London Daily

Focus on the big picture.
Saturday, Mar 07, 2026

Wanted: Millions of cybersecurity pros. Rate: Whatever you want

Wanted: Millions of cybersecurity pros. Rate: Whatever you want

A series of major digital security breaches over the past year are serving as a wake-up call to Corporate America about the need to invest in cybersecurity.

Friday brought yet another reminder of the risk of cyberattacks, when Microsoft (MSFT) said the hackers behind the 2020 Solar Winds breach launched a new attack on more than 150 government agencies, think tanks and other organizations globally.

But perhaps the most striking recent example is the Colonial Pipeline ransomware attack, which forced the company to shut down the pipeline temporarily - resulting in gas shortages and price spikes in multiple states over several days. The debacle cost Colonial at least $4.4 million, the amount its CEO admitted to paying the hackers.

In the weeks before the attack, the company had posted a job listing for a cybersecurity manager.

"As far as I know, this is the first cybersecurity incident that has led to a measurable economic impact on the American population," said Jonathan Reiber, senior director for cybersecurity and policy at AttackIQ and the chief strategy officer for cyber policy under the Obama administration's secretary of defense.

"It should be something that triggers people," he said.

The takeaway from such security breaches, according to experts, is that it's high time for companies to start investing in robust controls and, in particular, adding cybersecurity professionals to their teams.

The only hitch: There's a massive, longstanding labor shortage in the cybersecurity industry.

"It's a talent war," said Bryan Orme, principal at GuidePoint Security. "There's a shortage of supply and increased demand."

Millions of unfilled jobs


Experts have been tracking the cybersecurity labor shortage for at least a decade — and now, a new surge in companies looking to hire following recent attacks could exacerbate the problem.

The stakes are only growing, as technology evolves and bad actors become more advanced.

In the United States, there are around 879,000 cybersecurity professionals in the workforce and an unfilled need for another 359,000 workers, according to a 2020 survey by (ISC)2, an international nonprofit that offers cybersecurity training and certification programs.

Globally, the gap is even larger at nearly 3.12 million unfilled positions, the group says. Its CEO, Clar Rosso, said she thinks the need may actually be higher, given that some companies put off hiring during the pandemic.

The needs range from entry-level security analysts, who monitor network traffic to identify potential bad actors in a system, to executive-level leaders who can articulate to CEOs and board directors the potential financial and reputational risks from cyber attacks.

The US Bureau of Labor Statistics projects "information security analyst" will be the 10th fastest growing occupation over the next decade, with an employment growth rate of 31% compared to the 4% average growth rate for all occupations.

If demand for cybersecurity professionals in the private sector increases dramatically, some experts say talented workers could leave the government for more lucrative corporate jobs — a risk that is especially acute for smaller, local government agencies that manage critical infrastructure in their communities but have limited budgets.

"Think of the criticality of what your local government does: water purification, waste treatment, traffic management, communications for law enforcement, public safety, emergency management," said Mike Hamilton, chief information security officer at Critical Insight. "But Amazon is out there waving around bags of cash to protect their retail operation."

Hamilton — who was the former chief information security officer for Seattle, Washington, from 2006 to 2013 — added that local governments "cannot attract and retain these people when the competition for them is so high, which is why we've got to make lots of them."

'Not a short term solution'


A variety of education, training and up-skilling programs are already working to address the shortage.

GuidePoint helps train veterans leaving the military for cybersecurity careers. And Critical Insight's Hamilton runs a nonprofit called Public Infrastructure Security Cyber Education Systems, through which students at five universities get hands-on experience by doing security monitoring of real-time data on local government networks, providing a crucial service for small cities and counties that might not otherwise be able to afford it.

Experts say there's also an opportunity to bring new talent into the industry by focusing on diversity. Just 25% of cybersecurity professionals are women, so (ISC)2 launched a diversity, equity and inclusion program this year aimed at recruiting and keeping more women in the profession, Rosso said.

"We need to recognize that there is this huge diversity of people that can actually do ... this job very well," Hamilton said, referring to security analysts who monitor traffic on a network to look for behavior that might indicate a bad actor has accessed the system. "As a country, we are not taking very good advantage of the resources that we have."

In the meantime, as the industry works to grow its labor force, it could be a huge opportunity for service and software provider companies that can help firms beef up their cybersecurity protocols without hiring their own teams.

Because even with existing training programs, the global cybersecurity labor gap is expected to grow by 20% to 30% annually over the next several years, (ISC)2's Rosso said. Experts say both the public and private sectors must invest more in growing the industry's workforce.

Portions of President Joe Biden's $2 trillion American Jobs Plan could help. The infrastructure proposal includes $20 billion for state, local and tribal governments to update and improve cybersecurity controls for their energy systems.

Still, experts say more needs to be done, suggesting a broad rethinking of education systems from elementary school through higher education to include more cybersecurity training.

