FrontNexus — Your Education Partner
Cybersecurity 12 min read

The Cybersecurity Skills Gap: Why Training Existing Staff May Be the Fastest Fix

The Cybersecurity Skills Gap: Why Training Existing Staff May Be the Fastest Fix

Most companies talk about the cybersecurity skills gap as if the solution is obvious.

Hire more cyber people.

Hire another analyst. Hire a cloud security engineer. Hire a governance specialist. Hire an incident responder. Hire someone who understands AI risk. Hire someone who understands suppliers. Hire someone who can explain cyber risk to the board without sounding like a firewall manual.

There is only one problem.

Everyone else is trying to hire the same people.

That does not mean hiring is wrong. Many organisations genuinely need more cybersecurity specialists. But for most companies, hiring alone is too slow, too expensive and too narrow to solve the real problem.

The real problem is not only that there are too few cybersecurity professionals. The real problem is that too much cybersecurity responsibility sits with too few people.

That is why training existing staff may be the fastest fix.

Not because every employee should become a security expert. They should not. But because modern cyber resilience depends on many roles making better security decisions: IT, HR, procurement, finance, legal, operations, project management, compliance, leadership and front-line teams.

Cybersecurity is no longer a department problem. It is a capability problem.

The wrong question: “How many cyber people do we need?”

Headcount matters. But it is not the whole story.

A company can hire three more security specialists and still have weak security if managers approve risky exceptions, procurement ignores supplier risk, project teams launch systems without security review, employees fall for social engineering, and executives have never practised an incident scenario.

More specialists cannot compensate for weak organisational habits forever.

This is why the cybersecurity workforce conversation is changing. The 2025 ISC2 Cybersecurity Workforce Study makes an important point: in 2025, ISC2 did not include a single global workforce-gap estimate because respondents increasingly prioritised critical skills over simple headcount. ISC2 states that respondents in 2024 and 2025 placed more emphasis on the need for critical skills than on the need for more people alone.

That is a significant shift. It moves the conversation from “How many security people are we missing?” to “Which capabilities are missing, where are they missing, and how quickly can we build them?”

That second question is more useful for executives.

The skills gap is not only technical

There is a persistent myth that cybersecurity skills are mainly technical.

Technical skills are essential. No organisation can protect modern systems without people who understand networks, identity, cloud environments, vulnerabilities, security operations, incident response and secure architecture.

But the most damaging cyber failures are not always caused by a missing technical skill. They are often caused by weak communication, unclear ownership, poor judgement, slow escalation, bad prioritisation or a lack of business understanding.

ISACA's State of Cybersecurity 2025 found that, among the skills gaps respondents see in cybersecurity professionals, soft skills ranked highest at 59%. The top soft skills named were critical thinking, communication and problem-solving. ISACA also reported that adaptability had become the top qualification factor in demand.

That should make leaders pause. If the cyber skills gap were only about technical tooling, the solution would be simpler. Buy better tools. Hire more specialists. Outsource more operations.

But if the gap is also about communication, judgement, adaptability and business context, then the solution has to be broader.

  • A security analyst needs technical skill.
  • A CISO needs business influence.
  • A project manager needs enough security awareness to involve the right people early.
  • A procurement manager needs to understand supplier risk.
  • A finance manager needs to recognise payment fraud and approval manipulation.
  • An HR manager needs to understand candidate-data risk and AI screening risk.
  • An executive needs to understand cyber resilience as a business risk, not an IT cost.

That is not one skills gap. It is many gaps in different places.

Cybersecurity work is spreading into every department

The old model was simple: the security team protects the company.

The new model is more uncomfortable: the security team enables the company to protect itself.

That does not mean handing responsibility to people who are unprepared. It means training the roles that already influence security outcomes.

Think about where cyber risk now appears. HR handles personal data, onboarding, offboarding, recruitment tools and sometimes AI-assisted candidate screening. Procurement selects suppliers, negotiates contracts and decides which third-party tools enter the business. Finance faces invoice fraud, payment redirection, executive impersonation and approval-process manipulation. Project teams introduce new platforms, integrations, vendors and data flows. Operations depends on systems that must keep running during disruption. Legal and compliance need evidence, reporting processes and regulatory awareness. Executives need to make fast decisions during incidents. Employees handle email, documents, passwords, customer information and increasingly AI tools.

If these groups do not understand their security role, the security team becomes the last line of defence for decisions made elsewhere. That is expensive and dangerous.

The World Economic Forum's Global Cybersecurity Outlook 2026 makes the organisational point clearly. It reports that CEOs of insufficiently resilient organisations identified cybersecurity skills shortages and lack of funding as top barriers to improving cyber resilience. It also shows that highly resilient organisations shift attention toward broader ecosystem risks such as supply chains and third-party dependencies.

