Forge University
Industry News

The Cheapest Security Hire Is Already on Your Payroll

September 2, 2026

Randy Hall, CEO— AI-assisted and reviewed prior to publication.

An overhead office scene showing a path of light connecting a nearby desk to an empty one.

Fewer companies are training existing employees into open security roles even though unfilled positions keep climbing, and that gap is a budget decision, not an accident. Internal, certification-based upskilling costs a fraction of external recruiting, moves faster than a six-month search, and produces a candidate who already understands your systems and has already passed your background check. Leadership just has to choose to fund it before the next hiring cycle repeats the same mistake.

The operational risk compounds the longer a seat stays open. An unfilled analyst role does not just mean slower ticket resolution, it means fewer eyes on alerts, more manual work for the people covering the gap, and a widening exposure window that shows up later in an incident post-mortem. Internal mobility closes that seat with someone who understands the environment, which shortens the exposure window in a way an external hire cannot match on day one.

Why Are Fewer Companies Training Existing Staff Into Security Roles?

Because training budgets get treated as discretionary spending while recruiting budgets get treated as a fixed cost, even though the data argues the opposite. ISACA's 2025 State of Cybersecurity report found that despite more than half of cybersecurity teams reporting they are understaffed and 65 percent carrying unfilled positions, the share of enterprises training non-security staff to move into open security roles actually fell year over year, from 41 percent down to 29 percent.

That pattern would look strange in almost any other part of the business. No plant manager would leave a production line short-staffed while cutting the training budget for the warehouse workers next door who already know the facility. Yet security leaders make a version of that choice every budget cycle, because certification training gets filed under "nice to have" while a requisition for an external hire gets filed under "operational necessity." The same ISACA research found that 70 percent of security professionals expect demand for technical cybersecurity talent to keep rising, so the pressure driving this decision is not going away by itself, and neither is the cost of ignoring it.

What Does It Actually Cost to Hire a Security Analyst From Outside?

More than most budget owners assume once you count the full cycle from requisition to full productivity. The Society for Human Resource Management puts the average cost-per-hire at roughly $4,100 to $5,475 depending on the role, and that figure only covers recruiting activity. It does not include the weeks a seat sits empty or the ramp time before a new hire is actually contributing.

Cybersecurity roles make that math worse, not better. Reporting on ISACA hiring data, Dark Reading found that a large share of organizations now need three to six months to fill a cybersecurity position, and that fewer than half of applicants who apply are actually qualified for the role they are chasing. Compare that timeline against a help desk technician or network administrator who already clears your background check and already understands your environment, and just needs a structured path through a foundational credential like CompTIA Security+ to move into a junior analyst seat. The internal candidate is not free, but the total cost and elapsed time are almost always lower, and the retention math favors you too: someone you promoted has a reason to stay that an external hire has to earn from zero.

The Reskilling Gap Most Budgets Still Ignore

Most organizations do not treat internal mobility as a formal program, which is why the savings above stay theoretical for them. CompTIA's Workforce and Learning Trends research found that only 34 percent of companies have a formal, organization-wide program for reskilling or upskilling current employees, with most hiring effort still pointed at external recruiting instead of the workforce already on payroll. Tuition and certification benefits tell a similar story from the employee side. SHRM's benchmarking data shows that even where organizations offer tuition reimbursement, average employee participation sits at only about 6 percent, usually because nobody built a clear, tracked path from the benefit to a specific role and a specific raise.

That is the part a security leader can fix without waiting on a bigger headcount budget. A working internal pipeline needs three things: a named target role, a certification that maps to that role's actual day-to-day requirements, and a manager who tracks progress the way they would track any other project deliverable. Skip the third piece and tuition benefits turn into a line item nobody uses, which is exactly what the low participation numbers above show happening at scale across most employers.

How Is AI Changing Which Certifications Make Sense for an Internal Pipeline?

AI is raising the floor for what counts as job-ready, which makes a structured certification path more valuable for internal candidates, not less. ISC2's 2025 Cybersecurity Workforce Study, based on responses from more than 16,000 professionals, found that skills shortages have now overtaken headcount as the top concern among security teams, while rapid AI adoption is reshaping which skills actually matter. Budget constraints are holding roughly steady, but the skills bar for a given role keeps climbing, which means an internal candidate needs a credential that proves current, AI-aware competence rather than a generic security overview from several years ago.

Fortinet's research points the same direction from the employer side. Its global survey found that most cybersecurity professionals expect AI to make their roles more efficient, but say they need dedicated upskilling before they can use that potential, and a lack of AI skills across the team remains a real driver of risk rather than a hypothetical one. For an internal mobility program, that means the certification you choose for a career changer should account for how AI tools show up in daily security work, not only legacy fundamentals. A help desk analyst moving into security still needs the foundation first, but pairing that foundation with exposure to automated monitoring and AI-assisted triage shortens the distance between "certified" and "useful in the first ninety days."

Building the Internal Pipeline: What to Map Before You Spend

Start with a short map of current roles to target roles to the credential that bridges them, because vague reskilling goals are exactly what produces six percent participation rates.

Current RoleTarget Security RoleBridging Credential
Help desk or desktop supportJunior SOC analystCompTIA Security+
Network administratorNetwork security engineerSecurity+ plus a networking-focused credential
Systems or cloud administratorCloud security analystSecurity+ then a cloud security credential
IT auditor or compliance staffGRC analystSecurity+ then a governance-focused credential

Treat this as a starting map, not a finished curriculum, and adjust the bridging step to whatever your environment actually runs. If you want the full breakdown of exam objectives and prerequisites before committing budget to a cohort, the certification resource library walks through what each path covers and roughly how long a working professional needs to prepare for it.

Making the Business Case to Leadership

Frame the request in terms leadership already tracks: cost-per-hire, time-to-fill, and retention, not professional development for its own sake. Gartner's 2025 Leadership Perspective Survey found that CISOs are increasingly measured on driving growth and operational resilience alongside traditional risk reduction, and that security budgets for most organizations held flat or grew rather than shrank this year. That is a budget environment where a well-argued internal mobility proposal has a real chance, because it is framed as a hiring-cost offset rather than a training perk, and the external numbers above do most of the persuading for you. A CFO who sees a six-figure recruiting line and a six-month vacancy will listen to a plan that fills the same seat for the price of an exam voucher, a study plan, and a manager willing to track it.

Track the same three metrics the recruiting team already reports on: cost, time, and quality of the resulting hire. Quality is easy to measure here too, since a manager can score the internal candidate against the same job requirements used for external postings, and the certification exam itself already validates a baseline of technical competence before day one on the new team.

Start small enough to prove the model before asking for a bigger commitment. Pick one target role, one certification, and one cohort of two or three internal candidates, then track their time to competency against your last three external hires for the same role. If you want a study plan built around this, you can start training whenever you are ready, and use that first cohort as the case study for the budget conversation that follows next cycle. The data above already makes the argument. What most organizations are missing is not the justification, it is the decision to act on it before the budget closes it out again.

Start training free at Forge University