What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Cybersecurity’s future leadership pipeline could be weakened if employers keep narrowing routes into junior work—but no available evidence can identify today’s applicants as the people who will lead security teams in 2031. What the evidence does show is a tension: UK demand for applicants with under a year of experience has fallen, even as employers report difficulty filling experienced and specialist roles. That makes the entry-level pipeline a credible workforce risk, not a settled forecast.

What the hiring evidence says about entry-level access

The UK Department for Science, Innovation and Technology’s 2026 cyber skills study describes recruitment conditions in calendar year 2025. Its job-posting analysis shows that entry-level demand has declined from its 2022 level, while mid-level experience remains common. These are UK findings, not a measure of hiring in every country.

UK core cyber job-posting measure Finding
Demand for applicants with less than one year of experience 16% in 2025, compared with 17% in 2024 and 25% in 2022
Postings requiring mid-level experience, defined as 2–6 years Nearly two-thirds, according to the report’s summary

Education requirements can also make the first rung harder to reach, although they should not be mistaken for universal prerequisites. In the same UK study, 77% of employers required at least a bachelor’s degree or equivalent for a core cyber role, and 10% asked for postgraduate qualifications. Twelve percent were open to applicants whose education was at GCSE, A-Level, or foundational level. The figures describe requirements reported in the study; they do not establish that a degree is necessary for every cybersecurity career path.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The pattern is not simply “no junior jobs, many senior jobs.” Among the 66 UK cyber businesses in the study that had hard-to-fill vacancies, 23% said entry-level staff or graduates were hard to find. In that same group, 56% reported difficulty filling experienced or senior roles, typically requiring 3–5 years, and 35% reported difficulty with principal-level roles, typically requiring 6–9 years. These percentages apply only to businesses with hard-to-fill vacancies, not all employers or all openings.

Why a weak first rung can become a leadership problem

Senior specialists and leaders usually need more than credentials: they need practice making decisions with imperfect information, communicating risk, and learning from operational consequences. Entry-level work can provide supervised exposure to those routines. If fewer people can enter and build experience, employers may have a smaller pool from which to develop future experts and managers. That is a plausible pipeline mechanism, not proof that a particular current applicant will become a leader by 2031.

ISC2 Chief Qualifications Officer Casey Marks put the workforce implication plainly: “Entry- and junior-level roles are critical for the future of the cybersecurity profession,” in ISC2’s June 11, 2025 release of its hiring trends report. The practical issue is whether employers create work and development routes that allow juniors to acquire judgment, not only whether they advertise an entry-level title.

What employers say they will consider—and what junior development takes

ISC2’s 2025 Cybersecurity Hiring Trends Report summarizes a survey of 929 cybersecurity hiring managers in Canada, Germany, India, Japan, the UK, and the US. Respondents were surveyed in December 2024. The percentages below describe managers’ stated willingness to consider candidates with a particular background; they are not a ranking of actual hires or proof that any route guarantees a job.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Candidate background considered Managers who said they would consider it
Prior IT work experience only 90%
Entry-level cybersecurity certifications only 89%
Relevant IT, cybersecurity, or computer-science education only 81%

Hiring a junior is also a training commitment. In the same ISC2 survey, 56% of managers said entry-level hires typically take four to nine months of training before handling tasks independently, and 91% said they provide early-career employees with professional development during work hours.

Managers reported assigning a mix of foundational tasks to entry-level professionals. Those reported tasks are survey results, not a universal job description:

Task reported by hiring managers Share reporting it
Documentation 43%
Alert and event management 35%
Reporting 32%
Physical access controls 30%
User awareness training 29%

These findings suggest that a degree is not the only background employers may consider, and that early-career development often involves months of supported work. They do not show that employers consistently hire through non-degree routes or that all organizations provide comparable training.

How AI could change the first jobs in security

The UK 2026 study records qualitative concern that agentic AI could take on routine security operations center tasks, potentially reducing a traditional source of junior learning. It does not measure a number of entry-level jobs already eliminated by AI. The distinction matters: automation might remove repetitive work, change the tasks juniors do, or create different duties that still require supervision. The report identifies a potential training-route risk, not a measured outcome for the workforce.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For the study’s 2025 timeframe, 70% of UK cyber security firms reported staff using AI in daily work, while 73% expected their need for AI skills to increase over the next 12 months. These are survey findings about reported use and near-term expectations, not forecasts for 2031.

