security+, and CCSP leading the list. More than 96% report at least some positive impact on staff effectiveness and 41% report a strong impact. The certifications are working. The delivery model is not.
Seventy-one percent of executives would prefer 20-minute weekly micro-training sessions over 30 to 40 hours of training once or twice a year. The reason is straightforward: 47.5% cite urgent daily tasks as the primary reason development goals go unmet. A week-long course competes with incident response and loses. A 20-minute session can fit around it.
According to the National Institute of Standards and Technology (NIST) Cybersecurity Workforce Framework, continuous skill development mapped to real-world tasks is among the most effective approaches to closing competency gaps in security roles — lending independent weight to the report's argument for structured, ongoing learning over episodic training events.
Ram Varadarajan, CEO at Acalvio, frames the fix in operational terms. "To overcome training-time and onboarding challenges, organizations should treat learning as a business requirement with protected time and measurable goals." He notes this represents a genuine cultural shift from the era when training was considered discretionary spending.
What Top Performers Actually Look Like
The report also challenges the industry's emphasis on tool expertise over problem-solving ability. Roughly two-thirds of respondents said they would rather hire someone proficient in problem solving across any environment than an expert on a specific tech stack. When executives described their own top performers, the leading traits were:
- Strong curiosity and proactive learning habits
- Forensics capability
- Deep environmental knowledge
Years of experience and certifications ranked near the bottom.
Aviv Nahum, Co-Founder and CEO at Above Security, connects that finding directly to where the analyst role is heading. "A strong analyst used to be measured by how well they could investigate an alert or analyze an incident themselves. Increasingly they'll be measured by how effectively they can define the objective, give the right context to a set of agents, evaluate the result, and decide what should happen next." Nahum is clear that this raises the bar: "You need enough understanding to know when an agent is wrong and whether the result makes sense in the environment."
Sumedh Thakar, President and CEO at Qualys, identifies the dividing line ahead: "The human-in-loop approach to AI is here to stay, and that will separate those with the expertise to guide, shape, and govern AI from those who will be replaced by it."
The Readiness Confidence Gap
Despite widespread confidence — 96% of executives say they can provide objective data validating team readiness — the report finds that most readiness reporting relies on personal observation, audit results, and certification counts rather than evidence that a team can stop a live breach. There is no industry readiness standard, and the gap between confidence and proof is significant.
Organizations that conflate activity metrics with demonstrated capability are, in effect, managing a risk they cannot accurately see. Closing that gap requires moving from self-reported assurance to hands-on, scenario-based validation — measured regularly, not annually.
The report's conclusion is practical: continuous readiness requires ongoing assessment, hands-on practice, and short learning sessions built into daily operations rather than scheduled around them. Security leaders at SecureWorld Dallas on Oct. 8 will have an opportunity to engage these workforce challenges directly.
For practitioners and leaders navigating this landscape, three actions stand out as immediately addressable:
- Audit your junior role requirements. If entry-level positions demand two or more years of experience, the talent shortage is partly your organization's creation. Lab-based assessments offer a credible, evidence-backed alternative to resume screening.
- Shift onboarding focus toward IT fundamentals and security processes rather than tool familiarity — those are the proven drivers of the time-to-value gap.
- Bring objective performance data to board conversations rather than relying on anecdotal readiness assessments. Leaders who can demonstrate team capability with measurable evidence will hold a distinct advantage in every budget discussion.