Key Takeaways
- 60% of CISOs now view the cybersecurity skills gap as their top workforce concern, surpassing simple headcount shortages for the first time.
- Rapid enterprise AI deployment is the primary catalyst, exposing deficiencies in existing teams’ ability to secure AI‑enabled systems.
- Hiring alone cannot close the gap; the market for highly skilled AI‑security practitioners is limited and costly.
- Standardized frameworks (e.g., NICE) and baseline AI security training are essential structural fixes.
- Operational experience—not just technical certification—remains a critical, hard‑to‑train component of effective security teams.
- Immediate actions CISOs can take include auditing open roles against a skills framework, pre‑emptive AI security training, and defining dual career tracks (technical depth vs. operational breadth).
Overview of the SANS/GIAC 2026 Findings
The SANS/GIAC 2026 Cybersecurity Workforce Research Report, based on responses from 947 security leaders worldwide, reveals a notable shift in CISO priorities. Sixty percent of respondents identified “not having the right staff” as their foremost challenge, while only 40% cited “not enough staff.” This marks the first time the skills gap has outweighed pure headcount concerns in the survey’s history. The data underscore a growing realization that merely adding bodies to security teams does not solve the underlying problem of mismatched capabilities.
AI as the Main Driver of the Skills Gap
Rob T. Lee, SANS Institute’s chief of research, links the emerging skills gap directly to the accelerated adoption of artificial intelligence across enterprises. Organizations have embedded AI tools into virtually every business function, creating a technology stack that many security teams were neither hired nor trained to defend. Consequently, the deficit lies not in vacant positions but in the actual competencies of the people filling those roles. As AI systems evolve, the knowledge required to secure them outpaces the ability of existing staff to keep up, widening the gap faster than traditional hiring can address it.
Structural Barriers to Simple Hiring Solutions
Marling Engle, CEO of Cyberstar, explains why simply posting more jobs fails to resolve the issue. Companies often advertise entry‑level positions that demand advanced competencies because they lack a clear picture of what skills are truly needed in the market. This mismatch leads to “title drift,” where individuals hold job titles that do not reflect their day‑to‑day responsibilities—akin to labeling a pediatrician as a heart surgeon. Engle advocates for a disciplined approach: selecting a standardized skills framework (such as the NICE framework) and using it to define role requirements before any recruitment begins.
The Role of Standardized Skills Frameworks
Both Engle and Lee emphasize that shared vocabularies for cybersecurity roles are critical to eliminating ambiguity. The National Initiative for Cybersecurity Education (NICE) framework and its international counterparts provide a common language that maps tasks, knowledge, and skills to specific job functions. By aligning every open position to such a framework, organizations can identify whether a perceived need for a senior architect is actually better met by a SOC analyst with scripting abilities—a profile that is more readily available and cost‑effective. This pre‑emptive mapping prevents the accumulation of mismatched teams that cannot fulfill operational mandates.
Operational Experience Versus Technical Certification
JC Vega, a cybersecurity consultant and retired U.S. Army colonel, distinguishes between technical knowledge and operational expertise. He argues that while certifications can teach the “what” of cybersecurity, they cannot impart the “how” of responding to real‑world incidents under pressure. Senior practitioners who built the field possess deep organizational risk intuition forged through cross‑functional work; newer entrants, having grown up in narrowly defined cyber roles, often lack that breadth. Vega notes that this experience deficit is not a training shortfall—no amount of classroom learning can substitute for the pattern‑recognition developed over years of varied operational exposure.
The Learning Imperative Beyond Standard Hours
An anonymous senior security executive (speaking off the record) highlighted the relentless pace of change that forces continuous learning outside normal work hours. Threats, technologies, and attack surfaces evolve so rapidly that professionals must dedicate personal time to stay current; otherwise, they fall behind quickly. This reality reinforces the view that the skills gap is as much about sustaining up‑to‑date, applicable knowledge as it is about initial hiring or baseline training.
Immediate Actions CISOs Can Take This Quarter
The report’s nine strategic recommendations distill into three concrete steps that CISOs can implement right away. First, audit every open role against a standardized framework before posting the job description. This exercise frequently reveals that a perceived senior‑level need is actually a more junior, script‑savvy SOC analyst role—an easier‑to‑fill profile. Second, develop and deliver an AI security training program before the next AI tool rollout, treating baseline AI security literacy as a prerequisite rather than a remedial measure after an incident. Third, establish two visible career tracks—one for deep technical specialization and another for operational breadth across business and security functions—and surface these tracks in job postings. By clarifying pathways, organizations attract candidates whose intentions align with the needed skill mix, reducing the likelihood of title drift and improving retention.
Dual‑Track Career Model as a Long‑Term Solution
John Felker, a former U.S. Coast Guard officer and ex‑deputy chief of service cyber command who later served at CISA, proposes a dual‑track model to address both dimensions of the skills gap. The technical track caters to professionals who wish to specialize in areas such as threat hunting, malware analysis, or secure coding. The operational track targets those who aspire to bridge security with broader business objectives, risk management, and cross‑functional collaboration. By advertising these tracks explicitly, CISOs can signal expectations early in the hiring process, ensuring that candidates self‑select into the role that best matches their strengths and career goals. Over time, this structure helps build a workforce where deep expertise and operational insight coexist, closing the gap that hiring alone cannot fill.

