Hype vs. Reality · Updated August 2026
Cybersecurity & IT: Hype vs. Reality
Is there really a cybersecurity talent shortage? What cert-prep and training marketing claims, checked against real hiring data and what a CISA advisor has said about the shortage narrative itself.
Ready to actually start? Free step-by-step pathThe Hype
What course and training marketing in this space typically says.
A common claim across cert-prep and career-change marketing: get a single entry cert like CompTIA Security+, and that's enough on its own to break into a security role, no other experience required.
A recurring "career-changer to six-figure analyst in 12-16 weeks" narrative shows up across bootcamp and course advertising, sometimes framed as "barista to pentester" in a few months.
The most commonly recycled hype-adjacent statistic in this space: a "3.5 million" or "4.8 million unfilled cybersecurity jobs" figure, used to imply the field is desperate for newcomers and hiring is easy.
Self-reported job placement rates, often 85%+, advertised without third-party audit, is a documented pattern across training programs in this space.
The Reality: The Data
The 4.8 million global "workforce gap" figure is real and grew 19% year over year, but ISC2's own methodology note describes it as "perceived staffing need based on organizational surveys," not a direct count of open, fillable, entry-level jobs. It measures how understaffed employers feel, weighted toward mid and senior roles, not how many entry-level seats are actually open.
Source: ISC2, 2025 Cybersecurity Workforce Study, isc2.org
A CISA cybersecurity advisor has publicly pushed back on the shortage narrative itself, characterizing it as partly a myth driven by inadequate salaries and poor job or location fit rather than a true talent void.
Source: AFCEA Signal, "Is the Cyber Workforce Shortage a Myth?" (quoting Klint Walker, CISA)
Entry-level hiring tells a different story than the shortage number suggests: in one recent labor-market analysis, only 17% of employers actively recruited entry-level talent (down from 25%), 63% of postings wanted 2-6 years of experience, and 31% of organizations made zero entry-level cybersecurity hires in the prior year despite reporting a shortage. This data is UK-sourced, but the pattern is widely described as similar in the US.
Source: UK Cyber Security Skills in the Labour Market report, 2025
Real entry-level SOC (Security Operations Center) analyst pay varies a lot by source: reported averages range from roughly $58K to $90K depending on how "entry-level" is defined, with a 25th-75th percentile band closer to $40K-$62K. That's a wide, source-dependent spread, worth treating as a range rather than a single number, and it runs below our own $78K-$100K Income Snapshot figure for this path, which likely reflects 1-2 years of experience rather than a true first day on the job.
CompTIA Security+ genuinely is valued: it's the second most requested certification in US cybersecurity job postings. But it's consistently described as "the minimum needed to be taken seriously," not sufficient alone, pairing it with real hands-on skill (home labs, Wireshark, Splunk, CTF platforms) is the difference employers describe looking for.
Source: CyberSeek certification-demand data
There's a real contradiction worth naming: the same industry's own hiring-trends research found 90% of hiring managers would consider a candidate with only general IT experience (no cyber-specific background), and 89% would consider a candidate with only an entry-level cert and no experience. But actual job postings often don't reflect that stated openness, which is the catch-22 many career-changers describe: employers say they're open to it, then post reqs wanting years of experience anyway.
Source: ISC2, 2025 Cybersecurity Hiring Trends Study
The long-run outlook remains genuinely strong: information security analyst roles are projected to grow 29% from 2024 to 2034, one of the fastest-growing occupations tracked.
Source: BLS Occupational Outlook Handbook, bls.gov/ooh/computer-and-information-technology/information-security-analysts.htm
The AI Factor
How AI is actually changing this path
Multiple independent write-ups converge on the same theme here: augmentation and role-flattening, not full elimination, but it directly targets the classic first rung into this field.
The consistent, better-corroborated pattern across independent security-industry commentary: AI is absorbing Tier-1 SOC work specifically, log triage, alert correlation, initial ticket sorting, while demand grows for people who can validate AI output, do detection engineering, and threat-hunt.
This matters directly for career-changers because Tier-1 SOC analyst work, the traditional first job after getting a cert, is exactly the task category AI security tooling is being built to automate. That's a real, structural headwind on the classic on-ramp, separate from and in addition to the entry-level hiring gap above.
