Forge University
Industry News

The Hiring Freeze Is Real. The Skills Budget Just Became the Whole Strategy

September 16, 2026

Randy Hall, CEO— AI-assisted and reviewed prior to publication.

One analyst at a control desk surrounded by automated systems and empty chairs, symbolizing skills over headcount.

Security budgets are still growing, but the growth is going to tools and automation, not to new hires. If you're leading a security function in 2026, the honest answer to "how do we close the skills gap" is no longer "hire more people." It's making the analysts you already have capable of running the tools you already bought.

Why Are Cybersecurity Budgets Shifting Away From Headcount?

Because finance leaders now treat headcount as the most expensive, least flexible line in the budget, and automation as the lever that lets existing staff cover more ground. Only 45% of CISOs were able to add headcount in 2025, down from 51% in 2023 and 67% three years earlier, according to the IANS Research Security Budget Benchmark Report. Nearly half of teams reported flat headcount, and the rest saw reductions.

That is not a story of security losing budget. Global information security spending is on track to reach $212 billion in 2026, a 15% increase over 2025, according to figures compiled by StationX from Gartner's forecasts. The money is there. It's just being routed into platforms, licenses, and automation rather than salaries, because a Tanium analysis of 2025 budget planning put it plainly: automation isn't just about spending on tools, it's about spending on tools that let organizations save elsewhere, including by slowing headcount growth, as one industry expert told Tanium in its 2025 budget planning guide.

For a CISO or IT director, this is a mandate whether you asked for it or not. You're getting more capability funded through software, and you're expected to make that capability pay off with the staff already on your org chart.

What Does the Latest Workforce Data Actually Say?

It says the industry itself has stopped measuring the problem as a headcount gap. For the first time in its history, ISC2 declined to publish a global workforce shortage number in its 2025 study, explaining that respondents to the 2024 and 2025 studies have prioritized the need for critical skills as more important than the need for more people, according to the 2025 ISC2 Cybersecurity Workforce Study.

That's a real shift in how the profession's own trade body frames the problem, not a rhetorical one. It follows a year in which 59% of respondents reported critical or significant skills gaps on their teams, up sharply from 44% the prior year, per reporting on the same study, and the gaps clustered specifically around AI-driven threats, cloud security, and data governance rather than general staffing shortfalls, as one industry analysis of the 2025 ISC2 findings noted. Organizations can fill a seat. Filling the seat with someone who can operate a modern SOC stack, a cloud security posture tool, or an AI governance workflow is a different problem, and it's the one that now shows up on risk registers.

Where the Tooling Budget Actually Goes to Waste

The uncomfortable part of this shift is that tooling spend without matching skill investment doesn't just sit idle, it actively underperforms. Detection and response platforms, SIEM tuning, cloud security posture management, and SOAR playbooks all assume an operator who understands what the tool is telling them and why. When that operator isn't there, alerts pile up, automation rules go unwritten, and the licensing cost becomes sunk cost.

This is the part of the budget conversation that gets skipped in board decks. Leadership approves the platform purchase because the vendor pitch is clean and the risk story is urgent. Nobody line-items the training required to get full value out of it, and six months later the tool is running at a fraction of its intended capability. If you want a concrete look at what a skills-first curriculum for exactly this kind of role covers, the CompTIA CySA+ certification is built around the analyst work that sits directly on top of these tools: threat detection, log and behavioral analysis, incident response, and the vulnerability management workflows that automation is supposed to accelerate, not replace.

How Should Leaders Decide Which Skills to Fund First?

Start with the tools you've already paid for and the gaps that show up most often in your incident postmortems, not with a generic list of hot certifications. If your SOC generates alert fatigue, the fix is analysts who can tune detection logic and triage faster, which is a CySA+-level skill set. If your exposure is cloud misconfiguration, that's a different certification path entirely.

A few patterns hold across most mid-size and enterprise security functions right now:

  • Detection and response tooling (SIEM, EDR, SOAR) underperforms without analysts trained to configure and interpret it, which is exactly the gap CySA+ targets.
  • Cloud security posture and identity sprawl are consistently named among the hardest gaps to fill through hiring alone, per the workforce data above, which makes upskilling existing cloud-adjacent staff faster than recruiting a specialist.
  • AI governance and AI-assisted attack detection are new enough that almost nobody on your team has formal training in them yet, meaning the skill gap is uniform across your whole staff, not concentrated in one role.

None of this requires a hiring plan. It requires deciding, with some discipline, which three or four roles get funded training first and holding the line on that list instead of spreading a training budget thin across everyone.

The Business Case for Training the Team You Already Have

The math is straightforward once you frame it as capacity, not headcount. A newly hired mid-level analyst costs a full salary, months of ramp time, and still needs to learn your specific tool stack. A current employee who gets certified against a platform they already touch daily starts contributing improved detection and response almost immediately, with no ramp and no recruiting cost.

That's the case to bring to a CFO who is, per recent reporting on the shift in cyber budget ownership, increasingly the person steering the security purchasing cycle and demanding measurable return on every dollar, according to coverage of the 2025 CFO cybersecurity budget shift. Certification spend is a small, predictable, one-time cost against a tooling budget that's already been approved. It's an easier approval than a new headcount line, and it's the one lever most likely to actually move your detection and response metrics this year.

If you're building that plan for your team, a good starting point is mapping your current tool stack against the skill areas your incident reviews keep flagging, then matching each gap to a specific certification track rather than a general training budget. The Forge University resources hub has curriculum breakdowns that make that mapping easier, and if you want a study plan built around a specific role or tool gap, you can start training whenever you're ready to move past the planning stage.

What This Means for the Next Budget Cycle

Expect the headcount line to stay flat again next cycle. Expect the tooling and automation line to keep growing, because the spending data shows no sign of that trend reversing. The variable you actually control is whether the people running that tooling can use it at full capability, and that variable is decided by a training budget, not a recruiting budget.

Treat certification spend the same way you'd treat a platform renewal: tied to a specific capability gap, reviewed annually, and justified by the incident data that shows where your current team is stretched thin. That's a smaller, more defensible ask than headcount, and it's the one most likely to get approved.

Start training free at Forge University