The Cybersecurity Skills Gap Is About More Than Head Count
InformationWeek, Thursday, September 17th, 2026
ISC2 shifted from sizing the workforce gap to measuring the capability gap, and 88% report a consequence from it.
ISC2's latest Cybersecurity Workforce Study, covering 16,029 professionals, stopped estimating the size of the global workforce gap and now focuses on the gap between the skills organizations need and the capabilities their teams have.
The consequences are operational, not theoretical: 88% of respondents faced at least one major cybersecurity consequence tied to missing critical skills, and 69% reported more than one.
AI was the most frequently cited skill needed, named by 41%, as teams increasingly need people who can use AI, evaluate its output, secure AI systems and recognize threats using the same technology.
The underlying issue is opportunity cost, since most teams are short on time rather than dedication and security gets bolted on rather than built in.