Ransomware ready? Take the 3-minute assessment

Mid-Market Security Can’t Hire Its Way Out of the Judgment Gap

BLUF: The cybersecurity industry’s own research bodies have quietly stopped describing the skills gap as a headcount problem. The specific skills identified as scarce are judgment, critical thinking, and communication, not technical certifications, and fewer organizations are training for any of it. Mid-market security teams feel this harder than large enterprises because they run small, generalist programs with no specialist bench to catch what one person misses, and rarely have the scale to build a formal internal development pipeline. Posting another job requisition does not close a gap that hiring criteria were never built to measure.

A Number the Industry Stopped Leading With

For years, the standard cybersecurity workforce story opened with a single headline figure: the global gap between how many cybersecurity professionals organizations say they need and how many currently work in the field. In 2025, for the first time in its eleven-year history, ISC2’s annual workforce study declined to publish that estimate.

Drawing on responses from more than 16,000 cybersecurity professionals, ISC2 pointed instead to skills-specific measures as the more useful diagnostic. Ninety-five percent of respondents said their organization needed at least one skill it currently lacked, up five points from the prior year, and 59 percent described the gap as critical or significant, up from 44 percent in 2024. Eighty-eight percent reported that their organization had experienced a significant cybersecurity incident in the past year tied directly to a skills shortfall.

That is a meaningful shift in how the industry’s own researchers frame the problem. A raw headcount number implies the fix is more hires. A skills-specific number raises a different question: which skills, specifically, and are organizations doing anything to build them.

Most mid-market hiring plans have not caught up to that shift. Budget conversations still tend to start with an open seat count: how many analysts, how many engineers, how many people on the incident response rotation. That framing was reasonable when the primary constraint really was headcount. It is a weaker fit for a year in which the industry’s own researchers say the binding constraint is a specific, named skill set that a bigger seat count does not automatically supply.

What Employers Actually Say Is Missing

ISACA’s State of Cybersecurity 2025-2026 report, drawn from more than 3,800 practitioners, asked that more specific question directly. Fifty-nine percent named soft skills, not technical skills, as their top identified gap. Broken down further, critical thinking (57 percent) and communication (56 percent) outranked categories like threat detection (32 percent) and endpoint security (30 percent) as the areas organizations felt least covered.

This is not a case against technical training. It is a specific, sourced claim: the deficits organizations say are costing them the most are not the ones a certification exam or a tool-specific course is built to close.

Hiring Criteria Built for a Different Problem

Job postings have not caught up with what the data says is actually missing. Certification requirements remain the default screening filter. CISSP alone appeared in more than 82,000 open cybersecurity postings in 2025, more than any other credential, according to CyberSeek data. Certifications are useful, verifiable proxies for baseline technical competence. They are close to irrelevant as a signal for the two things ISACA’s data says organizations are shortest on: the judgment to make a defensible call under incomplete information, and the ability to explain that call to people who are not security practitioners.

This is not a case of careless hiring managers. Judgment and communication are difficult to verify at scale in a resume screen or a forty-five-minute technical interview, so screening defaults to what can be checked quickly: certifications, years of experience, named tools. A candidate either holds a CISSP or does not. Whether that same candidate can look at an ambiguous alert, decide correctly that it warrants escalation rather than suppression, and explain that call to a CFO in language that survives contact with a board meeting, is far harder to establish in a standard interview loop, and most loops do not try. The gap the data says matters most is the gap current hiring processes are least equipped to test for.

Why Mid-Market Teams Feel This Harder

Large enterprises can partially absorb a judgment gap inside one hire. A ten-person SOC has senior analysts positioned to catch a junior analyst’s bad call before it reaches an executive. A 300-employee manufacturer or a regional health system running security with one or two dedicated staff does not have that layer. A single missed escalation, or a technical update delivered to the board in language that gets rounded down to “handled,” is the entire program’s judgment on display, with no one behind it to catch the miss.

At the same time, ISACA’s data shows the industry investing less in developing this exact skill set, not more. Only 29 percent of surveyed enterprises trained non-security staff to move into security roles in 2025, down from 41 percent the year before, even as 55 percent describe their teams as understaffed and 65 percent report unfilled positions. Larger organizations can partially offset that gap by hiring away talent already developed elsewhere. Mid-market organizations, competing for the same shrinking pool of pre-formed judgment against buyers with deeper compensation budgets, mostly cannot.

The Part AI Adoption Does Not Fix

A common assumption is that AI tooling closes this gap by absorbing the technical workload that used to require more people. That assumption is only half right. AI adoption in security operations has been real and fast; ISACA’s data shows a growing share of security teams now involved in shaping how their own organizations govern and implement AI. What AI absorbs first is high-volume, pattern-matchable work: initial alert triage, log correlation, first-pass classification. What it does not absorb is the judgment call sitting on top of that output, deciding whether an AI-flagged anomaly is the real thing or noise, and communicating that decision to people who will act on it. As routine technical work gets automated, the proportion of a security role’s remaining value that depends on judgment and communication goes up, not down. A mid-market team that automates its way to fewer technical tickets and still has not addressed the judgment gap has automated the easy part of the problem.

Closing the Actual Gap

None of this argues against certifications or technical screening. A baseline of verified technical competence still matters. It argues that certifications were never designed to answer the question currently driving incidents, and treating a resume line as a substitute for tested judgment leaves that gap open regardless of headcount added against it.

Two changes address the gap the data actually describes, rather than the one that is easiest to post a requisition for. First, hiring processes can add a structured, scenario-based component: presenting a realistic, ambiguous incident and evaluating how a candidate reasons through it and explains the decision, rather than whether they can recite a framework. Second, budget for judgment and communication as a development line separate from certification renewal, aimed at staff already on the team, rather than assuming the market will eventually supply people who arrive with it fully formed.

Actionable Takeaways for Business Leaders

Cybersecurity’s own workforce researchers have already moved past the headcount framing. Mid-market organizations still writing job postings around it are solving a problem the data no longer describes.


References

  1. ISC2, 2025 Cybersecurity Workforce Study. https://www.isc2.org/Insights/2025/12/2025-ISC2-Cybersecurity-Workforce-Study
  2. ISACA, State of Cybersecurity 2025-2026. https://www.isaca.org/resources/state-of-cybersecurity
  3. ISACA, “New ISACA Study: Despite Understaffed Cybersecurity Teams, Fewer Enterprises Are Training Staff for Security Roles,” press release, September 29, 2025. https://www.isaca.org/about-us/newsroom/press-releases/2025/state-of-cybersecurity-2025-global-press-release
  4. CyberSeek certification-demand data, cited in Axis Intelligence, “Cybersecurity Jobs Statistics 2026.” https://axis-intelligence.com/cybersecurity-jobs-statistics/
Final CTA Section
GET STARTED

Ready to Strengthen Your Defenses?

Whether you need to test your security posture, respond to an active incident, or prepare your team for the worst: we’re ready to help.

📍 Based in Atlanta | Serving Nationwide

Discover more from Satine Technologies

Subscribe now to keep reading and get access to the full archive.

Continue reading