Blog / The Cybersecurity Talent Shortage Is a Hiring Problem

The Cybersecurity Talent Shortage Is a Hiring Problem

    Government breaches keep exposing the same gap: not enough security engineers. Here's why hiring them is so hard, and what actually works.

    The cybersecurity talent shortage means organizations can't hire the security engineers, DevSecOps specialists, and cloud security experts they need fast enough to keep up with threats. Across the EU, an estimated 299,000 cybersecurity roles sit unfilled. That gap doesn't just sit on a spreadsheet. It shows up as slower incident response, delayed patches, and systems that stay exposed longer than anyone wants to admit.


    You've probably seen the pattern by now. An organization gets hit. Investigators find out later that nobody's entirely sure the attackers are gone. Not because the security team didn't try. Because the team was too small, too stretched, or missing the specific skills the job needed.


    That's not a one-off. That's structural. And if you're a hiring manager trying to build out a security function, or an engineer wondering why every recruiter in your inbox sounds the same, this is worth understanding properly.

    Why is hiring cybersecurity professionals so hard right now

    Hiring cybersecurity professionals is hard because demand has grown faster than the supply of qualified people, and the roles themselves have gotten more complex. It's not one shortage. It's several, stacked on top of each other.


    The numbers back this up. The EU cybersecurity workforce gap grew from an estimated 274,000 in 2023 to 299,000 in 2024, a 9% jump in a single year. Globally, the gap sits around 4.8 million unfilled roles. These aren't projections from a hype cycle. They're counts of open positions nobody's filling.


    Part of the problem is skill mismatch. Organizations aren't just looking for someone who knows firewalls. They want people who understand cloud infrastructure, can read compliance frameworks, and can write secure automation into a CI/CD pipeline. That's a rare combination.


    45% of EU organizations report that difficulty finding candidates with the required skills is their main barrier to hiring cybersecurity staff, according to ENISA's analysis of cybersecurity investment drivers.

    On top of that, 76% of organizations say they struggle to attract cybersecurity professionals, and 71% struggle to retain them. That's not a sourcing problem. That's a market where demand permanently outstrips supply, and everyone is fishing in the same small pond.

    Which security roles are hardest to fill

    Cloud security engineers, DevSecOps specialists, and OT security experts are currently the hardest roles to fill, because they require a mix of skills that few candidates have all at once. These are not entry-level jobs. They need years of hands-on experience plus fluency in regulation.


    Security engineers who understand identity and access management, application security, and cloud hardening are in short supply everywhere, not just in government. Every bank, every scale-up, every consultancy wants the same small pool of people.


    DevOps and site reliability engineers with real security depth are arguably scarcer still. The job now expects someone who can build infrastructure-as-code, understand policy-as-code, and design systems that hold up under audit. A few years ago, security was a specialist's job bolted onto engineering. Now it's baked into the role itself.


    Operational technology security, meanwhile, sits in its own category. Securing industrial control systems and critical infrastructure is a niche within a niche. Analysts flag OT security as one of the areas where the skills gap is felt hardest, because the systems are old, the risks are high, and there simply aren't enough people who've worked with both IT security and OT environments.


    That's a hard combination to teach on the job. Most people who have it learned it the slow way, over years, not in a bootcamp.

    Why government agencies struggle more than private companies

    Government agencies and public bodies struggle more to hire cybersecurity talent because they compete on salary against banks, Big Tech, and consultancies that can simply pay more. That mismatch is well documented and it isn't closing on its own.


    The European Commission has flagged this directly, warning that public administrations, alongside smaller companies, are left vulnerable because they can't build enough in-house cybersecurity capacity. That's not a knock on the people working there. It's a structural pay and flexibility gap.


    Regulatory pressure is making this worse in a good way, if that makes sense. The NIS2 Directive now requires a wide range of public and critical infrastructure organizations to invest properly in security staffing and incident reporting. Roughly 70% of organizations cite regulatory compliance like NIS2 as their main driver for cybersecurity investment. That's pushing budgets up. Budgets alone don't create qualified candidates, though.


    Here's what happens in practice: agencies open roles, raise salary bands, offer more flexible contracts, and still take longer to fill critical positions than a private firm would. When there's a breach, the pressure spikes immediately, but hiring doesn't speed up just because the need got more urgent.


