Special Reports
A special report is content that is edited and produced by the special reports unit within The Irish Times Content Studio. It is supported by advertisers who may contribute to the report but do not have editorial control.

The evolving cyber workforce and the gap between skills and demand

How organisations can attract, develop and retain the talent needed to meet rapidly evolving cyber threats

AI is changing the skills that organisations need from their cybersecurity teams. Photograph: Getty Images
AI is changing the skills that organisations need from their cybersecurity teams. Photograph: Getty Images

The ISC2 Cybersecurity Workforce Study 2025 reports a gap between the cybersecurity skills organisations require and those available in the labour market. The study highlights growing demand for expertise in areas including cloud security, incident response and AI-related security.

In recent years, the cybersecurity skills challenge has shifted from a general shortage of people with cyber and STEM skills to a more focused shortage of specific capabilities, says Diarmuid Curtin, EY Ireland cyber consulting partner. “Most recently, through rapid advances in frontier AI, we are seeing the intersection of technology and threat activity moving at pace. This is increasing the demand for security engineering, incident response, cloud security and AI-related security.”

These skills require more than technical knowledge, Curtin says; they require people who can apply expertise in complex business and critical sectors, make decisions under pressure and work across multidisciplinary teams in technology, legal, operations and leadership areas. “Market forces are shaping this demand as organisations respond to emerging technologies, evolving threats, control gaps and increasing regulatory expectations related to AI.

“In many cases, this is not simply creating demand for new skills but also driving the need for teams that have expertise in cybersecurity, AI, data, cloud and risk management.”

Áine Clarke, digital and AI policy executive at Ibec
Áine Clarke, digital and AI policy executive at Ibec

Evidence points to both a volume shortage and a specific skills gap, says Áine Clarke, digital and AI policy executive at Ibec. “Cyber Ireland has estimated that the industry requires an additional 1,000 people per year to be trained or recruited to meet projected demand, with 48 per cent of surveyed firms having open or unfilled security roles, and nearly 20 per cent of roles taking six months or longer to fill; 34 per cent of respondents cited a lack of specific technical skills as the primary reason open roles remain unfilled.”

Changing skill sets

AI is certainly changing the skills that organisations need from their cybersecurity teams, Clarke says. “As AI becomes more widely adopted across the economy, cybersecurity professionals need not only traditional security expertise, but also an understanding of AI systems, data governance and emerging regulatory requirements.

“The pace of AI adoption highlights why these skills are becoming increasingly important. Recent CSO data shows that more than 20 per cent of Irish enterprises were using AI in 2025, up from just 8 per cent in 2023, while almost six in 10 large enterprises had adopted AI technologies.”

As AI becomes a bigger part of everyday business operations, Clarke says the role of cybersecurity teams is evolving. “They are increasingly expected to secure AI systems, safeguard sensitive data and help organisations manage the new risks that come with the technology. That means employers need cyber professionals who can both use AI to improve security and understand the governance, privacy and regulatory issues it can create.”

Organisations that attract and retain the best people are those that offer meaningful responsibilities, ongoing professional development, clear leadership direction and the opportunity to operate in a well-supported cyber environment, Curtin says.

Diarmuid Curtin, cyber consulting partner at EY Ireland
Diarmuid Curtin, cyber consulting partner at EY Ireland

“Organisations need to consider traditional hiring channels such as universities, colleges and experienced cyber professionals. However, they also need to look beyond these channels and create alternative entry pathways through internships, graduate programmes, apprenticeships, career conversion routes and internal mobility programmes.”

Employee retention is equally, if not more, important, Curtin says. “Leaders need to address workload, burnout and meaningful career progression across all levels. This means looking at automation and tooling to reduce repetitive work, allocating and protecting time for learning and certification and creating clear career pathways, ensuring that professionals feel both seen and heard.”

Many organisations also recognise that they do not need to build every capability internally, and for some, it makes sense to focus on developing strategic and business critical skills in-house while using external partners to provide specialist expertise and support in other areas, he says.

Internal upskilling

While businesses increasingly recognise the strategic importance of upskilling, they must balance an urgent need for digital and cybersecurity skills with ongoing cost and time constraints, says Clarke. “Ibec’s 2025 Skills Survey identified a clear ‘preparedness gap’ between large organisations and smaller firms, with resource-constrained SMEs often prioritising immediate operational and compliance training over strategic digital and cybersecurity skills development.”

Investment challenges are not limited to SMEs, Clarke says. “A May 2026 Saros Consulting report found that while half of organisations with more than 250 employees increased cybersecurity spending, one quarter reduced investment, highlighting the inconsistent nature of cybersecurity investment even among larger firms.”

Aside from cost and time constraints, Clarke says employers also face broader barriers to recruiting and retaining cybersecurity talent. “Cost of living and infrastructure and housing constraints can make Ireland a challenging environment for attracting and retaining mobile, highly sought-after global cybersecurity talent.”

Technical expertise remains essential, particularly in areas such as AI, cloud security, security engineering and risk assessment, which ISC2 identifies as priority skills, says Curtin. “However, cybersecurity is now directly connected to business continuity and resilience, regulatory alignment, customer and citizen trust, third-party risk and executive decision-making.

“Therefore, leading cyber professionals will be those who combine deep technical capability with business context, clear communication and strong risk management skills. Organisations should build these broader skills into cyber career pathways, leadership development and day-to-day engagement across the business.”


IN THIS SECTION