The cyber skills gap is really a visibility gap
I've been saying some version of this for almost a decade. At this point my friends can recite it back to me at dinner, which is its own kind of feedback.
Key takeaways
- Is the cybersecurity skills gap real?
Yes, but it's an incomplete diagnosis. Only 14% of organizations say they have the people and skills to meet their own cybersecurity objectives. - What is cyber skills visibility?
The ability to see which skills exist, what evidence sits behind them, and how they map to the work in front of you. - What counts as evidence?
Assessment, hands-on performance and manager validation. Not job titles, not course completions. - How do you close the gap?
Define the work, assess the evidence, then decide: develop, redeploy or hire.
In those ten years the conversation has barely moved. We've gotten very good at describing this problem. We measure it, benchmark it, panel it, build entire conference tracks around it. What we haven't done is fix it.
So let me skip the admiring part.
The cyber talent shortage is real. It is also an incomplete diagnosis. A large part of what we call the cybersecurity skills gap is a visibility gap: organizations cannot reliably see which skills they already have, what evidence sits behind them, which capabilities the work actually requires, or who could become ready with targeted development.
When that information is scattered across job titles, certifications, training records, managers' memories and a spreadsheet nobody remembers building, every gap looks like a hiring problem.
It isn't. And you can't close a gap you can't define.
The 4.8 Million Cyber Workforce Gap: A Number Nobody Can Use
Let's start with the greatest hit. In 2024, ISC2 estimated a global cybersecurity workforce gap of 4.8 million people.
Great number. Dramatic, memorable, fits on a slide, makes the room go quiet. I've used it. You've used it. We've all used it.
It's also useless the second anyone asks a follow-up question. Walk into a CISO's office, say 4.8 million, and watch them ask whether that means they're short on cloud security depth, AI security capability, incident response coverage, or the four specific people they need for the migration that starts in March. The number can't answer. It was never built to.
In its 2025 Cybersecurity Workforce Study, ISC2 did not publish another global headcount estimate because respondents kept saying critical skills were the more urgent problem. Ninety-five percent reported at least one skills need. Fifty-nine percent called those needs critical or significant.
Then the World Economic Forum found the uncomfortable one. Only 14% of organizations felt confident they had the people and skills to meet their own cybersecurity objectives.
Fourteen percent. Which means the other 86% are, at some level, winging it. I say that with real affection, because I've seen what they're expected to make these calls with.
A shortage number tells you the weather. Visibility tells you where the roof is leaking.
Why We Keep Admiring It
Because the shortage story lets everybody off the hook.
If the right people simply don't exist, the plan writes itself. Post more roles. Pay more recruiters. Wait for a unicorn to wander into the applicant tracking system and apply to a job description nobody has updated since 2019. Nobody has to look at their own data. Nobody has to defend a decision. It's the market's fault, and the market isn't in the meeting.
If the capability is already sitting inside your building and you can't see it, that's a very different conversation. That one has your name on the calendar invite.
Most enterprises aren't short on workforce data, they're buried in it. HR has titles and tenure. The learning platform has completions. Certification records have credentials. And the genuinely useful context lives in your managers' heads, where it stays right up until they leave and take it with them.
None of it answers the only question that matters. What can these people do against the work in front of us?
Everyone has data. Almost nobody has an answer.

How Cyber Skills Visibility Should Work: Assess, Harden, Validate, Repeat
Here's the part where I stop describing and start proposing.
At QuickStart we ended up applying cybersecurity principles to people management, mostly because it's the one operating model this audience already trusts.
You would never run a vulnerability program on self-reported data and a completion certificate. You'd get laughed out of the room, and rightly. You assess, you harden, you validate, and then you do it again next quarter because the environment moved.
That's exactly how workforce capability should work. It's almost never how it does.
It starts with being honest about where you actually are. At the bottom rung, capability lives in job descriptions, spreadsheets and people's memories. You know who's on payroll. You don't know what they can do. One rung up, you're tracking certifications, training activity and self-reported skills. Better. Still not something I'd bet a cloud migration on, because people rate themselves generously and that's very human of them.
At the top, skills connect to roles, tasks, projects and outcomes, backed by real evidence and refreshed when priorities shift. That's when visibility earns its keep, because it answers questions you actually have. Who is ready now? Who gets ready with a bit of investment? Where does the real risk sit? Which gap genuinely needs an outside hire?
That's QuickStart's Skills Visibility Maturity Model, and I'll break it down properly later in this series. The goal was never a prettier dashboard. It's whether you can staff the project, whether you have the AI security capability you believe you have, and where developing somebody beats writing another job description nobody will answer.
The NIST NICE Framework is genuinely useful for the assess step, and I say that as someone skeptical of most frameworks. It gives you language for cyber work in terms of roles, tasks, knowledge and skills, which drags the conversation off vague titles and onto what a human being has to do on a Tuesday. Not academic. Just honest. If you can't describe the capability, you can't assess it, build it or hire for it.
