Workforce surveys are usually a genre of comfortable news. They confirm the gap is large, the talent is scarce, and everyone should probably invest more in training. You read the headline number, nod, and move on.

The SANS 2026 Cybersecurity Workforce Survey is not that. Its findings describe an industry in the middle of a structural reorganization that most organizations have not consciously decided to undertake — and, crucially, have not resourced. The headline figure is that 73% of organizations report AI has influenced their team composition. Not their tooling. Not their roadmap. The shape of the team itself.

Read alongside the survey’s other findings, that number tells a coherent and slightly uncomfortable story.

The Findings That Matter

Demand for specialists in newly created roles more than doubled over the past year. These are not renamed versions of existing jobs. The survey identifies genuinely new categories: AI security engineers, AI governance analysts, AI/ML security specialists. Roles that did not appear on org charts two years ago are now the fastest-growing hiring category in the field.

Technical capability has overtaken work experience as the top hiring priority. This is the quietest finding in the survey and possibly the most consequential. For most of the profession’s history, years-in-seat functioned as the primary proxy for competence. Organizations are now ranking demonstrated skills ahead of it — and ahead of credentials alone. When the technology stack you need to secure is three years old, twelve years of experience securing the previous one is a weaker signal than it used to be.

Experienced professionals remain the hardest roles to fill, and senior leadership and CISO roles take longest of all. The apparent contradiction with the previous point is not a contradiction. Organizations want demonstrated capability and seniority; when forced to choose at the practitioner level they now take capability, but at the leadership level they cannot make that trade, so those searches stall.

Only 54% have implemented AI security policies, and just 38% provide comprehensive AI training. A quarter have no AI governance plan at all. Set that against the 73% who have already restructured their teams around AI, and the shape of the problem is unmistakable. Organizations are reorganizing faster than they are preparing. Teams are being handed responsibility for AI systems without policies to work within or training to work from.

The consequences are already measurable. SANS links skills gaps to delayed projects, slower incident response, increased burnout, and stalled technology adoption. And the primary barriers to closing those gaps are time and budget — meaning organizations understand the problem and are choosing not to fund the fix, or cannot.

James Lyne, SANS Institute’s CEO, framed it directly: organizations are building entirely new specialist positions, restructuring teams around regulatory requirements, and facing real enforcement consequences if they don’t.

The Story Underneath the Numbers

Put the findings in sequence and a familiar pattern appears — one that predates AI by decades but is running unusually fast this time.

The business adopts a technology. Security is told to secure it. The org chart changes to reflect the new responsibility. And the investment in policy, training, and governance arrives one to three years later, typically after an incident makes the case that a budget request could not.

What’s different now is the compression. Cloud took roughly a decade to run this cycle. AI has run it in about two years. The 73% figure tells you the org-chart step has already happened. The 38% training figure tells you the preparation step has not. That interval — where responsibility has transferred but capability hasn’t — is where incidents live.

There is also a subtler shift buried in the “skills over experience” finding. If demonstrated technical capability now outranks tenure, the traditional career ladder in security is being reweighted in real time. That is genuinely good news for capable people early in their careers and genuinely threatening for people whose seniority rests primarily on time served. Both of those things are true simultaneously, and the profession has not really absorbed either.

What This Means for Security Leaders

Audit the gap between your org chart and your training budget. If you have created or retitled roles to cover AI in the past eighteen months, ask a direct question: what training did those people receive, and what written policy do they operate under? If the honest answer is “they figured it out,” you are in the 73% who reorganized and outside the 38% who prepared. That is a documented, foreseeable risk position, which is a materially worse place to be than an unknown one.

Write the AI security policy before you hire the AI security engineer. A quarter of organizations have no AI governance plan. Hiring a specialist into a policy vacuum guarantees they spend their first two quarters writing the policy you should have had — expensive, slow, and a common reason these hires leave inside a year. The policy is cheaper than the turnover.

