For years, the story around cybersecurity talent in Canada has been told the same way: there aren’t enough skilled people, demand keeps growing, and the gap keeps widening. New data suggests that story is only half right, and the other half is a problem the industry may be causing itself.
Hiring Is Actually Picking Up
Start with the good news, because there is some. The Canadian Cybersecurity Network’s Q2 2026 labour market research identified 663 cybersecurity job postings during the quarter, the highest level across seven quarters of tracking and an increase of 23.7 percent from Q1. That marks three consecutive quarters of hiring growth, credible evidence that the cybersecurity employment market is recovering after a weak stretch through much of 2025.
If the conversation stopped there, it would look like a straightforward supply-and-demand story: demand is recovering, and the long-discussed talent shortage should start easing as more roles open up. But a closer look at what employers are actually asking for tells a different story.
The Shortage Has Changed Shape
The SANS Institute’s 2026 workforce report, titled “The Evolving Cyber Workforce: AI, Compliance, and the Battle for Talent,” found that for the first time in the report’s three-year history, skills gaps have decisively overtaken headcount shortages as the industry’s top workforce challenge. When organizations were asked to choose between “not having the right staff” and “not enough staff,” 60 percent identified skills gaps as the greater problem, compared to 40 percent citing staffing shortages outright. That gap has widened sharply, from just four points a year earlier to twenty points now.
This is a meaningful shift in how the industry should think about its own talent problem. It’s no longer primarily a headcount issue that more postings will solve. It’s increasingly a mismatch between the skills employers are demanding and the skills the available workforce actually has, including among people who are actively looking for cybersecurity roles right now.
Why Entry-Level Candidates Can’t Get In?
Here’s where the shortage starts looking self-inflicted. Job postings labelled “entry-level” routinely ask for SOC experience, cloud certifications, and several years working in environments that entry-level candidates, by definition, haven’t had the chance to work in yet. Candidates report a familiar and frustrating pattern: years of reports about a talent shortage and long-term demand, paired with job postings that quietly require experience no true beginner could have.
The economics of this are straightforward once named directly. A cybersecurity professional with five years of experience in 2031 needs an opportunity to gain a first year of experience in 2026. If employers overwhelmingly compete for people who already have that experience, rather than creating pathways for people to acquire it, the pipeline between education and employment narrows on its own, regardless of how many students graduate from cybersecurity programs or how many certifications get issued.
This reframes what’s often treated as purely a supply problem. Some of Canada’s cybersecurity shortage is undoubtedly a genuine scarcity of specialized expertise, particularly in areas like industrial control systems and operational technology security. But part of it may be a pipeline design problem: an industry that has built its hiring practices around finding people who already have the experience it isn’t creating enough opportunities to build.
The Stakes Are Highest in Critical Infrastructure
This isn’t an abstract workforce planning issue. It has direct consequences for the organizations Canadians depend on most. Power utilities, pipeline operators, and large industrial firms sit on the country’s list of critical infrastructure, and specialized roles like cyber risk and compliance analysts, who align operations with industrial protocols and regulatory standards, are exactly the kind of positions where the experience-first hiring pattern bites hardest.
The SANS report also found that 42 percent of organizations cite salary as a retention challenge, but 40 percent point to burnout and 31 percent highlight unclear career paths. In critical infrastructure environments, burnout isn’t simply an HR metric. It directly affects operational continuity in 24-hour environments like energy grids and manufacturing plants, where fatigue-driven errors carry real consequences. About 35 percent of organizations report moderate skills gaps affecting up to 29 percent of required capabilities, and 13 percent report major gaps exceeding 30 percent. Only 19 percent of organizations consider their security teams fully skilled.
Put together, this means even well-staffed critical infrastructure security teams are frequently operating with partial capability coverage, leaving specific operational technology or process-level risks inadequately addressed, not because the roles are empty, but because the people filling them don’t yet have every skill the role increasingly demands.
What This Means for Employers Right Now?
For organizations building or rebuilding cybersecurity teams, the practical implication isn’t to keep posting the same “entry-level, five years required” roles and hoping the market eventually produces enough qualified candidates. It’s to rethink how experience gets built in the first place.
That can mean structured pathways that bring people in through IT or operational technology support roles and develop them into specialized security functions over time, rather than expecting every hire to arrive fully formed. It can mean being more precise about which roles genuinely require years of hands-on experience versus which ones are being overspecified simply because employers can, in a tight market, ask for more than they strictly need.
It also means recognizing that the organizations best positioned to solve this aren’t necessarily the ones with the largest security budgets. They’re the ones willing to invest in developing talent internally, or partner with specialized workforce and delivery organizations that understand how to build cybersecurity capability without simply competing for the same narrow pool of already-experienced candidates everyone else is chasing.
The Bigger Picture
Canada’s cybersecurity talent shortage is real, and the stakes, particularly for critical infrastructure, are too high to treat casually. But the industry doing itself a disservice by hiring for experience it isn’t helping candidates gain is a different problem than a pure lack of interested, capable people. Hiring is recovering. The skills gap is if anything widening. Those two facts sitting side by side should be a signal to employers that the traditional playbook of waiting for perfectly qualified candidates to appear isn’t going to close the gap on its own.
Sources: Canadian Cybersecurity Network, Q2 2026 Labour Market Research; SANS Institute, "The Evolving Cyber Workforce: AI, Compliance, and the Battle for Talent," 2026 report, as covered by Industrial Cyber.