‘We’re not investing as much as we should in their skills and development’: Skills shortages remain a key factor in security breaches — and things could get worse with AI in the equation
Skills capabilities remain a key factor in security breaches, according to a new study
A leading cause of security breaches lies in a lack of employee skills and awareness, according to new research from Fortinet, and it’s an issue that’s plagued the industry for years.
In Fortinet’s 2026 Global Cybersecurity Skills Gap Report, more than half (56%) of security and IT leaders cited a lack of employee security awareness as a top cause of security breaches.
A similar number (54%) highlighted a lack of trained IT or security staff as a leading contributing factor on this front.
Speaking to ITPro, Melonia da Gama, director of training and learning programs at Fortinet, noted that this marks the third consecutive year in which the top cause of security incidents came from poor skills capabilities.
Indeed, it’s an issue that enterprises are failing to address despite obvious signs that threat actors are capitalizing on the problem by actively targeting staff.
“For the third year in a row, human skills, whether it be the IT or security teams, or the general security awareness of all your employees, has been the top concern for threats,” she said.
“And if you look at the top four attacks listed, they’re all targeted at the end-user, at the employees.”
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
According to Fortinet’s findings, the top four attacks reported by organizations over the last year included:
- Malware attacks (39%)
- Phishing attacks (36%)
- Web attacks (31%)
- Password attacks (30%)
These attack methods align consistently with previous iterations of the report, da Gama noted, and show that despite an increasingly sophisticated threat landscape, cyber criminals are still sticking with traditional techniques.
“Some of these simple attacks they have are still working on humans, because we’re not investing as much as we should in their skills and development,” she told ITPro.
The situation for enterprises is further exacerbated by the fact that many simply can’t find workers with relevant skills. Worse still, nearly half (49%) said they struggle to even get approval to bring on additional cybersecurity talent.
This flies in the face of what executives have told Fortinet repeatedly over the last few years - namely the fact that cybersecurity is now a mission-critical area.
More than three-quarters (73%) said cybersecurity is now a key priority for their organization, for example. Many, however, aren’t putting their money where their mouth is, with Fortinet finding that only 59% prioritize spending in this domain.
According to da Gama, Fortinet found that there’s a growing gap when it comes to business priorities and financial priorities. Put simply, boards are aware of the scale of threats, but they’re not quite willing to invest at the levels required.
The potential impact of this underinvestment is significant, Fortinet found. More than half (52%) of organizations reported that breaches now cost more than $1 million on average.
High stakes with AI in the equation
Poor skills capabilities come at a critical time for many organizations, particularly given many are ramping up AI adoption and deploying new tools and technologies.
AI brings with it an array of new considerations for IT and security leaders. It’s an enabler for employees, but it’s also widening attack surfaces and is even being leveraged by threat actors to supercharge attacks.
“Last year in our report, we said [AI] was an opportunity, obviously, to shore up our defenses really quickly,” da Gama told ITPro. “It’s a challenge, because we’re seeing even this year, the biggest challenge they have is how do we implement this within our organization – and it’s a threat.”
“The number one worry they have is AI,” she added. “Attacks that are leveraging AI, because we don't know what they're going to look like. They're getting better and better every day.”
Da Gama explained that many organizations are falling into the trap of “hanging our hats on technology and AI” while “forgetting about the people”.
Finding cyber talent was already a challenge, but when it comes to AI-related skills the situation is even more dire, according to Fortinet. Nearly two-thirds (60%) of respondents said their top recruitment challenge was finding cybersecurity professionals with experience in AI.
Meanwhile, 63% said they expect a great need for AI oversight and governance roles in cybersecurity teams over the next three years.
Efforts are being made to improve on these fronts, Fortinet found. The overwhelming majority (92%) of respondents said they plan to invest in AI-related security training or certifications over the next 12 months.
The same number said they’re willing to pay for employees to achieve certifications in a bid to boost their skills capabilities.
Attempts to source talent from traditionally underrepresented groups and through alternative talent pipelines are also accelerating, Fortinet found.
92% of respondents now use internships, apprenticeships, partnerships, or skills programs to attract talent from a range of demographics. Three-quarters also have dedicated recruitment initiatives targeting women, marking a positive increase compared to last year.
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.

Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.
He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.
For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.
-
Stellanor adds eight UK data centers to rapidly-growing portfolioNews The acquisition from Redcentric will aid its ambitions to become the UK's leading urban data center platform
-
Google is building its own OpenClaw alternativeNews The OpenClaw-style agent, dubbed ‘Remy’, is reportedly being tested by developers internally
-
Pay up or expect attrition: 77% of cyber professionals missed out on pay rises last year – and almost half now plan to switch rolesNews Organizations are overlooking cyber pros when it comes to pay increases, and it could cost them dearly
-
The rise of teen hackers ‘makes for a good headline’, but cyber crime activities peak later in lifeNews With family responsibilities and mortgages to pay, it's not teenagers dishing out malware or carrying out cyber extortion
-
Cyber budget cuts are slowing down, but that doesn't mean there's light on the horizon for security teamsNews A new ISC2 survey indicates that both layoffs and budget cuts are on the decline
-
Cyber skills shortages are pushing firms into dangerous shortcuts – and it’s putting them at huge risk of security breachesNews Chronic cyber skills shortages mean many businesses are implementing quick fixes
-
The UK’s ‘chronic shortage of cyber professionals’ is putting the country at riskNews While high-profile attacks grab headlines, a security researcher warns the UK's "chronic shortage of cyber professionals" is left unaddressed by government, industry, and academia.
-
SonicWall CEO Bob VanKirk hails ‘pivotal moment’ as firm unveils new MSP cyber solutionsNews The company is expanding its MSP solutions range and ramping up its focus on platform-based security
-
‘We are now a full-fledged powerhouse’: Two years on from its Series B round, Hack the Box targets further growth with AI-powered cyber training programs and new market opportunitiesNews Hack the Box has grown significantly in the last two years, and it shows no signs of slowing down
-
Law enforcement needs to fight fire with fire on AI threatsNews UK law enforcement agencies have been urged to employ a more proactive approach to AI-related cyber crime as threats posed by the technology accelerate.