ISMG Announces Strategic Growth Investment From Peak Rock Capital Affiliate

Read the Press Release

We Never Had a Cyber Talent Shortage

Henry Kogan

The millions of cyber jobs number is exaggerated

My car mechanic boasted how his son is going to be majoring in cybersecurity in college. He felt it would be a surefire way to fast track him to a high paying office job with air conditioning and a nice white collar free of grease stains. He said that there are millions of open jobs available.

Has anyone ever verified the famous “millions of unfilled cyber jobs”data point?

If I tell my AI agent to crawl every job database, could it come up with a similar number? I’m learning now how that figure was always an estimate of perceived need, not funded openings.

It turns out ISC2 stopped publishing it in 2025 because the industry itself now says the real problem is skills, not headcount. CyberSeek counted roughly 5OOK U.S. cyber job postings in a recent 12-month window — a lot, but not millions, and mostly not entry-level.

A field that advertises a talent famine while beginners starve outside the door has a serious education problem.

I wanted to tell my mechanic that his son should get started now, and not rely on “just a college degree” to get his foot in the door because he’ll need more than a battering ram to get through. I’d argue he’d need a powerful mentor, some kind of cyber god that would say the magic words to open the door.

“Give this kid a chance. He’s talented.”

The door’s welded shut for most newcomers

Start with the certs. They’re marketed as an ideal entry point. And Security+ deserves credit for adding performance-based simulation questions, but they’re a handful out of roughly 90 — you can still earn the industry’s default entry credential without ever administering a live network or triaging a real alert queue. The cert proves you studied. Employers want proof you can do. Newbies keep buying the first product thinking it’s the second.

Then they hit the listings. “Entry-level” roles routinely ask for two to three years of experience — some demand CISSP, a certification that literally requires five years of experience to hold.

The honest path is the one nobody advertises: help desk, IT support, network admin, especially if you don’t have a personal network handing you warm intros.

The bootcamps know this and sell around it. Barista to penetration tester, six figures, sixteen weeks. Reality: average tuition north of $10,000, entry salaries closer to $60,000–$75,000, and by the industry’s own numbers a fifth to a quarter of graduates don’t land a relevant role within six months — often because compressed programs skip the unsexy fundamentals like networking and OS internals that technical interviews are built on.

And there’s no trusted map. Everyone giving career advice has something to sell, degree programs lag the threat landscape by the length of an accreditation cycle, and while free labs like TryHackMe finally exist, a capture-the-flag is not a Tuesday in a SOC. Add the dirty secret — the field is sold as hacking when much of the actual work is GRC, ops, and paperwork — and nobody tells beginners which specializations are hiring versus saturated. They arrive expecting Mr. Robot, get a spreadsheet, and leave. Honesty at the start is cheaper than attrition at year two.

Continuing education is about attendance not learning

Once you’re in, the industry’s idea of continuing education is CPE credits — a system that rewards attendance, not learning. Webinar bingo in a background tab counts the same as building a detection lab. We measure hours, then act surprised the skills gap persists among the employed.

What training does exist mostly comes from vendors, and vendor training teaches the product, not the discipline. You learn where the buttons are in this year’s console; you don’t learn the craft that survives the next tooling swap. Meanwhile, certifications test yesterday’s threats, because attackers don’t wait for curriculum committees.

The mismatches pile up where it hurts. Cloud and identity are where the incidents live — and where ISC2’s own workforce study says the critical skill gaps are — yet training catalogs still tilt toward the on-prem world. AI security education is either breathless hype or nothing at all, with little practical middle. Advanced courses assume budgets most teams don’t have. Cross-training — detection people learning offense and vice versa — stays rare, so everyone deepens their silo.

And the human parts never make the syllabus: there’s no structured path from technical work to architecture or leadership, tabletop exercises are scripted theater rather than real pressure, and nobody teaches you to survive on-call, burnout, or a twenty-year career. We train practitioners like the job is technical. The job is technical for about a decade. Then it’s everything else.

Nobody will teach you how to be a CISO

The leadership education on offer is mostly generic MBA content with a cyber label — and it skips the one translation that decides the CISO’s fate: turning risk into the financial terms a board actually uses. Budget defense and business-case building get learned by trial and error, one bruising budget cycle at a time.