In other words, mature organisations do not only ask, “Do we have enough security staff?” They ask, “Is the whole organisation capable of managing cyber risk?”

Why existing staff are often the best starting point

Hiring new cyber talent is necessary in many cases. But upskilling existing staff has four advantages.

1. They already understand the business

External hires may know security. Existing employees know how the company actually works.

They know the systems people rely on. They know which processes are messy. They know where exceptions happen. They know which suppliers are critical. They know which teams are under pressure. They know where policy and reality diverge.

That context is valuable. A trained operations manager may spot a resilience issue a security specialist would miss. A trained procurement lead may ask better supplier questions before a risky tool is purchased. A trained project manager may involve security early enough to prevent rework.

Cybersecurity improves when business knowledge and security knowledge meet.

2. Training is faster than recruiting

Recruitment can take months. Specialist hiring can take longer. The best candidates may be expensive, unavailable or not interested.

Training can start now.

That does not mean a two-hour awareness session solves everything. It does not. But role-based training can quickly improve decision quality in high-risk areas.

  • A finance team can learn fraud patterns.
  • A project team can learn security-by-design basics.
  • Managers can learn incident escalation.
  • Procurement can learn supplier-risk questions.
  • IT staff can deepen cloud, identity or ISO 27001 knowledge.
  • Security professionals can develop governance and leadership skills through CISM.

The point is speed. Not superficial speed, but practical improvement.

3. It reduces dependence on a small security team

When only a few specialists understand security, every question becomes their problem.

  • Can we use this supplier?
  • Can we launch this system?
  • Can we approve this exception?
  • Can we use this AI tool?
  • Can we store this data here?
  • Can we respond to this customer requirement?
  • Can we accept this risk?

A trained organisation does not remove the need for specialists. It reduces unnecessary dependency on them.

Teams learn when to act, when to escalate and what information to bring. That makes security specialists more effective because they spend less time correcting avoidable mistakes and more time on high-value work.

4. It supports retention

Cybersecurity professionals are under pressure.

ISACA's 2025 report found that 66% of cybersecurity professionals said their role is more stressful now than five years ago, and that high stress was the top reason for attrition. The report also found that only 41% of respondents were confident in their team's incident response capabilities.

Training existing staff does not just help non-security teams. It can also reduce pressure on the security team. When the rest of the organisation understands security better, fewer problems land on the same overloaded people.

The AI factor: the gap is becoming a mismatch

AI is making the cyber skills gap more complicated.

Companies now need people who can secure AI systems, use AI in security operations, govern AI tools, understand AI-enabled attacks and make judgement calls where automation is helpful but not enough.

Accenture research reported by Axios found that 59% of open cybersecurity roles require a combination of technical skills and strategic business understanding, while only 40% of cybersecurity professionals currently have both. The same article reports that demand for AI-related cybersecurity skills has increased 2.5x since 2020.

That is not just a shortage. It is a mismatch.

Many companies still write job descriptions as if cybersecurity roles are purely technical. But the real work increasingly requires business context, risk judgement, AI awareness, governance capability and communication.

AI does not remove human expertise. It changes what expertise must include.

This is another reason existing staff matter. Some of the needed capability may come from security specialists learning AI and business governance. Some may come from business professionals learning enough cybersecurity to manage AI-related risk in their own functions.

The best workforce strategy is not “technical people only.” It is cross-functional capability.

What to train first

The fastest fix is not to train everyone in everything. That is how companies waste money.

A better approach is to train by risk, role and business need.

1. Cybersecurity awareness for everyone

Everyone needs a baseline. This should cover phishing, passwords, MFA, social engineering, data handling, safe use of AI tools, reporting suspicious activity and basic cyber hygiene.

But awareness training should be practical, not patronising. Adults do not need cartoon hackers. They need examples that resemble their real work.

2. Role-based training for high-risk teams

Some departments need more than basic awareness.

  • Finance needs payment fraud and impersonation training.
  • HR needs personal-data, recruitment-tool and AI-screening awareness.
  • Procurement needs supplier-risk training.
  • Project managers need security-by-design basics.
  • Executives need cyber crisis decision training.
  • IT teams need deeper technical and operational security training.

3. Governance and risk management

Security leaders, IT managers, compliance professionals and risk owners need a shared language for governance. This includes risk appetite, control ownership, reporting, incident escalation, supplier risk, audit evidence and management accountability.

CISM is highly relevant here because it focuses on security governance, risk management, programme management and incident management.

