Cybersecurity's Hiring Crisis Fuels Cybercrime Talent Pipeline
This opinion piece argues that the cybersecurity industry's hiring practices are inadvertently fueling the cybercrime talent pipeline. Despite widespread claims of a skills shortage, many capable candidates with certifications, home labs, and practical experience are rejected for lacking 'commercial experience' or due to AI-driven applicant tracking systems. The article contends that cybercriminal communities offer lower barriers to entry, providing mentorship and practical opportunities that legitimate employers often withhold. It calls for skills-based hiring, apprenticeships, and portfolio-based evaluations to open pathways into the profession, warning that every rejected candidate represents lost defensive capacity and potential recruitment into cybercrime. Key signal: Over 5,000 claimed ransomware attacks in 2026 alone, partly fueled by aspiring cybersecurity professionals pushed toward cybercrime due to hiring barriers. For hiring leaders, this matters because for CHROs and TA leaders, this story challenges the conventional narrative of a cybersecurity talent shortage. It suggests that the real issue may be overly restrictive hiring practices that exclude capable candidates, exacerbating the shortage and even contributing to cybercrime. The piece highlights the need to rethink entry-level hiring, moving away from experience-based filters toward skills-based assessments. For organizations struggling to fill cybersecurity roles, this offers a strategic imperative: invest in structured pathways, apprenticeships, and practical evaluations to tap into a broader talent pool. Ignoring this could mean losing talent to the very threats they aim to defend against. Teksands view: The cybersecurity industry is its own worst enemy. We scream about a talent shortage while our ATS filters out the very people who could fill the gap. The 'experience paradox' is real: you can't get a job without experience, and you can't get experience without a job. Cybercrime groups don't care about your CV; they care about what you can do. That's a wake-up call. If you're serious about closing the cybersecurity gap, stop gatekeeping and start skills-based hiring. Build apprenticeships, use practical assessments, and give juniors a chance. Otherwise, you're not just losing talent—you're feeding the adversary.
Key fact
Over 5,000 claimed ransomware attacks in 2026 alone, partly fueled by aspiring cybersecurity professionals pushed toward cybercrime due to hiring barriers.
Why it matters
For CHROs and TA leaders, this story challenges the conventional narrative of a cybersecurity talent shortage. It suggests that the real issue may be overly restrictive hiring practices that exclude capable candidates, exacerbating the shortage and even contributing to cybercrime. The piece highlights the need to rethink entry-level hiring, moving away from experience-based filters toward skills-based assessments. For organizations struggling to fill cybersecurity roles, this offers a strategic imperative: invest in structured pathways, apprenticeships, and practical evaluations to tap into a broader talent pool. Ignoring this could mean losing talent to the very threats they aim to defend against.
The Teksands point of view
The cybersecurity industry is its own worst enemy. We scream about a talent shortage while our ATS filters out the very people who could fill the gap. The 'experience paradox' is real: you can't get a job without experience, and you can't get experience without a job. Cybercrime groups don't care about your CV; they care about what you can do. That's a wake-up call. If you're serious about closing the cybersecurity gap, stop gatekeeping and start skills-based hiring. Build apprenticeships, use practical assessments, and give juniors a chance. Otherwise, you're not just losing talent—you're feeding the adversary.
Got a tech role that's refusing to close?
Send us the JD. We'll tell you whether the problem is talent supply, compensation, location, process - or the JD itself.