Talent & Recruitment

The Talent You Need Is Not Coming. Build It, Buy It, or Borrow It.

G
Jonathan Garzon
Founder & CEO, Garzon Cyber Solutions
April 2026 · 5 min read
Closing the Talent Gap, Part 3 of The Cyber Talent Crisis, Garzon Cyber Solutions

In Part 1 of this series, we examined the structural forces behind the cybersecurity talent crisis: 4.8 million unfilled roles, skills gaps overtaking headcount shortages, and a financial penalty that now costs understaffed organisations 1.76 million USD more per breach. In Part 2, we explored how artificial intelligence is transforming the way organisations source, screen, and secure specialist talent.

This instalment addresses the question every CISO and board member is now asking. If the talent pipeline cannot produce enough qualified professionals to meet demand, what do we do about it?

The answer is not a single strategy. It is three, deployed simultaneously.

1. Build: Upskill the Workforce You Already Have

The most underutilised talent pool in cybersecurity is the one already on the payroll.

ISC2’s 2025 Workforce Study found that 85% of employers now prefer upskilling existing staff over external hiring. The logic is sound. Internal candidates already understand the organisation’s risk profile, architecture, and culture. The cost of developing them is a fraction of the cost of recruiting externally in a market where median UK cybersecurity salaries have reached 55,000 GBP and specialist roles command significantly more.

Yet only 28% of organisations currently allocate dedicated working hours for professional development. The gap between stated intent and operational commitment is where most upskilling strategies collapse.

The organisations achieving results are treating capability development as infrastructure, not discretionary spend. IBM’s 2025 data shows that structured investment in retention and training reduced security costs by an average of 259,000 USD per organisation. A Fortune 500 case study demonstrated that targeted upskilling in cloud and AI defence reduced time to fill cyber roles by 40% and increased team retention by 30% within twelve months.

The return is measurable. The barrier is not budget. It is prioritisation.

2. Buy: Rethink How You Hire

The traditional cybersecurity hiring model is broken at the specification stage. Roles requiring five years of experience in technologies that have existed for three. Certification mandates that show limited correlation with on the job performance. Compensation benchmarks that mid market organisations cannot match against enterprise salary bands.

The result: roles stay open for six to nine months. Threat landscapes evolve in weeks.

Organisations that have adopted skills based hiring, evaluating what candidates can demonstrably do rather than which accreditations they hold, are twice as likely to identify better fit candidates with improved retention and reduced time to hire. The UK government has recognised this structural misalignment. ISACA has partnered with BIT Training to embed CISM and CRISC certifications directly into the Level 4 UK apprenticeship curriculum. The UK Civil Service now operates both Level 4 and Level 6 cybersecurity apprenticeship pathways.

Yet only approximately 600 new apprenticeship starts enter the UK cyber pipeline annually against a backdrop of 2,698 core cybersecurity job postings per month. The infrastructure exists. The scale does not.

The implication is clear. Organisations that depend solely on the external market to deliver qualified talent will continue to operate below capacity. Those that combine specialist recruitment with deliberate talent development will close roles faster and retain them longer.

Closing the Talent Gap. Build, Buy, Borrow: Three Strategies for the Cyber Talent Crisis

3. Borrow: Managed Services as a Strategic Capability

For many organisations, the most pragmatic response to the talent crisis is not to fill every role internally. It is to augment internal capability with managed security services.

52% of UK businesses already use a third party for security operations. A further 28% intend to outsource over the next two years. The primary driver is not cost reduction. 60% cite missing internal skills. 48% cite an inability to recruit qualified candidates.

The managed security services market reflects the scale of this shift, growing 22% in 2023 to reach 68 billion USD globally, with projected growth of 6.9% annually through 2029.

The UK has the widest workforce gap in Western Europe. Demand grew 27.1% while the workforce contracted 4.9% due to economic pressure and layoffs. For organisations operating in this environment, managed services are not a compromise. They are the mechanism by which security operations continue while the internal capability is being built.

The Regulatory Accelerant

The organisations waiting for the talent crisis to resolve itself face a second compounding pressure. Regulation is not waiting either.

The European Union faces a deficit of 299,000 skilled cybersecurity professionals. ENISA’s 2025 analysis concluded that NIS2 compliance is structurally impossible to achieve through human capital alone, and organisations are pivoting to technology and managed services to close the gap. ENISA’s European Cybersecurity Skills Framework now formally maps NIS2 role obligations to defined skill profiles, creating a compliance driven workforce planning tool across EU member states.

In the United Kingdom, the Cyber Security and Resilience Bill introduced to Parliament in November 2025 will bring approximately 2,500 managed service providers, data centres, and SOCs into regulatory scope by mid 2026. NCSC’s Cyber Accelerator and CAF assessments are rolling out in parallel, adding further compliance driven pressure on in house security teams.

The regulatory environment is creating mandated demand for qualified security professionals at precisely the moment the market cannot produce them. Organisations that have not already begun building their talent pipeline, through internal development, specialist recruitment, and managed service partnerships, will find themselves caught between enforcement timelines and capability gaps.

The Commercial Reality

The data across all three strategies tells a consistent story.

Organisations with high security skills shortages face average breach costs of 5.74 million USD. Those with low or no shortage face 3.98 million USD. The difference, 1.76 million USD, represents the direct financial cost of unresolved talent gaps. ISC2 reports that 88% of cybersecurity professionals have already witnessed real world consequences from skills shortfalls within their organisations.

Employment growth for information security analysts is projected at 33% through 2034. The talent market will remain structurally undersupplied for the foreseeable future. Waiting is not a strategy. It is an accumulating liability.

The organisations that will navigate this environment successfully are those executing all three levers simultaneously. Building internal capability through structured upskilling. Buying specialist talent through skills based recruitment with deep market expertise. Borrowing capability through managed security partnerships that maintain operational continuity while the internal team matures.

At Garzon Cyber Solutions, we operate across all three. We place specialist cybersecurity, AI, and compliance talent. We advise organisations on workforce strategy and capability development. And we provide the market intelligence that connects regulatory requirements to the resourcing decisions boards need to make.

The talent crisis is structural. The response must be strategic.

Sources: ISC2, 2025 Cybersecurity Workforce Study · IBM, Cost of a Data Breach Report 2025 · DSIT, Cyber Security Skills in the UK Labour Market 2025 · ENISA, 2025 NIS Investments Report · ENISA, Mapping NIS2 Obligations to ECSF Role Profiles 2025 · ISACA & BIT Training, UK Apprenticeship Programme 2024 · Marks Sattin, Skills Based Hiring in the UK 2025 · Technology Reseller UK · MarketsandMarkets, Managed Security Services Market Analysis 2025 · Garzon Cyber Solutions, Market Intelligence, 2026

Where does this sit on your own risk register?

A short, practical conversation about where the exposure actually is, and what a proportionate response looks like. No obligation and no product pitch.

Start the Conversation →
#CyberTalent#Recruitment#SkillsGap#CyberSecurity#Hiring#GarzonCyberSolutions