17.4.2026

The shortage of security specialists. Why security cannot be solved by hiring more people

When a company starts talking about an overloaded security team, the first solution is to hire more people. In cybersecurity, however, this logic now hits a hard ceiling. While attacks get ever faster, infrastructure more dispersed and traffic volumes higher than ever, security operations in many organisations still rest on manual administration, escalations and a human making decisions in the middle of an incident. As soon as the security model is built on manual work, the number of people needed to operate it grows with the infrastructure. But there are simply fewer security specialists on the market than this model would require.

Esther Idris Beshirová

Technical copywriter with several years of journalistic experience. Enjoys writing about technology and cybersecurity.

According to the 2024 ISC2 study, the global shortfall of cybersecurity workers has reached 4.8 million people. At the same time 90 % of respondents say their organisation feels a lack of security skills, and for 64 % the shortage of expertise is a bigger problem than the headcount itself.

Organisations around the world are looking for security specialists faster than the market can supply them. The situation is similar in the Czech Republic, where according to data from Czechitas tens of thousands of IT specialists have been missing for years, with the biggest deficit precisely in cybersecurity.

Meanwhile the volume of traffic and the number of attacks that security teams have to monitor and evaluate in real time keep growing. According to Cloudflare, in 2025 roughly 6 % of all internet traffic on its global network needed some form of mitigation.

For company leadership this leads to an uncomfortable conclusion. Security today cannot be strengthened sustainably just by adding more shifts, more on-call rotas and more people to the SOC. If the defence architecture itself depends on manual operation, headcount raises costs faster than resilience.

This means:

⇢ that the organisation responds to the growth of threats linearly, while attackers scale automatically and almost instantly,

⇢ that onboarding new specialists runs into the fact that companies mainly look for experienced profiles and build less of their own junior base,

⇢ that a bigger team often also means more handoffs (passing an incident or task between team members or shifts), more approvals and more waiting for decisions, not an automatically faster response,

⇢ and that at today's price of specialised roles security very quickly becomes a cost problem for the company's leadership too, not just for IT.

When you hire more people, security only rises partially

The idea that hiring will solve the security deficit sounds reasonable mainly because it is easy to measure. A position opens, a person arrives, the team grows. But security is not a production line where output can be raised simply by adding capacity. A new specialist has to find their way around historically layered rules, the logic of exceptions, approval processes and the links between tools. And that tends to be the hardest part in large organisations.

The problem also lies in the security architecture itself. Once the defence consists of many tools, appliances and vendors, every additional person adds not only expert capacity but another layer of coordination. Handoffs between teams, escalations and manual decisions multiply and slow down the response to incidents.

On top of that comes a fundamental asymmetry between attackers and defenders. Attackers can today rent a large amount of computing capacity in the public cloud within minutes and use it for automated activities such as generating bot traffic, scraping, DDoS attacks or credential stuffing. According to Cloudflare data, in 2025 roughly 14.4 % of observed bot traffic came from AWS, 9.7 % from Google Cloud and 5.5 % from Microsoft Azure. Almost a third of automated traffic thus came from just three large cloud platforms, where infrastructure can be deployed within minutes.

The shortage of people is often a consequence of a manual security architecture

Manually managed security in a hybrid organisation means that rules are maintained layer by layer and in different places of the infrastructure, the response to an incident consists of an initial assessment, escalation and a manual configuration change, lists of malicious addresses or geographic restrictions are updated continuously and the data about what is happening in the network is pieced together from several sources. Traditional hardware firewalls run into capacity limits, organisations buy more appliances, deal with their regular replacement and still struggle to keep security policies consistent.

The move to the cloud and hybrid operations adds to this. Once an organisation runs applications in the cloud, at branches and outside the traditional data centre, the number of places where security rules have to be enforced grows.

If every change or response to an incident requires a person, security grows linearly with the number of employees. Attackers and automated traffic, however, grow much faster. In 2025, for example, Cloudflare also recorded extremely large DDoS attacks exceeding 1 Tbps, with peaks of up to 31.4 Tbps. That is a reality that cannot be handled manually in the long run.

What this means in practice, even if you have a CISO and a SOC

In a corporate environment these difficulties show up as slower responses, higher error rates and a growing dependence on a few people who understand a specific configuration. NIST describes a continuous cycle of detection, analysis and response in its incident response methodology; in a real SOC that means alert triage, incident confirmation, escalation and only then intervention. If protection is based on manually driven changes, this process is inevitably slower than a scenario where known types of attacks are mitigated automatically.

The gap between the speed of an attack and the speed of the response is no longer theoretical. Splunk's State of Security 2023 puts the average incident response time at around 15.5 hours. CrowdStrike's 2024 report, by contrast, puts the average breakout time (the time an attacker needs after a breach to move laterally in the network) at 62 minutes.

According to Splunk research, 59 % of security operations teams face too many security alerts, 55 % too high a share of false positives and 57 % lose time because of problems with data and tools. The result is that even a well-staffed team can respond slowly.

#4: Automation does not lower quality. It lowers dependence on people

Automation is not a replacement for expertise but a way of not wasting it on routine operations. Repeatable and time-sensitive scenarios should be handled by the system, while exceptions and more complex decisions stay with people. If rules can be managed centrally and changes propagate across the infrastructure within seconds in a cloud environment, the security team can focus on architecture, the impact of changes and the analysis of unusual incidents instead of manually managing individual appliances.

Scalable security operations rest on four principles:

  • Continuously updated rules and threat knowledge.
  • Automatic response to common scenarios.
  • A central security policy across environments.
  • A traceable audit trail.

Modern SASE and Zero Trust architectures are built on these principles today: a single control layer, visibility of traffic, event records and the ability to automate, not another layer of manual administration.

How Cloudflare solves it

Cloudflare provides a model in which security rules originate centrally in the network. Known threats are reflected in managed rules and continuously updated threat intelligence, and repeatable responses to incidents happen automatically. When rules, traffic records and visibility of what is happening in the network work within one control framework, the internal team does not have to do as much routine maintenance and can concentrate on exceptions, changes to security policies and more complex decisions.

In an environment where, by its own figures, Cloudflare processes roughly 28 million HTTP requests per second and blocks 76 billion cyber threats every day, it is obvious that such a volume of traffic could not be handled by human work without automation.

Automatic protection

The shortage of security specialists is real, but on its own it does not explain why some organisations hit their limits faster than others. What is decisive is how much security work arises only because the architecture still relies on manual intervention, local configurations and round-the-clock supervision. A more sustainable model does not lie in adding people but in routine protection running automatically while specialists handle what cannot be automated.