Organizations are increasingly attributing security breaches to a skills gap, while as a validation of current cybersecurity skills and knowledge, certifications continue to be highly valued by employers, according to Fortinet’s recent report.

The security vendor surveyed more than 1,850 IT and cybersecurity decision-makers for its 2024 Global Cybersecurity Skills Gap Report. It found 87% of organizations experienced a breach in the last year that they partially attributed to a lack of cybersecurity skills, which was an increase from 84% in the 2023 report and 80% the year prior.

Fortinet’s report also found that breaches are having a more substantial impact on businesses, ranging from financial to reputational challenges. More than half of respondents indicated that breaches last year cost their organizations more than $1 million in lost revenue, fines and other expenses. This was up from 48% in the 2023 report and 38% from the previous year.

Corporate leaders are also increasingly being held accountable for cybersecurity incidents, with 51% of those surveyed noting that directors or executives have faced fines, jail time, loss of position or loss of employment following a cyberattack. As a result, executives and company boards are increasingly prioritizing cybersecurity, with 72% of respondents claiming their boards were more focused on security in 2023 than the previous year and almost all (97%) of the respondents said that their boards see cybersecurity as a business priority.

Leaders see certifications as validation of security skills Fortinet’s report also found hiring managers increasingly value continued learning and certifications and regard certifications as validation of cybersecurity knowledge. More than 90% of surveyed leaders prefer to hire candidates who hold certifications, 84% of them hold a certification themselves and 85% have a team member with a certification.

Certifications also improve organizational security posture. Nearly 90% of respondents said they would pay for an employee to obtain a cybersecurity certification, and 61% believe that certified individuals are better able to keep up with the evolving security landscape.

However, finding candidates with certifications isn’t easy, as more than 70% of respondents indicated it's difficult to find those candidates.

The need to expand hiring criteria To combat persistent security skill shortages, some organizations are broadening their hiring criteria to include candidates whose credentials fall outside traditional backgrounds, such as a four-year degree in cybersecurity or a related field, Fortinet noted. However, 71% of surveyed respondents said their organizations still require four-year degrees and 66% hire only candidates with traditional training backgrounds.

The report also found that 83% of organizations have set diversity hiring goals for the next few years, which is down from 89% in 2021.

Meanwhile, female hires declined from 89% in 2022 to 85% last year; hires from minority groups remained unchanged at 68%; and veteran hires increased slightly to 49% last year, but was down from 53% in 2021.

John Maddison, chief marketing officer at Fortinet, in a statement explained that the report highlights “the critical need for a collaborative, multi-faceted approach to closing the skills gap.”