The world is short roughly 4.8 million cybersecurity workers, a gap that grew 19% in a single year even as the active workforce barely moved. Demand keeps climbing, budgets are tightening, and the roles that do open take months to fill. This roundup pulls together the cybersecurity workforce statistics that matter for hiring and planning, from the size of the talent gap to skills shortages, time-to-fill, retention and the measurable cost of an understaffed team, with every figure traced to a primary source.
The single most-cited number in this field comes from the ISC2 Cybersecurity Workforce Study, the largest annual survey of security practitioners. It measured a global workforce gap of 4.8 million people, the difference between the professionals working in the field and the number employers say they need. That gap did not creep up. It jumped 19% in one year, and it widened for an uncomfortable reason: the workforce itself stopped growing.

Zoom in on the United States and the picture holds. CyberSeek, the workforce-data project run with the U.S. National Initiative for Cybersecurity Education, CompTIA and Lightcast, estimates the domestic cybersecurity workforce at about 1.33 million people. It then calculates a supply-demand ratio of 74%, meaning the available supply of workers is only enough to satisfy roughly three-quarters of what employers are looking for. Put plainly, about one in four cybersecurity roles the market wants filled has no qualified candidate available to fill it.
| The gap, measured four ways | Figure | Source |
|---|---|---|
| Active global cybersecurity workforce | 5.5 million | ISC2 |
| Global workforce gap (unmet demand) | 4.8 million (+19%) | ISC2 |
| Total global workforce needed | 10.2 million | ISC2 |
| Estimated U.S. cybersecurity workforce | ~1.33 million | CyberSeek |
| U.S. supply-demand ratio (workers available vs. demand) | 74% | CyberSeek |
These two numbers describe supply and shortfall, not the same thing counted twice. The 5.5 million is how many people currently work in cybersecurity worldwide. The 4.8 million is how many more the field would need to be fully staffed. Add them and you get the 10.2 million total requirement. The alarming part is the ratio: employers would need to nearly double the global workforce to close the gap, yet that workforce grew by a fraction of a percent last year. The shortfall is a supply problem first.
For a small or midsize business, the takeaway is not the raw size of the global number. It is that the pool of people you would hire to defend your network is far smaller than the demand chasing them, which pushes salaries up and time-to-hire out. That imbalance is the entire reason the outsourced security model has grown, and it is the backdrop for every other statistic in this guide.
Source: ISC2 Cybersecurity Workforce Study | CyberSeek Supply and Demand Heat Map
If supply is stuck, demand is not. Employers posted 514,359 cybersecurity job listings in the most recent twelve-month CyberSeek reporting period, an increase of nearly 57,000 listings, or 12%, over the year before. That is a market adding new openings faster than the workforce can grow into them, which is exactly what keeps the supply-demand ratio stuck below 100%.
The U.S. Bureau of Labor Statistics classifies information security analyst, the closest official occupation to a core cybersecurity role, as one of the fastest-growing jobs in the entire economy. It projects 29% growth from 2024 through 2034 and about 16,000 openings per year on average across the decade, a pace several times the all-occupation average. When a government labor agency and a private job-postings tracker independently point at the same steep demand curve, the trend is real, not a survey artifact.
Source: CyberSeek. Postings rose about 12% year over year.
Rising wages are the market’s signal that the shortage is genuine. A $124,910 median for a single analyst role, before benefits, recruiting cost and the salary premium scarce specialists command, is a number many small and midsize businesses cannot absorb for even one full-time hire, let alone the several specialists a complete security program requires. That economic reality is what makes a shared, outsourced team so appealing.
The demand behind these postings is driven by the same threat landscape our broader cybersecurity statistics roundup documents, and by the compliance obligations detailed in our cybersecurity compliance data. More threats and more regulation mean more roles to fill.
Explore Cybersecurity Services
Source: CyberSeek | U.S. Bureau of Labor Statistics, Occupational Outlook Handbook
The most important shift in recent workforce data is what the shortage is actually made of. For years the story was bodies: not enough people. The newest ISC2 study reframes it around skills. In fact, ISC2 found the skills problem so dominant that it stopped publishing a single headline gap number and rebuilt the survey around specific capabilities teams are missing.

This distinction matters because it changes what “solving the shortage” looks like. Hiring one more generalist does not close a gap in AI security or cloud configuration. An earlier ISC2 study found that two-thirds of professionals, 64%, viewed their skills shortages as more serious than their raw staffing shortages, and 90% of organizations reported a skills gap somewhere on the team. A business can be fully staffed on paper and still be exposed if nobody on the roster has done cloud incident response or evaluated an AI-driven detection tool.
Source: ISC2 Cybersecurity Workforce Study. Share of teams naming each as a top gap.
AI landing at the top of the list is telling. The same study found that roughly 69% of teams are on some path to adopting AI security tools, whether already integrated, in testing, or under early evaluation. Demand for the skill is being created by the tools meant to relieve the shortage, which is why specialist depth, not just headcount, is what a modern security program needs. Building that depth in-house means recruiting for cloud and AI expertise that the whole market is fighting over at once.
