Cyber Security passed 41,000 holders this year, making it the largest standard on the register. Growth of 4.1% understates the pressure, because the demand side grew considerably faster.
The shortage is not what people assume
Employers are not short of applicants. They are short of applicants who can evidence having handled something real. Training certificates are abundant; documented incident work is not, and the two are not interchangeable when the role involves being on call.
We can fill a room with people who have completed the course. We struggle to find people who have been woken at 3am and can tell us what they did next.
Why we added incident evidence
From this year, Level 3 and above require a documented response the candidate personally led. This raised the bar and, predictably, reduced the pass rate. We think that is the correct trade: a credential that does not discriminate is not doing its job.
Entering without incident experience
Level 2 remains reachable through supervised work, and it is the honest place for most people to start. Assurance, secure architecture and threat modelling all produce evidence that does not require an incident to have occurred.