4. ISO 27001 and information security management

Organisations that need a structured security programme should build ISO 27001 capability.

The ISO overview of ISO/IEC 27001:2022 describes it as the world's best-known standard for information security management systems and highlights its holistic approach involving people, policies and technology.

That is exactly what many organisations need: not isolated security activity, but a management system.

5. Incident response and resilience

Incident response cannot be learned for the first time during an incident. Teams should train and practise:

  • who escalates
  • who decides
  • who communicates
  • who contacts suppliers
  • who handles regulators
  • who restores systems
  • who updates customers
  • how lessons are captured afterwards

Cyber resilience is a muscle. It has to be exercised.

6. AI security and AI governance

AI training should not sit separately from cybersecurity training.

Staff need to understand shadow AI, data leakage, AI-generated phishing, deepfake risk, model security, human oversight and the security implications of AI tools. This is especially important for managers, IT, security, HR, legal, procurement and compliance.

A simple role-based training model

Executives do not need a complicated cyber academy to begin. They need a practical map of what each group should learn first:

  • All employees — phishing, MFA, reporting, data handling, safe AI use
  • Managers — risk ownership, escalation, approval risk, incident roles
  • IT teams — identity, cloud security, vulnerability management, secure configuration
  • Security teams — governance, CISM, incident management, AI-enabled threats
  • Procurement — supplier risk, contract security, third-party assurance
  • HR — personal data, onboarding/offboarding, AI in recruitment
  • Finance — fraud, payment controls, impersonation, approval workflows
  • Executives — cyber resilience, crisis decisions, board reporting, regulatory exposure
  • Compliance/risk teams — ISO 27001, audit evidence, control monitoring, NIS2/AI governance alignment

This model is not perfect. Every organisation is different. But it is far better than sending everyone the same generic training and hoping behaviour changes.

Why training existing staff is not a second-best option

Some companies treat upskilling as what they do when they cannot hire. That is the wrong mindset.

Training existing staff is not a consolation prize. It is a strategic control.

  • It increases organisational resilience.
  • It reduces avoidable mistakes.
  • It improves communication with the security team.
  • It creates internal career paths.
  • It makes cyber risk visible earlier.
  • It helps the company adopt AI and digital tools more safely.
  • It reduces dependence on scarce external talent.

ENISA's skills and competences work states that the cybersecurity sector faces workforce shortages and a widening skills gap, and that the gap creates significant cybersecurity risks, particularly as the global economy digitalises. ENISA also supports skills frameworks to help organisations align training and recruitment with current industry demands.

That last point matters. Training and recruitment should not be rivals. They should support each other.

A strong company hires where it must, trains where it can, and builds career pathways so people do not have to leave the organisation to grow.

The business case: faster capability, lower fragility

The business case for training existing staff is straightforward. Cyber risk is spreading faster than cyber headcount.

AI, cloud, remote work, suppliers, regulation, data growth and digital transformation all increase the number of decisions that have security consequences. If only the security team understands those consequences, the organisation becomes fragile.

A resilient organisation distributes capability. Not equally. Not randomly. But deliberately.

  • The people making risky decisions should understand the risks.
  • The people approving suppliers should understand supplier risk.
  • The people handling data should understand data risk.
  • The people managing teams should understand escalation.
  • The people leading the business should understand cyber resilience.

That is how training becomes more than professional development. It becomes risk reduction.

The fastest fix is usually already inside the company

The cybersecurity skills gap is real. But the answer is not only to search the market for people who may not exist, may be too expensive, or may leave after a year.

The faster answer is to look inside the organisation and ask:

  • Who already has the business knowledge?
  • Who already understands the systems?
  • Who already influences risky decisions?
  • Who could become much more effective with the right training?
  • Who could move into a security-adjacent role?
  • Who could help reduce pressure on the security team?

The people are often already there. They just need a clearer learning path.

Ready to build cyber capability across your organisation?

FrontNexus helps professionals and organisations build future-ready skills through industry-recognised training programmes, flexible learning formats and learning advisory across Information, Cyber & Operational Security, Data & Artificial Intelligence, Project & Agile Management, Leadership and related disciplines.

If your organisation is struggling with cybersecurity skills, the right answer may not be one course for everyone. It may be a role-based training plan that builds the right capabilities in the right places — cybersecurity awareness, CISM, ISO 27001, incident management, AI governance, cloud security, supplier risk, project security or executive cyber resilience training.

The goal is not just to close a skills gap. The goal is to build an organisation that can make better security decisions before it is under pressure.

Talk to our learning advisory team about the right path for you or your organisation, or get in touch and we will help you find it.

3 September 2026