Blog / The Cybersecurity Talent Shortage No One Is Fixing Fast

The Cybersecurity Talent Shortage No One Is Fixing Fast

    A minister warns of a digital 9/11. Meanwhile, thousands of cybersecurity roles sit unfilled. Here's what the talent shortage actually means for hiring in tech.

    The cybersecurity talent shortage means organizations cannot find enough qualified security engineers, architects, and analysts to fill open roles, especially senior and specialist positions. In the Netherlands alone, thousands of cybersecurity jobs stay vacant for months. That gap is not a future risk. It is already slowing down security work today.


    A government minister just said, out loud, that the country could slide into a digital 9/11 without noticing. Strong words. But strip away the drama and there's a simpler story underneath: the people who are supposed to prevent that scenario don't exist in enough numbers.


    You feel this if you're hiring right now. You feel it even more if you're the security engineer everyone is trying to poach. Either way, the shortage is not abstract. It shows up in your open vacancies, your project timelines, and your budget.

    Why is there a cybersecurity talent shortage?

    The shortage exists because demand for security skills is rising faster than the pipeline that trains people for those roles. New regulation, more attacks, and more digital infrastructure all pull in the same direction: more roles, same small pool of qualified people.


    Take the Netherlands. One 2026 estimate puts the country at roughly 13,800 open cybersecurity positions, with an average of 127 days to fill a cyber role, compared to 82 days for a typical IT position, according to research from Searchlab. That's more than four months of a seat sitting empty, often on a team that's already stretched.


    Another estimate suggests the country has around 45,300 cybersecurity professionals working today, but still counts roughly 8,200 unfilled positions, according to workforce gap data compiled by Stateglobe. Supply grew. It just didn't grow fast enough.


    Then there's regulation. The Dutch Cybersecurity Act, which brings the EU's NIS2 directive into national law, took effect in August 2026 and now applies formal security and reporting obligations to a much wider group of organizations, not just banks and critical infrastructure operators, as explained on the Netherlands business government portal. More companies now legally need a security program. Most of those companies did not budget for the hiring war that follows.

    What are the risks of a shortage of cybersecurity experts?

    The direct risk is slower detection and response when something goes wrong, plus compliance projects that stall because there's nobody to run them. Understaffed security teams patch later, monitor less, and miss the early signs of an incident.


    The Dutch Cyber Security Council has flagged this directly, stating that the shortage of cybersecurity professionals

    poses a growing risk
    and calling for more investment in education and training, per the same Searchlab research. That's not a hiring manager's frustration. That's a national advisory body saying the gap itself is now a threat.


    There's a second, quieter risk: paper compliance. Organizations register under NIS2, tick the boxes, write the policy documents. But without engineers to actually run detection, incident response, and secure architecture, the paperwork doesn't protect anything. A registration is not a defense.


    The scarcity is worst at the top of the skill ladder. Cleared security engineers who can work in government, defense, or otherwise sensitive environments are in a category of their own. One report projects a gap of roughly 14,000 roles by the end of 2026, with cleared security engineering as the tightest segment, according to analysis from Kitalent. You can't shortcut a clearance process. That part of the market stays slow no matter how much budget you throw at it.

    How does the cybersecurity skills gap affect national security?

    When there aren't enough qualified people to defend critical infrastructure, government services, and major companies, the country's collective defense gets thinner, not just any single organization's. That's the real read behind the "digital 9/11" language.


    A minister warning about ongemerkt sliding into a large-scale digital incident is really describing a staffing problem at scale. Attacks on large companies and government services are becoming normalized as background noise. The threat isn't smaller, there just aren't enough hands left to keep pushing back.


    This is where NIS2 compliance and recruitment start to overlap directly. Regulation assumes organizations can staff up to meet new obligations. In practice, the organizations most exposed, smaller and mid-sized companies newly caught by NIS2, are the ones with the least recruiting muscle and the smallest budgets to compete for senior talent.

    How can companies attract cybersecurity professionals?

    Companies attract cybersecurity professionals by offering real technical ownership, transparent hiring processes, and compensation that reflects how scarce the skill actually is. Slow, vague hiring processes lose senior candidates fast, especially in a market where they have three other offers on the table.


    Pay is already moving. One sector report puts Dutch cybersecurity compensation between roughly €42,000 for entry-level roles and €120,000 for senior experts, according to Mordor Intelligence's market analysis. The same research notes that 89% of Dutch firms expect to hire additional security staff before 2026 to meet NIS2 requirements. Nearly every company chasing the same small pool, at the same time.


