London Daily

Focus on the big picture.
Monday, Jun 29, 2026

Wanted: Millions of cybersecurity pros. Rate: Whatever you want

Wanted: Millions of cybersecurity pros. Rate: Whatever you want

A series of major digital security breaches over the past year are serving as a wake-up call to Corporate America about the need to invest in cybersecurity.

Friday brought yet another reminder of the risk of cyberattacks, when Microsoft (MSFT) said the hackers behind the 2020 Solar Winds breach launched a new attack on more than 150 government agencies, think tanks and other organizations globally.

But perhaps the most striking recent example is the Colonial Pipeline ransomware attack, which forced the company to shut down the pipeline temporarily - resulting in gas shortages and price spikes in multiple states over several days. The debacle cost Colonial at least $4.4 million, the amount its CEO admitted to paying the hackers.

In the weeks before the attack, the company had posted a job listing for a cybersecurity manager.

"As far as I know, this is the first cybersecurity incident that has led to a measurable economic impact on the American population," said Jonathan Reiber, senior director for cybersecurity and policy at AttackIQ and the chief strategy officer for cyber policy under the Obama administration's secretary of defense.

"It should be something that triggers people," he said.

The takeaway from such security breaches, according to experts, is that it's high time for companies to start investing in robust controls and, in particular, adding cybersecurity professionals to their teams.

The only hitch: There's a massive, longstanding labor shortage in the cybersecurity industry.

"It's a talent war," said Bryan Orme, principal at GuidePoint Security. "There's a shortage of supply and increased demand."

Millions of unfilled jobs


Experts have been tracking the cybersecurity labor shortage for at least a decade — and now, a new surge in companies looking to hire following recent attacks could exacerbate the problem.

The stakes are only growing, as technology evolves and bad actors become more advanced.

In the United States, there are around 879,000 cybersecurity professionals in the workforce and an unfilled need for another 359,000 workers, according to a 2020 survey by (ISC)2, an international nonprofit that offers cybersecurity training and certification programs.

Globally, the gap is even larger at nearly 3.12 million unfilled positions, the group says. Its CEO, Clar Rosso, said she thinks the need may actually be higher, given that some companies put off hiring during the pandemic.

The needs range from entry-level security analysts, who monitor network traffic to identify potential bad actors in a system, to executive-level leaders who can articulate to CEOs and board directors the potential financial and reputational risks from cyber attacks.

The US Bureau of Labor Statistics projects "information security analyst" will be the 10th fastest growing occupation over the next decade, with an employment growth rate of 31% compared to the 4% average growth rate for all occupations.

If demand for cybersecurity professionals in the private sector increases dramatically, some experts say talented workers could leave the government for more lucrative corporate jobs — a risk that is especially acute for smaller, local government agencies that manage critical infrastructure in their communities but have limited budgets.

"Think of the criticality of what your local government does: water purification, waste treatment, traffic management, communications for law enforcement, public safety, emergency management," said Mike Hamilton, chief information security officer at Critical Insight. "But Amazon is out there waving around bags of cash to protect their retail operation."

Hamilton — who was the former chief information security officer for Seattle, Washington, from 2006 to 2013 — added that local governments "cannot attract and retain these people when the competition for them is so high, which is why we've got to make lots of them."

'Not a short term solution'


A variety of education, training and up-skilling programs are already working to address the shortage.

GuidePoint helps train veterans leaving the military for cybersecurity careers. And Critical Insight's Hamilton runs a nonprofit called Public Infrastructure Security Cyber Education Systems, through which students at five universities get hands-on experience by doing security monitoring of real-time data on local government networks, providing a crucial service for small cities and counties that might not otherwise be able to afford it.

Experts say there's also an opportunity to bring new talent into the industry by focusing on diversity. Just 25% of cybersecurity professionals are women, so (ISC)2 launched a diversity, equity and inclusion program this year aimed at recruiting and keeping more women in the profession, Rosso said.

"We need to recognize that there is this huge diversity of people that can actually do ... this job very well," Hamilton said, referring to security analysts who monitor traffic on a network to look for behavior that might indicate a bad actor has accessed the system. "As a country, we are not taking very good advantage of the resources that we have."

In the meantime, as the industry works to grow its labor force, it could be a huge opportunity for service and software provider companies that can help firms beef up their cybersecurity protocols without hiring their own teams.

Because even with existing training programs, the global cybersecurity labor gap is expected to grow by 20% to 30% annually over the next several years, (ISC)2's Rosso said. Experts say both the public and private sectors must invest more in growing the industry's workforce.

Portions of President Joe Biden's $2 trillion American Jobs Plan could help. The infrastructure proposal includes $20 billion for state, local and tribal governments to update and improve cybersecurity controls for their energy systems.

