Workforce research published in 2025 puts the global cybersecurity staffing gap at a record 4.8 million unfilled roles, a 19% increase year on year, with 88% of surveyed professionals reporting staffing shortages in their own organisations.
This Corpus Has Been Describing The Consequence For 300 Files
The key rotation nobody completed at 25-0723. The connected-application inventory nobody maintains at 25-1207. The volumetric alerting that would have caught 300,000 bulk downloads at 25-0612. The support portal exempted from multi-factor at 25-0105.
None of those failures required an unknown technique or an unavailable product. Each required somebody with time to notice, decide and act. The corpus has consistently filed them as organisational failures; this file records that they are frequently the same failure, which is that nobody was there.
The Number Should Be Handled Carefully
It comes from survey research, largely published by professional certification bodies with a direct commercial interest in a large and growing skills gap. "Unfilled roles" is a modelled estimate, not a count of open requisitions.
This desk applies the same discount here that it applies to vendor telemetry at 26-0513 and to leak-site counts at 25-1230. A dissenting view is filed separately at 25-1102 and is worth reading against this.
What Survives The Discount
The 88% figure — practitioners reporting shortages in their own teams — is a weaker claim than a global modelled gap and a more useful one. It is a description of what people observe where they work, and it does not depend on anyone’s model.
The direction is not seriously contested. The magnitude is a marketing artefact and should not be quoted as though it were measured.
Built on published workforce research, listed below, which is survey-based with self-selected respondents and, in places, commercially motivated. Corrections: corrections@forensicpost.com.