Every cybersecurity conference eventually arrives at the same conversation:
There aren't enough people. The industry needs to attract more talent. Training pipelines must expand. Deidre Diamond doesn't disagree with any of that. She simply believes the conversation starts in the wrong place.
During a recent episode of CYBR.SEC.CAST, the CyberSN founder argued that cybersecurity has become so focused on bringing new people into the profession that it often overlooks the people already doing the work.
The result is a workforce that continues to burn out faster than organizations can replace it.
Full episode and related article:


Hiring delays create hidden costs
One reason, Diamond says, is that organizations have made hiring dramatically less efficient than it once was.
Earlier in her career, placing a cybersecurity professional often took only days.
Today, even organizations with urgent needs routinely spend weeks—or months—working through recruiting workflows, approvals and interviews before extending an offer.
"We had a five-day sales cycle," she said of her early recruiting experience. Today, identifying a successful candidate within 30 days is considered exceptional.
While positions remain open, someone else absorbs the work.
That "temporary" burden frequently lasts months.
Security teams don't stop monitoring alerts because a position is vacant. Incident response doesn't pause. Compliance deadlines don't move.
Existing staff simply carry the additional load.
Over time, that extra work becomes one of the hidden contributors to burnout.
Related:


The pendulum swung too far
Diamond also believes organizational hiring structures have shifted away from the people who understand cybersecurity work best.
Hiring managers once exercised significant authority over recruiting decisions.
Today, many organizations route nearly every step through centralized HR processes designed to serve every department equally.
Those processes may improve consistency, but they often increase hiring timelines and reduce the ability to make quick, informed decisions about highly specialized technical roles.
Diamond is careful not to blame HR professionals themselves. Instead, she sees a broader organizational challenge: systems that prioritize process over outcomes.
The data, she argues, speaks for itself. Hiring takes longer. Retention remains poor. Burnout continues to rise.
Professionalizing cybersecurity
Diamond believes cybersecurity should begin borrowing workforce practices from professions where continuous development isn't optional.
Pilots maintain certifications. Engineers complete continuing education. Healthcare professionals regularly demonstrate competency. Cybersecurity, despite protecting critical infrastructure and national security interests, lacks many of those structural expectations.
Diamond told White House officials she believes organizations should eventually adopt compliance requirements around retaining and developing cybersecurity professionals, not simply hiring them.
That idea may sound ambitious, but it reflects a broader shift occurring across the industry.
Increasingly, leaders recognize that technology alone cannot solve cybersecurity's workforce problems.
Organizations also need healthier teams.
Looking beyond today's hiring crisis
Diamond sees another reason to rethink workforce strategy. The definition of the cybersecurity workforce itself is changing. Employees increasingly work alongside contractors, consultants, managed service providers and, now, AI agents capable of performing operational tasks.
That makes workforce intelligence far more important than simply counting headcount. Organizations need to understand what capabilities exist, who performs them and where gaps remain.
Without that visibility, they risk making poor hiring decisions while simultaneously overlooking opportunities to better develop the talent they already have.
"The job description," Diamond said, has become "the source of truth" not only for hiring but for understanding operational capability itself.
For years, cybersecurity has measured workforce health by the number of open positions.
Diamond argues it's time to start measuring something different: how well the industry supports the professionals who choose to stay.
Both conversations matter. But if organizations continue treating hiring as the finish line instead of the beginning of workforce development, cybersecurity's talent shortage may never truly disappear.



