Blog / NIS2 and cybersecurity recruitment: who finds the people?

NIS2 and cybersecurity recruitment: who finds the people?

    NIS2 imposes a duty of care and a reporting obligation on thousands of organizations. But the security professionals who need to make that happen are barely out there. What does that mean for recruitment?

    Why compliance is no guarantee of security

    Complying with the law and actually being resilient are two different things. An organization can fill in all the forms and still have no idea who gets out of bed at night when there's an incident.


    Duty of care and reporting obligations sound bureaucratic, but they require real capacity: someone who assesses risks, someone who checks supply chain vendors, someone who reports an incident within the set deadline. Research shows that only 33% of European organizations consider themselves fully prepared for NIS2. The rest have the policy, but lack the people.


    The difference between compliant and prepared sits exactly in the people who do the work. A risk analysis on paper protects nobody. A SOC analyst who spots an anomaly at three in the morning does.

    Which roles are suddenly worth gold

    Not every security role is hit equally hard. Some profiles were already scarce, but NIS2 makes them acutely indispensable.


    The CISO is shifting from an IT function to a board-level responsibility: someone who can explain to the executive team what the risk is and what it costs to reduce it. On top of that, there's demand for the compliance lead who translates legal requirements into technical measures, the risk manager who builds audit trails and control frameworks, and the SOC analyst who makes the reporting obligation work in practice.


    Cloud security engineers and supply chain risk specialists are also high on the list. NIS2 explicitly demands attention for vendors and integrations, and that's exactly the domain where an architect who secures cloud environments from the ground up makes the difference between a paper process and a working process.


    The problem: all these profiles combine technical knowledge with the ability to explain it to non-technical people. That kind of person was already scarce. Now everyone wants them at the same time.

    Why classic recruitment breaks down here

    Posting a job ad and waiting for applications no longer works for these roles. The demand is too high and the supply too small.


    Labor market figures show that 76% of organizations already struggle to attract security professionals, and 71% struggle to retain them. Add to that the fact that thousands of organizations will start recruiting around the same deadline, and you understand why a generic approach doesn't work.


    Collecting CVs and hoping there's a suitable profile in the pile is not a strategy in this market. It's waiting for someone else to be faster.


    What does work: knowing exactly who is available before the vacancy goes online. That requires a network you've already built, not a network you start building once the need becomes urgent.

    How a structured recruitment process solves this

    At Doghouse we don't run volume. We run a Delivery Sprint: intake, targeted sourcing, interviews, in a fixed rhythm instead of a black box.


    That starts with a sharp intake. Not "we're looking for a CISO", but: which risk profile, which sector, which reporting line, which mandate. For security roles that difference is big. A CISO at a healthcare organization does different work than a CISO at an energy company, even though the same title is on the vacancy.


    Then we search with focus, with senior recruiters who know the market, not with junior recruiters who only search a system. For a role like a senior system developer with security affinity, that means: knowing who has deliberately moved into compliance work over the past two years, not just who has "security" on their LinkedIn.


    No quotas, no CV spam. We only propose what fits.

    What this means for security professionals themselves

    If you're in a security role right now, this is a good moment to be critical about what you accept.


    Demand is high. That means negotiating room, but also a risk of bad matches. Companies that have just been woken up by NIS2 sometimes offer a role that sounds good on paper, but in practice comes down to firefighting without a mandate.


    Ask the same questions you would ask with any career move. Who sits at the board table for security decisions? Is there a budget, or only a deadline? Is security seen as a board-level responsibility or as an IT chore that just happens to be important now?


    A recruiter who understands the field asks those questions to the client too, before proposing you. That saves a lot of disappointment afterwards.

    Frequently asked questions
    Which cybersecurity specialists do organizations need to comply with the NIS2 directive?

    Mainly a CISO or security lead for governance, a risk manager for risk analyses, SOC analysts for detection and incident reporting, and cloud security or supply chain specialists for third-party risks.

    How big is the shortage of cybersecurity professionals in the Netherlands?

    The Netherlands has an estimated 20,000+ open cybersecurity vacancies, while only a few thousand new professionals enter the field each year. Across Europe, it's more than 424,000 unfilled positions.

    What is the difference between complying with NIS2 and being truly prepared for cyber threats?

    Complying means your documents and processes are in order. Being prepared means there are people who actually execute those processes when something really goes wrong, within the set deadlines.

    How do you quickly find qualified cybersecurity talent for NIS2 compliance as a tech company?

    By not waiting for applications to a job ad, but sourcing directly through recruiters who already know the market and the role. A sharp intake prevents wasting time on candidates who don't fit.

    Conclusion

    NIS2 changes nothing about the underlying problem: there are too few security professionals for too much demand. What it does change is the urgency. Organizations that still have to start recruiting this fall are at the back of a line that has been forming for a long time.


    We'd rather fill one role well than ten roles halfway. That means: sharp intake, targeted search, no noise. Are you stuck finding security talent, or do you want to know what the market really demands for your role right now? Let's talk.