Blog / Why the cybersecurity talent shortage keeps getting worse

Why the cybersecurity talent shortage keeps getting worse

    Major breaches and critical vulnerabilities expose the same gap every time: not enough security talent. Here's why hiring cybersecurity professionals is so hard, and what actually works.

    The cybersecurity talent shortage exists because demand for narrow, high-value skills spikes the moment something breaks, while supply grows slowly and steadily. Incident responders, identity engineers, and SOC analysts get hired in a hurry. Building that kind of experience takes years. That mismatch is the whole problem.


    Two things happen almost every month now: a big breach makes the news, and a critical vulnerability forces companies to patch under pressure. Every time, the same question lands on a hiring manager's desk. Who do we call to fix this, and who do we hire so it doesn't happen again? That question is getting harder to answer, and it's not because good people don't exist. It's because the market for finding them is broken.

    What's actually driving the cybersecurity skills gap

    The gap isn't about a lack of interest in security careers. It's about a lack of senior, battle-tested people who can walk into a live incident and know what to do in the first hour. According to the ISC2 Cybersecurity Workforce Study, the global workforce gap has stayed in the millions for years, even as the number of people entering the field keeps growing.


    That's the paradox. More people are studying security, more bootcamps exist, more certifications get issued. But the roles companies struggle to fill are rarely entry-level. They're the ones that require someone who has actually handled a breach, actually rebuilt an identity system under pressure, or actually hunted a threat instead of just reading about one in a course.


    Recent events make this concrete. A large-scale telecom data breach in the Netherlands, combined with a critical remote-code-execution flaw in a widely used remote monitoring platform, both broke in the same short window. A security outlet reported that the platform vulnerability was the fourth emergency hotfix issued in five weeks, with confirmed active exploitation. Two separate incidents. Same underlying lesson: when trust breaks, demand for specific security skills spikes overnight.


    That's not a one-off. It's a pattern. And it explains why hiring cybersecurity professionals feels harder every year, even though headcount budgets for security keep growing.

    Which roles get hard to fill first

    When an incident hits, companies don't suddenly need "more security people." They need very specific ones, fast. That's the part generic recruiting misses.


    After a breach involving social engineering, you need people who can harden a helpdesk process and retrain staff to spot a fake login page or an impersonation call. After a platform vulnerability like a critical remote-code-execution flaw, you need engineers who understand identity and access management, privileged access, and how to audit exposure across on-premises and cloud deployments.


    A telecom breach case in the Netherlands is a good example of the human side of this. Investigators say the attackers got access after impersonating an IT colleague and convincing an employee to log into an internal system. That's not a firewall problem. That's an identity-and-process problem, and it needs people who understand both the technical and human sides of an attack.


    So the roles that spike first are narrow: incident responders, threat hunters, IAM and PAM engineers, SOC analysts, and people who specialize in social-engineering defense. Broad strategic hires come later. Recruiters who don't understand this difference end up sending generic profiles for very specific problems, and that's exactly why so many hiring managers have given up on volume-based agencies.

    Why classic agency recruitment fails here

    Most agencies work on volume. Post the vacancy, collect fifty CVs, forward the ones that vaguely match a keyword, and hope one sticks. That model works fine for roles where "good enough" is good enough.


    It falls apart completely for security roles.


    A junior recruiter scanning for "IAM" or "SOC" in a CV has no idea whether a candidate has actually run an access review under pressure, or just listed a tool they touched once in a training. Engineers see through that immediately. So do CTOs who've been burned before.


    We built our approach to cybersecurity recruitment around this exact gap. A structured intake means we actually understand the incident or the gap behind the vacancy before we start sourcing. No CV-spam, no forwarding profiles that vaguely match a keyword. If a role calls for someone who has led incident response in a live breach, we look for that, not for someone who once read about it.

    What skills actually matter now

    Technical depth still matters, but it's not the whole picture anymore. The security engineers in highest demand can explain risk to a board member as clearly as they can patch a server.


    Concretely, that means:


    Identity and access management, because most modern breaches start with stolen or abused credentials rather than a broken firewall. Incident response experience, meaning someone has actually worked a live breach, not just simulated one. Threat hunting, the ability to look for signs of compromise before an alert fires. And increasingly, awareness training and social-engineering defense, because so many breaches start with a phone call or a fake login page, not a zero-day exploit.


    None of this is exotic. It's what the market is actually asking for right now, based on what keeps breaking.

    What this means for hiring managers and CTOs

    If you're a CTO or hiring manager reading this after a bad experience with a bureau, here's the practical shift: stop asking for "a security engineer." Start asking for the specific gap the last incident, or the next likely one, would expose.


    A structured process helps here. We run a fixed Delivery Sprint: intake to understand the real gap, focused sourcing instead of a wide net, and interviews that test for judgment under pressure, not just tool familiarity. You know exactly where a search stands at every stage. No black box.


    That structure matters more in security hiring than almost anywhere else, because the cost of a bad match isn't just wasted time. It's a role that stays unfilled while risk stays open. Roles like a senior architect role or a specialized platform position take longer to fill precisely because the wrong hire is worse than no hire at all.

    What this means for security professionals

    If you're the one being recruited, you already know the drill. A recruiter reaches out with a generic message, clearly copy-pasted, clearly unaware of what your actual specialty is.


    That's not how it should work.


    A recruiter who understands the market should be able to tell you exactly why a role exists, what incident or gap triggered the hire, and what success looks like in the first ninety days. If they can't, that's a signal about the process behind them, not just the person you're talking to.


    We work as a team, not solo operators chasing a placement fee. That means you talk to someone who actually understands identity engineering, or SOC operations, or whatever your specialty is, backed by people who've placed similar profiles before.

    Frequently asked questions
    Why is it so hard to hire cybersecurity talent right now?

    Demand spikes fast after breaches or critical vulnerabilities, but experienced talent takes years to develop. Companies need specific, senior skills immediately, while the pool of people with real incident experience grows slowly.

    How can companies respond faster to critical vulnerabilities like the one in N-central?

    Speed comes from having the right people already in place: engineers who understand identity, access, and patch management before a crisis hits, not after. Reactive hiring during an active incident is always slower than having a bench ready.

    What skills should you look for when hiring a security engineer?

    Look beyond certifications. Prioritize hands-on incident response experience, identity and access management skills, threat hunting ability, and the capacity to explain risk clearly to non-technical stakeholders.

    How do geopolitical tensions affect IT security hiring needs?

    Geopolitical pressure raises the stakes on critical infrastructure and telecom security, pushing companies to hire for resilience and third-party risk roles sooner, rather than treating security as a back-office function.

    Conclusion

    The cybersecurity talent shortage isn't a talent problem. It's a matching problem. The people who can actually handle an incident, hold an identity system together, or explain risk to a board exist. Finding them fast, and recognizing the difference between someone who's read about a skill and someone who's used it under pressure, is the hard part.


    That's where structured recruitment earns its place: it does the intake work that generic sourcing skips.


    If you're staring down a hard-to-fill security role, or you're a security professional tired of copy-paste outreach, we're happy to talk through what you're actually looking for.

    Sources
    1. Stem van verdachte Odido-hack te horen in Opsporing Verzocht
    2. Politie deelt stem van verdachte in onderzoek naar hack Odido
    3. Datadiefstal Odido. Herkent u de stem?
    4. ShinyHunters lawyer up after police release audio clip of suspect in Odido hack
    5. Politie maakt stem van Odido-hacker openbaar: 'Iemand herkent die stem'
    6. N-able Issues Fourth N-central Hotfix in Five Weeks for ...

    Written by our AI, read by a flesh-and-blood recruiter.