Real Voices
“The shortage is partly a myth, driven by inadequate salaries and job or location fit, not a true talent void.”
Klint Walker, CISA cybersecurity advisor, quoted in AFCEA Signal
Our Honest Take
This isn't a bait-and-switch field: real growth, a real pay ceiling, and real demand exist, and the 29% projected growth rate is genuinely one of the strongest of any occupation tracked. But the on-ramp marketed to career-changers, get a cert, ride a 3.5-4.8 million job shortage into a fast hire, mischaracterizes what that shortage actually is. It's real at the aggregate, experienced level, and largely illusory at the entry level: employers report feeling understaffed while simultaneously not budgeting for, recruiting for, or training entry-level hires.
Layer an AI headwind on top: the Tier-1 SOC work that used to be the standard first job is exactly what security AI tooling is being built to absorb. The honest framing is that the destination is real, but the on-ramp is narrower and slower than advertised, and by most accounts getting narrower, not staying still.
We're keeping our current training partnership for this path because certs and hands-on skill are genuinely valued by hiring managers, per their own research. They're just not sufficient alone the way a lot of marketing implies.
Worth it if
- • People willing to build general IT, helpdesk, or sysadmin experience first, rather than jumping straight to a "security analyst" title with no IT background at all.
- • People who treat certs as a door-opener paired with real hands-on skill (home labs, CTFs, Wireshark, Splunk, scripting), not a credential that alone closes the deal.
- • People targeting a realistic 6-18 month runway, not a 12-16 week bootcamp-to-six-figures timeline.
Look elsewhere first if
- • Anyone expecting a single entry cert, with zero IT background, to produce a fast six-figure hire. The current hiring data doesn't support that pathway at scale.
- • Anyone not prepared for AI increasingly absorbing the Tier-1 triage work that used to be the standard entry point.
Quick Answers
Is there really a cybersecurity talent shortage?
Yes and no. The widely cited 4.8 million global "workforce gap" is real, but ISC2's own methodology describes it as employers' perceived staffing need from surveys, not a count of actual open entry-level jobs. It's weighted toward mid and senior roles. Meanwhile only 17% of employers actively recruit entry-level talent, and 31% made zero entry-level hires in the prior year despite reporting a shortage. A CISA cybersecurity advisor has publicly called the shortage narrative partly a myth, driven more by pay and job-fit issues than a true talent void.
Is CompTIA Security+ enough to get hired?
Not alone. It's genuinely valued, the second most requested certification in US cybersecurity postings, but it's consistently described as the minimum needed to be taken seriously, not a credential that closes the deal by itself. Pairing it with real hands-on skill (home labs, CTFs, tools like Wireshark or Splunk) is what employers describe actually looking for.
How do I get started in cybersecurity with no experience?
The most consistent advice across practitioner sources: build general IT, helpdesk, or sysadmin experience first rather than aiming straight for a security analyst title, then layer on a cert and demonstrable hands-on projects. Employers say they're open to candidates with IT-only experience or entry-level certs alone, but actual job postings often still ask for 2-6 years of experience, so budget for a real search, not a fast one.
Is cybersecurity oversaturated?
Not at the senior level, where real demand and a 29% projected growth rate through 2034 hold up. At the entry level, it's more competitive than the shortage headlines suggest: only 11% of the global cyber workforce is under 30, and AI tools are increasingly absorbing the Tier-1 SOC work that used to be the standard first job.
Sources (7)
- ISC2, 2025 Cybersecurity Workforce Study, isc2.org
- ISC2, 2025 Cybersecurity Hiring Trends Study, isc2.org
- AFCEA Signal, "Is the Cyber Workforce Shortage a Myth?", afcea.org
- BLS Occupational Outlook Handbook, bls.gov/ooh/computer-and-information-technology/information-security-analysts.htm
- UK Cyber Security Skills in the Labour Market report, 2025
- CyberSeek certification and job-posting data
- Cert-prep and cybersecurity training marketing pages, reviewed directly
Ready to see where you fit, with real numbers either way?
Take the free career-path quiz