Source: ISC2 Cybersecurity Workforce Study 2025 | ISC2 Cybersecurity Workforce Study 2024
Here is the contradiction at the center of the talent gap. Employers say they are desperate for security staff, yet a large share of open roles goes unfilled because of money, not applicants. When ISC2 asked organizations what was driving their shortage, a lack of budget outranked a lack of available people. The scarcity is real, but so is the spending freeze sitting on top of it.
The newer ISC2 data confirms the pattern rather than reversing it. In the most recent study, budget cuts affected 36% of teams, hiring freezes 39% and layoffs 24%, and when respondents ranked the causes of their skills shortage, being unable to find people with the right skills (30%) sat almost even with insufficient budget to hire (29%). A further 10% said they simply could not afford qualified candidates at market rates. Money and scarcity are now roughly equal partners in keeping roles empty.
The data says otherwise. The shortage is a squeeze from two directions at once. Yes, qualified specialists are scarce and expensive, but the leading reason roles stay open is that budgets have been frozen or cut, with 39% of organizations naming a lack of budget as their number-one obstacle. Treating the problem as pure talent scarcity leads businesses to wait for a hire that never comes, while the smarter move is often to convert an unaffordable, hard-to-fill salary line into a predictable managed-service cost that delivers a whole team immediately.
For a smaller business, this budget paradox is actually clarifying. If the barrier is partly money and partly scarcity, the answer is a model that fixes both: a flat monthly fee that buys shared access to a full bench of specialists, instead of a six-figure salary that buys one generalist. That is the core economics behind fractional and outsourced security leadership.
Source: ISC2 Cybersecurity Workforce Study 2024 | ISC2 Cybersecurity Workforce Study 2025
Even when a business has the budget and finds a candidate, the hiring machine is slow and the people it lands are hard to keep. ISACA’s State of Cybersecurity study measures the operational reality inside security teams, and the numbers explain why a job posting does not translate into a defended network for months, if at all.
The retention problem feeds the hiring problem. ISACA found that 66% of cybersecurity professionals say their role is more stressful than it was five years ago, a burnout signal that pushes experienced staff out the door and reopens the same seat a business spent six months filling. Worse, the training pipeline that could relieve the pressure is shrinking: only 29% of enterprises now train non-security staff to move into security roles, down from 41% the year before. Fewer businesses are growing their own talent at exactly the moment the market cannot supply it.
| Inside the hiring bottleneck | Figure | Source |
|---|---|---|
| Organizations with unfilled cybersecurity positions | 65% | ISACA |
| Security teams that are understaffed | 55% | ISACA |
| Non-entry-level roles taking 6+ months to fill | ~40% | ISACA |
| Organizations struggling to retain security talent | 50% | ISACA |
| Professionals whose role is more stressful than 5 years ago | 66% | ISACA |
| Enterprises training non-security staff into security roles | 29% (down from 41%) | ISACA |
Stack these facts on top of the salary and scarcity data and the in-house math gets daunting. A business must find a specialist the whole market wants, pay a six-figure premium, wait up to six months, and then work to keep that person from burning out or being poached. A managed security partner absorbs that entire cycle, because the team is already hired, trained, cross-covered and retained on the provider’s side.
For the wider staffing and spending backdrop, our small business cyber attack statistics show why even lean teams cannot opt out of a security program.
Source: ISACA State of Cybersecurity
The talent gap is easy to treat as an abstract industry problem until it shows up on an incident invoice. IBM’s Cost of a Data Breach Report puts a dollar figure on understaffing by comparing breach costs at organizations with and without a security skills shortage, and the difference is stark.

Read that against the earlier data and the chain is clear. A shortage of skilled staff (ISC2) leads to slower detection and thinner response (ISACA’s understaffed, burned-out teams), which leads to costlier breaches (IBM). The gap is not a hiring inconvenience. It is a measurable risk multiplier that lands on the balance sheet the moment something goes wrong, and more than half of breached organizations are now on the wrong side of it.
Source: IBM Cost of a Data Breach Report.
Two independent Tier 1 datasets combine into a single planning number. CyberSeek reports a U.S. supply-demand ratio of 74%, which means about 26% of the cybersecurity roles employers want are effectively unfillable at any given time. IBM reports that organizations carrying a high security skills shortage pay roughly $1.57 million more per breach ($5.22M versus $3.65M) than fully staffed peers. Read together, they show the gap is not free to leave open: for the quarter of demand the market cannot supply, understaffing converts directly into a seven-figure breach-cost exposure. Formula: unmet demand (CyberSeek, ~26% of roles) intersecting the understaffed-breach penalty (IBM, +$1.57M per incident) equals the understaffing tax a short-handed business quietly carries. Calculation and interpretation original to CNiC Solutions.
