As cyber threats become more sophisticated, organisations need more than new security technologies. They need a workforce with the skills to understand, operate and continuously improve those technologies.
Cybersecurity has become one of the most important priorities for organisations across industries.
Businesses are moving more applications and data online, adopting cloud platforms, connecting operational systems and increasingly relying on digital infrastructure.
At the same time, cyber threats are becoming more sophisticated.
This creates a difficult equation for organisations:
The attack surface is expanding faster than the cybersecurity workforce.
Finding experienced cybersecurity professionals has become increasingly difficult. But relying exclusively on external hiring is unlikely to solve the problem.
The more sustainable answer may already exist inside many organisations:
Upskill the workforce they already have.
The Cybersecurity Skills Gap Is Growing
Cybersecurity requires a combination of technical knowledge, analytical thinking, business understanding and continuous learning.
Security professionals need to understand areas such as:
- Cloud security
- Network security
- Identity and access management
- Threat detection
- Incident response
- Security operations
- Risk management
- Compliance
- Data protection
- Vulnerability management
The challenge is that these disciplines continue to evolve.
A security professional trained several years ago may now need additional expertise in cloud environments, automation, artificial intelligence and modern security architectures.
This means that cybersecurity is not a career where learning stops after certification or a degree.
Continuous upskilling is becoming part of the job itself.
Hiring Alone Cannot Close the Gap
When organisations encounter a shortage of cybersecurity professionals, recruitment is often the first response.
They increase salaries, engage recruitment agencies and search for candidates with increasingly specific combinations of certifications and technical experience.
But every organisation is competing for essentially the same limited pool of experienced professionals.
This creates a cycle.
Companies hire from competitors.
Competitors hire from other companies.
Salary expectations increase.
Vacancies remain open.
Meanwhile, existing employees may already possess many of the foundational skills needed to transition into cybersecurity roles.
The solution therefore needs to include internal talent development.
Look Beyond the Traditional Cybersecurity Candidate
One of the biggest opportunities lies in identifying employees working in adjacent technology and business functions.
Professionals in areas such as IT support, infrastructure, audit, compliance, risk and systems administration may already understand important components of an organisation’s technology environment.
With structured training, some of these employees can develop into cybersecurity professionals.
For example, an IT administrator who understands networks and systems may have a strong foundation for security operations.
An audit professional may transition towards governance, risk and compliance.
A cloud engineer may develop deeper expertise in cloud security.
The organisation does not necessarily need to start from zero.
It can build cybersecurity capability on top of existing knowledge.
Upskilling Is Different From Simply Giving Employees a Course
Successful upskilling requires more than purchasing access to an online training platform.
Employees need a clear pathway.
That pathway could include:
Assessment → Training → Practical Experience → Mentoring → Certification → Role Transition
The practical component is particularly important.
Cybersecurity cannot be learned effectively through theory alone.
Professionals need opportunities to work with real-world security scenarios, understand incident response procedures, analyse logs, investigate alerts and participate in security operations.
Hands-on learning can turn theoretical knowledge into operational capability.
Create Internal Cybersecurity Career Paths
One reason employees may hesitate to move into cybersecurity is uncertainty about career progression.
Organisations can address this by creating clear internal pathways.
For example:
IT Support → Security Analyst → SOC Analyst → Security Engineer → Security Architect
Or:
Audit → IT Risk → Cyber Risk → Security Governance
These pathways make the transition more tangible.
They also help organisations retain employees by showing them how acquiring new skills can lead to new responsibilities and career opportunities.
Certifications Have a Role — But They Are Not Everything
Cybersecurity certifications can provide useful structure.
They can help employees develop foundational knowledge and demonstrate proficiency in specific areas.
However, certification should not become the entire definition of cybersecurity capability.
A professional may hold several certifications but still lack practical experience.
Conversely, an employee with strong technical experience may have substantial cybersecurity potential even without a long list of certifications.
Organisations should therefore evaluate skills, experience, problem-solving ability and learning capacity alongside certifications.
Cybersecurity Needs Cross-Functional Talent
Modern cybersecurity is no longer limited to the security department.
