Gitnux/Report 2026

HR In The Cybersecurity Industry Statistics

Cybersecurity work looks healthier on paper with 81% of organizations planning to raise cybersecurity spending and automation already in place for 76% of respondents, yet the talent pressure is still brutal with more than 500,000 unfilled cybersecurity jobs in the US and 40% of SOC leaders pointing to talent shortages as their main bottleneck. This page puts the most telling workforce, pay, and incident trends side by side, including the jump in CVEs and the financial motive behind 55% of DBIR incidents, so you can see where HR planning will likely need to tighten first.
21Statistics
21Sources
6Sections
1Visuals
6mRead
2 mo agoUpdated
HR In The Cybersecurity Industry Statistics
Verified via a 4-step process
01Source

Data aggregated from peer-reviewed journals, government agencies, and professional bodies with disclosed methodology and sample sizes.

02Verify

Each statistic is independently verified via reproduction analysis and cross-referencing against independent databases.

03Grade

Figures are graded by cross-model consensus. Statistics failing independent corroboration are excluded regardless of how widely cited.

04Cite

Every figure carries a primary source. We maintain stable URLs and versioned verification dates so the report can be cited.

Read our full methodology →

Statistics that fail independent corroboration are excluded.

Within the next 43 days
The United States had more than 500,000 unfilled cybersecurity jobs in 2024 while incident reporting continued to rise. Survey results show 76% of respondents have implemented security automation in at least one area. With 33% of cybersecurity professionals saying they would leave for better compensation, workforce gaps and retention pressures shape HR decisions across the sector.

Key Takeaways

  • 41% of cybersecurity professionals have obtained at least one industry certification (ISC)² workforce study survey result)
  • 2,600+ occupations mapped to the NICE Framework across cybersecurity work roles (NICE Framework scope count)
  • 12,000+ U.S. federal cybersecurity professionals certified under DoD/USAF programs (DoD cyber workforce certification reporting; count in DoD cyber workforce statistics)
  • 74% of organizations reported a shortage of skills for roles in security engineering and operations (ISC)² workforce insights referenced in employer survey reporting
  • 81% of organizations plan to increase cybersecurity spending in 2024 (Gartner forecast figure reported across enterprise security planning)
  • $208.0 billion worldwide information security spending in 2023 (Gartner forecast figure cited in the same Gartner spending outlook release)
  • 28% year-over-year increase in the number of security incidents reported to the UK’s National Cyber Security Centre (NCSC) from 2022 to 2023 (UK NCSC annual report figure)
  • 61% of cybersecurity professionals have upskilled in the past year (ISC)² workforce development survey reported in (ISC)² continuing education findings
  • $120,000 median annual pay for information security analysts in the U.S. in 2022 (BLS OES prior year median)
  • $172,400 median annual pay for computer and information research scientists in the U.S. in 2023 (BLS OES; relevant high-skill cyber R&D)
  • $151,000 median annual pay for penetration testers and ethical hackers mapped to related BLS roles estimate in 2023 (PayScale cybersecurity salary benchmarking)
  • More than 500,000 unfilled cybersecurity jobs in the United States in 2024 (U.S. workforce gap estimate).
  • 76% of respondents said they have implemented security automation in at least one area (survey-reported automation adoption).
  • 59% of organizations reported using zero trust initiatives across the enterprise (survey-reported zero trust adoption).
  • In the 2024 DBIR, 55% of incidents were financially motivated (share of incidents).

Cybersecurity spending is rising, but talent gaps and skills shortages keep intensifying, driving automation and upskilling.

01 · Category

Skills & Certifications5 stats

01
41% of cybersecurity professionals have obtained at least one industry certification (ISC)² workforce study survey result)
02
2,600+ occupations mapped to the NICE Framework across cybersecurity work roles (NICE Framework scope count)
03
12,000+ U.S. federal cybersecurity professionals certified under DoD/USAF programs (DoD cyber workforce certification reporting; count in DoD cyber workforce statistics)
04
1,900+ training seats delivered by federal cyber apprenticeship programs in 2023 (CISA/NICE workforce program metrics)
05
40% of organizations cite talent shortages as the main constraint on their security operations center (SOC) effectiveness (industry SOC survey figure)
Interpretation

Skills & Certifications Interpretation

With 41% of cybersecurity professionals holding at least one industry certification and 40% of organizations still pointing to talent shortages as the biggest SOC bottleneck, the Skills and Certifications data suggest that scaling credential pathways and training seats is critical, especially since federal efforts alone delivered 1,900+ apprenticeship seats in 2023.

