COMMENTARY: For more than a decade, the cybersecurity industry has told itself the same story: there aren't enough skilled people to do the work, and to fix it we need more hiring, more training programs, more pipeline investment.Every year the workforce gap gets cited again, slightly larger than the year before, as proof the strategy isn't working fast enough. Maybe it's time to consider a less comfortable explanation: the strategy was never going to work, because hiring was never the actual constraint.[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]Security operations centers (SOCs) don't have a people problem. They have a throughput problem, and the two look identical on a staffing report while being completely different in cause.Alert volume scales with attack surface — more cloud services, more endpoints, more third-party integrations, more identities to track — and attack surface has been growing exponentially for years. Headcount, even in a generous hiring environment, grows linearly at best. We cannot out-hire an exponential curve. No SOC has ever closed this gap by adding analysts faster than the alert volume grew, and none ever will, because the two are growing on different curves entirely.What that means in practice: the "shortage" isn't a shortage of qualified people. It's a mismatch between a triage workload that scales with infrastructure and a workforce that scales with budget cycles. Framing it as a hiring problem set the entire industry chasing a fix that was structurally incapable of closing the gap, no matter how much was spent on it.Where the actual bottleneck livesMost SOC analyst time doesn't go to the high-judgment work — the actual threat hunting, the incident response that requires real expertise. It goes to triage: Is this alert real? Does it matter?
The <b>cybersecurity</b> talent shortage was never real | perspective
Read the original article
scworld.com →