DKDKCISSPSearch
Threat Research

57% of security execs report challenges with onboarding entry-level staff

A study released September 29 by SkillBit found that cybersecurity managers are having difficulty onboarding new employees and finding cyber talent, and as a result, maintaining cyber resilience has become very challenging.

DKCISSP News DeskSC Media30 Sept 2026, 12:49 am
57% of security execs report challenges with onboarding entry-level staff
Image courtesy of SC Media. Original report
DKCISSP REPORT

The survey also found that 70% of organizations say they have few roles available to candidates with under two years of experience, which means there’s fewer and fewer qualified entry-level candidates.

A study released September 29 by SkillBit found that cybersecurity managers are having difficulty onboarding new employees and finding cyber talent, and as a result, maintaining cyber resilience has become very challenging.

In a survey of 200 security executives, 57% reported a six-month time-to-value for a new employee, which puts a lot of pressure on security managers racing to onboard people in the wake of the compressed timeline for managing patches in the AI era.

According to the survey, 30% of leaders are receptive to “Interactive Lab” formats as a credential substitute, and another 49.5% are open to it if presented with convincing evidence of its effectiveness.

Varadarajan said the continued focus on AI, cloud, networking, risk management, administration, and analysis highlights the need for cybersecurity professionals to combine technical, operational, and business skills.

If we don't rebuild deliberate on-ramps, including apprenticeship models, AI-amplified junior roles, and academic pipelines that connect to real work, senior talent will age out faster than we can replenish it.

By replacing static resumes with interactive challenges, security executives can validate a candidate’s ability to perform in a live environment, effectively widening the candidate pipeline across security teams without lowering the skill level.

While more thorough, this training often takes a large amount of time to complete, at a time when most security teams can barely keep up.

In terms of training, 71% of security managers said they prefer 20-minute weekly upskilling sessions over annual training, yet 84% sponsor “Certification” training for their staff.

For those entering the field, it’s encouraging news: employers are investing more in training and onboarding, however, candidates still need foundational IT, cloud, networking, and AI skills to get hired and take advantage of those opportunities.” Diana Kelley, chief information security officer at Noma Security, said AI will create new cybersecurity roles, but employers are still looking for experience and proof-of-capability, even at the entry level.

What happened

The survey also found that 70% of organizations say they have few roles available to candidates with under two years of experience, which means there’s fewer and fewer qualified entry-level candidates.

A study released September 29 by SkillBit found that cybersecurity managers are having difficulty onboarding new employees and finding cyber talent, and as a result, maintaining cyber resilience has become very challenging.

What changed

In a survey of 200 security executives, 57% reported a six-month time-to-value for a new employee, which puts a lot of pressure on security managers racing to onboard people in the wake of the compressed timeline for managing patches in the AI era.

According to the survey, 30% of leaders are receptive to “Interactive Lab” formats as a credential substitute, and another 49.5% are open to it if presented with convincing evidence of its effectiveness.

Who is affected

Varadarajan said the continued focus on AI, cloud, networking, risk management, administration, and analysis highlights the need for cybersecurity professionals to combine technical, operational, and business skills.

If we don't rebuild deliberate on-ramps, including apprenticeship models, AI-amplified junior roles, and academic pipelines that connect to real work, senior talent will age out faster than we can replenish it.

Why it matters

By replacing static resumes with interactive challenges, security executives can validate a candidate’s ability to perform in a live environment, effectively widening the candidate pipeline across security teams without lowering the skill level.

While more thorough, this training often takes a large amount of time to complete, at a time when most security teams can barely keep up.

Attribution

SC Media: A study released September 29 by SkillBit found that cybersecurity managers are having difficulty onboarding new employees and finding cyber talent, and as a result, maintaining cyber resilience has become very challenging.

What to watch next

Watch for new exploitation reports and updated indicators of compromise.

Watch for updated vendor guidance and fixed-version details.

MORE IN THREAT RESEARCH

More cybersecurity reporting

Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility ToolsThe Hacker News · 2 Oct 2026, 4:45 pmMicrosoft is rolling out Linux container support to WSLBleepingComputer · 30 Sept 2026, 6:10 amDutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters InvestigationThe Hacker News · 29 Sept 2026, 6:56 pmEx-US soldier gets 70 months for role in AT&T, Snowflake data thefts - Help Net SecurityHelp Net Security · 28 Sept 2026, 2:15 pm