For years, we’ve heard the same warning:
Cybersecurity has a skills shortage.
So we’ve responded by encouraging more people into the industry.
More courses.
More certifications.
More bootcamps.
More degrees.
More career-change programmes.
And yet employers continue to say they struggle to find the cybersecurity capability they need.
That should make us question something.
Perhaps the problem isn’t simply that too few people want to work in cybersecurity.
There are already thousands of people studying cybersecurity, earning certifications and trying to enter the profession.
Perhaps there’s another gap hiding underneath the skills gap.
The gap between learning cybersecurity and being able to demonstrate that you can apply it.
I believe that’s where we need to focus next.
What is the cybersecurity skills gap?
The cybersecurity skills gap is generally understood as the difference between the cybersecurity capabilities organisations need and the skills available within the workforce.
But that definition can lead us towards a very simple conclusion:
We need more cybersecurity people.
I think the reality is more complicated.
An organisation doesn’t simply need another person with “cybersecurity” written on their CV.
It may need someone who can assess third-party risk.
Respond to incidents.
Interpret regulatory requirements.
Analyse vulnerabilities.
Secure cloud infrastructure.
Challenge weak controls.
Communicate risk to executives.
Or understand how cybersecurity supports a wider commercial objective.
Those are capabilities.
And producing more people with cybersecurity qualifications doesn’t automatically produce more people capable of doing those things.
We may have an experience gap
This is where the familiar cybersecurity career problem appears.
Employers want experience.
Candidates need employers to give them experience.
Neither side is necessarily wrong.
An employer protecting sensitive systems cannot simply lower its standards because somebody needs their first opportunity.
But telling aspiring professionals to “get experience” without creating meaningful ways for them to develop it isn’t much of a solution either.
We’ve created a loop:
Learn → Certify → Apply → Rejected for lack of experience → Learn something else → Certify again.
And eventually some people conclude that another qualification must be the answer.
Sometimes it is.
Sometimes it isn’t.
The missing ingredient may be application.
Certification and capability aren’t the same thing
I want to be careful here.
This isn’t an argument against certifications.
Cybersecurity certifications can provide structure, validate knowledge and help professionals understand important concepts.
But passing an exam answers one question:
What have you learned?
Employers frequently need the answer to another:
What can you do with what you’ve learned?
Can you work through an unfamiliar scenario?
Can you identify the important risk amongst ten less important ones?
Can you explain why a control matters?
Can you produce useful documentation?
Can you challenge somebody more senior than you appropriately?
Can you communicate a technical issue to someone who isn’t technical?
Can you make a recommendation when the answer isn’t obvious?
Those capabilities are harder to measure.
They’re also difficult to develop exclusively through theory.
The industry may also have a translation gap
There’s another part of the skills conversation that I think we underestimate.
Some of the capability cybersecurity needs already exists outside cybersecurity.
Consider someone who has spent 12 years in procurement.
They may understand suppliers, contracts, negotiation, due diligence, commercial risk and stakeholder management.
Those capabilities don’t become irrelevant when they enter third-party cybersecurity risk.
An auditor understands evidence and controls.
A finance professional understands risk and governance.
A project manager understands delivery and competing priorities.
An operations professional understands how businesses actually function.
A teacher may have exceptional communication skills.
Yet we often assess career changers primarily by asking:
“How many years of cybersecurity experience do you have?”
That’s understandable.
But it can also prevent us from seeing the wider capability standing in front of us.
Being new to cybersecurity isn’t always the same as being new to professional work.
Perhaps part of the cybersecurity skills gap is actually a skills translation gap.
We need better bridges into cybersecurity
If we accept that, the solution becomes different.
We still need education.
We still need certifications.
We still need technical development.
But we also need stronger bridges between:
Education → Application → Evidence → Employment
That might include practical projects.
Realistic business scenarios.
Mentoring from industry professionals.
Internships.
Apprenticeships.
Employer-led projects.
Portfolio evidence.
Workplace simulations.
University-industry partnerships.
Structured opportunities for career changers to apply transferable capabilities in a cybersecurity context.
This is where employers, universities, training providers and industry professionals all have a role.
Because cyber talent isn’t simply found ready-made.
It has to be developed.
Employers have a role too
We can’t have a serious conversation about the cybersecurity skills gap without talking about hiring.
Look at some “entry-level” cybersecurity vacancies and you’ll find requirements that don’t always feel particularly entry-level.
Multiple certifications.
Several years’ experience.
Knowledge across numerous technologies.
Industry-specific experience.
Strong communication.
Technical depth.
Commercial awareness.
Sometimes security clearance.
And then we wonder why the entry pipeline struggles.
I’m not suggesting organisations should reduce legitimate requirements.
Security is too important for that.
I’m suggesting we become much clearer about the difference between:
Essential on day one
and
Capable of being developed.
That distinction could unlock talent we’re currently overlooking.
Universities and training providers have a role
Education cannot end at knowledge acquisition either.
We should increasingly ask:
What can someone demonstrate at the end of this programme that they couldn’t demonstrate at the beginning?
Not simply:
How many modules did they complete?
How many hours did they attend?
Which certificate did they receive?
But:
What did they build?
What problems did they solve?
What evidence did they produce?
How did they apply their knowledge?
How has their professional judgement developed?
That’s a much harder standard.
But I think it’s closer to what the labour market actually needs.
It’s also a significant part of the philosophy behind Lateral Connect.
Frequently Asked Questions
Is there really a cybersecurity skills shortage?
- There is significant demand for cybersecurity capability, but describing the challenge purely as a shortage of people can oversimplify it. Organisations may struggle to find particular combinations of technical knowledge, practical experience, business understanding and professional skills.
Why do entry-level cybersecurity candidates struggle to get jobs?
- One factor is the gap between acquiring cybersecurity knowledge and demonstrating workplace capability. Employers may require practical evidence and experience that new entrants have had limited opportunities to develop.
Are cybersecurity certifications still worth it?
- Yes, when they support a defined career objective. The problem arises when certifications become substitutes for practical development rather than part of it.
How can organisations help close the cybersecurity skills gap?
- Organisations can create clearer entry pathways, support internships and practical projects, work with education providers, mentor emerging professionals and distinguish between capabilities required immediately and those that can be developed.
Perhaps we’re solving the wrong shortage
The cybersecurity skills gap is real.
But I don’t think we’ll solve it simply by convincing more people to study cybersecurity.
We need to get better at what happens after they learn.
How do they apply it?
How do they prove it?
How do employers recognise transferable capability?
How do people get meaningful experience before somebody gives them their first cybersecurity job?
And how do education and industry work together rather than standing at opposite ends of the pipeline?
Those questions are harder than:
“How do we get more people into cyber?”
But they may be much more important.
Because the future of cybersecurity doesn’t depend only on attracting talent.
It depends on our ability to recognise it, develop it, prove it and create pathways for it to succeed.
Cyber talent isn’t simply found. It’s built.
And building it should be a shared responsibility.
Let’s build better cybersecurity pathways
I’m Victoria Coker, Founder of Lateral Connect. We work to bridge the space between cybersecurity learning and professional capability through practical development, mentoring, leadership and meaningful career pathways.
For professionals: If you’ve been learning cybersecurity but still don’t know how to turn that knowledge and your previous experience into a credible career pathway, speak to us about our 5-Week Accelerator or 5-Month Lateral Connect Programme.
For organisations, universities and delivery partners: If you’re developing cybersecurity talent, improving employability or looking to create stronger pathways between learning and the workplace, I’d like to explore what we could build together.
The cybersecurity skills gap won’t be solved by one organisation. But it can be solved differently.
Responses