ISC2's 2023 Cybersecurity Workforce Study put the global talent shortfall at 4.8 million unfilled cybersecurity roles. That is not a rounding error or a projection. It is a count of positions that organisations are actively trying to fill and cannot. The gap has grown every year for the past decade, and there is no credible scenario under which it closes through hiring alone in any timeframe that matters for current security programmes.

The talent gap is not evenly distributed across security disciplines. The hardest roles to fill are the most technical ones: penetration testers, threat hunters, incident responders, and security engineers with cloud and application security depth. These are also the roles that most directly determine whether an organisation's security programme is actually finding and closing vulnerabilities, or just producing compliance artefacts.

67% of teams are understaffed by their own assessment

The ISC2 study asked security professionals whether their teams had the headcount needed to adequately protect their organisations. 67% said no. This is a self-assessment, which means it understates the problem — teams that don't know what they're missing can't report the gap. The number of organisations with significant unidentified capability gaps is certainly higher than the 33% who reported being adequately staffed.

The understaffing finding matters because of what it means for programme quality. A security team that is short-staffed does not run a reduced version of the same programme. It runs a fundamentally different programme — one in which the highest-effort, highest-value activities are the ones most likely to be deferred, deprioritised, or dropped entirely when the team is at capacity responding to incidents or producing compliance reports.

4.8M
Unfilled cybersecurity roles globally (ISC2 Cybersecurity Workforce Study 2023)
67%
Of security teams report being understaffed relative to the protection their organisation needs
48%
Of security roles take six months or more to fill, leaving gaps unaddressed for extended periods

Where the time actually goes

The talent gap is compounded by a second problem: the time allocation of the security professionals who are employed. Research consistently shows that security analysts spend approximately 40% of their time on tasks that do not require security expertise — primarily report writing, meeting preparation, ticket processing, and administrative overhead.

For penetration testers specifically, the ratio is even more extreme. The typical breakdown of a traditional penetration testing engagement is roughly 30% active testing, 70% documentation, report writing, and communication. A skilled penetration tester who is capable of finding complex chained vulnerabilities in a sophisticated environment spends most of their working time formatting Word documents and writing executive summaries.

The six-month vacancy problem. 48% of security roles take six months or more to fill from the time the position is opened. During those six months, the work that role was intended to do either doesn't happen or falls on the existing team members, who are already at capacity. The effective talent gap is not just the unfilled positions at any given moment — it is the cumulative capability shortfall across all the months those positions remain open.

The multiplication effect of automation

The logical response to a talent shortage is to make existing talent more productive. In security testing specifically, automation and agentic systems provide approximately three times the output per analyst hour compared to manual testing alone. That is not because automation replaces the analyst's judgement — it is because automation handles the tasks that consume 70% of the analyst's time without requiring their judgement at all.

Report generation, finding documentation, compliance framework mapping, CVSS scoring, and remediation guidance are tasks that follow deterministic rules once a finding has been identified. An agentic testing platform that produces structured findings can generate compliant output for all of these tasks automatically. The analyst's time is then available for the work that actually requires expertise: reviewing complex attack chains, assessing business context, and making judgements about risk that cannot be reduced to a formula.

The constraint is not the number of security professionals. It is the percentage of their time spent on work that requires them.

India's specific talent challenge

India has over a million unfilled cybersecurity roles. The education pipeline produces graduates with theoretical security knowledge but limited hands-on experience with the specific techniques, tools, and frameworks that enterprise security programmes require. The experience gap at the junior level means that mid-career professionals are in permanent high demand, that senior professionals are overextended managing teams that need closer supervision than they can provide, and that the effective capacity of the security industry is significantly lower than the headcount numbers suggest.

For Indian financial services entities specifically, the RBI and CERT-In regulatory requirements create a floor of security programme activity that must be maintained regardless of team capacity. The compliance work is non-negotiable; the proactive security work — threat hunting, continuous testing, attack surface management — is what gets deferred when teams are at capacity. Automation that handles the compliance output enables teams to spend more of their available hours on the proactive work that compliance requirements were designed to incentivise.

Close your security gaps — continuously.

Arxiis runs the full penetration testing workflow autonomously — discovery, exploitation, reporting, compliance mapping — so your security team can focus on decisions that require human judgement. The output is board-ready in hours. The coverage is continuous.