CISOs should broaden the response beyond recruiting and revisit the whole talent model. The article suggests aligning business and cybersecurity teams, creating mentoring programs, and improving how the profession is valued internally. When openings remain unfilled, the likely problem is not just candidate scarcity, but a combination of over-demand, poor incentives, and screening practices that may be too restrictive.
Why the opening is really a workforce design problem, not just a hiring problem
When cybersecurity roles stay open for too long, the useful question is not only how to source more candidates. It is whether the organisation has made the role, the compensation, and the career path attractive enough for the market that actually exists. Long vacancies often point to a mismatch between what the business needs, what the team will accept, and what the role signals to experienced practitioners.
That mismatch can show up in several ways: unrealistic screening requirements, titles that are too narrow, compensation that trails adjacent disciplines, or job designs that ask one person to cover too much ground. In practice, the vacancy persists because the organisation is trying to buy a structure problem as if it were a recruiter problem.
How CISOs should widen the response beyond recruiting
The stronger response is to treat staffing as a portfolio decision. Some work can be shifted through better internal alignment, stronger mentoring, cleaner role definitions, and more deliberate use of business partners who understand risk and operational constraints. That does not mean lowering standards. It means deciding which capabilities must be hired, which can be developed, and which can be redistributed across the function.
For many CISOs, the key move is to reduce friction for the people they want to keep and promote. If internal staff cannot see progression, if managers do not reinforce the value of security work, or if the operating model isolates the security team from the business, recruiting becomes a revolving door. A healthier talent model usually combines hiring, upskilling, retention, and clearer shared ownership of cyber outcomes.
One practical corollary is that screening should be calibrated to the actual risk profile of the role. A role that needs sound judgment, response discipline, and stakeholder communication does not always need an exhaustive checklist of tools or certifications. Overly rigid filters can exclude capable candidates who would perform well once inside the organisation.
What to change first in the talent model
Start by separating critical roles from replaceable ones. Identify where the gap creates real exposure, then decide whether the fastest risk reduction comes from hiring, contracting, cross-training, or simplifying the scope of the role itself. This is especially important when the function is under pressure from adversarial activity and persistent recruitment delays.
For context on the kind of attack pressure that makes unfilled security work consequential, teams can review CISA cyber threat advisories alongside CISA Known Exploited Vulnerabilities Catalog to keep workforce decisions tied to active exposure, not abstract headcount goals.
Where the issue is structural rather than temporary, the organisation should also look at whether the role design itself is discouraging applicants. That includes unclear escalation paths, unbounded on-call expectations, and mismatched seniority. In those cases, the fix is often to redesign the job before intensifying the search.
Risk and Threat Considerations
Vacant cybersecurity roles create more than inconvenience. They can stretch the remaining team, slow remediation, and leave known control gaps open longer than the business realises. If the hiring process is too restrictive, the organisation can also end up selecting for credentials instead of operational capability, which makes the staffing problem persist even while demand for security work stays high.
Failure mechanism: Security work piles onto a smaller number of people, response times lengthen, and management mistakes the absence of applicants for a lack of need rather than a failure in role design, incentives, or screening.
Impact: Exposure remains open longer, teams burn out faster, and the organisation becomes more dependent on a handful of overextended practitioners whose departure would create an even larger gap.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-14 — Security Awareness and Skills Training | Mentoring and internal capability-building are central to filling security skill gaps. |
| Recommendation — Build mentoring and training paths to grow scarce security capability internally. | ||
| NIST CSF 2.0 | GV.OC-01 — Organizational Context | Role vacancy decisions should reflect business context and security operating needs. |
| Recommendation — Align security staffing with business context and risk-bearing responsibilities. | ||
| NIST SP 800-53 Rev 5 | PS-7 — Personnel Sanctions | Role design and screening practices affect who is suitable for sensitive security duties. |
| Recommendation — Calibrate hiring and screening controls to the sensitivity of the role. | ||
| ISO/IEC 27001:2022 | A.6.3 — Terms and conditions of employment | Prolonged vacancies and retention issues are influenced by employment conditions and role expectations. |
| Recommendation — Review employment terms and role conditions that affect attraction and retention. | ||
Practitioner Guidance
What to prioritise: Treat prolonged vacancies as a management signal, not just a recruiting outcome. If a role has been open across multiple hiring cycles, review compensation, scope, and screening before assuming the market is the only constraint.
Decision rule: If the role is tied to high-risk work, reduce time-to-coverage first by using interim coverage, redistributing work, or narrowing scope; do not wait for the “perfect” candidate while controls remain understaffed.
What to verify: Check whether the team can actually absorb the gap without degrading response, review, or engineering support. If not, the staffing issue is already an operational risk, not a future one.
Practitioner takeaway: The best CISOs do not treat open roles as a pure recruiting metric, they treat them as evidence that the operating model, incentives, or expectations need to change.