Cyber Skills Assessment Means Evidence, Not Job Titles
Which brings us to the thing most workforce plans are quietly built on. I don't trust job titles, and neither should you.
A “security analyst” at one company triages alerts all day. At another, that same title covers threat hunting, cloud investigations and governance. Same two words on the org chart, completely different humans. Two people hold the identical certification and have nothing close to the same readiness. Meanwhile someone with no cyber title at all is doing security-critical work in networking, cloud engineering, development, fraud, audit or IT ops right now, today, and nobody has counted them.
Job titles are shorthand. They are not evidence.
Course completions aren't evidence either, and I know that dashboard looks fantastic. Completions tell you somebody was in the room. They don't tell you what stuck, and they definitely don't tell you what that person can do at 2am when something is actively on fire.
Certifications still matter. I'm not here to burn them down. I'm here to stop us asking one proxy to carry an entire workforce decision. Because when the evidence is thin, we guess. Then we build the hiring plan on the guess, the training plan on the hiring plan, put it all in a dashboard and call it strategy. I've watched that happen more than once. I've probably helped.
Real evidence looks like role-based assessment, hands-on performance, completed projects, manager validation and operational outcomes. Harder to collect. Considerably harder to argue with.
Look Inside Before You Hire Outside
Hire externally, absolutely. Cyber needs more people and more doors into the profession. But you cannot hire your way out of every gap when skills move faster than the requisition process. ISC2's April 2026 analysis is blunt: expecting fully trained candidates at scale, especially across AI and cloud security, is unrealistic.
The faster answer may already be on payroll. Networking, cloud, development, risk, audit, fraud and compliance teams often contain people who are closer to cyber readiness than their titles suggest. Map the adjacent skills, validate the evidence and develop the people who are already halfway there. I'll come back to that properly later in this series.
Stop Admiring the Cyber Skills Gap. Start Deciding.
Seeing the gap only counts if you do something about it.
Good visibility should tell you whether to develop, redeploy or hire. It should also quietly expose the decisions you've been making on assumptions, stale role profiles and training activity that looks busy and proves very little.
The shortage is real. I'm not arguing that. But a shortage and a blind spot are two different problems, and they don't take the same fix. You can spend more on recruiting, more on training and more on tooling, and still not be able to answer one slightly embarrassing question. Do we have the capability to deliver what the business just asked for?
If that answer lives across six systems and three people's heads, that isn't workforce intelligence. That's admin with better graphics.
AdaptIQ is the AI layer built to connect those signals across the platform. Employers use that intelligence through HiringIQ: the Talent Hub supports workforce planning and recruitment, while the Learning Hub supports assessment and development.
The point is not another dashboard. It is a defensible decision about whether to develop, redeploy or hire.
So before you ask where all the cyber talent went, try the more uncomfortable question. Would you recognize it if it were already sitting in the room?
The first problem isn't always supply. It's whether you can see.
Don't believe me? Come argue with me. I've been having this argument for a decade. I can manage another round.
Stop guessing where the capability sits. Assess your workforce visibility with HiringIQ.

Cyber Skills Visibility: Quick Answers
What is the cyber skills gap?
The cyber skills gap is the difference between the cybersecurity capabilities an organization needs and the skills its current or available talent can demonstrate. It can reflect both genuine headcount shortages and an inability to see existing capability.
What is cyber skills visibility?
Cyber skills visibility is the ability to see which skills exist, what evidence supports them, how current they are and how they map to roles, tasks, projects and business priorities.
How should employers close cyber skills gaps?
Start by defining the work and assessing the evidence. Then decide which gaps to close through internal development, redeployment or external hiring.
Sources
- ISC2, 2024 Cybersecurity Workforce Study: Key Findings https://www.isc2.org/Insights/2024/09/Employers-Must-Act-Cybersecurity-Workforce-Growth-Stalls-as-Skills-Gaps-Widen
- ISC2, 2025 Cybersecurity Workforce Study https://www.isc2.org/Insights/2025/12/2025-ISC2-Cybersecurity-Workforce-Study
- World Economic Forum, Global Cybersecurity Outlook 2025 https://www.weforum.org/publications/global-cybersecurity-outlook-2025/in-full/executive-summary-4e44b16c32/
- NIST NICE Framework https://www.nist.gov/itl/applied-cybersecurity/nice/nice-framework-resource-center
- ISC2, Aligning Skills, People and Hiring in Cybersecurity, April 2026 https://www.isc2.org/Insights/2026/04/aligning-skills-people-and-hiring-in-cybersecurity
About the Author
Launa Rich, Cyber Skills & Talent Intelligence Leader
10+ years building cybersecurity workforce pipelines, hiring intelligence programs, and go-to-market strategy for enterprise security teams. Focused on closing the gap between credentials and capability.
