The cybersecurity hiring boom of the early 2020s created an enormous expansion of the profession. Organizations hired security analysts, engineers, architects, penetration testers, GRC professionals, incident responders and security managers at a rapid pace.
Then the broader technology market changed.
Layoffs, hiring freezes, budget pressure and economic uncertainty reached cybersecurity teams. The 2025 ISC2 Cybersecurity Workforce Study found that 36% of respondents reported cybersecurity budget cuts, 24% reported cybersecurity layoffs, and 39% reported hiring freezes.
That does not mean cybersecurity stopped being important.
It means organizations became more selective about what cybersecurity capability they were willing to pay for.
This distinction is extremely important for people entering the profession.
A company may not want to hire five junior analysts to manually perform tasks that can increasingly be automated. It may instead want two experienced analysts who know how to use AI-enabled security tools, investigate complex incidents, write detection logic, understand cloud environments and supervise automated workflows.
That changes the economics of hiring.
The question employers are increasingly asking is not:
“How many cybersecurity people do we need?”
It is:
“What capabilities do we need, and what combination of people, technology and automation can deliver them?”
That is one of the defining characteristics of the 2026 cybersecurity employment market.