The cybersecurity skills gap has overtaken headcount shortages as the top workforce challenge facing organizations globally, according to the 2026 SANS | GIAC Cybersecurity Workforce Research Report released at RSAC 2026. Drawing on responses from 947 practitioners, leaders, and HR professionals across six regions, the report finds that 60% of organizations say their teams lack the skills needed to defend against current threats, while 27% report actual security breaches tied directly to workforce capability gaps.
SANS Institute CEO James Lyne and Chief AI Officer and Chief of Research Rob T. Lee presented the findings to a packed audience. The report marks the first time in its three-year history that skills gaps have decisively overtaken staffing shortages as the industry’s primary concern. A year ago, the margin between the two was just four percentage points. Today, it stands at 20 points.
The Cybersecurity Skills Gap in Numbers
The consequences of widening capability gaps are measurable. Beyond the 27% of organizations reporting breaches, skills shortages drive delayed projects (57%), increased team burnout (47%), slower incident response (47%), and reduced monitoring capabilities (42%). Budget limitations and time constraints together account for 57% of the primary obstacles preventing organizations from closing those gaps.
“This is no longer a story about filling seats. Organizations have people. But those people are overwhelmed, under-resourced, and unable to develop the capabilities they need because they’re too busy running today’s operations.”
Rob T. Lee, Chief AI Officer and Chief of Research, SANS Institute
AI Reshapes Entry-Level Roles Faster Than Governance Catches Up
Seventy-four percent of organizations report that artificial intelligence is already affecting their team size and role structures. However, governance has not kept pace: only 21% have a full AI security framework in place, and 7% have no AI policy at all. More than half of organizations (54%) have AI governance policies on paper, yet only 38% provide full AI security training to staff.
AI’s primary impact is on efficiency rather than elimination. Some 49% of organizations report reduced manual analysis time, and 48% cite workflow automation gains. Only 16% report actual headcount reductions. Among organizations experiencing role changes, SOC and security analysts lead reductions at 32%, followed by threat intelligence analysts at 26% and incident responders at 22%. These are the entry-level positions where the next generation of cybersecurity professionals has traditionally built foundational skills.
New job categories are emerging in parallel. Among organizations adding roles, 34% have filled AI/ML security specialist positions, 32% added AI security engineers, and 30% employed AI governance analysts. Lee noted more than 2,500 active AI/ML security engineer postings on job platforms as of March 21, a category that barely existed three years ago.
“Policy without practice is just paper. What does your policy say about agentic AI? Can people use agents in your organization? What are they connected to? These are the questions organizations should be answering right now.”
Rob T. Lee, Chief AI Officer and Chief of Research, SANS Institute
Regulatory Pressure Drives the Biggest Hiring Shift on Record
The report’s sharpest year-over-year change involves regulatory impact on hiring. In 2025, 40% of organizations said regulatory directives were affecting their hiring practices. By 2026, that figure surged to 95%, a 55-point increase described as the fastest acceleration of any metric in the report’s history. NIS2 leads at 30% of organizations reporting hiring impact, followed by CMMC at 29%, DORA at 26%, DoD 8140 at 24%, and SEC regulations at 21%.
NIS2 is now in active enforcement, with approximately 19,000 companies estimated non-compliant as of March 6, 2026, and fines reaching up to €10 million or 2% of global turnover. The U.S. Department of Justice settled seven cybersecurity fraud cases in 2025 under the False Claims Act, adding personal liability pressure on executives. Demand for new specialist roles nearly doubled, jumping from 23% to 53% year over year.
“This isn’t mild compliance adjustment. Organizations are building entirely new specialist positions, restructuring teams around regulatory requirements, and facing real enforcement consequences if they don’t.”
James Lyne, CEO, SANS Institute
Career Progression and Certification Trends
Unclear career progression tripled as a hiring obstacle, rising from 9% to 32% year over year, making it the third-largest challenge in attracting talent. Yet only 24% of organizations provide well-defined cybersecurity career paths. Senior executives and CISOs now control 53% of hiring decisions, and expert-level roles requiring 15 or more years of experience are the hardest to fill at 27%, with 55% of senior hires taking six months or longer.
Certifications now rank as the leading skill validation method at 64%, ahead of skills assessments at hiring (49%) and internal evaluations (48%). Academic degrees rank last among hiring priorities at just 17%. Technical capability leads all hiring criteria at 55%, followed by work experience at 46%, attitude at 37%, and aptitude at 34%.
Burnout and Stress Compound the Workforce Challenge
Sixty-one percent of organizations report increased stress within cybersecurity teams over the past two years. The top drivers are workload and understaffing (46%), budget constraints (40%), and threat complexity (40%). Lyne flagged emerging research on what he called “AI fry,” where productivity tools paradoxically increase burnout through constant context switching.
The report features case studies from Microsoft Federal, Bayer, and Singapore’s Cyber Security Agency (CSA). Bayer’s Global CISO Dr. Kevin Jones details a shift from hierarchy to a skills-based operating model across 90,000 employees. CSA Singapore reports training over 22,000 individuals since 2020. The 2026 report outlines nine strategic recommendations, including building AI governance programs, using workforce frameworks such as NICE and ECSF, and creating structured career paths for security professionals.
The survey covered 947 respondents across North America (56%), Europe (16%), Latin America (14%), Asia-Pacific (7%), Africa (5%), and the Middle East (2%). A webcast titled “Inside the 2026 Cyber Workforce” is scheduled for June 24, 2026.





