Both the experts and the awareness of cyber security are missing
On a global shortfall of more than four million cyber security professionals, and on what companies and states can fix immediately and for free.
The interview opens on a structural problem: cyber security demands specialised skills built through years of practice and continuous education, while educational capacity and training programmes cannot keep pace with the speed at which both technology and threats evolve. The world is short more than four million specialists, the growth in demand shows no sign of slowing, and the upside of that grim arithmetic is that information security is one of the most durable career paths available.
Companies respond with partnerships with educational institutions, internship programmes, investment in training and certification, and better working conditions. Inside BrightMarbles Group, the UN1QUELY Cyber Security Centre hit the talent wall in its first year and answered it by founding its own academy — training new people and hiring them on completion. The durable fix, however, is joint: private sector, public sector and academia building a continuous chain of education from secondary school through university to lifelong learning, so that older workers can also retrain into the field.
On regulation, protection systems have to track the laws on personal data protection, information security and data secrecy, and standards such as ISO 27001, GDPR and NIS2 — the directive that defines obligations for critical sectors from energy and transport to banking, health, water and digital infrastructure. On threats, roughly 80% of successful global attacks involve email phishing, alongside ransomware, DDoS and exploitation of software vulnerabilities. Most of that risk can be reduced or eliminated at no cost: correct account configuration, mandatory multi-factor authentication, strong passwords, and employees who can recognise a phishing email and know where to report it. What is still missing is enforcement capacity — the number of information security inspectors is too small to cover the sectors that need supervision, and GDPR showed what happens to compliance when inspection lags.
Key findings
- 01The world is short more than four million cyber security professionals, with no sign of demand slowing.
- 02Education and training capacity cannot match the speed at which technology and sophisticated threats evolve.
- 03UN1QUELY's academy inside BrightMarbles Group was founded as a direct answer to the hiring wall — train new people, then employ them.
- 04The lasting fix is a private–public–academic chain of education from secondary school to lifelong learning.
- 05Around 80% of successful global attacks involve email phishing; ransomware, DDoS and unpatched vulnerabilities follow.
- 06Most risk can be cut for free: correct account configuration, mandatory MFA, strong passwords, and staff trained to spot and report phishing.
- 07Too few information security inspectors to cover the sectors requiring supervision — GDPR showed compliance collapses when enforcement lags.