BLUF: The cybersecurity industry’s own research bodies have quietly stopped describing the skills gap as a headcount problem. The specific skills identified as scarce are judgment, critical thinking, and communication, not technical certifications, and fewer organizations are training for any of it. Mid-market security teams feel this harder than large enterprises because they run small, generalist programs with no specialist bench to catch what one person misses, and rarely have the scale to build a formal internal development pipeline. Posting another job requisition does not close a gap that hiring criteria were never built to measure.
A Number the Industry Stopped Leading With
For years, the standard cybersecurity workforce story opened with a single headline figure: the global gap between how many cybersecurity professionals organizations say they need and how many currently work in the field. In 2025, for the first time in its eleven-year history, ISC2’s annual workforce study declined to publish that estimate.
Drawing on responses from more than 16,000 cybersecurity professionals, ISC2 pointed instead to skills-specific measures as the more useful diagnostic. Ninety-five percent of respondents said their organization needed at least one skill it currently lacked, up five points from the prior year, and 59 percent described the gap as critical or significant, up from 44 percent in 2024. Eighty-eight percent reported that their organization had experienced a significant cybersecurity incident in the past year tied directly to a skills shortfall.
That is a meaningful shift in how the industry’s own researchers frame the problem. A raw headcount number implies the fix is more hires. A skills-specific number raises a different question: which skills, specifically, and are organizations doing anything to build them.
Most mid-market hiring plans have not caught up to that shift. Budget conversations still tend to start with an open seat count: how many analysts, how many engineers, how many people on the incident response rotation. That framing was reasonable when the primary constraint really was headcount. It is a weaker fit for a year in which the industry’s own researchers say the binding constraint is a specific, named skill set that a bigger seat count does not automatically supply.
What Employers Actually Say Is Missing
ISACA’s State of Cybersecurity 2025-2026 report, drawn from more than 3,800 practitioners, asked that more specific question directly. Fifty-nine percent named soft skills, not technical skills, as their top identified gap. Broken down further, critical thinking (57 percent) and communication (56 percent) outranked categories like threat detection (32 percent) and endpoint security (30 percent) as the areas organizations felt least covered.
This is not a case against technical training. It is a specific, sourced claim: the deficits organizations say are costing them the most are not the ones a certification exam or a tool-specific course is built to close.
Hiring Criteria Built for a Different Problem
Job postings have not caught up with what the data says is actually missing. Certification requirements remain the default screening filter. CISSP alone appeared in more than 82,000 open cybersecurity postings in 2025, more than any other credential, according to CyberSeek data. Certifications are useful, verifiable proxies for baseline technical competence. They are close to irrelevant as a signal for the two things ISACA’s data says organizations are shortest on: the judgment to make a defensible call under incomplete information, and the ability to explain that call to people who are not security practitioners.
This is not a case of careless hiring managers. Judgment and communication are difficult to verify at scale in a resume screen or a forty-five-minute technical interview, so screening defaults to what can be checked quickly: certifications, years of experience, named tools. A candidate either holds a CISSP or does not. Whether that same candidate can look at an ambiguous alert, decide correctly that it warrants escalation rather than suppression, and explain that call to a CFO in language that survives contact with a board meeting, is far harder to establish in a standard interview loop, and most loops do not try. The gap the data says matters most is the gap current hiring processes are least equipped to test for.
Why Mid-Market Teams Feel This Harder
Large enterprises can partially absorb a judgment gap inside one hire. A ten-person SOC has senior analysts positioned to catch a junior analyst’s bad call before it reaches an executive. A 300-employee manufacturer or a regional health system running security with one or two dedicated staff does not have that layer. A single missed escalation, or a technical update delivered to the board in language that gets rounded down to “handled,” is the entire program’s judgment on display, with no one behind it to catch the miss.
At the same time, ISACA’s data shows the industry investing less in developing this exact skill set, not more. Only 29 percent of surveyed enterprises trained non-security staff to move into security roles in 2025, down from 41 percent the year before, even as 55 percent describe their teams as understaffed and 65 percent report unfilled positions. Larger organizations can partially offset that gap by hiring away talent already developed elsewhere. Mid-market organizations, competing for the same shrinking pool of pre-formed judgment against buyers with deeper compensation budgets, mostly cannot.
The Part AI Adoption Does Not Fix
A common assumption is that AI tooling closes this gap by absorbing the technical workload that used to require more people. That assumption is only half right. AI adoption in security operations has been real and fast; ISACA’s data shows a growing share of security teams now involved in shaping how their own organizations govern and implement AI. What AI absorbs first is high-volume, pattern-matchable work: initial alert triage, log correlation, first-pass classification. What it does not absorb is the judgment call sitting on top of that output, deciding whether an AI-flagged anomaly is the real thing or noise, and communicating that decision to people who will act on it. As routine technical work gets automated, the proportion of a security role’s remaining value that depends on judgment and communication goes up, not down. A mid-market team that automates its way to fewer technical tickets and still has not addressed the judgment gap has automated the easy part of the problem.
Closing the Actual Gap
None of this argues against certifications or technical screening. A baseline of verified technical competence still matters. It argues that certifications were never designed to answer the question currently driving incidents, and treating a resume line as a substitute for tested judgment leaves that gap open regardless of headcount added against it.
Two changes address the gap the data actually describes, rather than the one that is easiest to post a requisition for. First, hiring processes can add a structured, scenario-based component: presenting a realistic, ambiguous incident and evaluating how a candidate reasons through it and explains the decision, rather than whether they can recite a framework. Second, budget for judgment and communication as a development line separate from certification renewal, aimed at staff already on the team, rather than assuming the market will eventually supply people who arrive with it fully formed.
Actionable Takeaways for Business Leaders
- Review your last few open security postings: are they screening for certifications and tool tenure, or for reasoning under ambiguity?
- Add one scenario-based question to every security interview loop, evaluated on reasoning and communication, not technical recall alone
- Set aside a training budget specifically for judgment and communication development, distinct from technical certification renewal
- Do not expect added headcount alone to reduce incidents tied to this specific gap; the data points to a skill deficit, not a seat-count deficit
Cybersecurity’s own workforce researchers have already moved past the headcount framing. Mid-market organizations still writing job postings around it are solving a problem the data no longer describes.
References
- ISC2, 2025 Cybersecurity Workforce Study. https://www.isc2.org/Insights/2025/12/2025-ISC2-Cybersecurity-Workforce-Study
- ISACA, State of Cybersecurity 2025-2026. https://www.isaca.org/resources/state-of-cybersecurity
- ISACA, “New ISACA Study: Despite Understaffed Cybersecurity Teams, Fewer Enterprises Are Training Staff for Security Roles,” press release, September 29, 2025. https://www.isaca.org/about-us/newsroom/press-releases/2025/state-of-cybersecurity-2025-global-press-release
- CyberSeek certification-demand data, cited in Axis Intelligence, “Cybersecurity Jobs Statistics 2026.” https://axis-intelligence.com/cybersecurity-jobs-statistics/

