Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Future, Trends and Insight - ISC2 2025 Workforce Study: Stable Budgets, Growing Cybersecurity Skills Gap
Future, Trends and Insight Artificial Intelligence Latest News News & Analysis Security Study & Research

ISC2 2025 Workforce Study: Stable Budgets, Growing Cybersecurity Skills Gap

Kirsten DoyleBy Kirsten DoyleDecember 5, 20253 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
ISC2 2025 Workforce Study
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

ISC2 has released its 2025 Cybersecurity Workforce Study, and while the economic headwinds that battered security teams last year appear to be stabilizing, the industry’s skills gap is getting worse.  

The report, based on responses from more than 16,000 cybersecurity professionals, indicates that layoffs and budget cuts have ceased to accelerate.  

Reports of budget cuts (36%) and layoffs (24%) dipped slightly year over year. However, that modicum of relief isn’t translating into stronger teams. A third of respondents claimed their firms still can’t afford to staff security properly, and nearly as many reported they can’t hire the expertise they need.  

Unsurprisingly, 72% agreed that shrinking headcount directly increases the risk of breach. 

Skills Now Outrank Staffing as the Top Risk 

The most remarkable shift, is that skills, not headcount, are now the primary concern. 

Almost nine in 10 professionals said their business suffered a significant cybersecurity incident due to a skills gap, many of them more than once. Ninety-five percent reported at least one skill is needed (up five points from 2024), and critical skill shortages have jumped 15% year over year. 

“A shift is happening. This year’s data makes it clear that the most pressing concern for cybersecurity teams isn’t headcount but skills,” said ISC2 Acting CEO and CFO Debra Taylor, CC.  

“Skills deficits raise cybersecurity risk levels and challenge business resilience. At the same time, we are seeing emerging technologies like AI are perceived as less of a threat to the workforce than anticipated,” she added. 

Instead, Taylor said many cybersecurity professionals see AI as an opportunity for career advancement. “They are using AI tools to automate tasks, and they are investing their time to learn more and demonstrate their expertise in using and securing AI systems.” 

AI Uptake Surges and Expands the Skills Mandate 

According to the study, AI is quickly embedding itself into daily security operations. 

Twenty-eight percent of those surveyed said they have already integrated AI tools, and nearly three-quarters (70%) are at least somewhere along the adoption curve, from evaluation to full deployment. 

Professionals overwhelmingly believe AI will reshape the skills landscape: 

  • 73% expect more specialized AI-related cybersecurity skills 
  • 72% said AI will demand more strategic, big-picture thinking 
  • 66% claimed it will broaden the mix of skills required across teams 

AI is also the top rising skill demand for the second year running (41%), ahead of cloud security (36%). Nearly half of the respondents are actively building their foundational AI knowledge, while others are focusing on understanding AI-driven attack vectors and vulnerabilities. 

Passion Remains High, Even as Burnout Looms 

Despite constant pressure and fast-moving threats, cybersecurity professionals are deeply committed to their work. 

  • 87% believe cybersecurity roles will always be needed 
  • 81% are confident in the long-term strength of the profession 
  • 80% said they’re passionate about the work they do 

Job satisfaction also improved slightly, though stress indicators are still high. Forty-eight percent said staying current with threats is exhausting, and 47% are overwhelmed by workload.  

Retention outlooks are steady in the near term (75% said they expect to stay with their current employer for the next year), but their confidence falls to 66% over a two-year window. 

Career advancement and recognition are always key drivers: nearly a third pointed to growth opportunities as key to engagement, while others cited rewards such as bonuses or extra time off. 

The full 2025 ISC2 Cybersecurity Workforce Study, including recommended actions for leaders looking to build resilient teams, is available here. 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals
  • Kirsten Doyle
    ShinyHunters targets Oracle PeopleSoft customers through critical zero-day
  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Building cyber resilience for mission-critical operations in 2026

May 27, 20267 Mins Read

Investigating the aftermath: understanding digital forensics after a cyber incident

May 7, 20265 Mins Read

Microsoft Edge Found Holding Saved Credentials in Plaintext Memory

May 6, 20263 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}