Skip to main content

2026 Cybersecurity Workforce Research Report by SANS | GIAC

The 2026 Cybersecurity Workforce Research Report, published by SANS Institute and GIAC Certifications in March 2026, examines how artificial intelligence, regulatory compliance, and hiring practices are reshaping cybersecurity teams. The report drew on 947 global respondents, primarily cybersecurity and InfoSec leadership, covering AI adoption, workforce frameworks, hiring authority, and the widening gap between the skills organizations have and the skills they need.

Key findings:

  • The skills gap now dominates as organizations' top workforce challenge at 60%, compared with 40% citing headcount shortages, up from a 52%/48% split in 2025
  • 95% of organizations report that regulatory directives are affecting hiring in 2026, up from just 40% in 2025, a 55-point jump in one year
  • 74% of cybersecurity teams report AI is changing team size and role structures, though the effect is concentrated in efficiency gains rather than headcount cuts, with only 16% citing workforce reduction
  • Organizations needing more job specialists to handle new roles jumped from 23% in 2025 to 53% in 2026, driven largely by regulatory compliance demands
  • Senior executives and CISOs now control 53% of final hiring decisions, consolidating authority once distributed across HR and hiring committees
  • Expert (27%) and senior (22%) roles are collectively cited alongside mid-level (23%) as the hardest to fill, representing 72% of recruitment difficulty, while only 4% of organizations struggle to fill entry-level roles
  • 55% of senior-level hires take six months or longer to fill, compared to much faster fill times for entry-level roles
  • Unclear career progression surged from 9% to 32% as a top hiring challenge year-over-year, more than tripling in one year
  • Only 24% of organizations report having well-defined and clearly communicated cybersecurity career paths
  • 27% of organizations report having experienced a breach as a direct impact of workforce skills gaps
  • SOC and security analyst roles lead AI-driven role reductions at 32%, followed by threat intelligence analysts (26%) and incident responders (22%) — traditionally the entry-level roles that trained the next generation of analysts
  • Cybersecurity certifications are the most-used skill validation method at 64%, ahead of skills assessments during hiring (49%) and internal competency evaluations (48%)

The report describes a workforce being squeezed from multiple directions at once. AI is automating the repetitive entry-level analysis that once trained junior analysts, regulatory frameworks like NIS2, CMMC, DORA, and DoD 8140 are forcing rapid specialist hiring, and organizations are responding by rebuilding from the top down rather than developing talent internally. That combination concentrates hiring authority and skills at senior levels while leaving broader teams under-skilled, and the very budget and time constraints preventing organizations from closing the gap are the same constraints blocking the training that could fix it. Respondents were surveyed globally, with North America representing 56% of the sample, followed by Europe (16%), Latin America (14%), Asia-Pacific (7%), Africa (6%), and the Middle East (2%). Organizations ranged from fewer than 100 employees (19%) to enterprises exceeding 100,000 staff, and 72% of respondents held cybersecurity or InfoSec leadership roles.

SANS_WFS-2026_Digital_v3 (PDF, 16.93MB)

11 Mar 2026
BySANS Institute, GIAC Certifications
Share
All papers are copyrighted

No re-posting of papers is permitted

Subscribe to GIAC’s Monthly Newsletter

Receive expert insights, priority access to certifications, essential updates on regulatory changes and industry developments.