"Sadly, there's not a short-term solution," GuidePoint's Orme said. "I think we need to take a long-term view of it — as a lot of our adversaries do — to say, how can we systematically build the next generation and the generation after that and create a flywheel of qualified security talent that will be entering the workforce over the next 50 to 100 years?"

Newsletter

Related Articles

0:00
0:00
Close
Starmer Defends UK Role in Iran Conflict After Renewed Criticism from President Trump
Blue Owl Reveals £36 Million Exposure After Collapse of UK Lender Serving Wealthy Clients
UK Asylum Reform Plan Triggers Fierce Debate Over Border Control and Humanitarian Impact
US Stealth Bombers Head to UK Base as Trump Issues Stark Warning to Iran
UK Deputy Prime Minister Says Legal Case Could Exist for British Strikes on Iranian Missile Sites
Investigators Link Mysterious Parcel Fires Across Europe to Russian Intelligence Operation
Debate Intensifies Over Britain’s Legal Justification for US Military Operations Launched From UK Bases
Britain Faces Heightened Energy Price Risks as Iran-Linked Tensions Threaten Global Oil and Gas Supplies
British Counter-Terror Police Arrest Four Suspected of Spying on Jewish Community for Iran
Axel Springer Agrees $770 Million Deal to Acquire Britain’s Daily Telegraph
Iceland Supermarket Drops Trademark Challenge Against Icelandic Government in Long-Running Naming Dispute
UK Defence Secretary Visits Cyprus Following Scrutiny of Britain’s Response to Drone Attacks
Questions Grow Over Britain’s Military Readiness as Response to Iran Conflict Draws Scrutiny
UK Offers Failed Asylum Seeker Families Up to Forty Thousand Pounds to Leave Voluntarily
Saharan Dust Could Bring ‘Blood Rain’ to Parts of the UK as Weather Systems Shift
UK Deploys Additional Typhoon Fighter Jets to Qatar and Helicopters to Cyprus Amid Rising Middle East Tensions
Experts Urge Britain to Accelerate Renewable Energy Push as Global Conflicts Drive Up Costs
British Public Shows Strong Reluctance to Join Wider War in Iran
First UK Evacuation Flight Departs Middle East After Lengthy Delay
United Kingdom Imposes New Visa Requirements on Travelers from St. Lucia and Nicaragua
Iran Conflict Strains U.S.–U.K. Alliance as Trump and Starmer Clash Over Military Strategy
UK Interest Rates Could Rise Above Four Percent Again if Energy Shock Continues, Think Tank Warns
Starmer Defends Britain’s Iran Strategy as Badenoch Urges Stronger Military Support
Labour MP Says She Saw No Sign Husband Broke Law After Arrest in China Espionage Investigation
UK Jobless Rate Overtakes Italy’s for First Time in Years as Labour Market Weakens
United Kingdom Suspends Student Visas for Four Countries in Unprecedented Immigration Move
Campaigners Warn UK Student Visa Ban Could Push Migrants Toward Dangerous Channel Crossings
First U.K. Charter Flight for Stranded Nationals Set to Depart Oman Amid Middle East Crisis
France and United Kingdom Deploy Warships to Eastern Mediterranean as Middle East Conflict Escalates
U.K. Arrests Three Men Including Lawmaker’s Partner in Suspected China Espionage Investigation
Trump Says UK–US ‘Special Relationship’ Is Diminished Amid Middle East Dispute
UK Economic Forecasts Face Fresh Strain from Middle East Conflict and Rising Energy Costs
UK Reaffirms Close US Ties After Trump’s Public Criticism
Reeves Stresses Stability and Fiscal Discipline in UK Budget Update as Growth Outlook Shifts
UK Deploys Royal Navy Destroyer HMS Dragon to Cyprus After Drone Strike on RAF Base
Green Party Surges Past Labour in New UK Poll as Traditional Party Support Crumbles
Majority of Britons Oppose U.S. Use of UK Military Bases in Iran Conflict
UK Intensifies Evacuation Efforts from Oman, Working with Airlines to Boost Flight Capacity
Trump Condemns UK and Spain in Unusually Sharp Rift Over Iran Military Action
Trump Repeats UK Claims That Diverge from Verified Facts Amid Diplomatic Strain
UK Arrests Prominent Figures Linked to Epstein Network as Questions Mount Over US Action
Trump Says UK ‘Took Far Too Long’ to Approve Use of Airbases for Iran Strikes
Scope of Britain’s Role in the Expanding Middle East Conflict Comes Under Scrutiny
Trump Says He Is ‘Very Disappointed’ in Starmer Over Iran Comments
U.S. Embassy in Riyadh Struck by Drones Amid Escalating Iran Conflict
Starmer Confronts Strategic Test After Drone Strike Near British Base in Cyprus
Rolls-Royce Chief Signals Openness to Germany Joining UK-Led Fighter Jet Programme
UK Stocks Slip as Escalating Iran Conflict Triggers Global Market Selloff
UK Overhauls Asylum System to Make Refugee Status Temporary
Starmer Warns of ‘Reckless’ Iranian Strikes Amid Escalating Regional Tensions
×