TL;DR
- The cyber security skills shortage is structural, not cyclical. ISC2 put the global workforce gap at 4.8 million professionals in 2024, a 19% year-on-year increase, and in the UK, DSIT’s 2025 labour market reportshows 49% of businesses have a basic cyber security skills gap and 48% have an incident response skills gap, up from 27% in 2020.
- Hiring more people doesn’t fix a shortage this size, and it’s compounded by burnout: up to 70% of cyber security professionals report burnout globally, and nearly half of security leaders were projected to change jobs, roughly a quarter of those leaving the profession entirely.
- The answer isn’t a bigger team, it’s a resilient one: overlapping capabilities instead of single points of failure, and a deliberate mix of in-house and outsourced coverage so the loss of one person doesn’t become a coverage gap.
The Shortage by the Numbers
This isn’t a perception problem, it shows up consistently across every serious data source, global, UK and NZ:
| Source | Finding |
| ISC2, 2024 Workforce Study | Global cyber security workforce gap of 4.8 million professionals, up 19% year on year |
| DSIT, Cyber Security Skills in the UK Labour Market 2025 | 49% of UK businesses have a basic cyber security skills gap; 30% have an advanced skills gap |
| DSIT, same report | 48% of UK businesses report an incident response skills gap, up from 27% in 2020 |
| ISC2 vs DSIT workforce gap estimates | DSIT estimates a UK annual workforce gap of 3,800; ISC2’s methodology puts it at roughly 93,000 |
| NZ market data, 2026 | Nationwide shortage of around 3,500 cyber security professionals; open IT and security roles up roughly 80% year on year |
Worth flagging plainly: DSIT and ISC2 use different methodologies and land on very different UK figures. That gap between official and independent estimates is itself a useful signal, however you measure it, the shortage in specialist areas like incident response, cloud security and security architecture isn’t closing.
Why Hiring Your Way Out Doesn’t Work
Even organisations with the budget to compete on salary run into a harder constraint: burnout is thinning the pool faster than training programmes can refill it. Globally, up to 70% of cyber security professionals report experiencing burnout, driven by relentless workloads, constant incident response, and, increasingly, AI oversight added on top of existing responsibilities without any increase in capacity.
We covered the analyst-level version of this in our piece on alert fatigue, where 71% of SOC analysts report burnout and roughly 28% leave annually in a role people already only stay in for three to five years. The leadership-level version is just as stark: nearly half of security leaders were projected to change jobs, with around a quarter leaving the profession for something else entirely, workplace stressors, not better offers elsewhere in the field, being the driver.
Our take: every organisation currently trying to solve its skills gap purely through recruitment is competing for the same shrinking, increasingly burned-out pool as everyone else, and in New Zealand specifically, also competing against remote roles in Sydney, London and Singapore offering higher pay for the same skillset.
Building a Resilient Team Without Overhiring
If the talent isn’t reliably available to hire, the practical response is to design a team, and a security programme, that doesn’t depend on any single person being available. That means:
- Overlapping capabilities, not single points of failure: more than one person (or a managed partner) able to cover incident response, patching, and access reviews, so one resignation doesn’t create a coverage gap.
- Treating AI governance and emerging risk areas as a shared system, not a dedicated headcount line, spreading the responsibility across security, legal, IT and compliance rather than waiting to hire a specialist who may not exist in your market.
- A deliberate build/outsource split, running the functions that benefit from institutional knowledge in-house, and outsourcing the functions that require 24/7 specialist coverage, exactly the calculus we set out in our SOC build, buy or outsource piece.
- Investing in upskilling existing IT and network staff into security-adjacent roles, rather than only recruiting fully-formed specialists externally, widens the usable talent pool considerably.
- Documented, repeatable processes for the highest-risk functions, so institutional knowledge survives a departure instead of walking out the door with the person who held it.
None of this is about doing less. It’s about not structuring a security programme so that its resilience depends entirely on retaining a small number of specific people in a market that can’t reliably supply their replacements.
What We’re Seeing in Practice
What we’re seeing with UK and NZ clients working through this:
- The organisations coping best aren’t the ones with the biggest security headcount, they’re the ones who’ve already split coverage between in-house institutional knowledge and an outsourced or managed layer for specialist, round-the-clock functions.
- A single departure at a small in-house team is still the most common trigger for a client coming to us, usually a lone security lead or senior analyst leaving with no documented handover and no second person who understood the environment.
- Upskilling existing IT staff into security-adjacent roles is working well for clients who start early, waiting until a vacancy is urgent leaves no time to build that capability internally.
UK & New Zealand Perspective
The shape of the shortage differs slightly by market:
- UK: DSIT’s own figures show the skills gap widening in specific areas, incident response skills gaps nearly doubled since 2020, even as the overall workforce has grown, the problem is depth and specialism, not headline numbers.
- NZ: a market of five million people means the candidate pool is inherently smaller, and geographic isolation makes it harder to draw from talent clusters the way Sydney, London or Singapore can, remote work has made losing people to better-paid offshore roles a live risk, not just a hiring inconvenience.
ITogether’s Independent Verdict
The cyber security skills shortage isn’t a temporary hiring market blip, it’s structural, and every credible data source, ISC2, DSIT, and NZ’s own labour market signals, agrees on that even where they disagree on the exact numbers. Planning a security team around eventually hiring your way out of it is planning around a fix that consistently doesn’t arrive.
The organisations managing this well have stopped treating team resilience as a headcount problem. They’ve built overlapping coverage, a deliberate mix of in-house and outsourced capability, and documented processes that don’t depend on any one person, which is a more durable strategy than competing indefinitely for a shrinking, increasingly burned-out talent pool.
👉 Curious how a resilient in-house and outsourced mix could look for your team? Get in touch.
📞 UK +44 (0) 113 341 0123
📞 NZ +64 (0)9 802 2444
📧 hello@itogether.com
FAQs
How Big Is the Cyber Security Skills Shortage Really?
ISC2 puts the global workforce gap at 4.8 million professionals as of 2024. In the UK, DSIT’s 2025 labour market report shows 49% of businesses have a basic cyber security skills gap and 48% have an incident response skills gap specifically, up sharply from 27% in 2020. New Zealand faces a shortage of around 3,500 cyber security professionals against strong demand growth.
Why Can’t Organisations Just Hire More Security Staff?
The available pool is shrinking as fast as demand grows, and burnout is accelerating that: up to 70% of cyber security professionals report burnout, and nearly half of security leaders were projected to change jobs, with roughly a quarter leaving the profession entirely.
What Does a Resilient Security Team Structure Actually Look Like?
Overlapping capability rather than single points of failure, a deliberate split between in-house institutional knowledge and outsourced specialist or 24/7 coverage, documented processes that survive a departure, and upskilling existing IT staff into security-adjacent roles rather than relying solely on external specialist hires.
Is Outsourcing the Answer to the Skills Shortage?
Not entirely, but it’s part of a resilient structure. The functions that need round-the-clock specialist coverage are often better run by a managed provider, while functions that benefit from institutional knowledge of your environment are usually better kept in-house, the split matters more than defaulting entirely to one model or the other.

0 Comments