Shortage of skilled security engineers¶

Imagine the city of Ankh-Morpork suddenly decided it needed Watch officers who could spot a Klatchian spy, break up a troll bar fight, mediate a guild dispute, and understand dwarf mining law before breakfast. Now imagine there are twelve such people in the whole city, and everyone from The Patrician to Mrs Cake’s boarding house wants to hire them. Welcome to the world of security engineering.
The arithmetic does not add up and has not for years. Universities cannot graduate experts on demand, training an existing IT person takes two or three years, and every organisation that digitises suddenly wants a security person. You cannot hire five people when only one exists, you cannot train faster than demand grows, and you cannot pay charity-level wages and expect private-sector talent to appear. And yet the city expects miracles.
Vimes and the great talent squeeze¶
The Watch has Vimes, Carrot, Angua, Detritus, Cheery, and dozens of others, each with a specialisation, each able to take a holiday while the city continues to function. Now imagine the Watch is just Vimes: one man to patrol the streets, investigate crimes, train recruits, manage the budget, and prevent wars. He would prioritise ruthlessly and delegate what he could, and inevitably something would go wrong, and everyone would ask why Vimes did not stop it. This is the life of the sole security engineer in many organisations: a juggling act of firewalls, suspicious emails, audit questions, patch management and meetings that never needed to exist, with proactive work squeezed into whatever the calendar has not already eaten.
How the city spends¶
Financial incentives skew almost everything. A bank can offer a mid-level engineer roughly double what central government manages, and central government in turn outbids the local council, which outbids the charity hoping that moral fervour will do what money cannot. The result is that organisations protecting vulnerable people can rarely afford talent while organisations protecting capital snap it up. The market has efficiently allocated security expertise to money rather than human lives. Well done, market.
The pipeline behind it is narrow. Lecturers who could teach security can double their salary in industry, lab kit costs tens of thousands per cohort, and curricula move slower than the field. Certifications add their own absurdity: recurring fees in the hundreds or thousands of euros, while brilliant self-taught people with home labs are overlooked in favour of staff whose employer paid for the course. Entry-level positions demand years of experience, so graduates often bounce between helpdesk roles collecting the wrong kind until they leave for development jobs that pay better and end at five.
One person armies¶
Consider a mid-sized charity: forty-five staff, ten thousand vulnerable people’s records, two IT generalists, security expertise zero. The IT manager becomes responsible for security by default, implements the free basics, is denied the tools that cost money, reads about security in the evenings, and slowly burns out. A phishing email lands, consultants arrive at day rates, recommendations pile up unfunded, and the IT manager leaves for a development role with evenings intact. The replacement knows less. The cycle repeats. Small and medium businesses live a similar story: too small for dedicated staff, too big to escape regulation, too visible to escape ransomware, too broke for consultants.
The fixes are known and largely unfunded: training at scale, realistic salaries, career paths that let specialists thrive, cultures that value the work. Politicians tend to prefer ribbon-cutting to slow patient investment, so the shortage persists, and one overworked Vimes-like figure is expected to secure everything for everyone. At root it looks less like a skills problem than a funding problem, and a structural one.
The clerk’s brief¶
From the clerks, for the Patrician’s eyes
Compiled July 2026. Newest first; the long view sits at the end, under So far. The clerks apologise for the brevity of this file. The people who could have written more of it were, without exception, busy.
December 2025: The shortage is now official arithmetic¶
ENISA’s NIS Investments report, published December 2025 from data across all 27 member states, puts the EU’s deficit at around 299,000 skilled cybersecurity professionals, with three quarters of organisations reporting difficulty attracting qualified staff and 71 per cent difficulty retaining those they have. The same report finds security chiefs redirecting budgets toward outsourcing and tooling to bridge the gap. The clerks translate: the city has stopped trying to hire more Watch officers and has begun buying more whistles.
August 2025: The mainframe generation is leaving the building¶
Analysis of banking modernisation, published August 2025 and citing McKinsey research, expects close to a third of COBOL programmers to retire by 2030, while the majority of banks still run core platforms coded in COBOL and Assembler, some four decades old. The systems holding European savings are maintained by an ageing and shrinking group of specialists, whose scarcity raises their fees, which in turn makes keeping the old systems alive look affordable right up until the specialists are gone. The clerks note the deadline is demographic, and demography does not grant extensions.
So far¶
The squeeze has been visible in every measurement on file: demand rising with each wave of digitisation and each new regulation, supply constrained by a narrow training pipeline and salaries that sort talent toward capital, and burnout quietly returning trained people to other careers. What changed in December 2025 is that the gap acquired an official number and an official response, and the response is automation and outsourcing rather than people. The clerks’ standing assessment: a shortage this structural does not resolve, it redistributes, away from those who can least afford the market rate. The file on who inherits the risk is the underfunding file.