When the people who would detect an intrusion don't exist on your payroll, the gap is no longer about hiring. It is about survivability.
Most boards still file cybersecurity staffing under human resources. A role is open, a recruiter is briefed, and the assumption is that the market will eventually supply a candidate. For the specialists who actually matter — the people who would notice an intrusion in its first hour rather than its first month — that assumption no longer holds.
The shortage is not evenly distributed. There is no scarcity of people who can pass a certification exam. There is an acute scarcity of people who have sat in a live incident, watched an adversary move laterally through a network, and made the right call under pressure with incomplete information. That experience cannot be conjured by raising a salary band, and it cannot be taught quickly to someone who has never seen it.
This is why we treat the gap as a question of survivability rather than headcount. An organisation without that capability is not simply understaffed; it is operating without the one control that turns a breach into a contained event instead of a public one. The cost of the missing person is not their salary. It is the difference between an incident nobody hears about and a headline that reaches the regulator before it reaches the board.
There are two honest ways to close the gap. The first is to find the rare people who already have the experience — a slow, discreet search, because they are rarely looking and never on a job board. The second is to build the capability deliberately: take people with the right foundations and judgement, and train them on real work until the experience is theirs. Both are deliberate acts. Neither happens by leaving a vacancy open and hoping.
The board's job is not to approve a hiring plan. It is to decide, with clear eyes, whether the organisation can survive the day it is tested — and to fund the answer before that day arrives, not after.
This is part of how we think, shared publicly. The specifics we cannot publish, we discuss privately.
Speak with us about this