Report: 3.1M professionals are needed to bridge the global cybersecurity talent gap; experts urge companies to adjust hiring requirements for cybersecurity jobs
Researchers say cyber talent is available but often not considered — Companies need millions more cybersecurity professionals … Tweets: @ron_miller Tweets: Ron Miller / @ron_miller : Hiring manager: Do you know what security means in a cyber context? Candidate: Um sure. Hiring Manager. Great. You're hired. When can you start? https://twitter.com/...
Context & Ripple Effects
This report lands mid-arc in a shortage story that has only deepened since: earlier coverage framed the $266B cybersecurity market as constrained by exactly this talent gap, and a survey of 500+ practitioners had already flagged which candidate skills employers say they can't find. The report's core claim is that the talent exists but is being filtered out by overly rigid job requirements.
The arc validates the diagnosis: three years later the global workforce had grown to 4.7M yet the shortage still stood at 3.4M, suggesting supply-side hiring alone isn't closing the gap — which is why the report's push to loosen hiring criteria matters more than another headcount estimate.
First-order effects
- Employers clinging to narrow degree-and-certification checklists keep roles vacant even as qualified candidates apply — the researchers' point that cyber talent is 'available but often not considered' means the bottleneck is screening, not supply.
- Security teams at companies that don't adjust stay understaffed against an active threat environment, the same pressure that later pushed the US government to accelerate filling roughly 600K open cybersecurity roles.
Second-order effects
- Competition for the scarce pool of credentialed candidates bids up pay — consistent with the $120K–$150K average salary range cited in later workforce research — pushing cost-conscious employers toward candidates without traditional credentials.
- Vendors of automation and AI security tooling gain a sales argument: earlier market analysis positioned these technologies as a way to stretch thin teams, so every unfilled seat strengthens the case for buying tooling over hiring.
Third-order effects
- If hiring filters don't change, the gap persists structurally rather than cyclically — the 2023 data showing a 3.4M shortfall despite a larger workforce suggests credential-gated pipelines simply cannot produce enough people.
- Persistent private-sector shortfalls invite government labor-market intervention, as the Biden administration's push to fill hundreds of thousands of US cybersecurity roles previews; expect states to treat security staffing as a national-capacity issue.
The trend: Global demand for cybersecurity professionals is growing faster than credential-gated hiring pipelines can supply them, turning the talent gap into a durable structural feature of the industry.