2026 Cybersecurity Workforce Research Report by SANS | GIAC
The 2026 Cybersecurity Workforce Research Report, published by SANS Institute and GIAC Certifications in March 2026, examines how artificial intelligence, regulatory compliance, and hiring practices are reshaping cybersecurity teams. The report drew on 947 global respondents, primarily cybersecurity and InfoSec leadership, covering AI adoption, workforce frameworks, hiring authority, and the widening gap between the skills organizations have and the skills they need.
Key findings:
- The skills gap now dominates as organizations' top workforce challenge at 60%, compared with 40% citing headcount shortages, up from a 52%/48% split in 2025
- 95% of organizations report that regulatory directives are affecting hiring in 2026, up from just 40% in 2025, a 55-point jump in one year
- 74% of cybersecurity teams report AI is changing team size and role structures, though the effect is concentrated in efficiency gains rather than headcount cuts, with only 16% citing workforce reduction
- Organizations needing more job specialists to handle new roles jumped from 23% in 2025 to 53% in 2026, driven largely by regulatory compliance demands
- Senior executives and CISOs now control 53% of final hiring decisions, consolidating authority once distributed across HR and hiring committees
- Expert (27%) and senior (22%) roles are collectively cited alongside mid-level (23%) as the hardest to fill, representing 72% of recruitment difficulty, while only 4% of organizations struggle to fill entry-level roles
- 55% of senior-level hires take six months or longer to fill, compared to much faster fill times for entry-level roles
- Unclear career progression surged from 9% to 32% as a top hiring challenge year-over-year, more than tripling in one year
- Only 24% of organizations report having well-defined and clearly communicated cybersecurity career paths
- 27% of organizations report having experienced a breach as a direct impact of workforce skills gaps
- SOC and security analyst roles lead AI-driven role reductions at 32%, followed by threat intelligence analysts (26%) and incident responders (22%) — traditionally the entry-level roles that trained the next generation of analysts
- Cybersecurity certifications are the most-used skill validation method at 64%, ahead of skills assessments during hiring (49%) and internal competency evaluations (48%)
The report describes a workforce being squeezed from multiple directions at once. AI is automating the repetitive entry-level analysis that once trained junior analysts, regulatory frameworks like NIS2, CMMC, DORA, and DoD 8140 are forcing rapid specialist hiring, and organizations are responding by rebuilding from the top down rather than developing talent internally. That combination concentrates hiring authority and skills at senior levels while leaving broader teams under-skilled, and the very budget and time constraints preventing organizations from closing the gap are the same constraints blocking the training that could fix it. Respondents were surveyed globally, with North America representing 56% of the sample, followed by Europe (16%), Latin America (14%), Asia-Pacific (7%), Africa (6%), and the Middle East (2%). Organizations ranged from fewer than 100 employees (19%) to enterprises exceeding 100,000 staff, and 72% of respondents held cybersecurity or InfoSec leadership roles.
SANS_WFS-2026_Digital_v3 (PDF, 16.93MB)
11 Mar 2026Related Content
A Startups Guide to Implementing a Security Program
Research PaperStartups struggle to balance survival with the practical implementation of a security program. There...
- 8 Oct 2020
- Vanessa Pegueros
Putting it all together through Automation
Research PaperMost problems faced in Information Security are typically time sensitive. For Forensic Engineers and...
- 22 Apr 2019
- Kenneth Ray
Information Security Best Practices While Managing Projects
Research PaperTo maximize long-term return on investment (ROI) with a project's delivery, taking information...
- 25 Mar 2019
- Dallas Smith
Logon Banners
Research PaperLogon banners have been a common feature of operating systems and applications for many years....
- 20 Mar 2019
- Keelan Stewart
Security Considerations for Team Based Password Managers
Research PaperPassword management applications are a common and practical way to store complex passwords. They use...
- 23 Jul 2018
- Matthew Schumacher
Content Security Policy in Practice
Research PaperThe implementation of Content Security Policy to leverage web browser capability in protecting a web...
- 6 Jul 2018
- Varghese Palathuruthil
Agile Security Patching
Research PaperSecurity Patch Management is one of the biggest security and compliance challenges for organizations...
- 3 May 2018
- Michael Hoehl
Speed and Scalability Matter: Review of LogRhythm 7 SIEM and Analytics Platform
Research PaperJust how scalable, fast and accurate are SIEM tools when under load? To find out, we put the...
- 13 Apr 2017
- Dave Shackleford
Bill Gates and Trustworthy Computing: A Case Study in Transformational Leadership
Research PaperThe notion that IT security is a serious issue is non-controversial. The market for cybersecurity...
- 20 Sep 2016
- Preston S. Ackerman
Filling the Gaps
Research PaperThere should be an emphasis on the importance of regular internal and external auditing focusing on...
- 18 Aug 2016
- Robert Smith
Investing in Information Security: A Case Study in Community Banking
Research PaperSmall businesses, such as community banks, often do not have resources dedicated to information...
- 12 Aug 2016
- Wes Earnest
Introduction to Rundeck for Secure Script Executions
Research PaperMany organizations today support physical, virtual, and cloud-based systems across a wide range of...
- 11 Aug 2016
- John Becker
Using Information Security as an Auditing Tool
Research PaperAs cyber-attacks are gaining visibility within mainstream media, what once was knowledge for...
- 14 Jul 2016
- Adi Sitnica
Applying Data Analytics on Vulnerability Data
Research PaperOrganizations, by law, should exercise due care and due diligence in securing data at rest, in...
- 23 Dec 2015
- Yogesh Dhinwa
Framework for Innovative Security Decisions
Research PaperRemember the Periodic Table of chemical elements (Dayah, Dynamic Periodic Table, 1997)? It...
- 3 Nov 2015
- Ergash Karshiev
Security Data Visualization
Research PaperThe objective of this paper is to provide guidelines on information security data visualization and...
- 28 Oct 2015
- Balaji Balakrishnan
Behind the Curve? A Maturity Model for Endpoint Security
Research PaperBehind the Curve? A Maturity Model for Endpoint Security
- 22 Oct 2015
- G. Mark Hardy
The Sliding Scale of Cyber Security
Research PaperThe Sliding Scale of Cyber Security is a model for providing a nuanced discussion to the categories...
- 1 Sep 2015
- Robert M. Lee
Protecting Third Party Applications with RASP Infographic
Research PaperProtecting Third Party Applications with RASP Infographic
- 27 Aug 2015
- SANS Institute
What Companies need to consider for e-Discovery
Research PaperWithin the legal environment, Discovery is the process of identifying, locating, preserving,...
- 24 Aug 2015
- Thomas Vines
