Cyber budget cuts are slowing down, but that doesn't mean there's light on the horizon for security teams
A new ISC2 survey indicates that both layoffs and budget cuts are on the decline
While 2024 saw a surge in layoffs, budget cuts, and hiring and promotion freezes, the economic conditions hitting cybersecurity teams appear to be levelling off.
A new report from ISC2 shows that budget cuts across the industry fell by one percentage point to 36% this year, with layoffs also dropping by one percentage point to 24%.
However, while budget cuts are slowing down, a continued lack of budget is still a key hurdle for security leaders, exacerbating long-running staff shortages.
Around one-third (33%) of respondents to the ISC2 survey noted their organizations didn't have the resources to adequately staff their teams. Meanwhile, 29% said they couldn't afford to hire staff with the skills they need to adequately secure their organizations.
As a result, 72% agreed that reducing security personnel significantly increases the risk of a breach in their organizations.
Crucially, it's a shortage of skilled personnel, rather than mere numbers, that's really giving security professionals headaches. Nearly nine-in-ten said they'd experienced at least one significant cybersecurity-related consequence in their organization because of skills shortages, while 69% said they'd experienced more than one.
An overwhelming 95% of respondents said they had at least one skill need - up 5% from 2024 - and 59% cited critical or significant skills needs, up 15% from last year.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
“A shift is happening. This year’s data makes it clear that the most pressing concern for cybersecurity teams isn’t headcount but skills,” said ISC2 acting CEO and CFO Debra Taylor.
“Skills deficits raise cybersecurity risk levels and challenge business resilience.”
AI is a big opportunity for cyber teams
Notably, Taylor said the increased adoption of technologies such as generative AI is welcomed by cybersecurity workers. Nearly three-quarters (73%) said AI will create more specialized cybersecurity skills while 72% said the technology will create the need for more strategic cybersecurity mindsets.
Two-thirds, meanwhile, said AI will require broader skillsets across the workforce.
At present, around 28% of respondents have integrated AI tools into their operations, with 69% engaged in some sort of adoption process: integration, active testing, or early evaluation.
Demand for AI-related cybersecurity skills is also growing, ISC2 found, remaining among the top skills for the second consecutive year.
This year, 41% of respondents cited AI as a top skill needed followed by cloud security at 36%.
Nearly half of respondents said they were already working to gain more generalized AI knowledge and skills, while 35% are educating themselves on AI solutions at risk to better understand vulnerabilities and exploits.
All of this is leading to more confidence, with 87% believing there will always be a need for cybersecurity professionals and 81% confident the profession will remain strong.
"Many cybersecurity professionals view AI as an opportunity for career advancement," said Taylor. "They are using AI tools to automate tasks, and they are investing their time to learn more and demonstrate their expertise in using and securing AI systems."
Make sure to follow ITPro on Google News to keep tabs on all our latest news, analysis, and reviews.
MORE FROM ITPRO
- Cybersecurity skills: Addressing gaps and challenges in 2025
- The cybersecurity skills your business needs
- Cyber skills shortages are pushing firms into dangerous shortcuts
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
The trends that will shape workplace culture in 2026In-depth Tech leaders share their insights on how businesses can embrace change across hiring, training, and culture
-
Why the UK is primed to lead a global charge in ‘green AI’ innovationNews UKAI says there are major economic incentives and a big opportunity for the UK to lead the world in green AI development
-
90% of companies are woefully unprepared for quantum security threats – analysts say they need to get a move onNews Quantum security threats are coming, but a Bain & Company survey shows systems aren't yet in place to prevent widespread chaos
-
LastPass issues alert as customers targeted in new phishing campaignNews LastPass has urged customers to be on the alert for phishing emails amidst an ongoing scam campaign that encourages users to backup vaults.
-
NCSC names and shames pro-Russia hacktivist group amid escalating DDoS attacks on UK public servicesNews Russia-linked hacktivists are increasingly trying to cause chaos for UK organizations
-
An AWS CodeBuild vulnerability could’ve caused supply chain chaos – luckily a fix was applied before disaster struckNews A single misconfiguration could have allowed attackers to inject malicious code to launch a platform-wide compromise
-
There’s a dangerous new ransomware variant on the block – and cyber experts warn it’s flying under the radarNews The new DeadLock ransomware family is taking off in the wild, researchers warn
-
Supply chain and AI security in the spotlight for cyber leaders in 2026News Organizations are sharpening their focus on supply chain security and shoring up AI systems
-
Veeam patches Backup & Replication vulnerabilities, urges users to updateNews The vulnerabilities affect Veeam Backup & Replication 13.0.1.180 and all earlier version 13 builds – but not previous versions.
-
NHS supplier DXS International confirms cyber attack – here’s what we know so farNews The NHS supplier says front-line clinical services are unaffected
