Cybersecurity needs 4,7 million professionals

December 2024 Information Security

Despite all the efforts organisations worldwide put into preventing cyberattacks, global cybercrime has snowballed to $9,2 trillion in 2024 and is expected to grow by another 70% to $15,6 trillion by the end of a decade. This figure is even more worrying given that companies across the sectors worldwide hire only half of the cybersecurity staff they need to keep their organisations secure.

According to data presented by AltIndex.com, the global cybersecurity workforce hit 5,4 million in 2024, yet companies lack another 4,7 million professionals to keep their businesses secure. The workforce gap is growing 190 times faster than the global cybersecurity workforce.

Cyberattacks, including ransomware, data breaches, cyber espionage, and phishing, continue inflicting trillions of dollars of damage to companies worldwide. This cost includes stolen money, damage and destruction of data, lost productivity, theft of intellectual property and personal or financial data, post-attack return to the ordinary course of business, and reputational harm.

According to the 2024 ISC2 Cybersecurity Workforce Study, companies worldwide employ over 5,4 million cybersecurity professionals, but this number is far from what they need to keep their organisations secure. Moreover, the number of hired cybersecurity professionals increased by a minor 0,1% year-over-year, showing cybersecurity workforce growth has slowed for the first time in six years.

On the other hand, the global cybersecurity workforce gap saw bigger growth, with cost-saving cutbacks, economic uncertainty, artificial intelligence (AI), and a challenging threat landscape as key driving forces. The ISC2 figures show the total number of professionals needed to secure organisations adequately surged by 19% in a year, and hit an all-time high of 4,7 million. That is nearly twice the growth rate reported a year before.

In global comparison, Asia-Pacific is the region hit the worst by the lack of cybersecurity professionals. Statistics show Asian companies need roughly 3,3 million professionals to keep their business secure, 26% more than last year and 2,5 times more than all other regions combined. The cybersecurity workforce gap in North America is much smaller and stands at around half a million, while Europe lacks more than 400 000 cybersecurity professionals.

Lack of budget is the top cause

The ISC2 survey also showed that a lack of budget is the key driver of the global cybersecurity staffing shortage, with nearly 40% of surveyed organisations needing more money to complete their cybersecurity teams. Unfortunately, that is unlikely to change, with over one-third of companies across sectors planning further cybersecurity cutbacks next year.

Besides lacking enough cybersecurity professionals, one-third of companies also tackle finding people with the right skills to meet their goals. The lack of competitive wages was the third key reason for the staff shortage, with a 28% share among respondents.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
Cybersecurity a challenge in digitalising OT
Kaspersky Information Security Industrial (Industry)
According to a study by Kaspersky and VDC Research on securing operational technology environments, the primary risks are inadequate security measures, insufficient resources allocated to OT cybersecurity, challenges surrounding regulatory compliance, and the complexities of IT/OT integration.

Read more...
Cybersecurity in South Africa
Information Security
According to the Allianz Risk Barometer 2025, cyber incidents, including ransomware attacks, data breaches and IT outages, are now the top global business risk, marking their fourth year at the top.

Read more...
Are AI agents a game-changer?
Information Security
While AI-powered chatbots have been around for a while, AI agents go beyond simple assistants, functioning as self-learning digital operatives that plan, execute, and adapt in real time. These advancements do not just enhance cybercriminal tactics, they may fundamentally change the battlefield.

Read more...
Disaster recovery vs cyber recovery
Information Security
Disaster recovery centres on restoring IT operations following events like natural disasters, hardware failures or accidents, while cyber recovery is specifically tailored to address intentional cyberthreats such as ransomware and data breaches.

Read more...
Back-up securely and restore in seconds
Betatrac Telematic Solutions Editor's Choice Information Security Infrastructure
Betatrac has a solution that enables companies to back-up up to 8 TB of data onto a device and restore it in 30 seconds in an emergency, called Rapid Access Data Recovery (RADR).

Read more...
The rise of AI-powered cybercrime and defence
Information Security News & Events AI & Data Analytics
Check Point Software Technologies launched its inaugural AI Security Report, offering an in-depth exploration of how cybercriminals are weaponising artificial intelligence (AI), alongside strategic insights defenders need to stay ahead.

Read more...
The deepfake crisis is here and now
Information Security Training & Education
Deepfakes are a growing cybersecurity threat that blur the line between reality and fiction. These AI-generated synthetic media have evolved from technological curiosities to sophisticated weapons of digital deception, costing companies upwards of $600 000 each.

Read more...
What does Agentic AI mean for cybersecurity?
Information Security AI & Data Analytics
AI agents will change how we work by scheduling meetings on our behalf and even managing supply chain items. However, without adequate protection, they become soft targets for criminals.

Read more...
Phishing attacks through SVG image files
Kaspersky News & Events Information Security
Kaspersky has detected a new trend: attackers are distributing phishing emails to individual and corporate users with attachments in SVG (Scalable Vector Graphics) files, a format commonly used for storing images.

Read more...