Cyber Skills Diminish Quicker than Organizations Can Build Readiness

In a rapidly evolving cybersecurity landscape, organizations are experiencing lapses in in onboarding talent, cultivating skills, and maintaining readiness.
This is suggested by SkillBit’s research, which found that within three months, approximately two-thirds of organizations expect cybersecurity hires to be fully productive. However, most (57%) state it takes six months to achieve full productivity.
Onboarding isn’t the only challenge. 39% also consider the decay of skills to be a notable concern, and among organizations employing more than 50,000, that figure reaches 60%.
The research asserts that together, these findings suggest a worrying cycle: organizations take longer than expected to build readiness, then risk losing forward progress as skills decay.
Security Leaders Weigh In
Sumedh Thakar, President and CEO at Qualys:
The future belongs to those organizations who can deploy AI responsibly, minimize risk, and navigate the changing regulatory environment. We need professionals who understand how AI models behave in production environments, especially under adversarial conditions. However, as AI technology matures and improves, it will soon achieve complex tasks such that tenure alone will matter less. The human-in-loop approach to AI is here to stay, and that will separate those with the expertise to guide, shape, and govern AI from those who will be replaced by it.
Hiring strategies and employee onboarding must align directly with business outcomes. If the goal is greater efficiency, then hiring and onboarding should focus on productivity – streamlining roles and responsibilities to do more in less time, with fewer people. That efficiency helps the business strengthen its top line, leading to expansion and ultimately fuels future hiring. At the same time, more SaaS vendors and service providers will offer built-in AI agents. Organizations should factor this into their workforce planning so they can leverage AI technology to achieve results, instead of buying more tools and hiring people to manage them.
Aviv Nahum, Co-founder and CEO at Above Security:
Today, cybersecurity professionals are moving from being individual operators to managers of machine labor. A strong analyst used to be measured by how well they could investigate an alert, write a detection, or analyze an incident themselves. Increasingly, they’ll be measured by how effectively they can define the objective, give the right context to a set of agents, evaluate the result, and decide what should happen next.
I don’t think the answer is to artificially preserve every manual skill that AI can perform better. We stopped expecting engineers to calculate everything by hand when calculators arrived. The same thing will happen in cybersecurity. If an agent can write a query, correlate telemetry or reconstruct an incident faster and better than a person, we should let it. The human value moves up a layer.
That makes technical depth more important, not less. You need enough understanding to know when an agent is wrong, what context it is missing and whether the result makes sense in the environment. But business context becomes equally important. The best security professionals will understand not only what happened technically, but why it matters to the company, which business process is involved and what response is proportionate.
Communication changes too. Security professionals will increasingly have to translate between agents, technical teams, and business stakeholders. In that sense, prompt engineering is probably the least interesting long-term skill. The durable skill is orchestration: breaking a complex objective into work that agents can execute, supplying the right context, and being accountable for the outcome.
Ram Varadarajan, CEO at Acalvio:
These latest findings reflect a meaningful shift from just a few years ago, when cybersecurity training was viewed as discretionary spending. Today, rising threats, cloud adoption, regulatory pressures, and AI have made workforce development and employee onboarding a strategic priority. CISOs are keeping pace with AI because budgets are growing, training resources are more accessible, and organizations recognize AI is becoming integral to security operations.
The continued focus on AI, cloud, networking, risk management, administration, and analysis highlights the need for cybersecurity professionals to combine technical, operational, and business skills. Increasingly, they also need to understand emerging concepts such as AI-driven, game-theoretic cyber defense, which uses intelligent deception and adaptive strategies to shape attacker behavior.
To overcome training-time and onboarding challenges, organizations should treat learning as a business requirement with protected time and measurable goals. For those entering the field, the news is encouraging: employers are investing more in training and onboarding, however, candidates still need foundational IT, cloud, networking, and AI skills to get hired and take advantage of those opportunities.
Shane Barney, Chief Information Security Officer at Keeper Security:
The cybersecurity skills gap has become a business risk, not just a technical one. Eighty-six percent of organizations experienced a breach last year, and more than half cited a lack of security expertise as a contributing factor. With nearly every company adopting Artificial Intelligence (AI) to strengthen defenses, the absence of in-house skills to manage these tools safely is widening the gap between technology and readiness.
Cybersecurity training must be ongoing, not occasional. AI streamlines detection and efficiency, but it still relies on human oversight and sound governance to operate securely. Security teams need the skills to interpret data, validate AI-driven insights and act with precision and accountability.
The organizations best prepared to withstand today’s threats are those that align skilled people, advanced technology and a culture of accountability. When teams are empowered to make informed decisions and supported by intelligent, well-governed systems, access remains tightly controlled, visibility stays comprehensive and real-time, and responses are swift and coordinated. That balance of human expertise and technological capability turns cybersecurity from a reactive function into a true driver of resilience.
Diana Kelley, Chief Information Security Officer at Noma Security:
AI is quickly being woven into the fabric of all business operations and workflows. With AI everywhere, workers with skills that enable effective use of AI will be well positioned to help companies make the most of the AI revolution. Skilled AI security practitioners are now, and will be, in high demand with a substantial need for AI guardrails to be implemented in parallel with the adoption of AI in the enterprise.