    We've seen this pattern play out with clients working through similar staffing crunches. Reading up on how NIS2 is reshaping cybersecurity recruitment gives a good sense of how compliance pressure and hiring pressure are now the same conversation.

    What actually works when hiring security engineers

    Hiring security engineers successfully starts with a tight, honest scope of the role, not a wishlist copied from ten other job posts. Vague requirements attract vague candidates, and in a market this competitive, that wastes everyone's time.


    Start with what the role actually needs on day one. Not every security hire needs OT experience. Not every DevOps hire needs to be a compliance expert. Stacking every possible skill into one posting shrinks your candidate pool to almost nobody, and the good candidates notice immediately when a job description doesn't reflect reality.


    Speed matters more than most hiring managers expect. Good security engineers get multiple offers within days, not weeks. A slow, multi-stage interview process that drags for a month loses candidates to competitors who move faster. That's frustrating for hiring teams, but it's the market you're in.


    A structured process helps here more than a large candidate list does. Knowing exactly who you're intaking for, running focused sourcing instead of broad CV collection, and giving candidates a clear, fast interview timeline changes outcomes. We've built our own approach to security hiring around exactly that idea: fewer, better-matched candidates, moving through a process people can actually follow.


    None of this is complicated. It just requires discipline that a lot of high-volume recruiting skips.

    How the demand for security talent is shifting

    Demand for security talent is shifting from isolated specialist roles toward integrated positions where security is baked into engineering, operations, and compliance all at once. That shift changes who counts as a strong candidate.


    A few years back, a security engineer could focus purely on defense: firewalls, monitoring, incident response. That's changing. Organizations increasingly want people who can also write secure code, automate compliance checks, and speak the language of both engineering teams and auditors.


    This is showing up clearly in job postings for DevSecOps and SRE roles. It's also visible in forum discussions among security engineers themselves, where people openly talk about how the bar for what counts as "senior" keeps rising, while the flow of junior talent into the field stays thin.


    That combination, rising expectations plus thin junior inflow, is exactly why the shortage keeps compounding instead of easing. Training programs help. ENISA's own skills initiatives aim to upskill at least 100,000 professionals between 2025 and 2027. That's a meaningful number. It's still a fraction of the gap.


    Companies serious about closing this gap internally are looking at broadening where they source technical talent from, including graduate and international talent pools, rather than competing purely on salary for the same experienced pool everyone else wants.

    Frequently asked questions
    Why is it so hard to hire qualified cybersecurity professionals?

    Demand has outpaced supply for years. The EU alone has an estimated 299,000 unfilled cybersecurity roles, and the skills required now span security, cloud infrastructure, and compliance, which few candidates combine.

    How can government agencies improve their IT security staffing?

    By offering competitive pay bands, faster interview processes, and flexible contract structures. Speed and honesty about the role matter as much as salary in a market this tight.

    What skills should a security engineer have to prevent breaches like this?

    Strong fundamentals in identity and access management, cloud security, and secure application development, plus enough DevOps knowledge to build security into automated pipelines rather than bolt it on afterward.

    How long does it typically take to fill a critical cybersecurity role?

    It varies widely, but strong candidates often have multiple offers within days. Organizations with slow, multi-stage processes routinely lose candidates to faster-moving competitors.

    Conclusion

    The cybersecurity talent shortage isn't going away because a headline made it urgent for a week. It's structural, it's been building for years, and it hits public sector organizations hardest because they're competing on salary against companies that can simply pay more.


    Fixing it isn't about writing a longer job description or hoping the right CV lands in your inbox. It's about knowing exactly who you need, running a process that respects candidates' time, and being honest when a role is genuinely hard to fill instead of pretending otherwise.


    That's the whole job.


    If you're building out a security or DevOps team and keep hitting the same wall, it's worth talking to people who work this market daily. That's a conversation, not a pitch.

    Sources
    1. [PDF] ENISA SINGLE PROGRAMMING DOCUMENT 2025 -2027
    2. What’s Driving Cybersecurity Investments and where lie the challenges?
    3. EUROPEAN COMMISSION Strasbourg, 20.1.2026 SWD( ...
    4. NIS Investments 2025 - Main report.pdf - ENISA
    5. [PDF] NIS Investments 2025: Main Report. - ENISA
    6. [PDF] 2025 Consolidated Annual Activity Report - ENISA

    Written by our AI, read by a flesh-and-blood recruiter.