The Cybersecurity Skills Gap Is Real. But We're Measuring the Wrong Thing.

Companies keep buying courses and certifications. Breaches keep happening anyway. The problem is not a shortage of trained people. It is a shortage of people who have actually practised under fire.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: A darkened server room with long rows of blinking rack-mounted computers stretching into the background
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • The World Economic Forum's 2025 Global Cybersecurity Outlook report named skills shortages and budget constraints as the top barriers to cyber resilience.
  • IBM data collected from 600 organisations between March 2024 and February 2025 found that 13% had suffered a breach of an AI model or application.
  • In that same IBM survey, 63% of breached organisations had no AI governance policy in place, or were still drafting one when the breach happened.
  • Only 49% of organisations planned to increase security spending in 2025, down from 63% the year before.
  • Some organisations using hands-on simulation platforms report saving more than $400,000 in training costs, according to figures cited by CSO Online.

The cybersecurity industry has spent years talking about a "skills gap," the idea that there aren't enough trained security professionals to go around. That argument wobbles once you notice that many security graduates can't find work. The positions go unfilled not because the people don't exist, but because employers can't tell who's actually ready.

Call it a validation gap instead.

Why do breaches keep happening if we keep training people?

Because most training doesn't resemble real work. A certification exam tests memory. A live breach tests judgment under pressure, in your specific environment, with your specific tools misbehaving in ways no textbook anticipated. Those are different skills.

AI makes this harder. Criminals now use AI tools to write more convincing phishing emails (fake messages designed to trick staff into handing over credentials), find weaknesses in software faster, and automate attacks that previously required a skilled human operator. The certifications sold today were written before these threats existed.

IBM's survey data makes the governance problem concrete. Thirteen percent of the 600 organisations polled had already suffered a breach of an AI model or application. Eight percent didn't know whether they'd been breached at all. Those aren't training failures in the traditional sense. They're readiness failures, and our June report on structural preparedness gaps found the same pattern: Proofpoint's 2025 data put 58% of organisations unprepared to respond to an attack.

Spending more on courses doesn't fix that. More tools produce more alerts, which exhaust the analysts reading them, who then miss things. The breach happens anyway.

Should you worry about cyber ranges being oversold?

A little. The approach gaining ground is the cyber range: a simulated version of a company's real systems where staff can practise responding to attacks without touching live data. Think of it as a flight simulator for incident response. Pilots don't learn to handle engine failures by reading about them; they drill until the response is instinctive.

A well-built range replicates the actual software stack the organisation runs, throws realistic attack scenarios at it, and produces a detailed report on what the team did well and where they froze. That report is also useful when a security manager needs to argue for budget: concrete evidence of a gap beats a vendor's brochure.

For ordinary employees outside the security team, the principle is familiar. Phishing simulations work precisely because they create a low-stakes version of the real thing. Muscle memory built in practice carries over.

Security teams need the same thing at a much higher level of complexity. Continuous, realistic practice provides it. Annual training days don't. The vendors pitching ranges will oversell the ROI figures, so treat that $400,000 savings claim as a ceiling, not a promise, and ask hard questions about how closely a vendor's default scenarios actually match your stack before you sign anything.

© 2026 Threat Vectr