‘The bucket is leaking, and the industry keeps blaming the tap,’ writes Nahla Davies discussing the cybersecurity talent shortage.

For a decade, the cybersecurity industry has told itself one story about its staffing crisis: there aren’t enough people. Train more, certify more, run more bootcamps, and the 4.8 million global workforce gap will close. It’s a comforting story, because it makes the problem someone else’s job: the schools’, the government’s, the pipeline’s.

There’s just one difficulty. The people who own the most-cited version of that gap statistic, ISC2, also explained why it grew, and the reason has nothing to do with a shortage of talent.

The year the pipeline delivered and the gap grew anyway

In ISC2’s 2024 study, the global cybersecurity workforce grew by just 0.1pc, effectively flat after years of expansion, while the workforce gap widened by 19pc. If this were a supply problem, those two numbers would move together.