Cybersecurity teams are struggling to bring new hires to full productivity quickly while keeping experienced professionals’ skills current, according to a 2026 SkillBit survey of more than 200 cybersecurity leaders. The findings point to growing demand for continuous cybersecurity training rather than periodic learning.
Cybersecurity workforce development is facing a timing problem: organisations need new security professionals to become productive quickly, while the skills of experienced employees can become outdated as attack techniques, technologies and defensive tools change.
New research from SkillBit suggests that gap is creating a persistent workforce-readiness challenge. The 2026 SkillBit Micro-Training Survey Report, based on responses from more than 200 cybersecurity leaders, examines onboarding, skills development and ongoing readiness across security teams.
One of the clearest findings concerns the difference between employer expectations and reality. Nearly 64% of respondents said three months is an acceptable time for a new cybersecurity hire to deliver value, but 57% reported that employees typically take six months to reach full productivity.
The problem does not stop once onboarding ends. SkillBit found that 39% of cybersecurity leaders consider skills decay a significant concern. Among organisations with more than 50,000 employees, the figure rises to 60%.
The results suggest that security teams face two related workforce challenges: getting employees up to speed and preventing those skills from deteriorating afterwards.
That matters because cybersecurity is unusually sensitive to changes in technology and threat behaviour. Employees may need to adapt to new cloud architectures, identity systems, security tools, AI-enabled attacks and defensive automation without waiting for an annual training cycle.
The broader cybersecurity labour market remains constrained. ISC2’s 2025 Cybersecurity Workforce Study estimated that the global cybersecurity workforce reached approximately 5.78 million people, but the workforce gap remained at about 4.76 million. The organisation also found that skills shortages were increasingly considered a more significant concern than headcount shortages by cybersecurity professionals. (isc2.org)
SkillBit’s research highlights another issue within that talent market: limited opportunities for early-career candidates. Seventy percent of respondents said their organisations have few or no cybersecurity roles available to candidates with less than two years of experience.
That can create a difficult pipeline problem. Organisations may struggle to hire entry-level security professionals while simultaneously reporting shortages of experienced talent, potentially increasing reliance on lateral hiring and external recruitment.
The survey also suggests that cybersecurity leaders want a different model for workforce development. Seventy-one percent of respondents preferred weekly 20-minute learning experiences to 30-to-40-hour training programmes delivered once or twice annually.
The preference aligns with the broader rise of microlearning and continuous learning in enterprise workforce technology. Rather than separating training from daily work, short learning interventions can be delivered repeatedly and focused on specific skills or scenarios.
For cybersecurity teams, that approach has an additional potential benefit: it can connect training with hands-on performance. A short exercise that requires an employee to identify a suspicious authentication event or respond to a simulated security scenario can test application of knowledge rather than simply whether a course was completed.
SkillBit describes this model as Continuous Readiness, combining ongoing assessment, hands-on practice and short-form learning. The company argues that completion certificates and periodic courses provide limited information about whether employees can perform effectively when confronted with an actual security incident.
The distinction between knowledge and demonstrated capability is becoming increasingly relevant as AI changes cybersecurity work. AI tools can automate parts of threat detection, security analysis and incident response, but they can also introduce new attack vectors and change the skills security professionals need.
ISC2’s 2025 workforce research found that AI was viewed by many cybersecurity professionals as more likely to augment cybersecurity jobs than eliminate them. At the same time, respondents identified AI as a technology area that would require additional skills and expertise. (isc2.org)
That makes adaptability an important workforce capability. SkillBit’s survey found that more than two-thirds of respondents placed greater value on problem-solving, critical thinking and adaptability than on expertise tied narrowly to a particular technology stack.
For HR and learning-and-development teams, this changes the way cybersecurity training may need to be measured. Traditional metrics such as course completion, certification counts and annual training hours can show participation but may not demonstrate operational readiness.
A continuous model instead asks whether employees can apply skills under realistic conditions and whether those capabilities remain current over time.
The approach also creates a closer connection between cybersecurity, HR technology and workforce analytics. Security leaders need visibility into which employees possess particular capabilities, where skills are weakening and where additional practice is required. L&D teams, meanwhile, need mechanisms to deliver targeted interventions without taking employees away from their jobs for extended periods.
The SkillBit findings do not establish that micro-training itself produces stronger security outcomes, and the survey is based on leaders’ reported experiences rather than controlled measurements of employee performance. But they do illustrate the growing tension between conventional training cycles and the pace of change in cybersecurity.
For organisations, the challenge is therefore broader than hiring enough security professionals. It is also about creating systems that help employees become effective sooner, maintain relevant skills and demonstrate that capability as the threat environment changes.
As cybersecurity becomes increasingly intertwined with AI, cloud infrastructure and automated defence systems, workforce readiness is becoming a continuous process rather than an annual training event.
Market Landscape
Cybersecurity workforce development is shifting from a pure headcount problem toward a combined skills, readiness and adaptability challenge. ISC2’s 2025 research estimates a global cybersecurity workforce of 5.78 million and a workforce gap of 4.76 million, while finding that skills shortages are becoming increasingly prominent. (isc2.org)
That environment is creating demand for cybersecurity training platforms that can move beyond annual compliance courses and certification preparation. Microlearning, skills assessments, hands-on simulations and continuous workforce analytics are emerging as components of more dynamic security-skills programmes.
AI is adding another layer. Security professionals increasingly need to understand AI-enabled threats and defensive systems, while employers must determine which existing skills remain relevant and which new capabilities should be developed.
For HR and cybersecurity leaders, the emerging model is therefore less about documenting that someone completed training and more about demonstrating that employees can perform specific security tasks as requirements change.
Top Insights
- SkillBit’s survey found 57% of cybersecurity leaders report that new hires typically require six months to reach full productivity.
- Skills decay was cited as a significant concern by 39% of respondents, rising to 60% among organisations with more than 50,000 employees.
- Seventy-one percent preferred weekly 20-minute learning experiences over longer annual training programmes.
- Seventy percent reported few or no cybersecurity roles for candidates with less than two years of experience.
- More than two-thirds prioritised adaptability, critical thinking and problem-solving over narrow technology-specific expertise.
Join thousands of HR leaders who rely on HRTechEdge for the latest in workforce technology, AI-driven HR solutions, and strategic insights
Business Wire, a Berkshire Hathaway company, is the global leader in press release distribution and regulatory disclosure. Public relations, investor relations, public policy and marketing professionals rely on Business Wire for secure and accurate distribution of market-moving news and multimedia. Founded in 1961, Business Wire is a trusted source for news organizations, journalists, investment professionals and regulatory authorities, delivering news directly into editorial systems and leading online news sources via its multi-patented NX network. Business Wire’s global newsrooms are available to meet the needs of communications professionals and news media worldwide.