Then there’s the liability question, which the industry discusses in whispers and teaches nowhere. The facts are worth stating precisely, because they’ve moved: Uber’s former CSO Joe Sullivan was criminally convicted over the cover-up of a breach — obstruction and failure to report, not the breach itself. The SEC’s case against SolarWinds’ CISO, the one that terrified the profession, was dismissed with prejudice in late 2025. The lesson courts have actually drawn is that exposure follows concealment and misstatement, not getting hacked. That’s a teachable, career-saving distinction — and no program teaches it.

Nothing prepares a CISO for managing through a breach either, when legal, comms, and regulators all arrive at once. Nothing covers the political side — the turf wars with the CIO, legal, and audit that consume more of the job than any exploit. Metrics education pushes vanity numbers like “attacks blocked” over actual risk reduction. And succession is an afterthought; CISOs aren’t taught to build their replacements.

Where do security leaders actually learn all this? At dinners and roundtables, off the record, from peers who bled first. I’ve watched it happen — it’s the best education in the industry, and it’s completely informal. The most consequential security role in the company runs on an apprenticeship model nobody designed.

Executives and boards get an hour a year

At the top of the ladder, cyber education often shrinks to a one-hour annual briefing, treated as a compliance ritual. Directors come away with vocabulary, not judgment — they can say “ransomware,” but they can’t evaluate a CISO’s answer, and without a framework for what to ask, oversight defaults to “are we secure?” An unanswerable question, asked annually, satisfies no one and protects nothing.

The stakes stopped being theoretical. The SEC’s 2023 rules require public companies to disclose material cyber incidents within four business days of determining materiality, and to describe the board’s oversight of cyber risk in annual filings. That’s a demand for oversight competence no one has trained directors to have — and many boards discover their own crisis responsibilities mid-crisis, learning about incidents from headlines instead of structured post-mortems.

What education boards do get usually comes from vendors and insurers with something to sell. Cyber risk stays siloed instead of being taught alongside financial and legal risk. The fashionable fix — hiring one “cyber expert” director — becomes a checkbox that lets everyone else stay illiterate. And too many boards still believe risk transfer is accountability transfer. Insurance and outsourcing move dollars. They do not move responsibility. Nobody teaches that limit until the incident does.

 

Cyber education is hard to do right

Four audiences, one pattern: at every level, the formal education optimizes for what’s easy to sell and easy to measure — certificates, attendance, vocabulary — while the things that actually decide outcomes get learned by accident, at dinners, in incidents, or not at all.

We argue that the best cyber education in the industry is the informal kind — the panel discussion, the hands-on workshop, the peer who bled first — and that nobody has ever tried to make it systematic.

That’s the gap CyberEd.io was built around, and the entry point is the Security Insights Library.

  • It’s the panel discussion, on the record. The Library is drawn from sessions at ISMG’s global events — practitioners describing what actually happened, not instructors summarizing what’s supposed to happen. The conversation that used to require a seat at the table is now on demand.
  • It starts with insight, not enrollment. You don’t have to commit to a pathway or a certification track to get value on day one. Watch the session on the problem in front of you this week. That’s the whole ask.
  • It refreshes at the speed of the threat, not the accreditation cycle. New sessions land continuously, which is the only honest answer to the complaint that curricula test yesterday’s attacks.
  • It’s weighted where the incidents actually are. Cloud, identity, AI security, OT, incident response, GRC — the categories the workforce studies keep flagging as critical gaps, rather than the ones that are easiest to build a course around.
  • Insight is the on-ramp, not the destination. Where it leads is hands-on: skill pathways and cloud-based lab environments that turn a session you watched into something you can demonstrate. The article’s core complaint is that the industry sells the proof of study and calls it proof of skill. The point of starting with insight is to not stop there.

The cyber talent shortage was never a shortage of interested people. It’s a shortage of honest on-ramps, honest curricula, and honest conversations at every rung. The people are showing up. The education isn’t.

Learn more about CyberEd.io Security Insights

See the Courses

Related Content