Fully Staffed, Still Exposed
Some 95% of security teams now report at least one skills gap, and 59% call that gap critical or significant, up from 44% a year earlier. Meanwhile the UK's raw workforce shortfall has fallen to roughly 3,800 roles a year, down from 11,100 in 2022. The headcount problem is easing. The capability problem is getting worse. Most boards are still reading the vacancy count, which is now the wrong number.
The data
ISC2 surveyed 16,029 security professionals across EMEA, North America, LATAM and APAC in May and June 2025, publishing in December. The finding that should reach the board is not about hiring volume. Some 95% of respondents reported at least one skill need on their team, up from 90% the year before. More telling, 59% described those needs as critical or significant, up from 44%. That is a fifteen point movement in a single year on the measure that actually correlates with exposure.
The consequence side of the study is blunter. Some 88% of respondents had experienced at least one adverse security event they attributed to a skills shortage, and 69% had experienced more than one. When ISC2 asked what those events looked like, the answers were operational rather than dramatic: 26% reported oversights in process, 25% reported placing underqualified people into roles, 24% reported misconfigured systems, and 24% reported parts of the organisation left under-secured.
Read that list again. Placing underqualified people into roles is not a vacancy. It is a filled seat. Misconfiguration is not an unfilled position either. Both show up on the org chart as full establishment and on the risk register as nothing at all.
The UK picture from the Department for Science, Innovation and Technology points the same way. Around half of UK businesses, 49%, report a gap in basic technical cyber skills such as configuring firewalls or detecting malware, and 30% report gaps in advanced skills such as penetration testing and forensic analysis. Yet the annual workforce shortfall has narrowed sharply, from 11,100 roles in 2022 to roughly 3,800. Supply has improved. Competence has not kept pace with what organisations now run.
There is a third figure worth holding. DSIT's sectoral analysis, published December 2025, records 2,603 UK cyber security firms generating £14.7bn in revenue, employing 69,600 full time equivalents. The average firm now employs 27 people, down from 31. The specialist providers many organisations plan to outsource to are running leaner teams than they were a year ago. Buying capability is not the automatic release valve it is assumed to be.
Why this matters operationally
Vacancy count is an input measure. It tells the board how many chairs are empty. It says nothing about whether the people in the occupied chairs can perform the controls the organisation has committed to.
Consider what a modern security function is asked to hold. Identity and access management across hybrid estates. Cloud configuration across more than one provider. Detection engineering against attacker tooling that now uses generative models. Third party risk assessment at supplier volumes that grow every year. Regulatory reporting against clocks measured in hours. Evidence production for ISO 27001, SOC 2 and PCI DSS, and for customers who ask harder questions than any of them.
Few of those are things a generalist absorbs on the job. ISC2 found 41% naming artificial intelligence as their most pressing skill need and 36% naming cloud security. Those are new bodies of practice rather than extensions of existing ones, and the market for people who hold them properly is thin at any salary.
So an organisation can sit at full establishment, report zero open roles to the board, and still be unable to perform four of its named controls. The gap is invisible because nobody measures it.
The commercial exposure
Regulatory. The Cyber Security and Resilience Bill, published in 2026 and subject to Parliamentary approval, extends the NIS framework to managed service providers and designated data centre operators, and introduces initial incident notification within 24 hours and full notification within 72 hours. Maximum penalties reach the greater of £17m or 4% of worldwide turnover for serious breaches. A 24 hour clock is a capability test, not a headcount test. It asks whether somebody on your team can triage, classify and characterise an incident correctly under time pressure at two in the morning. Note also what the UK Bill does not do. It does not carry the personal accountability for senior management that NIS2 places on EU boards. Organisations operating across both jurisdictions are governed to two different standards on the same question.
Contractual. Enterprise security questionnaires have moved past asking whether a function exists. They increasingly ask who owns a control by name, what qualifies them, and what happens when that person is unavailable. An answer naming one person twice in the same questionnaire is a finding waiting to be written.
Transactional. In diligence, buyers price key person dependency. A security function where one individual holds cloud configuration, detection tuning and audit evidence is a concentration risk that either reduces the offer or lands in the disclosure schedule. Founders rarely see it coming, because through the whole growth period that individual was the reason things worked.
Insurance. Underwriters have become materially more specific about who operates a control rather than whether a tool is deployed. A tool nobody is trained to tune is a premium question and, after an incident, a coverage question.
The Capability Register
Vacancies belong on an HR dashboard. Capability belongs on the risk register, with an owner, a rating and a review date, exactly like any other control. We use a four test structure for this, applied to each skill the organisation genuinely depends on rather than to job titles.
Coverage. Does anyone in the organisation actually hold this skill, at the standard the control requires? Not adjacent to it, not willing to learn it. Holds it.
Concentration. How many people hold it? One is not a team, it is a dependency. Any control resting on a single individual should be rated the same way a board rates a single supplier with no alternate.
Currency. Is the skill current against what the organisation runs today? Cloud security learned three years ago against a single provider is not cloud security across a hybrid estate. Detection engineering that predates model-assisted attacker tooling is partially obsolete.
Confirmation. Can the capability be evidenced externally, to a regulator, an auditor, an insurer or an acquirer? Internal confidence in a colleague is not evidence. Certification, tested runbooks, exercise results and named control ownership are.
