
Only 34% of security professionals surveyed plan to stay with their current employer. The sharper signal is a 54-point career-satisfaction gap tied to whether security feels like a core organizational priority.
I’m still in Las Vegas. Black Hat has wrapped and DEF CON is underway, which puts an unusual amount of the security profession within a few miles of each other for a week.
It’s a strange place to be thinking about retention.
Or maybe exactly the right one
IANS Research and Artico Search surveyed more than 500 security professionals for their 2026 Cybersecurity Talent Report, published in April. Only 34% said they plan to stay with their current employer.
That does not mean the other 66% have resignation letters drafted. Some are considering a move. Some are probably undecided. But only about a third are willing to say, yes, I plan to remain here.
For a field that spends so much time talking about talent shortages, that’s a pretty uncomfortable number.
The 54-point number
The same report contains a finding I think is more useful than the headline.
Among security staff who see security as a core organizational priority, 73% report being satisfied with their careers. Among those who perceive little or no organizational backing for security, satisfaction falls to 19%.
That’s a 54-point gap.
Not between the highest-paid people and the lowest-paid. Not between executives and analysts. The split in this particular finding is how respondents perceive their organization’s commitment to the work.
That’s correlation, and it’s worth saying so clearly. The survey does not prove that organizational backing causes career satisfaction. People who are happier may also judge their organizations more favorably, and there are probably other variables moving underneath both numbers.
Still, 73 to 19 is hard to wave away.
It suggests that what people believe about the organization’s commitment to security is connected to how they feel about the career they’re building inside it.
The pay answer, and where it runs out
Pay people more.
Fair answer.
Money matters. I’ve never met an engineer who works day after day for gratitude, and anyone trying to explain retention while pretending compensation is irrelevant has probably skipped an important part of the problem.
But the IANS and Artico data adds an interesting wrinkle: wage growth matters more for retention than absolute pay level. Employees receiving even modest increases reported higher satisfaction and stronger intent to stay than employees whose compensation remained flat, regardless of where the absolute number started.
That makes intuitive sense to me. The number matters, but movement carries information too.
A raise says something changed.
Steve Martano, an IANS faculty member and partner at Artico Search, framed the larger issue around rising expectations and constrained resources. His point was that top talent is looking for more than compensation alone. Visibility, career growth and support from security leadership matter too.
So I don’t think the data says pay doesn’t matter.
It says pay isn’t the whole message.
What people are working inside
The pressure underneath these retention numbers isn’t especially mysterious.
ISC2’s 2025 Cybersecurity Workforce Study surveyed 16,029 people responsible for cybersecurity around the world. 59% reported critical or significant skills needs on their teams, up from 44% the year before.
More interesting to me is what happened downstream.
ISC2 reports that 88% of respondents experienced at least one significant cybersecurity consequence because of a skills deficiency within their team or wider organization. Sixty-nine percent reported more than one.
That isn’t a prediction about what a shortage might eventually do.
Respondents were describing consequences they said had already happened.
You can pay somebody well and still place them inside a system where the responsibility keeps expanding faster than the resources available to meet it. The salary changes. The queue doesn’t. The person is still accountable for an outcome they increasingly suspect the organization has not equipped them to produce.
Eventually that becomes information.
Not just about the job.
About the place.
The person expected to fix it may be looking too
Leadership isn’t standing outside this problem.
Proofpoint’s 2025 Voice of the CISO surveyed 1,600 CISOs across 16 countries. Sixty-three percent said they had experienced or witnessed burnout during the previous year. The same report found 66% facing what respondents described as excessive expectations.
Then IANS and Artico surveyed 662 CISOs for their 2026 State of the CISO benchmark. Nearly seven in ten said they were open to making a career move within the next year.
That doesn’t mean seven in ten are quitting either.
It does mean the people we’re asking to stabilize security teams are themselves unusually mobile.
I think that matters when we reduce retention to something a manager is supposed to fix with better one-on-ones.
The manager may be looking at the same door.
What Vegas builds really well
This week makes the contrast difficult to miss.
Black Hat’s Business Hall had more than 400 vendors and startups this year. Its own description talks about networking, making connections and discovering career opportunities alongside all the products, demos and meetings.
Then there’s BSides Las Vegas.
Its Hire Ground program has existed since at least 2016. The archived description talks openly about interview preparation, recruiters, resume help, social profiles and career mapping. Hire Ground is still on the BSidesLV schedule in 2026, with sessions this week on high-performing security teams, getting hired, surviving the cyber job market and standing out in it.
That’s useful infrastructure. I’m not criticizing it.
People need ways into better jobs. People need ways out of bad ones.