The number that closes this section is the one worth repeating to a budget committee: the gap between a fully staffed and an understaffed breach response is larger than the annual salary of the specialists a business could not find or afford. Prevention through adequate staffing, in-house or outsourced, is cheaper than the incident it prevents. For the full breach-economics picture, see our average cost of a data breach statistics.
Source: IBM Cost of a Data Breach Report | CyberSeek
Every statistic in this guide points toward the same set of responses, and none of them require a business to win an unwinnable recruiting war. The organizations weathering the talent gap best are the ones that stopped trying to hire their way out of a market-wide shortage and changed the model instead.
The data supports a short, practical playbook for a small or midsize business facing this gap:
| What the data shows | What works in response |
|---|---|
| Only enough workers to fill 74% of demand, wages bid up to a $124,910 median | Share a team through managed services instead of competing for one costly hire |
| Skills gaps (AI, cloud) outrank headcount as the top concern | Buy specialist depth on demand rather than hoping one hire covers every domain |
| Non-entry roles take 6+ months to fill; 50% struggle to retain | Outsource the seat so coverage is immediate and retention is the provider’s job |
| Understaffed organizations pay ~$1.57M more per breach | Treat adequate coverage as breach-cost insurance, not overhead |
| Leadership and strategy gaps, not just technical seats | Add fractional leadership through a virtual CISO or virtual CIO |
This is not a pitch dressed up as data. It is the logical conclusion of the numbers: when supply is capped, prices are high, hiring is slow and retention is fragile, pooling demand across a shared provider is the model that scales. It is exactly why managed IT and security adoption has climbed in lockstep with the talent gap, and it is what CNiC Solutions delivers to businesses that cannot, and should not have to, build a full security team from scratch.
Turning the workforce gap into a solved problem, a full team plus fractional leadership for a predictable monthly cost, is the entire premise of managed security.
See How Managed IT Closes the Gap
Source: ISC2 Cybersecurity Workforce Study | ISACA State of Cybersecurity
| Statistic | Figure | Source |
|---|---|---|
| Global cybersecurity workforce gap | 4.8 million (+19%) | ISC2 |
| Active global cybersecurity workforce | 5.5 million (+0.1%) | ISC2 |
| Total global cybersecurity workforce needed | 10.2 million | ISC2 |
| Estimated U.S. cybersecurity workforce | ~1.33 million | CyberSeek |
| U.S. supply-demand ratio | 74% | CyberSeek |
| U.S. cybersecurity job postings (12 months) | 514,359 (+12%) | CyberSeek |
| Projected growth, information security analysts (2024-2034) | 29% | U.S. BLS |
| Projected annual openings, information security analysts | ~16,000/year | U.S. BLS |
| Median wage, information security analysts (May 2024) | $124,910 | U.S. BLS |
| Teams reporting at least one skills need | 95% | ISC2 |
| Teams calling skills needs critical or significant | 59% (from 44%) | ISC2 |
| Top skills gap: artificial intelligence | 41% | ISC2 |
| Second and third skills gaps: cloud security / risk assessment | 36% / 29% | ISC2 |
| Organizations with skills gaps on the team | 90% | ISC2 |
| Naming lack of budget as the top shortage cause | 39% | ISC2 |
| Experiencing hiring freezes / budget cuts / layoffs | 38% / 37% / 25% | ISC2 |
| Organizations with unfilled security positions | 65% | ISACA |
| Security teams that are understaffed | 55% | ISACA |
| Non-entry roles taking 6+ months to fill | ~40% | ISACA |
| Organizations struggling to retain talent | 50% | ISACA |
| Professionals whose role is more stressful than 5 years ago | 66% | ISACA |
| Enterprises training non-security staff into security | 29% (from 41%) | ISACA |
| Breach cost with high skills shortage | $5.22M | IBM |
| Breach cost with little or no shortage | $3.65M | IBM |
| Rise in breached orgs reporting a severe staffing shortage | 26.2% | IBM |
Every figure in this article is drawn directly from a Tier 1 primary source: the largest annual cybersecurity workforce surveys, a government labor agency, a government-backed workforce-data project, and a major annual breach-cost report. No statistic is sourced from a blog citing another blog, and no figure has been invented, estimated or rounded beyond the source’s own reporting. Where a survey’s most recent edition changed its methodology, that change is noted in the text. The CNiC Solutions Analysis box combines two independent Tier 1 sources and is clearly labeled as original interpretation.
Primary sources:
You are welcome to cite the statistics in this article with attribution to CNiC Solutions and a link back to this page. The CNiC Solutions Analysis figure is original interpretation combining CyberSeek and IBM data and should be attributed to CNiC Solutions. Please cite the underlying primary sources listed above for their respective figures.
DDoS attacks more than doubled in 2025, with Cloudflare alone mitigating 47.1 million of them, up…
Nearly nine in ten organizations (89%) say attackers went after their backups during a ransomware incident,…
The most effective cybersecurity tips are not exotic tools, they are a handful of well-run basics…
A message lands in your inbox: a coworker shared a document with you, or your cloud…