Solving the Cyber Security Skills Crisis: Steps for Regulated Industries

Neil Holland

~ 4min read

Arrows decoration graphic
Grid decoration graphic

~ 4min read

There are 4.8 million unfilled cyber security roles worldwide. Think of it for a moment. That’s not a shortage of budget lines or job titles; it’s a shortage of people. And according to ISC2's latest workforce study, that gap grew by 19% in a single year. The organisations most exposed to this vacuum are the ones that can least afford it: those operating in highly regulated environments where a breach doesn't just cost money. It costs trust, licence to operate, and in some cases, lives.

The data story is stark. Fortinet's 2025 Cybersecurity Skills Gap Report found that 87% of organisations experienced at least one breach in the past year, with more than half suffering financial losses exceeding $1 million. IBM's 2024 Cost of a Data Breach Report calculates that organisations with understaffed security teams pay an average of $1.76 million more per breach than their well-resourced peers. These are not abstract risks. They are the predictable, recurring cost of a skills gap that is widening faster than the talent pipeline can fill it.

> Pressure on resources is building

The nature of the problem is also shifting. For the first time in 2025, economic pressure including budget cuts, hiring freezes, and layoffs, has overtaken talent shortage as the primary driver of cyber security understaffing. The World Economic Forum's Global Cybersecurity Outlook 2025 reinforces this: 2 in 3 organisations now report moderate-to-critical skills gaps, an 8% deterioration from the year before. ISACA's 2025 State of Cybersecurity report adds that only 29% of enterprises are training staff to transition into security roles, down from 41% the previous year. This is a clear retreat when the talent pipeline needs expanding most.

For leaders in regulated industries, the skills and people shortage is not a standalone concern. It is the gateway to a set of legal and regulatory risks that are becoming increasingly difficult to navigate.

> The impact of the resource shortage

The nature of the problem is also shifting. For the first time in 2025, economic pressure including budget cuts, hiring freezes, and layoffs, has overtaken talent shortage as the primary driver of cybersecurity understaffing. The World Economic Forum's Global Cybersecurity Outlook 2025 reinforces this: 2 in 3 organisations now report moderate-to-critical skills gaps, an 8% deterioration from the year before. ISACA's 2025 State of Cybersecurity report adds that only 29% of enterprises are training staff to transition into security roles, down from 41% the previous year. This is a clear retreat when the talent pipeline needs expanding most.

For leaders in regulated industries, the skills and people shortage is not a standalone concern. It is the gateway to a set of legal and regulatory risks that are becoming increasingly difficult to navigate.

> When understaffing is a cyber-compliance failure

The regulatory landscape governing data and information security has grown both broader and more aggressive. The EU's General Data Protection Regulation (GDPR) has now levied a cumulative total of over €6 billion in fines since its introduction in 2018.

Fines include:

· In Ireland, €1.2 billion in fines was imposed against Meta Platforms Ireland Limited. The Irish Data Protection Authority has imposed two substantial fines on LinkedIn (€310 million) and again against Meta Platforms Ireland Limited (€251 million) making it the supervisory authority that has imposed the highest fines to date.

· In 2024 alone, €1.2 billion in penalties were issued across Europe.

In the UK, the Data Protection Act 2018 and UK GDPR mirror the EU framework. The Information Commissioner's Office (ICO) is empowered to issue fines of up to £17.5 million or 4% of global annual turnover. Actions include:

·  The ICO fined outsourcing firm Capita £14 million following a breach that exposed the personal data of 6.6 million people.

· £3.1 million fine was issued to Advanced Computer Software Group after a ransomware attack disrupted NHS services. The regulator citing a lack of multi-factor authentication and poor patch management as root causes. In other words, basic, preventable security hygiene failures.

Across the Atlantic, HIPAA continues to define data security obligations for US healthcare and its business associates. Penalties reach up to $1.5 million per violation category per year, and enforcement is tightening. In 2025, Solara Medical Supplies was fined $3 million for multiple breaches of electronic protected health information. Healthcare remains the most expensive sector for breach costs, averaging $10.93 million per incident according to IBM.

Emerging regulation is adding further layers. The EU's Digital Operational Resilience Act (DORA), now in force for financial entities, mandates specific ICT risk management and incident response capabilities. The EU AI Act introduces fines of up to €35 million or 7% of global turnover for the most serious violations. Regulators across jurisdictions are increasingly treating inadequate cyber security not as an accident, but as a governance failure, one for which executives can be held personally accountable.

The common thread running through these enforcement actions is not sophisticated nation-state attacks. It is organisations that lacked the skilled people and structured processes to implement and maintain basic security controls.

> A checklist for cyber security progress in regulated environments

Implementing a plan is the first-step to securing an effective and productive cyber security team. 

Download now>>

> A multi-faceted solution

The cyber security skills crisis will not resolve itself any time soon. Regulated organisations that treat it only as a talent pipeline problem will miss the point. The organisations that navigate it best will be those that combine investment in their people with clear governance, strong technical controls, and a culture in which security is understood as everyone's responsibility.

The fines are real. The breaches are serious. With leadership and planning, organisations in regulated environments can build the skills to prevent them.

Download the checklist and find out how we can help you solve the cyber security skills gap in your organisation.

> Neil Holland

Director, Global Sales and Growth

Neil stays one-step ahead of the challenges facing the industry by making relationships with customers a priority. Whether you're ready for an in-depth discussion or just want to have a general chat about new ideas and technologies, Neil is is your go-to for insight and solutions.