Run those four tests across the controls that carry the most exposure and the output is a short list, usually between four and eight items. That list is the real hiring brief, and it looks nothing like the job specifications most organisations are currently advertising.
What this changes about hiring
Three practical consequences follow.
First, the brief changes. Hiring against a title produces candidates who match a title. Hiring against a named capability gap, with the standard written down, produces a shorter shortlist and a faster decision. Time to hire falls because the assessment criteria exist before the first conversation rather than emerging from it.
Second, the shape of the hire changes. Some gaps warrant a permanent hire. Others are better closed by a fractional or interim specialist, by a partner delivering the function under contract, or by developing an existing person against a defined standard with a deadline. The four tests tell you which, because concentration and currency point to different answers than coverage does.
Third, retention becomes a control question rather than a satisfaction question. ISC2 found 75% of professionals likely to stay twelve months but only 66% beyond two years. If a single individual satisfies the only Coverage entry for a control, their notice period is a governance event. That belongs in front of the board before it happens, not after.
What leaders should do now
These are decisions rather than tasks, and each one can be taken in a single sitting.
- Commission a capability register. Take the ten controls carrying the most exposure, not the full control set, and name the individual who owns each. Give it a fortnight and a named executive sponsor. If nobody can complete the list, that is itself the finding.
- Rate every single-person control as a sole supplier. Boards already understand supplier concentration. Use the language they have rather than inventing a new category, and put the ratings in the next board pack alongside the supplier register.
- Split evidenced capability from asserted capability. For every skill your regulatory and contractual commitments require, decide today whether you could demonstrate it externally. Fund the difference, and treat the funding decision as risk spend rather than training budget.
- Rewrite the next hiring brief against a capability gap. Name the skill, write the standard, define the assessment before the first conversation. Time to hire falls because the criteria stop being negotiated mid-process.
- Make sole-holder attrition a reportable event. Where one person satisfies the only coverage entry for a control, their resignation is a governance matter. Decide now what gets escalated, to whom, and within what window.
Three questions for the board
- Which of our security and compliance controls currently depend on exactly one individual, and what is our stated plan for each if that person resigns this quarter?
- Of the skills our regulatory and contractual commitments require, which can we evidence externally today, and which rest on internal confidence alone?
- When we last reported a fully staffed security function, what were we measuring: seats filled, or controls we can demonstrably perform?
The strategic takeaway
The market has quietly changed the nature of the problem. For most of the last decade, security hiring was a supply argument: not enough people, too much competition, salaries rising faster than budgets. That argument is weakening on the numbers. What has replaced it is harder to see and more expensive to ignore, because it does not appear as an empty chair.
Capability is a control. It should be registered, owned, rated and reviewed like one. Organisations that make that shift will hire less often and hire better, and will be able to answer the questions that regulators, customers, underwriters and acquirers are already asking. Organisations that continue to report headcount will keep telling their boards a number that has stopped meaning anything.
Working with Garzon Cyber Solutions
Garzon Cyber Solutions is a young firm. We say that plainly because it matters to how we work. Recruitment is delivered on a contingency basis, so nothing is payable until a candidate accepts and starts, and the founder runs the assignment personally rather than passing it to a delivery team.
The reason we approach hiring through capability rather than headcount is the same reason the three service lines sit together. My career was in sales. I sold cybersecurity, compliance and technology to security and technology buyers, working alongside marketing and technical colleagues in doing so, and the pattern was consistent across every deal: the control gets bought, the audit gets passed, and then nobody owns the capability that keeps either true. Security, compliance and the people to sustain them are one commercial problem, not three procurement events.
It is worth saying what is not our ground. We do not certify. Our compliance work is readiness and evidence, delivered with specialist partners, and on CMMC specifically we work to readiness rather than certification. On hiring, our ground is cybersecurity, security compliance and GRC, plus the commercial roles that sell into security and technology buyers. If the brief is anti-money laundering, financial crime operations or pure fintech compliance, a specialist in that niche will beat us and we will say so rather than take the assignment.
If you want a second view on where your capability actually concentrates before you write the next job specification, that conversation costs nothing.
Confidence note: The workforce figures are survey findings, self-reported by respondents rather than independently verified, and should be read as what security professionals say about their own organisations. The ISC2 percentages are drawn from a sample of 16,029 professionals surveyed in May and June 2025. The DSIT workforce and sector figures are official statistics. The Cyber Security and Resilience Bill provisions described here are as published and remain subject to Parliamentary approval, so the penalty ceilings and notification windows are proposed rather than in force. The commercial consequences set out in this piece are our assessment, not a finding of the underlying research.
Sources: ISC2, 2025 Cybersecurity Workforce Study, published December 2025, based on 16,029 respondents surveyed May and June 2025. Department for Science, Innovation and Technology, Cyber Security Skills in the UK Labour Market. Department for Science, Innovation and Technology, Cyber Security Sectoral Analysis 2026, published December 2025. UK Government, Cyber Security and Resilience Bill, published 2026 and subject to Parliamentary approval.
Where does your capability actually concentrate?
A short review of which controls depend on one person, what a resignation would take with it, and where the next hire should sit. Useful before the job specification is written rather than after.
Start the Conversation →