Cybersecurity & Protection

ISC2 Study: Security Teams Prioritize AI Skills in Training

Aug 18, 2026 4 min read
All articles

The 2025 ISC2 Cybersecurity Workforce Study already showed a significant tightening of the IT security job market: 59 percent of respondents worldwide reported a critical need for cybersecurity skills, a sharp jump from 44 percent the year before. The skills gap is therefore not a temporary phenomenon but a fundamental brake on growth. To close it and strengthen their own resilience, companies are investing more in training and upskilling, according to a current ISC2 study, though rising budgets are often undermined by a lack of time.

AI tops the priority list

In the "Security Training Trends 2026" study, 43 percent of German security leaders name artificial intelligence knowledge as their top training priority, putting Germany below the international average of 47 percent. In the US and UK, the figures are even higher at 54 and 55 percent respectively, according to ISC2. The rise of AI agents and growing automation in security operations centers is massively shifting the required skill set; teams today need to do more than configure systems, they also need to ensure the integrity of autonomously acting algorithms.

Worldwide, respondents currently prioritize AI at 47 percent, followed by cloud computing security and security analysis at 44 percent each, and risk management and security administration at 40 percent each. German decision-makers spread their focus more broadly: after AI comes a trio of cloud security, network monitoring, and security analysis, each at 39 percent. That spread suggests a holistic approach, but it also risks falling behind international standards in specialized AI defense.

More budget, but little time

Worldwide, 73 percent of the companies surveyed have increased their security training budgets over the past twelve months. Whether that money translates into real competence or unused licenses, though, depends on resource planning. While 98 percent of companies officially allow training during working hours, 53 percent of security leaders still cite lack of time and difficult scheduling as the biggest obstacle to effective training. More budget alone doesn't solve the skills gap.

Another structural problem is the timing of training: 54 percent of companies only determine training needs when rolling out new systems, a reactive pattern that unnecessarily extends time-to-protection. Strategic training should really happen before rollout, to ensure operational security from day one.

Certifications as proof of quality

Another ISC2 study, the "2026 Value of Cybersecurity Certifications Report," examines the perceived value of cybersecurity certifications. 67 percent of experts surveyed worldwide rate vendor-neutral certifications as highly effective, and 65 percent say the same about vendor-specific qualifications. The fact that 71 percent of vendor-neutral certificate holders also hold product-specific credentials underscores the trend toward dual qualification.

The business value shows up in three areas: certification catalogs offer a precise roadmap for systematically closing gaps in critical fields like cloud or AI. Certified professionals also show a greater willingness toward continuous learning, which supports employee retention. And certified teams reach a higher level of maturity in incident response, reducing downtime and liability risk. For professionals, these qualifications serve as career accelerators, with vendor-neutral certificates usually forming the foundation and vendor-specific credentials adding deeper specialization.

For the "Security Training Trends 2026" study, more than 995 cybersecurity executives from six countries were surveyed in December 2025, all from large enterprises with more than 5,000 employees. For the certification report, ISC2 surveyed 1,533 cybersecurity professionals worldwide who hold at least one vendor-neutral certification.