A separate SANS Institute and GIAC Certifications workforce report published in 2026 summarizes a survey of 947 global respondents, primarily cyber and information-security leaders. On its report page, 60% cited skills gaps as a workforce challenge, 40% cited headcount shortages, and 74% said AI was changing team size or role structures. The report also says only 4% struggled to fill entry-level roles, with the greatest recruitment difficulty concentrated at mid-level and above. These figures use a different survey and population from the UK study and ISC2 survey; they should be read as a separate snapshot, not combined into one labor-market series.

Why shortage estimates do not settle the question

Workforce shortage figures can sound definitive while measuring different things. The US National Center for Science and Engineering Statistics’ statistical report cautions that estimates vary with data source, occupation definitions, years, and search terms. It contrasts more than 570,000 US openings estimated by CyberSeek for 2023 with more than 480,000 unfilled openings in an ISC2 estimate for the last calendar year cited in that report. Those are not directly comparable counts and should not be added or treated as movement in a single time series.

The same NCSES report points to a lack of entry-level opportunities and employers’ premium on experience. Separately, a NIST update in October 2024 described CyberSeek as a free career-seeker tool offering job titles, salaries, and credential information, and said nearly 265,000 more US cybersecurity workers were then needed to address current staffing needs. That is a historical 2024 snapshot, not a current 2026 count. Broad shortage estimates can establish pressure on the workforce, but by themselves they do not show whether the bottleneck is entry-level access, a skills mismatch, experienced hiring, or some combination.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The World Economic Forum’s 2024 Strategic Cybersecurity Talent Framework stated that there was a shortage of nearly four million cybersecurity professionals worldwide and that the deficit showed no sign of abating. That is a dated 2024 estimate, not a current measurement. Its more durable contribution is a four-part framework for building talent: attract people, educate and train professionals, recruit for the right capabilities, and retain them.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What employers can do to keep a leadership pipeline open

The evidence does not identify a single best hiring program. It does point to practical questions employers should use when designing entry routes and deciding how AI changes junior work.

Attract talent beyond one credential profile

  • Write role requirements around tasks and demonstrable capabilities, distinguishing essential qualifications from preferences.
  • Consider relevant IT experience, foundational certifications, and education as potentially different ways to show readiness, while assessing each candidate against the work to be done.
  • Make the real entry route visible, including what experience a candidate can build after joining.

Educate and train on the job

  • Budget supervisor time and structured development alongside hiring. ISC2’s reported four-to-nine-month independence timeline shows why a junior role is not simply a cheaper version of an experienced hire.
  • Use supervised operational work, documentation, reporting, alert triage, and user education as learning opportunities where appropriate to the organization’s environment.
  • Set clear milestones for increasing responsibility so that routine task completion develops into analysis, prioritization, and communication.

Recruit for capability and progression

  • Define how a junior role can lead into specialist areas such as governance and risk, security testing, or secure architecture—areas cited as hard to fill by some UK employers with vacancies.
  • Look for evidence of problem-solving, reliability, and learning alongside prior job titles. A willingness to consider a route is not the same as evidence of capability, so use work-relevant assessment.
  • Track progression and retention, not only time-to-fill for each vacancy; otherwise, an organization can fill senior roles by competing for scarce talent without developing its own future supply.

Retain useful learning work as AI changes tasks

  • Review which routine activities are being automated and what judgment, verification, escalation, and communication tasks remain for people.
  • When automation removes a task that previously taught a junior how operations work, replace the learning objective with supervised work that still exposes the person to systems, decisions, and consequences.
  • Evaluate AI skills as part of role design rather than treating automation as an assumed substitute for every junior position.

What this means for a prospective entrant

The evidence supports more than one possible way into cybersecurity, but it does not promise that any particular credential or background will secure a role. A prospective entrant can use the hiring-manager findings as a reason to build a coherent case from relevant IT experience, entry-level certification, or relevant education, then show how that preparation maps to the tasks in a specific posting. Career seekers in the US can consult CyberSeek for job titles, salary information, and credentials; NIST described it as a free tool in its October 2024 update. The information is useful for exploring routes, while the local employer and role requirements remain decisive.

For employers, the risk is not simply that a job title called “junior analyst” disappears. It is that the work, supervision, and progression that turn beginners into capable practitioners become harder to access. The title’s 2031 framing is therefore best read as a warning about decisions being made now, not a roster of future leaders already identified.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.