Rebuild your job requisitions around demonstrated capability. If the market has moved to skills-over-experience and your postings still lead with “8–10 years required,” you are filtering out exactly the candidates your competitors are now hiring. Replace year thresholds with capability statements and assess against them. This is one of the few workforce interventions that costs nothing and works immediately — and it is the same lesson visible in the long-running struggle to hire security professionals well.

Treat the leadership-hiring lag as a succession problem. CISO and senior leadership roles taking longest to fill is not primarily a recruiting failure; it is a pipeline failure that began years earlier. If you cannot name two internal candidates who could take your job in eighteen months, you are contributing to the statistic. Development plans for those people are the actual fix, and they need to start now to matter later.

Fund training as incident-response cost avoidance, not as a perk. SANS ties skills gaps directly to slower incident response and higher burnout. Both have quantifiable costs — extended breach dwell time, attrition and rehiring expense. Presenting the training budget in those terms rather than as professional development is the difference between a line item that survives budget season and one that doesn’t. Burnout in particular compounds quietly, and it sits at the center of the broader talent retention crisis the field has been living through.

What This Means for Careers

The new specialist roles are the clearest opportunity in the market right now. AI security engineering, AI governance analysis, and AI/ML security are the fastest-growing categories in the survey, and the supply of people who can credibly claim them is thin. Roughly a year of deliberate focus is enough to be genuinely competitive in a field where almost nobody has a decade of background — because the field is not a decade old.

Governance is underrated relative to engineering. Most practitioners drawn to AI security gravitate toward the technical side: model attacks, prompt injection, pipeline security. But a quarter of organizations have no AI governance plan and only about half have policies. The people who can write the framework, map it to regulation, and make it operational are rarer than the people who can attack a model — and they are closer to the budget.

Demonstrable skill is now the currency. Build artifacts, not just credentials. If technical capability has overtaken experience as the top hiring criterion, then the ability to show capability is what converts. A public repository, a detection you built, a documented lab, a conference talk, a write-up of a real problem you solved — these now outperform another certification line on a résumé for practitioner roles. The advice has been circulating for years; the survey is evidence that hiring behavior has finally caught up to it, a shift also visible in guidance for entering the cybersecurity workforce.

If you’re mid-career, pick a specialization deliberately this year. The gap between generalist security professionals and specialists in the new categories is widening, and it will not narrow. The people who choose a lane in the next twelve months will be the senior specialists of 2029. The people who wait for the market to settle will be competing against them with a three-year deficit.

A caution worth stating plainly: the survey measures demand, not stability. New role categories can consolidate or get absorbed as tooling matures. The safer bet is not “AI security” as a job title but the underlying combination — deep security fundamentals plus genuine understanding of how AI systems fail. That combination transfers regardless of what the roles end up being called.

The Bigger Picture

The uncomfortable truth in the SANS data is that the industry has become good at reacting to structural change and remained bad at preparing for it. Seventy-three percent restructured. Thirty-eight percent trained. That is not a talent shortage; it is an investment-sequencing failure, and the same one the field made with cloud, with mobile, and with every prior platform shift.

The organizations that will come through this well are the ones that close their own 73/38 gap deliberately, on their own schedule, before an incident sets the schedule for them. That is not a technology problem or a hiring problem. It is a leadership decision about what to fund this year — and, on the current data, most organizations are quietly deciding not to.

Sources: SANS Institute — 2026 Cybersecurity Workforce Survey, as reported by Help Net Security, “AI can’t fix cybersecurity’s hiring problem” (July 22, 2026); quote attributed to James Lyne, CEO of SANS Institute, as reported by Help Net Security; supporting context from Dice career research on 2026 cyber skills demand.

This article is provided for informational purposes only and reflects reporting available as of late July 2026. Survey figures are drawn from published summaries of the SANS 2026 Cybersecurity Workforce Survey; methodology and respondent composition are as described by the publisher.