Cybersecurity teams are under pressure to defend against increasingly sophisticated threats, yet new research from SkillBit suggests organizations are falling short in onboarding talent, developing skills, and sustaining readiness in a rapidly changing security environment.

The 2026 SkillBit Micro-Training Survey Report, supported by CyberBay and Bellini Capital, finds that organizations face challenges across the talent lifecycle, from onboarding new hires to keeping experienced professionals current as technologies and attack methods evolve.

Nearly two-thirds of organizations expect cybersecurity hires to become fully productive within three months, yet most report it takes six months to reach full effectiveness. The challenge extends beyond onboarding. While 57% of cybersecurity leaders say new hires need six months to become fully productive, 39% also cite skills decay as a significant concern. Among organizations with more than 50,000 employees, that figure climbs to 60%.

Together, the findings expose a persistent cycle: organizations take too long to build readiness, then risk losing ground as skills decay.

The report, which draws on responses from more than 200 cybersecurity leaders, points to the need for continuous readiness, an approach that combines ongoing assessment, hands-on practice, and bite-sized learning to help teams build, maintain, and demonstrate real-world cybersecurity capabilities over time.

“Cybersecurity is about people, and the organizations that treat their talent strategically will have a competitive advantage,” said Thomas Rogers, Co-Founder and President of SkillBit. “Organizations need to onboard talent faster, reinforce critical skills, and measure whether teams can apply them as the security landscape changes. Readiness must be continuously built and sustained in a way that aligns with how teams learn best and allows them to keep pace with change.”

Additional findings from the report include:

  • The cybersecurity talent pipeline remains constrained: 70% of organizations reported having few or no roles available to candidates with less than two years’ experience.

  • Onboarding takes longer than organizations can afford: Nearly 64% of respondents said three months is an acceptable time-to-value for new cybersecurity hires, while 57% reported that full productivity typically takes six months.

  • Leaders favor shorter, ongoing development: 71% preferred weekly 20-minute learning experiences over 30 to 40 hours of training delivered once or twice a year.

  • Adaptability outweighs narrow specialization: More than two-thirds of respondents valued problem-solving, critical thinking, and adaptability more than expertise tied to a specific technology stack.

The findings reinforce the limits of workforce development models built around periodic courses, point-in-time certifications, and completion-based measures. As AI capabilities, attack methods, and security technologies advance, organizations need a more responsive system to develop and validate cybersecurity skills.

“A completed course or certification documents a moment in time. Security leaders need to know whether teams can perform today and be ready for tomorrow’s challenges,” said Roman Bohuk, Co-Founder and CEO of SkillBit. “Continuous Readiness gives organizations a practical way to build, validate, and strengthen skills before those skills are tested in a real incident.”

The full 2026 SkillBit Micro-Training Survey Report is available at https://skillbit.com/blogs/micro-training-survey-report

About SkillBit

Focused on real-world application and accessibility, SkillBit helps organizations build, measure, and maintain the cybersecurity skills that matter most in today’s evolving threat landscape. Its AI-powered platform delivers immersive, hands-on assessment and training experiences for individuals and teams, enabling organizations to accelerate onboarding, identify capability gaps, and develop cybersecurity talent.

Media gallery

About The Author