Security increasingly affects:
- Cloud teams
- Developers
- Data teams
- Infrastructure teams
- HR
- Legal
- Compliance
- Finance
- Operations
This means cybersecurity awareness needs to spread across the organisation.
A developer should understand secure coding.
A cloud engineer should understand cloud security.
An HR team should understand identity and access risks.
Employees should recognise phishing and social-engineering attempts.
Security therefore becomes stronger when cybersecurity knowledge is distributed across the organisation.
Upskilling Can Also Improve Retention
Cybersecurity professionals are in high demand.
This creates another challenge: retention.
Talented employees may leave if they do not see opportunities to learn, grow or progress.
Investing in employee development can therefore have a double benefit.
It helps organisations create the cybersecurity skills they need while also providing employees with opportunities for professional growth.
Career development becomes part of the retention strategy.
Employees who see that their organisation is willing to invest in their future have a stronger reason to build their careers there.
Build a Culture of Continuous Learning
Cybersecurity changes too quickly for organisations to rely on occasional training.
Threat actors constantly adapt.
New vulnerabilities appear.
Cloud environments evolve.
AI introduces new attack and defence techniques.
Regulatory requirements change.
Security teams therefore need a continuous learning culture.
This could involve:
- Regular technical workshops
- Security simulations
- Capture-the-flag exercises
- Threat-intelligence sessions
- Mentoring
- Cross-functional rotations
- Certification programmes
- Incident-response drills
- Internal cybersecurity communities
Learning should become part of normal security operations rather than an annual compliance exercise.
AI Is Changing the Skills Required in Cybersecurity
Artificial Intelligence is creating another layer of change.
AI can help security teams analyse large amounts of data, identify unusual patterns, automate repetitive investigations and accelerate incident response.
But this does not eliminate the need for cybersecurity professionals.
Instead, it changes the skills they need.
Security professionals increasingly need to understand how AI systems work, where they can be trusted, how attackers can manipulate them and how AI-generated insights should be validated.
The future cybersecurity workforce will therefore need a combination of:
Cybersecurity + AI + Data + Automation + Human Judgement
The Goal Should Be Capability, Not Headcount
Organisations often measure recruitment success by the number of cybersecurity positions they fill.
A better measure may be security capability.
Can the organisation:
- Detect threats quickly?
- Respond effectively?
- Protect critical systems?
- Investigate incidents?
- Secure cloud environments?
- Manage identity risks?
- Understand its attack surface?
- Recover from attacks?
If the answer is yes, the organisation has built meaningful cybersecurity capability.
That capability can come from a combination of experienced hires, internal mobility, automation and upskilling.
Government and Industry Also Have a Role
The cybersecurity talent challenge cannot be solved by individual companies alone.
Universities, training institutions, industry associations and governments can contribute by creating stronger pathways into cybersecurity careers.
Practical education is particularly important.
Students and early-career professionals need exposure to real cybersecurity environments rather than only theoretical concepts.
Internships, apprenticeships, cyber ranges and industry-led programmes can help bridge the gap between education and employment.
The Future Cybersecurity Workforce Will Be Built, Not Just Hired
The cybersecurity talent shortage is fundamentally a workforce-development challenge.
Organisations will continue to recruit experienced security professionals, but external hiring alone cannot meet the growing demand.
A stronger strategy is to create a pipeline of talent from within.
That means identifying employees with transferable skills, providing structured training, giving them practical experience and creating clear career paths.
It also means making cybersecurity learning continuous.
Conclusion
Cybersecurity threats are evolving rapidly, and organisations cannot afford to wait for the perfect security professional to appear in the job market.
They need to build capability themselves.
Upskilling and reskilling can turn existing employees into tomorrow’s cybersecurity workforce.
The organisations that invest in continuous learning will be better positioned not only to fill today’s security vacancies but also to prepare for tomorrow’s threats.
The cybersecurity workforce of the future will not be created solely through recruitment.
It will be created through education, opportunity, practical experience and continuous upskilling.
And for organisations facing a growing cyber talent shortage, that may be their most sustainable competitive advantage.