Still, experts say more needs to be done, suggesting a broad rethinking of education systems from elementary school through higher education to include more cybersecurity training.

"Sadly, there's not a short-term solution," GuidePoint's Orme said. "I think we need to take a long-term view of it — as a lot of our adversaries do — to say, how can we systematically build the next generation and the generation after that and create a flywheel of qualified security talent that will be entering the workforce over the next 50 to 100 years?"

Newsletter

Related Articles

0:00
0:00
Close
UK Launches New Measures to Improve Safety Standards in Night-Time Venues
UK Tightens Import Rules for Low-Value Parcels to Support Domestic Retailers
UK Launches £85 Million Obesity Care Programme Targeting Early Intervention Projects
UK Commits Up to $26 Million to Ebola Response in Democratic Republic of Congo
Security Industry Authority Flags Safety Failures in Night-Time Economy Inspections
Cambridge South Railway Station Opens After £250 Million Investment
UK Moves to Close Import Duty Loophole for Small Parcels by 2028
UK Invests £85 Million in Projects to Transform Obesity Care
Berkeley Group Warns London Housebuilding Falling Far Short of Demand
UK Council Tax Arrears Rise to £9.3 Billion Amid Ongoing Household Financial Strain
Markets Watch Political Transition as Andy Burnham Emerges as Labour Leadership Frontrunner
Extreme Heat Raises Long-Term Risks for UK Inflation and Productivity, Analysts Warn
UK Health Alerts Extended as Record June Heatwave Grips England
UK Parliament Faces High-Stakes Week of Spending, Security and Industrial Legislation
UK Repeals Vagrancy Act Ending Criminalisation of Rough Sleeping in England and Wales
GB News Pundit Charged With Fraud Over Alleged Conduct as Former Labour Adviser
Reform UK Gains Parliamentary Visibility in First Senedd Opposition Appearance
Metropolitan Police Arrest Man on Suspicion of Attempted Murder After London Car Incident
Ocado Chief Executive Tim Steiner Faces Scrutiny Over £100 Million Remuneration Package
British Chambers of Commerce Downgrades UK Growth Outlook to 0.9 Percent for 2026
Nottingham University Hospitals Maternity Failings Trigger Renewed Calls for Public Inquiry
Severe Heatwave Disrupts UK Transport Networks and Strains Public Services Across England
Labour Leadership Transition Raises Prospect of Andy Burnham Becoming UK Prime Minister
UK Government Confirms Further Medicine Price Concessions for Community Pharmacies in June
British Chambers of Commerce Calls for Public Procurement Reform to Boost Regional Growth
Thousands Mark Armed Forces Day Across the United Kingdom With National Parades and Flypasts
Man Arrested in Ealing on Suspicion of Attempted Murder After Vehicle Ramming Incident Injures Five
Cambridge South Station Opens With £250 Million Investment to Strengthen Life Sciences Corridor
UK Heat-Health Alerts Extended Across England as High Temperatures Persist
Thames Water and Energy Operators Warn of Peak Demand Risks During UK Heatwave
Government Conference Highlights Push for Evidence-Led Policy Across UK Public Sector
Insolvency Service Reports Improved Confidence in UK Insolvency System
Security Industry Authority Finds Widespread Safety Failures in UK Night-Time Economy
Nigel Farage Expands Anti-WHO Campaign Into United States With New Lobbying Structure
Home Secretary Seema Mahmood Unveils New Safe Routes Plan for Asylum Seekers
UK Government Warns of Peak Electricity and Water Pressure Amid Ongoing Heatwave
New Nuclear Plant in Wales Named Gwyndod Power Station as Energy Strategy Advances
UK Announces First Major Hydropower Projects in Four Decades to Expand Renewable Capacity
Thirteen Men Charged in Major UK Sexual Abuse Case as Investigation Continues
UK Launches Cross-Sector Climate Security Taskforce Linking Environment and National Security
UN Secretary-General António Guterres Calls for Urgent Global Methane Emissions Cuts in London
World Bank Approves $1 Billion UK-Backed Financing Package for Ukraine Recovery
UK Pledges Emergency Aid and Rescue Team Deployment to Earthquake-Hit Venezuela
Bank of England Holds Interest Rates at 3.75 Percent for Fourth Straight Meeting
Record-Breaking Heatwave Puts Strain on UK Health Services and Energy Networks
London Ambulance Service Sees Record Emergency Demand as Heatwave Intensifies
British Chambers of Commerce Warns of Prolonged Weak Investment Climate Through 2027
Bank of England Holds Interest Rates as Inflation Risks Persist
UK Construction Sector Faces One Percent Contraction Amid Cost and Investment Pressures
Former DUP Leader Sir Jeffrey Donaldson Convicted of Sexual Offences
×