    That's the part CV-blasting doesn't solve. A generic job post competing against 89% of the market posting the same generic job post gets ignored. What works instead is a structured intake that actually maps the role, the stack, and the team, so a senior engineer can tell within five minutes whether this is worth their time.


    We run a Delivery Sprint process for exactly this reason. Intake, sourcing, and interviews happen on a fixed structure, so a hiring manager knows where things stand and a candidate isn't left guessing for three weeks after a first call. No CV-spam. No junior recruiter reading a job description they don't understand. Roles like SRE positions or senior engineering leads get matched by someone who actually understands what the role does.

    Reskilling and hybrid models: the practical way out

    Posting more vacancies won't close this gap. The talent simply isn't sitting on the sidelines waiting to be found. What actually moves the needle is redesigning how security work gets staffed, not just who gets hired.


    Reskilling adjacent engineers is one of the fastest paths. Cloud engineers, DevOps specialists, and network admins already understand infrastructure. With targeted training, some of them convert into strong security engineers faster than a brand-new graduate could ramp up. Reskilling isn't a perfect substitute for deep specialist experience, but it widens the pool considerably.


    That's a real shortcut.


    Hybrid staffing models help too: an in-house lead paired with managed detection and response for round-the-clock monitoring. That combination covers gaps that a single junior hire never could, without requiring a full internal team overnight. It also buys time while a company builds a longer-term pipeline through universities, vocational programs, and internal training tracks.


    None of this is exotic. It's a build-versus-buy decision, made deliberately instead of by default. Companies that make that call early tend to hit their compliance deadlines. Companies that wait for the "perfect" senior hire often don't.

    What this means for hiring managers and engineers right now

    If you're a hiring manager, the market has shifted the advantage toward candidates, especially at the senior and cleared end. Slow internal processes, vague job descriptions, and unclear compensation bands cost you the exact people you need most.


    If you're an engineer working in security today, this is a strong market for you. Also a demanding one. Skills like cloud security architecture, OT security, and SOC leadership are pulling premium offers. Roles such as senior engineering positions tied to AI infrastructure increasingly need security awareness baked in, not bolted on afterward.


    That's an advantage. Use it wisely.


    Whichever side you're on, the honest move is the same: get specific about what the role actually needs, be upfront about what's realistic on timeline and budget, and don't waste three months chasing a profile that doesn't exist in the numbers the market can currently supply.

    Veelgestelde vragen
    Why is there a cybersecurity talent shortage?

    Demand for security skills is rising faster than training pipelines can supply, driven by more regulation, more attacks, and more digital infrastructure needing protection. Senior and cleared roles are hit hardest.

    How can companies attract cybersecurity professionals?

    Offer real technical ownership, transparent and fast hiring processes, and pay that reflects genuine scarcity. Vague job descriptions and slow interview loops lose senior candidates to competitors within days.

    What are the risks of a shortage of cybersecurity experts?

    Slower incident detection, stalled compliance projects, and paper-only compliance where policies exist but nobody runs them. Advisory bodies now describe the shortage itself as a growing national risk.

    How does the cybersecurity skills gap affect national security?

    Fewer qualified defenders means critical infrastructure and government services carry more risk collectively, not just individual companies. Regulation assumes staffing capacity that many organizations simply don't have yet.

    Conclusion

    The cybersecurity talent shortage won't close because a minister raised the alarm. It closes when hiring gets more deliberate: reskilling adjacent engineers, building hybrid staffing models, and running a hiring process sharp enough to win over candidates who have other offers waiting.


    That's the work we do every day. Structured intake, senior recruiters who understand the stack, and a process that doesn't waste anyone's time. If you're building a security team and tired of CVs that don't match the brief, or you're an engineer wondering whether your recruiter actually understands what a SOC does, get in touch and let's talk about what you actually need.

    Sources
    1. Cybersecurity Workforce Gap Statistics in Netherlands (2026)
    2. Cybersecurity Statistics Netherlands 2026 - Searchlab
    3. NIS 2 directive sets obligations for more companies
    4. Netherlands Cybersecurity - Market Share Analysis, Industry Trends ...
    5. The Hague Cybersecurity Hiring: Why the Government That Fuels This
    6. Minister van Weel: 'We kunnen ongemerkt in een digitale 9 ...

    Written by our AI, read by a flesh-and-blood recruiter.