Workforce research for 2025 reports that budget cuts overtook talent scarcity as the primary driver of security staffing shortages, with 33% of organisations saying they lack the budget to staff their teams adequately and 29% saying they cannot afford people with the skills they need.
That Is A Different Problem With A Different Remedy
A skills shortage is addressed by training, certification, apprenticeships and immigration policy. It is a supply problem, it takes years, and it produces a large industry of people offering to solve it.
A budget shortage is a demand problem. The people exist and are available; organisations have decided not to buy them. No amount of training changes that, and the entire apparatus built around the skills-gap framing is aimed at the wrong side of the market.
It Also Reframes Most Of This Database
This corpus has repeatedly filed the funding argument on the public side: water districts at 26-0729, county governments at 25-0918, school boards at 26-0228. The framing there was that public bodies cannot raise money the way commercial organisations can.
This file says commercial organisations are also declining to spend — not because they cannot, but because security staffing competes with everything else and loses. The forty-partner law firm at 25-0910 that let its cyber cover lapse was making the same decision as a county, for different reasons.
And It Makes The Compliance Argument Weaker
The regulatory files at 25-1121 and 25-1124 assume that obligations change behaviour. An obligation lands on an organisation that has already decided it cannot afford the staff to meet it.
The corpus filed this at 25-1223 as the gap regulation cannot close: a duty without capacity produces non-compliance, not security. This is the evidence for that claim rather than the assertion of it.
The Caution
Graded medium. This is self-reported cause attribution: organisations asked why they are understaffed, choosing between options offered by the survey. "We could not afford it" is a more comfortable answer than "we could not find anyone", and the shift may partly reflect that.
Built on published workforce research, listed below. Cause attribution is self-reported by survey respondents. Corrections: corrections@forensicpost.com.
- 2025 ISC2 cybersecurity workforce studyISC2
- AI isn’t solving cybersecurity workforce woesCybersecurity Dive