Skip to main content

2026 Cybersecurity Workforce Research Report by SANS | GIAC

The 2026 Cybersecurity Workforce Research Report, published by SANS Institute and GIAC Certifications in March 2026, examines how artificial intelligence, regulatory compliance, and hiring practices are reshaping cybersecurity teams. The report drew on 947 global respondents, primarily cybersecurity and InfoSec leadership, covering AI adoption, workforce frameworks, hiring authority, and the widening gap between the skills organizations have and the skills they need.

Key findings:

  • The skills gap now dominates as organizations' top workforce challenge at 60%, compared with 40% citing headcount shortages, up from a 52%/48% split in 2025
  • 95% of organizations report that regulatory directives are affecting hiring in 2026, up from just 40% in 2025, a 55-point jump in one year
  • 74% of cybersecurity teams report AI is changing team size and role structures, though the effect is concentrated in efficiency gains rather than headcount cuts, with only 16% citing workforce reduction
  • Organizations needing more job specialists to handle new roles jumped from 23% in 2025 to 53% in 2026, driven largely by regulatory compliance demands
  • Senior executives and CISOs now control 53% of final hiring decisions, consolidating authority once distributed across HR and hiring committees
  • Expert (27%) and senior (22%) roles are collectively cited alongside mid-level (23%) as the hardest to fill, representing 72% of recruitment difficulty, while only 4% of organizations struggle to fill entry-level roles
  • 55% of senior-level hires take six months or longer to fill, compared to much faster fill times for entry-level roles
  • Unclear career progression surged from 9% to 32% as a top hiring challenge year-over-year, more than tripling in one year
  • Only 24% of organizations report having well-defined and clearly communicated cybersecurity career paths
  • 27% of organizations report having experienced a breach as a direct impact of workforce skills gaps
  • SOC and security analyst roles lead AI-driven role reductions at 32%, followed by threat intelligence analysts (26%) and incident responders (22%) — traditionally the entry-level roles that trained the next generation of analysts
  • Cybersecurity certifications are the most-used skill validation method at 64%, ahead of skills assessments during hiring (49%) and internal competency evaluations (48%)

The report describes a workforce being squeezed from multiple directions at once. AI is automating the repetitive entry-level analysis that once trained junior analysts, regulatory frameworks like NIS2, CMMC, DORA, and DoD 8140 are forcing rapid specialist hiring, and organizations are responding by rebuilding from the top down rather than developing talent internally. That combination concentrates hiring authority and skills at senior levels while leaving broader teams under-skilled, and the very budget and time constraints preventing organizations from closing the gap are the same constraints blocking the training that could fix it. Respondents were surveyed globally, with North America representing 56% of the sample, followed by Europe (16%), Latin America (14%), Asia-Pacific (7%), Africa (6%), and the Middle East (2%). Organizations ranged from fewer than 100 employees (19%) to enterprises exceeding 100,000 staff, and 72% of respondents held cybersecurity or InfoSec leadership roles.

SANS_WFS-2026_Digital_v3 (PDF, 16.93MB)

11 Mar 2026
BySANS Institute, GIAC Certifications
Share
All papers are copyrighted

No re-posting of papers is permitted

Related Content

A Startups Guide to Implementing a Security Program

Research Paper

Startups struggle to balance survival with the practical implementation of a security program. There...

  • 8 Oct 2020
  • Vanessa Pegueros

Putting it all together through Automation

Research Paper

Most problems faced in Information Security are typically time sensitive. For Forensic Engineers and...

  • 22 Apr 2019
  • Kenneth Ray

Information Security Best Practices While Managing Projects

Research Paper

To maximize long-term return on investment (ROI) with a project's delivery, taking information...

  • 25 Mar 2019
  • Dallas Smith

Logon Banners

Research Paper

Logon banners have been a common feature of operating systems and applications for many years....

  • 20 Mar 2019
  • Keelan Stewart

Security Considerations for Team Based Password Managers

Research Paper

Password management applications are a common and practical way to store complex passwords. They use...

  • 23 Jul 2018
  • Matthew Schumacher

Content Security Policy in Practice

Research Paper

The implementation of Content Security Policy to leverage web browser capability in protecting a web...

  • 6 Jul 2018
  • Varghese Palathuruthil

Agile Security Patching

Research Paper

Security Patch Management is one of the biggest security and compliance challenges for organizations...

  • 3 May 2018
  • Michael Hoehl

Speed and Scalability Matter: Review of LogRhythm 7 SIEM and Analytics Platform

Research Paper

Just how scalable, fast and accurate are SIEM tools when under load? To find out, we put the...

  • 13 Apr 2017
  • Dave Shackleford

Bill Gates and Trustworthy Computing: A Case Study in Transformational Leadership

Research Paper

The notion that IT security is a serious issue is non-controversial. The market for cybersecurity...

  • 20 Sep 2016
  • Preston S. Ackerman

Filling the Gaps

Research Paper

There should be an emphasis on the importance of regular internal and external auditing focusing on...

  • 18 Aug 2016
  • Robert Smith

Investing in Information Security: A Case Study in Community Banking

Research Paper

Small businesses, such as community banks, often do not have resources dedicated to information...

  • 12 Aug 2016
  • Wes Earnest

Introduction to Rundeck for Secure Script Executions

Research Paper

Many organizations today support physical, virtual, and cloud-based systems across a wide range of...

  • 11 Aug 2016
  • John Becker

Using Information Security as an Auditing Tool

Research Paper

As cyber-attacks are gaining visibility within mainstream media, what once was knowledge for...

  • 14 Jul 2016
  • Adi Sitnica

Applying Data Analytics on Vulnerability Data

Research Paper

Organizations, by law, should exercise due care and due diligence in securing data at rest, in...

  • 23 Dec 2015
  • Yogesh Dhinwa

Framework for Innovative Security Decisions

Research Paper

Remember the Periodic Table of chemical elements (Dayah, Dynamic Periodic Table, 1997)? It...

  • 3 Nov 2015
  • Ergash Karshiev

Security Data Visualization

Research Paper

The objective of this paper is to provide guidelines on information security data visualization and...

  • 28 Oct 2015
  • Balaji Balakrishnan

Behind the Curve? A Maturity Model for Endpoint Security

Research Paper

Behind the Curve? A Maturity Model for Endpoint Security

  • 22 Oct 2015
  • G. Mark Hardy

The Sliding Scale of Cyber Security

Research Paper

The Sliding Scale of Cyber Security is a model for providing a nuanced discussion to the categories...

  • 1 Sep 2015
  • Robert M. Lee

Protecting Third Party Applications with RASP Infographic

Research Paper

Protecting Third Party Applications with RASP Infographic

  • 27 Aug 2015
  • SANS Institute

What Companies need to consider for e-Discovery

Research Paper

Within the legal environment, Discovery is the process of identifying, locating, preserving,...

  • 24 Aug 2015
  • Thomas Vines

Subscribe to GIAC’s Monthly Newsletter

Receive expert insights, priority access to certifications, essential updates on regulatory changes and industry developments.