02 · Category

Industry Budgeting4 stats

01
74% of organizations reported a shortage of skills for roles in security engineering and operations (ISC)² workforce insights referenced in employer survey reporting
02
81% of organizations plan to increase cybersecurity spending in 2024 (Gartner forecast figure reported across enterprise security planning)
03
$208.0 billion worldwide information security spending in 2023 (Gartner forecast figure cited in the same Gartner spending outlook release)
04
$7.3 billion global market size for cybersecurity professional services in 2024 forecast (MarketsandMarkets cybersecurity services market estimate)
Interpretation

Industry Budgeting Interpretation

As budgets move up with 81% of organizations planning to increase cybersecurity spending in 2024 and global information security spending reaching $208.0 billion in 2023, the HR reality is that 74% are already reporting skill shortages in security engineering and operations, making staffing and talent investment a critical part of industry budgeting.

03 · Category

Hiring & Mobility2 stats

01
28% year-over-year increase in the number of security incidents reported to the UK’s National Cyber Security Centre (NCSC) from 2022 to 2023 (UK NCSC annual report figure)
02
61% of cybersecurity professionals have upskilled in the past year (ISC)² workforce development survey reported in (ISC)² continuing education findings
Interpretation

Hiring & Mobility Interpretation

From a Hiring and Mobility perspective, cybersecurity organizations are operating in a rapidly intensifying environment, with the UK’s NCSC reporting a 28% year over year jump in security incidents from 2022 to 2023 while 61% of professionals upskilled in the past year, signaling that talent movement and learning are becoming essential to keep pace.

04 · Category

Pay & Benefits5 stats

01
$120,000median annual pay for information security analysts in the U.S. in 2022 (BLS OES prior year median)
02
$172,400median annual pay for computer and information research scientists in the U.S. in 2023 (BLS OES; relevant high-skill cyber R&D)
03
$151,000median annual pay for penetration testers and ethical hackers mapped to related BLS roles estimate in 2023 (PayScale cybersecurity salary benchmarking)
04
$140,000median annual pay for cybersecurity analysts in 2024 (Glassdoor salary benchmark for “Cyber Security Analyst”)
05
33% of cybersecurity professionals report they would leave for a better compensation package (2024 survey finding reported in trade press)
Interpretation

Pay & Benefits Interpretation

Pay & Benefits is becoming a critical retention lever as compensation levels vary widely across cybersecurity roles, with median pay ranging from $120,000 for information security analysts to $172,400 for computer and information research scientists, and the risk is real since 33% of cybersecurity professionals say they would leave for a better compensation package.

05 · Category

Workforce Demand1 stats

01
More than 500,000 unfilled cybersecurity jobs in the United States in 2024 (U.S. workforce gap estimate).
Interpretation

Workforce Demand Interpretation

In the workforce demand category, the United States faced a gap of more than 500,000 unfilled cybersecurity jobs in 2024, underscoring how strongly demand is outpacing available talent.
report visual · Key figures

Talent shortages and upskilling are driving HR urgency in cybersecurity

A large share of both professionals and employers report skill gaps—while a majority of professionals are upskilling and many organizations plan higher cyber budgets.

74%
74% of organizations reported a shortage of skills for roles in security engineering and operations (ISC)² workforce ins
61%
61% of cybersecurity professionals have upskilled in the past year (ISC)² workforce development survey reported in (ISC)
81%
81% of organizations plan to increase cybersecurity spending in 2024 (Gartner forecast figure reported across enterprise
500,000
More than 500,000 unfilled cybersecurity jobs in the United States in 2024 (U.S. workforce gap estimate).
40%
40% of organizations cite talent shortages as the main constraint on their security operations center (SOC) effectivenes
source-verifiedisc2.org · gartner.com · cyberseek.org2024
Reference

Cite This Report

This report is designed to be cited. We maintain stable URLs and versioned verification dates. Copy the format appropriate for your publication below.

APA
Min-ji Park. (2026, February 13). HR In The Cybersecurity Industry Statistics. Gitnux. https://gitnux.org/hr-in-the-cybersecurity-industry-statistics
MLA
Min-ji Park. "HR In The Cybersecurity Industry Statistics." Gitnux, 13 Feb 2026, https://gitnux.org/hr-in-the-cybersecurity-industry-statistics.
Chicago
Min-ji Park. 2026. "HR In The Cybersecurity Industry Statistics." Gitnux. https://gitnux.org/hr-in-the-cybersecurity-industry-statistics.

Sources & references

21 datasets cited across this report · attribution is report-level

+6 additional datasets cited (not shown individually)