Skip to main content
CybersecurityIncident Response

Cybersecurity Skills Decay Outpaces Organizational Readiness

Person sitting at desk with laptop and notepad, looking concerned.

“Within three months, approximately two-thirds of organizations expect cybersecurity hires to be fully productive. However, most (57%) state it takes six months to achieve full productivity.” That mismatch, SkillBit’s research warns, is one clear sign that organizations are building readiness more slowly than the workforce is eroding.

SkillBit’s headline numbers: onboarding expectations versus reality

SkillBit’s research draws a stark contrast between employer expectations and operational experience. While roughly two-thirds of organizations say they expect new cybersecurity hires to be fully productive within three months, a majority (57%) report that it actually takes six months to reach that level.

The study also flags skill decay as a growing worry: 39% of surveyed organizations identify the deterioration of cybersecurity skills as a notable concern. That anxiety scales with organizational size — among employers with more than 50,000 employees, 60% name skill decay as a significant issue. SkillBit’s authors summarize the pattern as a “worrying cycle”: organizations take longer than expected to build readiness and then risk losing forward progress as skills diminish.

Sumedh Thakar, Qualys: AI governance, business-aligned hiring, and built‑in agents

Sumedh Thakar, President and CEO at Qualys, framed the problem around responsible AI adoption and workforce design. “The future belongs to those organizations who can deploy AI responsibly, minimize risk, and navigate the changing regulatory environment,” he said, adding that companies need “professionals who understand how AI models behave in production environments, especially under adversarial conditions.”

Thakar argued the human role will shift rather than disappear: “The human-in-loop approach to AI is here to stay, and that will separate those with the expertise to guide, shape, and govern AI from those who will be replaced by it.” He also urged hiring and onboarding to “align directly with business outcomes” and counseled leaders to factor SaaS vendors’ built-in AI agents into workforce planning so organizations can “leverage AI technology to achieve results, instead of buying more tools and hiring people to manage them.”

Aviv Nahum, Above Security: from individual operator to orchestrator of agents

Aviv Nahum, Co‑founder and CEO at Above Security, described a practical shift in daily skill requirements. “Today, cybersecurity professionals are moving from being individual operators to managers of machine labor,” he said, explaining that analysts will be judged less on manual investigations and more on “how effectively they can define the objective, give the right context to a set of agents, evaluate the result, and decide what should happen next.”

Nahum warned against trying to “artificially preserve every manual skill that AI can perform better.” He compared the transition to the arrival of calculators for engineers and said the human contribution will “move up a layer.” That higher layer, he added, requires deep technical understanding to detect when an agent is wrong and business context to judge “what response is proportionate.” For Nahum, the durable skill is orchestration: “breaking a complex objective into work that agents can execute, supplying the right context, and being accountable for the outcome.”

Diana Kelley, Noma Security: pipeline risk and the need for apprenticeship models

Diana Kelley, Chief Information Security Officer at Noma Security, focused on long-term workforce sustainability. She argued that AI’s spread across business operations will increase demand for “skilled AI security practitioners” and that employers are still looking for experience even at entry level. Kelley recommended pairing “foundational knowledge with hands-on experience, whether that’s labs, internships, or contributing to real projects.”

She warned of “a pipeline that runs dry,” stressing that “if we don’t rebuild deliberate on-ramps, including apprenticeship models, AI-amplified junior roles, and academic pipelines that connect to real work, senior talent will age out faster than we can replenish it.” The implication: without structured pathways, organizations risk losing the next generation of defenders even as AI reshapes roles.

What this means for security teams, procurement leaders, and managed service providers

  • Security teams: Nick Heddy, President and Chief Commerce Officer at Pax8, urged treating readiness as continuous learning rather than a single onboarding milestone. He recommended “short, recurring, hands-on training that reinforces skills throughout the year” and measuring whether staff “can detect, investigate, and respond to real-world threats” rather than simply tracking course completion.
  • Procurement leaders: Several leaders in the research advised planning for built-in AI agents from SaaS vendors and aligning hiring to business outcomes. Thakar recommended workforce plans that leverage vendor-provided AI capabilities instead of adding tools and roles to manage them.
  • Managed service providers and security partners: Pax8 and other contributors highlighted a growing role for partners. Heddy said partners can “aggregate expertise across hundreds or thousands of customers” and spread the cost of advanced AI security tools, making them important force multipliers for organizations that cannot build every skill internally.

Taken together, the reporting sketches a single, urgent problem: organizations are expecting rapid productivity while the nature of cybersecurity work is changing faster than most training cycles. The remedies offered in the record are concrete — govern AI, reorient hiring to outcomes, adopt continuous hands-on learning, leverage partners, and rebuild apprenticeship pathways — but the research leaves open who will execute those programs at scale. As SkillBit and the security leaders quoted here make clear, the test ahead is whether enterprises can turn those prescriptions into sustained operational readiness before the skills they depend on erode further.

https://www.securitymagazine.com/articles/102610-cyber-skills-diminish-quicker-than-organizations-can-build-readiness