Forge University
Industry News

Certify or Hire? The Real Math Behind Building a Security Team

September 16, 2026

Randy Hall, CEO— AI-assisted and reviewed prior to publication.

Two paths, one long and coin-lined, one short and book-lined, converging on the same doorway

Certifying an existing employee for a security role is usually faster and cheaper than hiring one externally, once you account for recruiting spend, months of vacancy, and the retention gains of internal promotion. The exception is highly specialized or urgent-need roles, where external hiring still makes sense despite the premium.

What Does It Actually Cost to Hire a Cybersecurity Professional Right Now?

More than most leaders assume, and the gap is widening. SHRM's 2025 benchmarking data puts the average cost per hire at nearly $4,700 for a standard role, and many employers estimate the fully loaded cost, including lost productivity and ramp-up time, at three to four times the position's salary. For a $90,000 security analyst role, that math points toward a real cost well north of $250,000 before the person is fully productive.

That number assumes you can fill the role at all. CompTIA's State of Cybersecurity 2025 report found more than 514,000 U.S. job postings for cybersecurity-related roles in a single 12-month period, a 9% increase from the year before, with 81% of organizations rating cybersecurity a high priority. Priority and supply are moving in opposite directions, and time-to-fill has stretched right along with demand.

The global picture backs this up. ISC2's 2024 Cybersecurity Workforce Study put the worldwide workforce gap at 4,763,963 people, a 19.1% jump from the prior year, even as the active workforce grew by less than 1%. That is not a temporary dip you can wait out with a better job posting. It is a structural mismatch between the roles organizations need filled and the people available to fill them externally.

Is Certifying Your Current Team Actually Faster Than Hiring?

In most cases, yes, and the time savings compound with the cost savings. A certification-driven upskilling track for an existing IT generalist typically runs weeks to a few months, depending on the credential and the employee's starting point, compared to a hiring cycle that regularly stretches past the industry's already-elevated averages given how tight the qualified candidate pool has become.

You also already know the person works out. An internal candidate has a track record inside your systems, your culture, and your risk tolerance, none of which a resume or interview panel can fully verify for an external hire. That known quantity matters more in security roles than almost anywhere else in the business, because the cost of a bad fit is not just a wasted salary. It is unmonitored access sitting in your environment for months.

This is also where the CompTIA research gets specific about what leadership should actually do. CompTIA's ongoing State of Cybersecurity coverage argues that the old model of pulling mid-career infrastructure staff into security roles is not sustainable at current demand levels, and recommends organizations build a deliberate pipeline that combines early-career hiring with internal training and reskilling. That is a direct instruction to treat certification as a supply strategy, not a perk.

The Retention Case Nobody Puts in the Budget Request

Certifying your own people does not just fill a seat. It changes whether that person stays. LinkedIn's Workplace Learning Report data found that companies excelling at internal mobility retain employees for an average of 5.4 years, compared to 2.9 years at companies that struggle with it. That retention gap alone offsets a meaningful share of the training investment, since every year of extended tenure is a year you avoid paying the hiring costs described above all over again.

A useful way to lay this out for a budget conversation is side by side.

FactorCertify existing staffHire externally
Typical direct costExam and training fees, often under $2,000 per person$4,700+ average, often 3-4x salary fully loaded
Typical time to productivityWeeks to a few monthsMonths, longer for specialized roles
Retention impactHigher, tied to internal mobilityUnknown until after hire
Institutional knowledgeRetainedRebuilt from zero
Best fit forFoundational and mid-tier roles, scaling existing teamsHighly specialized skills, urgent single-role gaps

The table is a starting point, not a universal rule. Specialized roles, like a lead penetration tester or a cloud security architect for a platform your team has never touched, often still require external hiring because the depth of experience needed cannot be built quickly enough internally, no matter how good the training program is.

Where AI Changes the Calculation

AI is not eliminating the need for security staff, but it is reshaping which entry points into the field still exist, and that has direct consequences for how you build your bench. Automation is absorbing more of the repetitive, tier-one detection and triage work that used to be where junior analysts cut their teeth, which means the traditional "hire junior, grow them up" pathway is narrowing at exactly the moment the workforce gap is widening.

That makes internal reskilling more valuable, not less. An existing IT support technician or network administrator who already understands your environment can move into a security role through a structured certification path faster than a true outside hire can be found, vetted, and onboarded. A foundational credential like the one covered in Forge University's CompTIA Security+ certification prep is built for exactly this transition, giving generalist IT staff the baseline security knowledge to take on real responsibility without a multi-year detour through a degree program.

If your organization is weighing where to start, it helps to see the full range of what a structured path actually covers before committing budget. Forge University's certification resources hub walks through curriculum breakdowns and common questions for each track, which is useful when you are building the internal case for training spend rather than a new requisition. And if you already know which people you want to move into security roles, you can start training them on a defined timeline rather than waiting on an open req to close.

How Should Leadership Decide Which Path Fits Which Role?

Use certification-driven internal moves for roles where the skill can be taught in months and the candidate already knows your environment, and reserve external hiring for roles where deep, hard-to-teach specialization is the actual requirement. Most organizations get this backwards, defaulting to external hiring for every open security seat regardless of whether the role actually needs a stranger's expertise or just a trained insider.

The decision gets easier once you separate the question into two parts. First, does this role require specialized experience your current staff genuinely cannot acquire through training in a reasonable window, such as advanced penetration testing or incident response leadership for a novel threat class? If yes, hire externally and expect to pay the premium the SHRM and CompTIA data describe. If no, and the role is closer to security operations, compliance monitoring, or endpoint administration, a certification path for an existing employee will almost always beat the cost, timeline, and retention profile of an external search.

Boards and finance teams increasingly want this framed as a capital allocation decision, not a training nice-to-have. The numbers now exist to make that case in plain terms: a workforce gap that is not closing, hiring costs that keep climbing, and retention data that rewards organizations willing to build rather than only buy. Treating certification budgets as a hiring alternative, not a separate line item competing for scraps, is the strategic shift that data actually supports.

Start training free at Forge University