How Organizations Are Looking Beyond Recruitment to Close the Cybersecurity Skills Gap
Organizations understand they need highly skilled cybersecurity professionals to defend against today’s increasingly sophisticated, AI-powered threats. The challenge isn’t recognizing the need; it’s securing the people, budget, and resources to meet it.
The Fortinet 2026 Cybersecurity Skills Gap Report found that 49% of the organizations surveyed face pushback from their top leadership when requesting additional cybersecurity headcount. Furthermore, 52% say they struggle to retain their cybersecurity talent currently on staff. These challenges are forcing organizations to rethink how they build, develop, and retain cybersecurity teams.
The Talent Pool Is Limited
According to the report, 71% of organizations say the cybersecurity skills gap increases operational risk, underscoring the real business impact of unfilled roles and limited access to experienced talent. At the same time, demand for cybersecurity professionals continues to rise. In fact, 87% of organizations expect to grow their cybersecurity teams over the next 12 months.
While recruitment remains an essential part of workforce planning, organizations are increasingly recognizing that hiring alone cannot close the gap. To build long-term resilience, organizations are complementing recruitment with broader workforce development strategies.
The Cost of Waiting
As the process of acquiring cybersecurity talent becomes more cumbersome and time-consuming, IT leaders must find ways to fully support their existing security team members. Delays in building cybersecurity capacity, whether through hiring or workforce development, can leave organizations more vulnerable to evolving cyberthreats.
In this year’s report, the data illustrates the potential costs of the delay in hiring highly experienced cybersecurity professionals:
- 71% say the cybersecurity skills gap creates additional risk.
- 56% say skills shortages contributed to breaches.
- 52% report breach costs exceeding $1 million.
- 29% say recovery took four months or longer.
These findings reinforce an important point: Organizations can’t afford to wait for the “perfect hire.” Organizations that treat workforce readiness as an ongoing strategy, rather than simply as a hiring initiative, will be better positioned to adapt to evolving threats, reduce operational risk, and build long-term cyber resilience.
Develop Internal Talent
How can IT leadership help decrease business risks and keep their short-handed teams from burning out and buckling under the weight of defending the organization from ever-evolving cyberthreats? Simple: invest in developing internal talent along with more aggressive recruitment tactics.
Organizations that successfully address the cybersecurity skills gap won’t necessarily be those that hire the most people. They will be the ones that build adaptable, resilient workforces capable of keeping pace with changing threats. This means investing in the people already in the organization. Leading organizations are strengthening their cybersecurity team members’ capabilities by providing them with continuous learning, upskilling, reskilling, internal mobility, cross-training, and professional certification opportunities. These investments help employees expand their expertise, prepare for new responsibilities, and adapt as cybersecurity and AI-driven threats continue to evolve.
Building lasting cyber resilience requires more than filling open positions. It requires developing a workforce that can continuously learn, adapt, and respond to an increasingly dangerous threat landscape.
Building Workforce Readiness
Continuous learning and professional development have become essential components of a modern cybersecurity workforce strategy. The Fortinet Training Institute and the Fortinet NSE Certification program help organizations build, validate, and continuously strengthen the cybersecurity skills needed to defend against today’s AI-powered cyberthreats.
In our next blog, we’ll explore another growing workforce challenge: helping boards and executive leadership understand the opportunities, risks, and governance responsibilities that come with AI. As AI adoption accelerates, effective governance will become just as important as technical expertise.




