SecurityIndependently confirmed2 publishers2 min readPublished Updated
57% of security executives tell SkillBit a new hire needs six months to deliver value
SkillBit's survey of 200 security executives found 57% say a new hire takes six months to deliver value. A team that loses an analyst therefore stays short-staffed for months after the replacement starts, whatever its patch deadlines.
The Watch · Security desk
What happened
- Seventy percent of the organizations surveyed say they have few roles open to candidates with under two years of experience.
- 84% sponsor certification training for staff, even though 71% of the managers said they prefer 20-minute weekly upskilling sessions to annual training.
- 30% of leaders would accept interactive lab formats in place of credentials, and another 49.5% would if shown convincing evidence that labs work.
- ThreatLocker CTO Michael Jenkins said his team hires early-career staff, including people straight out of high school, and grows them into advanced roles.
Why it matters
- constraint A budget case built on shrinking patch windows cannot cite this survey as support. Its data covers hiring and training, and the patch link comes from the write-up.
- decision With 79.5% of respondents at least open to lab tests, the two-year experience filter is open to negotiation. Whoever can show that labs predict job performance will settle it.
- cost At least 55% of respondents pay for certification courses while preferring short weekly sessions. The course hours come out of teams the write-up says can barely keep up.
SC Media's write-up ties the six-month figure to "the compressed timeline for managing patches in the AI era" [22]. The results it reports cover hiring and training. None of them measure patch windows or exploit timing, so the link between onboarding and patching is the publication's framing, and the numbers do not test it [22].
SkillBit released the study on September 29 [1]. On a base of 200, the six-month group is about 114 executives [20]. The article gives the sample size but not how respondents were chosen [1].
The training figures overlap heavily. If the 71% and the 84% share that base, at least 55% of respondents both prefer short weekly sessions to annual training and pay for certification courses [21]. According to SC Media, certification training "often takes a large amount of time to complete, at a time when most security teams can barely keep up" [9].
Respondents are more flexible on the experience requirement. Leaders said they are open to changing the strict two-year rule if a candidate can show subject knowledge [5]. Counting the conditional group, 79.5% would at least consider interactive labs as a credential substitute [18]. Most of that is conditional: 49.5% want convincing evidence of effectiveness first [7]. The remaining 20.5% fall outside both groups [19].
"We can't keep asking for experienced cybersecurity professionals without giving people a chance to gain that experience," said Michael Jenkins, chief technology officer at ThreatLocker [10]. "AI can help with some tasks, but it cannot replace human judgement, and that needs to be learned through experience," he said [11]. On the six-month figure, Jenkins said every job has a learning curve. What matters, he said, is whether new staff get the chance to contribute and grow during that training time [14].
His method is review. "Every code commit is reviewed by multiple people, and significant actions get a second look, even when a senior employee is involved," Jenkins said [13].
Ram Varadarajan, chief executive officer at Acalvio, said that a few years ago cybersecurity training was viewed as discretionary spending [16]. "To overcome training-time and onboarding challenges, organizations should treat learning as a business requirement with protected time and measurable goals," he said [15]. Diana Kelley, chief information security officer at Noma Security, said employers are still looking for experience and proof of capability, even at entry level [17].
What to watch
- Publication of SkillBit's full questionnaire and respondent profile, which would show whether the 71% and 84% figures share a base and who was surveyed.
- Any data linking onboarding time to patch or remediation times, which would test the patch-window framing the write-up attaches to the six-month figure.
- Outcome data on hiring through interactive labs, the evidence 49.5% of respondents say they need before accepting labs in place of credentials.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives60
- Confidence60
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
SkillBit released a study on September 29 based on a survey of 200 security executives.
ReportedSupportedSource: SC Media report on SkillBit study2 sources— create a free account to open themView cited source - [2]
57% of the 200 security executives surveyed reported a six-month time-to-value for a new employee.
ReportedSupportedSource: SkillBit survey via SC Media2 sources— create a free account to open themView cited source - [3]
70% of organizations say they have few roles available to candidates with under two years of experience.
ReportedSupportedSource: SkillBit survey via SC Media2 sources— create a free account to open themView cited source - [4]
71% of security managers said they prefer 20-minute weekly upskilling sessions over annual training.
ReportedSupportedSource: SkillBit survey via SC Media2 sources— create a free account to open themView cited source - [5]
Cybersecurity leaders are becoming open to changing the strict 2-year experience requirement so long as the candidate can demonstrate some subject knowledge.
ReportedSupportedSource: SkillBit survey via SC Media2 sources— create a free account to open themView cited source - [6]
30% of leaders are receptive to 'Interactive Lab' formats as a credential substitute.
ReportedSupportedSource: SkillBit survey via SC Media2 sources— create a free account to open themView cited source - [7]
Another 49.5% of leaders are open to Interactive Lab formats as a credential substitute if presented with convincing evidence of its effectiveness.
ReportedSupportedSource: SkillBit survey via SC Media2 sources— create a free account to open themView cited source - [8]
84% sponsor 'Certification' training for their staff.
- [9]
Certification training often takes a large amount of time to complete, at a time when most security teams can barely keep up.
- [10]
"We can't keep asking for experienced cybersecurity professionals without giving people a chance to gain that experience,"
- [11]
"AI can help with some tasks, but it cannot replace human judgement, and that needs to be learned through experience."
- [12]
Jenkins said his team tends to hire early-career employees, including people straight out of high school, and help them grow into more advanced roles.
- [13]
"Every code commit is reviewed by multiple people, and significant actions get a second look, even when a senior employee is involved."
- [14]
On the 57% time-to-value number, Jenkins said every job has a learning curve when someone joins a new organization, and what matters is whether they get the chance to contribute and grow during that training time.
- [15]
"To overcome training-time and onboarding challenges, organizations should treat learning as a business requirement with protected time and measurable goals."
- [16]
Varadarajan said the findings reflect a shift from a few years ago, when cybersecurity training was viewed as discretionary spending.
- [17]
Diana Kelley said employers are still looking for experience and proof-of-capability, even at the entry level.
- [18]
79.5% of leaders are at least conditionally open to interactive labs as a credential substitute.
- [19]
20.5% of leaders fall outside both the receptive and the conditionally open groups.
- [20]
About 114 of the 200 executives reported a six-month time-to-value.
- [21]
If both figures share the 200-respondent base, at least 55% of respondents both prefer weekly 20-minute sessions to annual training and sponsor certification training.
- [22]
SC Media wrote that the six-month time-to-value puts a lot of pressure on security managers racing to onboard people in the wake of the compressed timeline for managing patches in the AI era.
ReportedInsufficientSource: SC Media framing2 sources— create a free account to open themView cited source
Sources
2 independent publishers whose own reporting we read for this story.
- helpnetsecurity.comCybersecurity hiring practices leave little room for junior talent
1 article · September 29, 2026
- scworld.com57% of security execs report challenges with onboarding entry-level staff
1 article · September 29, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.