
Amanda Finch at CIISec describes how organisations can hire from less trodden pathways
In 2023, the global cyber-security workforce grew to a record high of 5.5 million people. Whilst this may seem like good news, the demand for skills is still outpacing growth – at a rate of 12.6%. This talent drought, coupled with the ever-changing nature of the cyber-security industry, makes bringing in new faces as important as ever.
Cyber-security sits against a backdrop of an increasingly volatile threat landscape, with AI, new threat groups, and complex tooling to repel attacks posing challenges. To future-proof against these threats, it will be critical for organisations to recruit more cyber-security professionals who are equipped with the know-how to tackle these risks.
In addition, investing in cyber-teams to communicate and educate the wider business is a step in the right direction for ensuring the cyber-skills gap doesn’t open up, as more individuals will understand exactly what is needed from a cyber-security perspective.
Currently, organisations are sticking with traditional requirements to screen for candidates with very specific technical capabilities. Although cyber-security is a technical profession, there are so many beneficial transferable skills like critical thinking, problem solving and attention to detail that are being dismissed.
In fact, a UK Government report revealed that only 33% of new recruits in 2023 came from the non-cyber-security sector.
But people from outside the industry can offer so much to cyber-security. For example, a professional with a background in finance may be able to apply their skills in risk management to cyber-security. Or marketeers could apply their skills in communication to translating complex security terms into language that people will be able to understand.
In addition to hiring practices and technical barriers, the cyber-security industry faces a ‘boys only club’ image problem, which is limiting talent applying for roles in the first place. The industry is really missing a trick here. Individuals from different backgrounds bring their unique views to the table, which may help to uncover and reduce security threats that might otherwise be ignored.
The industry must act quickly to break down these barriers and attract individuals of different backgrounds to help build stronger and innovative teams to defend against rising threats. But after decades stuck in the same mindset, it can be difficult shake off the traditional ways of working.
Here are a few ways cyber-security organisations can recruit and retain talent, equipping the workforce with the skills to succeed:
The cyber-security industry urgently needs more people, not only to bridge the skills gap, but to bring innovative and inclusive ways of solving global challenges to the table.
Moving forward, organisations must emphasise that there’s a role for everyone – not just those with technical expertise – and ensure that they’re doing everything they can to retain staff once they’re through the door.
If the industry doesn’t, then it risks getting stuck in limbo and cyber-security will lose out, with talented individuals being attracted by other sectors.
Amanda Finch is CEO at The Chartered Institute of Information Security (CIISec)
Main image courtesy of iStockPhoto.com and kyonntra
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543