Security leaders now say a shortage of skilled people, not a shortage of budget, is what’s really holding their defences back.
In this year’s Cyberthreat Defense Report from CyberEdge Group, lack of skilled personnel ranked as the top barrier to effective cyberthreat defence, while lack of budget ranked last of ten factors, even as nine in ten organisations expect their security budget to grow this year.
The funding, in other words, is less of a problem than finding the people to put behind it.
The report surveyed 1,200 IT security decision makers and practitioners across 17 countries in late 2025, all at organisations with more than 500 employees.
Where Does a Cybersecurity Skills Shortage Actually Show Up?
It’s rarely an empty seat in the org chart. It’s in the tooling.
Most IT teams will recognise the pattern. A good product gets bought and deployed to about sixty percent. Alerting gets switched on and never quite tuned. A dashboard stops being opened once the person who set it up moves on. None of that comes from a lack of care or a lack of funding. It comes from a team with more surface area than hours.
Which points to something the report doesn’t say directly. If budget is no longer the binding constraint, buying more isn’t the fix. And the shortage is difficult to hire your way out of, because the same shortage is what’s driving the salaries. That leaves two practical paths: run fewer things properly, or borrow the capability rather than employ it.
Is Rising Ransomware Payment a Security Problem or a Recovery Problem?
Among organisations hit by ransomware, the share that paid rose from 40.7% to 55.0% in a single year. The report attributes the jump to healthcare, retail and manufacturing, and to companies between 500 and 10,000 employees.
Payment rates had been falling for several years. That has now reversed.
Nobody pays a ransom because their firewall failed. They pay because restoring from backup isn’t a realistic option in the time available. So a rising payment rate says less about how severe attacks have become and more about how many organisations found out, at the worst possible moment, that recovery was the weaker half of their plan.
Paying didn’t reliably solve it either. Close to four in ten organisations that paid still did not get their data back.
Why Are AI and Third-Party Risk the Least Trusted Security Areas?
Respondents rated their security posture across fourteen areas of IT. The lowest score of the fourteen went to their own large language models. Across twelve security capabilities, the weakest was third-party risk management.
Both are newer surfaces, and both are being adopted faster than anyone is given time to take ownership of them. That’s a capacity problem rather than a knowledge one: confidence tends to follow familiarity, and there hasn’t been time to get familiar with what’s new.
What Does the 2026 Cyberthreat Defense Report Say About Australia?
69.4% of Australian respondents reported at least one successful compromise in the previous 12 months, against 80.7% globally.
Worth handling carefully, though. The Australian subsample was around 50 respondents, and CyberEdge itself describes country-level results as anecdotal, recommending decisions be based on the global data instead.
It does leave a fair question open. Either Australia is a genuinely quieter operating environment, or Australian organisations are counting differently. On a sample that size the report can’t tell you which, and neither can we.
Where Should a Growing Security Budget Actually Go?
Security budgets are rising almost everywhere this year, but this report found that a shortage of skilled people, not a shortage of funding, is what actually holds security teams back. That means the highest-value use of a bigger budget may not be another product. What’s scarce is the expertise to run what you already own well, and the time to work out which parts of it are genuinely doing their job.
That’s not something you fix by spending more. It’s something you fix by taking a proper look at what’s already running, and getting it working as hard as it can.
If you’d like an honest, current read on how your existing setup is actually performing, and where it could be doing more, our team is happy to talk it through with you.
FAQs
What is the Cyberthreat Defense Report?
It’s CyberEdge Group’s annual global survey of IT security decision makers, now in its 13th year. The 2026 edition surveyed 1,200 respondents across 17 countries and organisations with more than 500 employees, between November and December 2025.
Why did ransomware payment rates increase this year?
The report found the share of ransomware victims paying a ransom rose from 40.7% to 55.0%, reversing several years of decline. It attributes the increase mainly to healthcare, retail and manufacturing organisations, and to companies with between 500 and 10,000 employees.
Is a lack of budget still the biggest barrier to cybersecurity?
No. A shortage of skilled personnel ranked as the top barrier to effective cyberthreat defence, while lack of budget ranked last of ten factors. Nine in ten organisations surveyed also expect their security budget to increase this year.
How reliable is the Australian data in the report?
Australia made up roughly 50 of the report’s 1,200 respondents, and CyberEdge itself describes country-level results as anecdotal, recommending decisions be based on the global data rather than any single country’s figures.