Urgent.News

600+ sources. One page. See who else covered it.

Editions

Business

Why employee retention is at the heart of the cyber skills gap

‘The bucket is leaking, and the industry keeps blaming the tap,’ writes Nahla Davies discussing the cybersecurity talent shortage. Read more: Why employee retention is at the heart of the cyber skills gap

Why employee retention is at the heart of the cyber skills gap

The cybersecurity talent shortage has long been attributed to a lack of skilled individuals. However, a closer examination reveals that the real issue lies elsewhere. In ISC2's 2024 study, while the global cybersecurity workforce grew by just 0.1%, the gap widened by 19%. Budget constraints were the primary factor, cited by 39% of organizations, followed by hiring freezes, layoffs, and budget cuts. This suggests that the gap is growing despite steady supply and reduced demand for hiring.

At the entry level, the problem is even more acute. A third of organizations reported having no entry-level staff at all. Yet, many managers demand certifications like CISA and CISSP for junior roles, which require around five years of experience. The industry demands more pipeline, yet refuses to hire the existing talent.

The data on why experienced people leave is telling. Pay is not the issue, as CISO compensation rose significantly in 2025. It's the working conditions. According to ISACA's 2025 research, 55% of teams are understaffed, 50% struggle to retain talent, and 47% cite high stress as the leading reason for leaving. Among SOC analysts, over half are likely to change employers within a year, citing manual work and alert fatigue as major frustrations.

Gartner predicted back in 2023 that nearly half of cybersecurity leaders would change jobs by 2025, with a quarter leaving the field entirely due to work-related stress. This prediction now seems more like a description than a forecast. Adding to the problem is the concern about personal liability, with 66% of CISOs reporting worry over this issue, and 70% saying liability stories have soured their view of the role.

Experience cannot be manufactured through bootcamps. It takes time to acquire and this is a fact that the industry fails to acknowledge. Furthermore, it takes a significant amount of time to fill cybersecurity roles, especially at the senior level. Every burned-out senior analyst who leaves creates a vacancy that cannot be filled by a graduate, and takes valuable institutional knowledge out of the organization.

The all-island cybersecurity sector report for 2025 counted 632 firms, 10,600 professionals and €3.2bn in revenue, with Cyber Ireland's labour-market work setting a target of 17,000 cyber jobs by 2030. However, this target assumes a retention rate that the sector is not currently achieving. The fixes are known, cheaper than perpetual re-hiring, and almost entirely within an employer's control.

Automating repetitive tasks can alleviate the heavy workload on SOC analysts, building a blameless culture can help retain talent, and proper liability cover and governance can prevent experienced professionals from being frightened out of the profession.

Written by urgent.news from Silicon Republic's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at siliconrepublic.com →

More in Business

More from Wednesday 12 August →