A recent announcement from Fortinet revealed concerning data regarding the ongoing challenge of the global cybersecurity skills shortage. The report, titled “2024 Global Cybersecurity Skills Gap Report,” emphasises the detrimental impact this lack of qualified professionals is having on organisational security postures.
Fortinet’s findings paint a stark picture. Nearly 90% of surveyed organizations reported experiencing at least one security breach within the past year, and a significant portion (87%) attributed these incidents, at least partially, to a deficit in cybersecurity expertise. This figure represents a concerning upward trend from previous years, highlighting the growing vulnerability organizations face due to the talent gap.
The report delves deeper, exploring the specific causes of these breaches linked to the skills shortage. The top three factors identified were:
- Lack of necessary skills and training among IT security staff (61%): This finding underscores the critical need for ongoing professional development and up-skilling initiatives within IT departments. Security threats are constantly evolving, and a failure to equip staff with the latest knowledge and techniques leaves organizations exposed.
- Lack of organisational or employee security awareness (63%): A well-informed workforce is a crucial line of defence against cyberattacks. Phishing scams and social engineering tactics often rely on a lack of awareness to trick employees into compromising sensitive information or systems. Organizations must prioritise robust security awareness training programs to educate staff on best practices and potential threats.
- Insufficient cybersecurity products (59%): While skilled personnel are essential, they also require the right tools to effectively defend against cyberattacks. This highlights the importance of organizations investing in appropriate security solutions that complement and enhance the capabilities of their security teams.
The financial repercussions of these security breaches are significant. The report indicates that over half (50%) of respondents experienced losses exceeding $1 million USD due to a breach in 2023. This figure has steadily climbed in recent years, further emphasising the urgent need to address the cybersecurity skills gap.
Fortinet’s announcement also explores the growing recognition of cybersecurity as a top priority at the board level. There is a clear demand from executives for increased investment in IT security headcount. This highlights a shift in corporate perception, with cybersecurity no longer viewed solely as an IT concern but a critical business risk that requires strategic direction and resource allocation.
The report underscores the importance of certifications in validating an individual’s cybersecurity skillset. A staggering 90% of business leaders surveyed indicated a preference for hiring candidates with technology-focused certifications. Additionally, 90% of respondents expressed a willingness to financially support employees pursuing cybersecurity certifications. This demonstrates a strong commitment from employers to bridge the skills gap through targeted training and development programs.
Fortinet’s findings offer valuable insights for organizations seeking to improve their cybersecurity posture in the face of a persistent skills shortage. By prioritising employee training, fostering a culture of security awareness, investing in appropriate security solutions, and attracting skilled personnel through competitive compensation and professional development opportunities, organizations can mitigate the risks associated with the cybersecurity skills gap. The announcement serves as a call to action for both employers and employees, emphasising the shared responsibility in building a more secure digital landscape.



