New ISACA Study Reveals Rising Job Stress in Cybersecurity Teams

cybersecurity workforce ISACA study 2025 staffing challenges AI in cybersecurity cybersecurity skills gap
Edward Zhou
Edward Zhou

CEO & Co-Founder

 
September 29, 2025
3 min read

New ISACA Study: Cybersecurity Workforce Challenges

ISACA’s State of Cybersecurity 2025 survey report reveals that 70 percent of security professionals expect the demand for technical cybersecurity professionals to rise in the next year. Despite this, 55 percent of cybersecurity teams are understaffed, and 65 percent have unfilled cybersecurity positions. Only 29 percent of enterprises are providing training for non-security staff to transition into security roles, a decrease from 41 percent last year. This is concerning as 46 percent of respondents noted that many staff had previously transitioned from other fields. For more details, visit ISACA.

Staffing and Resource Challenges

The survey indicates a high demand for technical cybersecurity professionals, but hiring and retention challenges remain significant. 38 percent report it takes three to six months to fill entry-level roles, and 39 percent report similar delays for non-entry-level roles. Additionally, half of the organizations struggle to retain cyber talent. The financial outlook is mixed, with 53 percent indicating budgets are underfunded, but only 41 percent expect budget increases. For insights on improving hiring practices, refer to ISACA Cybersecurity Resources.

Skills Gap and AI Involvement

In the evolving cybersecurity landscape, adaptability (61 percent) and prior cybersecurity experience (60 percent) are the top qualifications sought. Notably, 59 percent of respondents identified soft skills as a significant skills gap, with critical thinking (57 percent), communication (56 percent), and problem-solving (47 percent) being the most crucial. As cybersecurity teams increasingly adopt AI, 47 percent have contributed to AI governance, and 40 percent have been involved in its implementation, primarily in areas like threat detection and routine task automation. More on AI's role in cybersecurity can be found at TechRepublic.

Complex Threat Landscape and Job Stress

The report highlights a complex threat landscape, primarily characterized by social engineering attacks (44 percent), followed by exploited vulnerabilities (37 percent) and malware (26 percent). Despite this awareness, only 41 percent are confident in their incident response capabilities. Stress levels are on the rise, with 66 percent of cybersecurity professionals expressing that their roles are more stressful than five years ago, largely due to the complex threat environment. For a deeper understanding of workplace stress factors, check out ISACA's findings.

Cybersecurity in Europe

Nearly Two-thirds of Cybersecurity Pros Say Job Stress Is Growing, According to New ISACA Research

In Europe, nearly 39 percent of IT and cybersecurity professionals report an increase in cyberattacks compared to the previous year. However, confidence in readiness remains low, with only 38 percent feeling fully confident in their organizations' detection and response capabilities. This situation is compounded by 65 percent citing the complex threat landscape as a significant stressor. For further details on the European cybersecurity outlook, consult the Datamation article.

Budget and Staffing Issues

Despite some improvements, 58 percent of organizations still report being understaffed, and 54 percent say their cybersecurity budgets are underfunded. The slow progress in staffing and funding fails to align with the escalating cyber risks. 68 percent of professionals feel their jobs are more stressful than five years ago, with many citing unrealistic workloads and insufficient training as contributing factors. For more insights into the stress and hiring challenges in cybersecurity, read the full report on ISACA's website.

Retention and AI Integration

The retention of cybersecurity professionals remains a challenge, with 52 percent of organizations struggling to keep qualified staff. The integration of AI into cybersecurity is accelerating, with 51 percent of teams contributing to AI governance. AI is being utilized for threat detection (29 percent) and endpoint security (28 percent). As legislative measures like the EU AI Act advance, the urgency for stronger AI security regulation and continuous training is evident. Explore more about AI's implications in cybersecurity at ISACA and TechRepublic.

Edward Zhou
Edward Zhou

CEO & Co-Founder

 

CEO & Co-Founder of Gopher Security, leading the development of Post-Quantum cybersecurity technologies and solutions.

Related News

New Industry Report Defines Enterprise Maturity Benchmarks for Zero Trust Identity and Access Architecture
zero trust architecture maturity model

New Industry Report Defines Enterprise Maturity Benchmarks for Zero Trust Identity and Access Architecture

Discover how the new Zero Trust Maturity Model is replacing perimeter-based security with identity-centric frameworks for modern enterprise protection.

By Alan V Gutnov August 5, 2026 5 min read
common.read_full_article
Critical Ruflo MCP Bridge Vulnerability Enables Arbitrary Command Execution and AI Agent Hijacking
CVE-2026-59726

Critical Ruflo MCP Bridge Vulnerability Enables Arbitrary Command Execution and AI Agent Hijacking

Urgent: CVE-2026-59726 'RufRoot' vulnerability exposes Ruflo AI to RCE and agent hijacking. Update to v3.16.3 immediately to prevent total system compromise.

By Divyansh Ingle August 4, 2026 4 min read
common.read_full_article
Rising Endpoint Security Breaches Drive Shift Toward Zero-Trust Architectures for Global Enterprise Remote Access
zero trust architecture maturity model

Rising Endpoint Security Breaches Drive Shift Toward Zero-Trust Architectures for Global Enterprise Remote Access

Discover why Zero Trust is the new baseline for enterprise security. Learn how to combat rising endpoint breaches and secure a distributed, hybrid workforce.

By Brandon Woo August 3, 2026 5 min read
common.read_full_article
NIST Lead Andrew Regenscheid Details Strategic Roadmap for Enterprise Post-Quantum Cryptography Migration
NIST post-quantum cryptography standards

NIST Lead Andrew Regenscheid Details Strategic Roadmap for Enterprise Post-Quantum Cryptography Migration

Learn how to migrate to NIST PQC standards. Expert Andrew Regenscheid details strategies against 'harvest now, decrypt later' quantum threats in 2026.

By Alan V Gutnov July 31, 2026 4 min read
common.read_full_article