The cybersecurity skills gap isn’t a hiring problem

The cybersecurity talent shortage remains a major challenge in the United States. The number of professionals has not kept pace with demand, and while AI is helping close some gaps, organizations still need skilled people. Despite years of hiring efforts, the problem continues to worsen.

The numbers are stark. The global cybersecurity workforce gap has reached 4.8 million unfilled roles, a 19 percent year-over-year increase, according to the ISC2 2025 Cybersecurity Workforce Study. Workforce growth has nearly stalled, increasing just 0.1% since 2023. More telling, 95 percent of respondents reported at least one critical skill need, leading ISC2 to conclude that skills shortages now outweigh headcount shortages as the primary issue.

Organizations with understaffed security teams pay a measurable price. According to IBM, they incur an average of $1.76 million more per data breach than organizations with adequate staffing. For MSPs attempting to build SOCs and help desks in this environment, the challenge is significant.

The problem goes beyond recruitment

Andrew Curtis, founder and CEO of CiBRAI and Gadget Access, brings more than 20 years of experience as a CISO, vCISO, and security architect. He has worked across government, law enforcement, intelligence, critical infrastructure, and enterprise environments. Throughout his career, he has led cyber uplift programs, worked with large security operations teams, and built managed security models for organizations that cannot maintain every specialist capability in-house.

Curtis sees the cybersecurity talent shortage as a broader ecosystem issue.

“My view is that the cybersecurity talent shortage is not simply a recruitment problem. It is also a workforce-design, retention, and operating-model problem,” Curtis said.

He noted that many MSPs advertise entry-level SOC positions while expecting expertise in cloud, identity, networking, endpoint security, SIEM, incident response, compliance, and customer communication. “They are effectively searching for experienced security leaders at junior analyst prices,” Curtis said.

He argues that the profession needs a new approach. “MSPs cannot recruit their way out of that problem. They need to redesign how security work is divided, create pathways into the profession, and use automation to increase the effectiveness of the people they already have,” Curtis said.

Building talent from within

According to Curtis, MSPs may already have their strongest talent pipeline inside their organizations.

“Help-desk, network, systems, and cloud engineers often understand customer environments better than an external cybersecurity candidate,” Curtis said.

With structured training in investigation, identity, endpoint telemetry, incident handling, and risk management, these employees can move into security roles while retaining valuable operational knowledge.

Curtis recommends creating clear career paths from service desk and infrastructure positions into SOC analysis, engineering, threat hunting, incident response, and security leadership. “MSPs should define a visible career pathway from service desk and infrastructure roles into SOC analysis, engineering, threat hunting, incident response, and security leadership,” Curtis said.

He also believes training should be tied to supervised work rather than treated as a checklist of certifications. “A junior analyst learns far more by investigating real cases with an experienced mentor than by completing another generic online course,” Curtis said.

Curtis supports partnerships with universities, vocational institutions, veterans’ programs, and professional associations. However, he believes MSPs must prioritize aptitude over experience in many hiring decisions.

“Curiosity, careful reasoning, communication, and the willingness to document decisions are often better predictors of success than a long list of security products on a résumé,” Curtis said.

Retention matters as much as hiring

Hiring talent is only part of the challenge. Keeping employees is equally important. “Retention deserves as much attention as recruitment. Analysts leave when they face relentless alert queues, poor shift design, weak mentoring, and no clear path forward. Increasing salaries may delay departures, but they do not fix an operating model that burns people out,” Curtis said.

Curtis believes AI-assisted workflows can help address some of these pressures. AI can enrich alerts, correlate events, remove duplicates, gather threat intelligence, draft case notes, recommend playbooks, and assemble evidence for review.

“That allows analysts to spend more time understanding what happened and deciding what should happen next,” Curtis said.

At the same time, he cautions against using AI solely to reduce headcount or eliminate entry-level positions.

“If AI performs every Tier 1 task, the industry needs to answer an uncomfortable question: where will the Tier 3 analysts come from in five years?” Curtis said.

Balancing AI, people, and partnerships

Curtis advocates for a human-plus-AI model rather than an AI-only approach.

“AI performs repetitive, high-volume analysis and explains how it reached its recommendation. Junior analysts review the evidence and learn from the process,” Curtis said.

He believes experienced analysts should focus on customer context, ambiguity, escalation management, and high-impact decisions.

“Humans remain accountable for actions that could interrupt a customer’s business,” Curtis said.

He also encourages MSPs to be realistic about which security capabilities must remain internal.

“A provider does not need permanent employees covering every specialist discipline around the clock,” Curtis said.

Capabilities such as digital forensics, malware analysis, red teaming, legal response, and specialized threat intelligence can often be sourced through trusted partners.

“The MSP should retain customer accountability and incident command while using partners for capabilities that are difficult to recruit and maintain,” Curtis said.

His recommendation is straightforward:

“Stop searching for finished cybersecurity professionals and start building them. The MSPs that solve the talent shortage will be the ones that turn their existing technical people into security practitioners, give junior staff meaningful supervised experience, and use AI to remove drudgery rather than remove human judgment.”

Next week, we’ll explore additional steps MSPs can take to address the cybersecurity talent shortage.

Photo: Ink Drop / Shutterstock

This post originally appeared on Smarter MSP.