I've been sitting in cybersecurity conversations since before cybersecurity was cool.
Growing up, my father ran a data forensics company and spent many years in cybersecurity, ultimately becoming a CISO. So while the rest of the world still pictured a hacker as a hoodie in a basement, the dinner-table talk I grew up on was breaches, budgets, and board reports. I watched this field for 20 years go from an afterthought that nobody wanted to fund to the thing that keeps every boardroom awake at night.
We even had a joke as a family that “Dad won’t be around for the holidays” because that's when all the major ransomware attacks would happen.
Now I sit on the other side of the table with the CISOs, helping organizations figure out who and what they can actually trust. Interestingly enough, that seat has taught me something the industry doesn't love to say out loud: somewhere along the way, we started confusing tenure with trust.
We say we can't find people, then bolt the door behind us
Talk to anyone trying to break into security right now. They’ve done everything they were told to do. They know all the acronyms, have taken all the courses, and passed the exams. However, they are now caught sending out hundreds of applications daily just to find an inbox full of rejection.
Meanwhile the same industry recites its favorite line “millions of unfilled roles, a talent shortage of crisis proportions.” Both things are true at once, and that's the part that should bother us. We've built a field so obsessed with keeping the wrong people out that we've made it nearly impossible for the right ones to get in.
We got so good at security that we secured ourselves against our own future. That's not caution. That's shortsightedness wearing a compliance badge.
Related:


Credentials became a security blanket for the hiring manager
For the most part, I believe in credentials. They signal effort, baseline knowledge, and a willingness to do the work, which is important when you need to trust people to secure your organization's environment.
However, somewhere along the line, credentials stopped being a signal and became a shield for the hiring manager. A certification on a résumé has quietly turned into a risk-mitigation checkbox, a way to say "no one can blame me for this hire or a security incident" if things go sideways.
The problem is that some of the sharpest people I've ever watched in a room don't map cleanly to an exam. They have judgment, instinct, the ability to read a threat and a boardroom in the same breath. Additionally, for those trying to break into the industry, they simply have not been around long enough to acquire all the credentials and experience.
Reducing trust to a credential is a shortcut and ironically… shortcuts in security are exactly the thing we warn everyone else against.
AI is wiping out the bottom rung of the ladder
Here's what makes this moment genuinely hard for the next generation, plain and simple, the traditional way of breaking into cybersecurity is disappearing.
The entry-level path has always run through the repetitive work: L1 SOC triage, alert enrichment, first-line monitoring. That work is exactly what today's automation is becoming "good enough" at. When companies adopt that automation, they rarely do it to make an analyst's life easier, they’re doing it to depend on fewer analysts.
Recent workforce research bears this out, among organizations already reshaping roles around AI, a striking share are cutting SOC and analyst positions outright. Those are the roles where practitioners are made and where you learn what an alert actually means and why it matters to a specific business.
Cut the bottom rungs and you don't just lose entry-level jobs. You stop producing the seniors everyone will be desperate for in five to ten years. It's the same anxiety I hear over and over from people trying to get in: the door was already heavy, and now the handle is being cut off through automation.
I also want to note, I’m not against AI SOC’s but there needs to be an alternative for those trying to break in. Maybe we model the trades and start requiring apprenticeships.
The top of the ladder is on fire, too
You'd think the answer is "just aim higher", but look at the top of the field and it's no better.
There's been a real uptick in open CISO seats and that's not the good-news story it sounds like. The modern CISO is expected to absorb personal legal liability, answer to the board, general counsel, and the CFO all at once, and do it with a budget that hasn't grown to match the accountability. All of the responsibility, with almost none of the authority.
Seasoned leaders are looking at that seat and simply walking away. Worse, peer executives have begun to shun security expertise for AI-based solutions.
It seems like we are squeezing the field from both ends, pulling the ladder up on the people trying to climb it, and burning out the people already at the top.
Trust isn't something you age into
Here's what my seat on the buyer's side actually taught me. Trust isn't a function of years served. I've watched gray-haired veterans lose a room, and I've watched people half their age earn one. This is because trust comes from how you think, how honestly you communicate risk, and whether you tell someone the hard truth they didn't want to hear.
Gray hair was never the gold. It has simply been the easiest thing to measure.
If this industry truly believes it has a shortage, it has to stop treating experience as the only currency that counts and start building doors instead of locking them. The next generation is standing right outside.
We're the ones who decided that being secure meant keeping them out.

