According to a SkillBit survey reported by Help Net Security, cybersecurity hiring remains heavily skewed toward experienced candidates. More than 70% of organizations have few or no junior positions open to people with less than two years of experience, shrinking the entry-level talent pool. The report also found that 57% of executives say new hires need about six months to become fully productive, with gaps in general IT knowledge and cybersecurity processes cited as the main reasons.

The same survey points to a mismatch in how training is delivered. About 71% of security leaders said they would prefer short, weekly 20-minute online or interactive sessions over the traditional 30- to 40-hour annual training blocks. Respondents also cited urgent daily tasks, excessive vendor training, and lack of enjoyment as top reasons employees miss development goals. Roughly two-thirds favored building problem-solving skills that apply across technology stacks rather than deep expertise in a specific toolset.

Skills decay is another concern, with 39% of respondents reporting it in their teams—rising to 60% at companies with 50,000 or more employees. Of those, 75% described the impact as a moderate irritation, affecting readiness, morale, and assignment flexibility. The survey also revealed a lack of common metrics for measuring team readiness: most executives expressed only moderate confidence in their data, and board reports often rely on personal observation, audit results, and certification counts rather than a standardized measure of whether a team can stop an active breach.