The Cybersecurity Skills Gap: Why Headcount Alone Isn't Enough
ISC2 surveyed 16,029 professionals and shifted the workforce conversation. The primary challenge isn't simply headcount—it's evaluating and building demonstrated capability in AI, Cloud, and Risk.

Headcount Alone Isn't Enough
For years, cybersecurity maturity was often discussed in terms of headcount: counting open requisitions and calculating unfilled seats on an organizational chart. However, headcount alone is no longer a sufficient measure of cybersecurity capability.
The 2025 ISC2 Cybersecurity Workforce Study—based on responses from 16,029 cybersecurity practitioners and decision-makers globally—signals a clear shift in the industry conversation: the primary operational challenge is increasingly about skills and capabilities, not simply the number of people on the team.
In 2025, 34% of respondents reported having the right level of cybersecurity staffing, and 44% reported only a slight shortage. Yet, 95% of respondents reported that their organizations have at least one cybersecurity skills need, and 59% cited critical or significant skills needs. Headcount still matters, but capability is where risk is ultimately managed.
Deconstructing the ISC2 Research Data
To understand why capability measurement has become paramount, we must examine the specific findings from ISC2's research across North America, Latin America, APAC, and EMEA.
The study reveals that skills deficiencies have direct operational consequences. 88% of respondents reported that their organizations experienced at least one significant cybersecurity consequence due to a skills deficiency.
These consequences extend far beyond hypothetical risk. ISC2 found that 26% of respondents reported cybersecurity process or procedure oversights, 25% had to place underqualified or inexperienced personnel into roles, 24% experienced misconfigured systems, and 24% reported parts of their organization being left under-secured.
- 01. 88% of organizations experienced operational consequences directly linked to skills deficiencies.
- 02. Financial constraints persist: 33% reported lacking budget resources to adequately staff teams, and 29% noted they cannot afford candidates with required skill levels.
- 03. 72% of respondents agreed that reducing security staff significantly elevates organizational risk exposure.
Top Skills Needs & The Hiring Disconnect
ISC2's research provides a clear hierarchy of the most pressing technical requirements facing enterprise security teams.
Artificial Intelligence topped the list of cybersecurity skills needs at 41%, followed by cloud computing security at 36%, risk assessment at 29%, application security at 28%, and security engineering and GRC at 27% each. AI has transitioned into active operational use across 69% of organizations, requiring practitioners to navigate defensive automation while establishing governance over internal AI deployments.
ISC2 also identified a notable disconnect between what hiring managers prioritize and what cybersecurity professionals consider most in demand. Hiring managers prioritized cloud security, AI, security engineering, security analysis, and risk assessment, while professionals placed additional emphasis on GRC and zero-trust implementation. This disconnect highlights why generic skill checklists fail to ensure team readiness.
How Security Leaders Can Evaluate Capability
Faced with budget constraints and evolving threat complexity, security leaders cannot rely on recruitment alone. Organizations must focus on measuring and building demonstrated capability within existing teams. Here is how leaders can adapt:
- 1Focus on Continuous Capability Development
Prioritize internal upskilling and scenario-based training over static course completions to ensure personnel keep pace with technology shifts.
- 2Operationalize AI as a Defender Multiplier
Equip security teams with guided AI tools to automate routine triage tasks while establishing formal governance policies for enterprise AI use.
- 3Augment Resume Screening with Applied Assessment
Complement traditional credential screening with scenario-based evaluations that observe how candidates analyze evidence and make decisions.
From Credentials to Demonstrated Capability
Certifications remain valuable for demonstrating foundational knowledge against a defined body of material. However, as cybersecurity roles become increasingly specialized, a certification alone does not necessarily provide a complete picture of how someone applies that knowledge in a realistic operational scenario.
ISC2's research identifies the core challenge: organizations don't simply need more personnel; they need people with demonstrated capabilities. This raises a fundamental question: how can security leaders reliably measure those capabilities?
A useful capability assessment must move beyond simple recall to evaluate how a professional interprets information, identifies risks, prioritizes actions, and reaches defensible decisions under realistic scenario constraints. SecNav approaches this through scenario-based evaluation:
The Role Readiness Index (RRI) evaluates a professional's readiness across defined cybersecurity scenarios, providing a structured view of how prepared they are to recognize and respond to security challenges. Complementing this, the Decision Action Report (DAR) examines the specific decisions made within a scenario—what the professional identifies, how they prioritize risk, what actions they choose, and how they justify those decisions.
By incorporating scenario-based evaluation, organizations gain clear insight into their team's operational readiness—moving from static credential proxies to measurable, demonstrated capability.
Source: ISC2 2025 Cybersecurity Workforce Study, based on responses from 16,029 cybersecurity practitioners and decision-makers surveyed across North America, Latin America, APAC, and EMEA.
TABLE OF CONTENTS
ASSESS YOUR TEAM'S CYBERSECURITY READINESS
The next step isn't simply hiring more cybersecurity professionals. It's understanding the capability you already have—and identifying where critical gaps remain.