
Cybersecurity teams are under pressure to defend against increasingly sophisticated threats, yet new research from SkillBit suggests organizations are falling short in onboarding talent, developing skills, and sustaining readiness in a rapidly changing security environment.
According to the report, nearly two-thirds of organizations expect cybersecurity hires to become fully productive within three months, yet most report it takes six months to reach full effectiveness. The challenge extends beyond onboarding. While 57 percent of cybersecurity leaders say new hires need six months to become fully productive, 39 percent also cite skills decay as a significant concern.
Together, the findings expose a persistent cycle: organizations take too long to build readiness, then risk losing ground as skills decay. The report points to the need for continuous readiness, an approach that combines ongoing assessment, hands-on practice, and bite-sized learning to help teams build, maintain, and demonstrate real-world cybersecurity capabilities over time.
The findings offer perspective on the limits of workforce development models built around periodic courses, point-in-time certifications, and completion-based measures. As AI capabilities, attack methods, and security technologies advance, organizations may need to explore other strategies to develop and validate cybersecurity skills.
Industry stakeholders offered the following perspectives.
Sumedh Thakar, President and CEO at Qualys
"The future belongs to those organizations who can deploy AI responsibly, minimize risk, and navigate the changing regulatory environment. We need professionals who understand how AI models behave in production environments, especially under adversarial conditions. The human-in-loop approach to AI is here to stay, and that will separate those with the expertise to guide, shape, and govern AI from those who will be replaced by it.
"Hiring strategies and employee onboarding must align directly with business outcomes. If the goal is greater efficiency, then hiring and onboarding should focus on productivity – streamlining roles and responsibilities to do more in less time, with fewer people. That efficiency helps the business strengthen its top line, leading to expansion and ultimately fuels future hiring.
"At the same time, more SaaS vendors and service providers will offer built-in AI agents. Organizations should factor this into their workforce planning so they can leverage AI technology to achieve results, instead of buying more tools and hiring people to manage them."
Aviv Nahum, Co-founder and CEO at Above Security
"Today, cybersecurity professionals are moving from being individual operators to managers of machine labor. A strong analyst used to be measured by how well they could investigate an alert, write a detection, or analyze an incident themselves. Increasingly, they’ll be measured by how effectively they can define the objective, give the right context to a set of agents, evaluate the result, and decide what should happen next.
"I don’t think the answer is to artificially preserve every manual skill that AI can perform better. We stopped expecting engineers to calculate everything by hand when calculators arrived. The same thing will happen in cybersecurity. If an agent can write a query, correlate telemetry or reconstruct an incident faster and better than a person, we should let it. The human value moves up a layer.
"That makes technical depth more important, not less. You need enough understanding to know when an agent is wrong, what context it is missing and whether the result makes sense in the environment. But business context becomes equally important. The best security professionals will understand not only what happened technically, but why it matters to the company, which business process is involved and what response is proportionate.
"Communication changes too. Security professionals will increasingly have to translate between agents, technical teams, and business stakeholders. In that sense, prompt engineering is probably the least interesting long-term skill. The durable skill is orchestration: breaking a complex objective into work that agents can execute, supplying the right context, and being accountable for the outcome."
Nick Heddy, President and Chief Commerce Officer at Pax8
"The most important finding in this survey is not that it takes six months for a new hire to become productive. It's that the half-life of cybersecurity knowledge is shrinking faster than most organizations can train people. AI is accelerating the pace of change in security operations, threat detection, software development, and adversary behavior.
"Security leaders can no longer think about readiness as an onboarding problem. They need to think about it as a continuous learning problem. We're entering a period where the demand for cybersecurity expertise will exceed the industry's ability to hire and train talent.
"Here are three strategies for security teams:
Build a continuous learning culture. Annual training cycles cannot keep pace with AI. Security teams need short, recurring, hands-on training that reinforces skills throughout the year, not just during compliance deadlines.
Leverage partners as force multipliers. Organizations should not assume every emerging AI skill must be developed in-house. MSPs, MSSPs, and cybersecurity partners can provide specialized expertise, accelerate adoption, and help organizations maintain readiness while internal teams focus on strategic priorities.
Measure readiness, not certifications. The question isn't whether someone completed training. It's whether they can detect, investigate, and respond to real-world threats. Organizations should regularly evaluate operational readiness through simulations, exercises, and practical assessments.
"AI is creating more security work, not less. As threats become more sophisticated, organizations will need a combination of skilled employees, AI-powered tools, and trusted security partners to stay ahead. The winners won't necessarily be the companies with the largest teams. They'll be the companies that can continuously learn, adapt, and tap into expertise wherever it exists."
Shane Barney, CISO at Keeper Security
"The cybersecurity skills gap has become a business risk, not just a technical one. Cybersecurity training must be ongoing, not occasional. AI streamlines detection and efficiency, but it still relies on human oversight and sound governance to operate securely. Security teams need the skills to interpret data, validate AI-driven insights and act with precision and accountability.
"The organizations best prepared to withstand today’s threats are those that align skilled people, advanced technology and a culture of accountability. When teams are empowered to make informed decisions and supported by intelligent, well-governed systems, access remains tightly controlled, visibility stays comprehensive and real-time, and responses are swift and coordinated. That balance of human expertise and technological capability turns cybersecurity from a reactive function into a true driver of resilience."
Diana Kelley, CISO at Noma Security
"AI is quickly being woven into the fabric of all business operations and workflows. Skilled AI security practitioners are now, and will be, in high demand with a substantial need for AI guardrails to be implemented in parallel with the adoption of AI in the enterprise.
"AI is creating new cybersecurity roles, but employers are still looking for experience and proof of capability. For new candidates, that means pairing foundational knowledge with hands-on experience, whether that’s labs, internships, or contributing to real projects, and developing a working fluency in how AI is used in enterprise environments.
"Going forward, every security professional needs a working understanding of AI and agent risk. That includes how models are trained, where data exposure can happen, how outputs can be manipulated, agentic blast radius, and how AI integrates into business workflows.
"The long-term risk is a pipeline that runs dry. Cut off the early-career pathways and you lose the next generation of defenders. If we don't rebuild deliberate on-ramps, including apprenticeship models, AI-amplified junior roles, and academic pipelines that connect to real work, senior talent will age out faster than we can replenish it. The organizations that thrive will be the ones that figure out how to onboard new employees quickly, and use AI to make junior practitioners more capable, rather than replace them."
Melonia Da Gama, Director of Training & Learning at Fortinet
"When thinking about managing resilience, rather than approaching cybersecurity reactively, leaders need to treat cybersecurity as a strategic, corporate-wide initiative that includes managing risk proactively. The 2025 Cybersecurity Skills Gap Report highlighted a three-pronged approach to building stronger cyber resilience, which includes:
- Security awareness for all employees.
- IT security skills and training.
- Deployment of the right security solutions.
"The report introduced a new focus on AI which found that nearly half of IT decision-makers (48 percent) cite the lack of staff with sufficient AI expertise as their greatest challenge. Given that 97 percent of organizations are already using or planning to use AI-driven cybersecurity solutions, the data indicates that the skills gap has become a pressing concern. Taking a proactive approach to cybersecurity means an organization’s leadership ensures the team is skilled up and representative where its organization’s gaps exist."