But we’ve gotten remarkably good at building machinery around movement.
Recruiting systems. Career tracks. Interview coaching. Resume reviews. Job boards. Search firms. Conference programming.
There’s a whole apparatus for helping somebody become somebody else’s employee.
I can’t find an equivalent apparatus for making the current place worth staying.
Nobody rents floor space to retention
That’s the line I keep coming back to.
Nobody rents floor space to keeping people.
There’s no retention booth because retention isn’t really a product. You can’t buy it in a hall at Mandalay Bay, integrate it next quarter and put a green check beside it.
It’s mostly ordinary decisions.
Whether someone gets the headcount they were told was coming. Whether the project that matters gets funded. Whether a strong engineer can see an actual next step instead of another year of “we’re working on the leveling framework.” Whether the security leader is allowed to make decisions or simply absorbs accountability from people who can.
None of that demos especially well.
It still shows up in the numbers.
The mentorship answer
Nick Kakolowski, IANS’s Senior Research Director, argues that leaders should invest harder in mentorship, coaching and career development. The idea is straightforward: give people a sense of progression and purpose before burnout gets to make the decision for them.
I agree with that.
I also think mentorship has a failure mode we don’t talk about enough.
A mentor who can’t move can’t model movement.
If the person coaching you has no budget, no headcount, no authority over progression and no realistic path of their own, eventually the coaching becomes a description of a room neither person can change.
Good conversation. Same room.
Mentorship works when it’s attached to something real.
A decision someone can make. A training budget that actually exists. Scope that can expand. A title that can change. Compensation that moves. Access to work that develops the person instead of simply consuming them.
Otherwise we’ve handed somebody a sympathetic listener and called it a career path.
What “backing security” actually looks like
This is where I think the 73% versus 19% number gets interesting.
Saying security is important is free.
Every company can do that.
The team learns what you mean by watching everything that costs something.
Budgets. Hiring approvals. Deferred projects. Incident staffing. Whether security gets involved before or after a decision. Whether the CISO has access to the people making the tradeoffs. Whether the same three people keep absorbing the work created by every new priority.
Those are signals.
People are good at reading them.
Which may be why “organizational backing” shows up so loudly in the satisfaction data. Whatever the direction of causation, employees are not judging the company’s commitment from the values page.
They’re living inside the allocation decisions.
The test I’d rather use
I’ve never loved tenure by itself as a measure of a healthy team.
Long tenure can mean someone is thriving. It can also mean they haven’t looked recently, the market isn’t cooperating or leaving would cost too much personally.
I’d rather ask something harder:
Could this person leave without guilt, and would I help them do it well?
A team where the answer is yes has a chance of making staying an actual choice.
That’s different from retention through friction.
Different from loyalty through dependency.
Different from quietly building a room with a difficult door.
And I think people can feel the difference.
The hall for the other half
Black Hat is over now. DEF CON is going.
Vegas is still full of movement: people meeting each other, exchanging ideas, discovering companies, finding opportunities and figuring out what they might do next.
That machinery works.
I’m glad it exists.
But after looking at the retention numbers, I’m more interested in the machinery that doesn’t have a hall.
The part where someone goes back to work after all of this and decides, again, that the place they’re already in is still worth choosing.
Nobody gets a booth for that.
Somebody still has to build it.
Resources
2026 Cybersecurity Talent Report announcement - IANS Research and Artico Search
Primary source for the survey of 500+ security professionals, the 34% stay-intent figure, 73%/19% career-satisfaction split, wage-growth finding and comments from Nick Kakolowski and Steve Martano.
2025 ISC2 Cybersecurity Workforce Study
Primary study based on 16,029 respondents. Source for the 59% critical/significant skills-needs figure and the 88%/69% reported security-consequence figures.
Proofpoint 2025 Voice of the CISO
Primary source for the survey of 1,600 CISOs across 16 countries and the 63% experienced-or-witnessed-burnout figure.
2026 State of the CISO Benchmark - IANS Research and Artico Search
Primary source for the 662-CISO sample and the finding that nearly seven in ten CISOs are open to a career move within the next year.
Black Hat USA 2026 Business Hall
Black Hat’s official description of the 2026 Business Hall, including its 400+ vendors and startups, networking focus and career-opportunity language.
BSides Las Vegas 2026 Schedule
Official 2026 schedule showing Hire Ground and its current career-focused programming.
BSidesLV Hire Ground archive, 2016
Archived description of Hire Ground’s interview preparation, recruiter networking, resume support, social-profile help and career mapping.
DEF CON 34 Conference Information
Official DEF CON 34 conference information for the August 6-9, 2026 event in Las Vegas.