AI is creating new cybersecurity roles, but employers are still looking for experience and proof of capability, even at the entry level. For new candidates, that means pairing foundational knowledge with hands-on experience, whether that’s labs, internships, or contributing to real projects, and developing a working fluency in how AI is used in enterprise environments.
Going forward, AI will continue to be embedded in all aspects of our businesses, and every security professional needs a working understanding of AI and agent risk. That includes how models are trained, where data exposure can happen, how outputs can be manipulated, agentic blast radius, and how AI integrates into business workflows. In the real world, those risks show up inside existing domains like productivity tools, data loss prevention, access control, application security, cloud security, and risk management.
The long-term risk is a pipeline that runs dry. Cut off the early-career pathways and you lose the next generation of defenders. If we don’t rebuild deliberate on-ramps, including apprenticeship models, AI-amplified junior roles, and academic pipelines that connect to real work, senior talent will age out faster than we can replenish it. The organizations that thrive will be the ones that figure out how to onboard new employees quickly, and use AI to make junior practitioners more capable, rather than replace them.
Robb Reck, Chief Information, Trust, and Security Officer at Pax8:
The uncertain economy is driving tighter evaluations of ROI on any security spend. Rather than expanding teams, organizations today are looking to AI to increase their existing workforce’s effectiveness — still, leaders remain careful, continuing to gauge how AI adoption will ultimately affect employee onboarding, team dynamics, and resource needs.
AI isn’t replacing cybersecurity professionals — it’s augmenting them. However, organizations may still be cautious to hire. Many organizations are slowing hiring while they wait to see how AI agents will actually perform. The candidates who are getting hired? Those who lead with an AI-first mindset and can articulate how they’ll drive transformation, not just use the tools.
Professionals who treat AI as something that will amplify their work, rather than threaten it, are the ones landing roles.
Melonia Da Gama, Director of Training and Learning Programs at Fortinet:
Today’s ever-changing cyber landscape has seen significant changes over the past couple of years, becoming much more structured and proving to be more effective in its attacks. New technology continues to evolve that did not exist before, and the introduction of Artificial Intelligence (AI) has made it even more transformative, as a threat, an opportunity, and a challenge for organizations. When thinking about managing resilience, rather than approaching cybersecurity reactively, leaders need to treat cybersecurity as a strategic, corporatewide initiative that includes managing risk proactively.
The 2025 Cybersecurity Skills Gap Report highlighted a three-pronged approach to building stronger cyber resilience, which includes:
- Security awareness for all employees
- IT security skills and training
- Deployment of the right security solutions
The report introduced a new focus on AI which found that nearly half of IT decision-makers (48%) cite the lack of staff with sufficient AI expertise as their greatest challenge. Given that 97% of organizations are already using or planning to use AI-driven cybersecurity solutions, the data indicates that the skills gap has become a pressing concern.
Taking a proactive approach to cybersecurity means an organization’s leadership ensures the team is skilled up and representative where its organization’s gaps exist. This can be accomplished by looking to all populations to hire in new professionals with the skills you need, or by upskilling and reskilling employees in growing areas of concern.
Nick Heddy, President and Chief Commerce Officer at Pax8:
The most important finding in this survey is not that it takes six months for a new hire to become productive. It’s that the half-life of cybersecurity knowledge is shrinking faster than most organizations can train people. AI is accelerating the pace of change in security operations, threat detection, software development, and adversary behavior. Security leaders can no longer think about readiness as an onboarding problem. They need to think about it as a continuous learning problem. For many organizations, especially SMBs, that creates a significant opportunity to leverage trusted technology partners who can bring expertise, managed services, and AI-enabled security capabilities that would be difficult to build internally.
We’re entering a period where the demand for cybersecurity expertise will exceed the industry’s ability to hire and train talent. That’s why managed service providers and security partners are becoming increasingly important. Partners can aggregate expertise across hundreds or thousands of customers, spread the cost of advanced AI security tools, and provide access to skills that many businesses simply cannot hire for on their own.
AI readiness is not just about deploying new technology. It’s about creating an operating model where people, processes, AI systems, and external expertise work together. The organizations that move fastest will combine internal talent with trusted partners that bring specialized security knowledge, continuous monitoring capabilities, and real-world experience helping organizations navigate rapid change.
Three Strategies for Security Teams:
- Build a continuous learning culture. Annual training cycles cannot keep pace with AI. Security teams need short, recurring, hands-on training that reinforces skills throughout the year, not just during compliance deadlines. The survey points toward growing interest in shorter, ongoing learning approaches that align with how practitioners actually retain knowledge.
- Leverage partners as force multipliers. Organizations should not assume every emerging AI skill must be developed in-house. MSPs, MSSPs, and cybersecurity partners can provide specialized expertise, accelerate adoption, and help organizations maintain readiness while internal teams focus on strategic priorities.
- Measure readiness, not certifications. The question isn’t whether someone completed training. It’s whether they can detect, investigate, and respond to real-world threats. Organizations should regularly evaluate operational readiness through simulations, exercises, and practical assessments rather than relying solely on course completion metrics.
AI is creating more security work, not less. As threats become more sophisticated, organizations will need a combination of skilled employees, AI-powered tools, and trusted security partners to stay ahead. The winners won’t necessarily be the companies with the largest teams. They’ll be the companies that can continuously learn, adapt, and tap into expertise wherever it exists.
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!









