Denis Medvedev by way of iStock / Getty Photographs Plus
Observe ZDNET: Add us as a most popular supply on Google.
ZDNET’s key takeaways
- There is a massive mismatch between demand and rewards in cyber.
- Working strain is barely more likely to enhance as a consequence of the usage of AI.
- Safety employees ought to concentrate on technique and communication expertise.
Nearly 20% of organizations have reported a serious safety assault previously two years, and the risk setting, whether or not as a consequence of felony exercise or the rise of recent AI-enabled fashions, reminiscent of Anthropic’s Mythos, continues to evolve at breakneck pace. Nonetheless, the cybersecurity professionals who assist their enterprises handle these challenges do not feel adequately rewarded — and most are fed up with the state of affairs.
That is the conclusion from the newly launched Harvey Nash World Tech Expertise & Wage Report, which surveyed over 3,646 know-how professionals globally. Whereas 19% of respondents reported a serious assault at their agency previously 24 months, these working within the safety specialism had been the least more likely to report a pay enhance over the past yr.
Additionally: These 4 crucial AI vulnerabilities are being exploited quicker than defenders can reply
Solely 29% of cyber professionals stated they’d obtained further compensation for his or her efforts, which is in stark distinction to different roles, the place a minimum of half of tech professionals obtained a pay enhance in 2025, particularly in DevOps (56%), product administration (51%), and enterprise evaluation (50%).
“The analysis clearly tells us that there is a massive mismatch between the demand and the reward in cyber,” stated Ankur Anand, group CIO at know-how and expertise options supplier Nash Squared, which owns tech recruiter Harvey Nash, the agency that produced the survey.
“I believe this mismatch is because of the complacency of many boards saying nothing unhealthy has occurred in the previous couple of years, so safety have to be nice. And that is the irony — that when safety groups are doing a lot, they usually’re stopping harm to the group, they’re getting the least recognition.”
Motivation is waning
Unsurprisingly, the survey discovered that safety specialists have had sufficient. Individuals working in cybersecurity are the third-most sad IT professionals globally (23%), simply behind these working in high quality assurance/testing (24%) and infrastructure/help (25%).
What’s extra, the dearth of recognition and a common sense of despondency imply nearly half (49%) of cybersecurity professionals wish to transfer jobs within the subsequent 12 months, effectively above the worldwide common (39%) throughout know-how roles.
“Cyber is likely one of the few roles the place success is invisible, and failure may be very seen,” stated Anand, referring to the age-old enterprise problem of too many executives assuming safety is okay as a result of their group hasn’t been attacked.
Additionally: 10 methods AI can inflict unprecedented harm in 2026
Nonetheless, this complacency may rapidly change into a serious situation. Whereas 80% of organizations haven’t suffered a serious assault previously two years, a failure from senior executives to acknowledge the size of the cyber problem and to take care of their safety groups may imply the enterprise is subsequent within the firing line.
In these circumstances, the place cybersecurity considerations proceed to rise, and firms proceed to stall at rewarding and retaining their gifted employees, many professionals can really feel their motivation for work begin to wane.
“It is the mixture of the dearth of recognition, the strain when it comes to making certain that the harm is just not executed, and that provides to the workload due to the legacy tech stack and the distributed workforce construction that’s doing the harm to individuals’s motivation,” stated Anand.
AI brings new threats
Crucially, the working strain is barely more likely to go a technique: upwards. The rise of AI brings new fashions, strategies, and dangers. Anand stated organizations and safety professionals should take into account the pace at which AI is evolving and its seemingly impression on enterprise operations.
“Once I evaluation the risk vectors with my head of safety, it boggles my thoughts concerning the variety of vulnerabilities that outsiders try to compromise within the enterprise IT setting, and that actuality makes it very tense to work within the safety group,” he stated.
Such is the tempo of change that Anand stated the risk setting is transferring quicker than most organizations can structurally adapt. He frequently speaks with digital leaders at different corporations who say they’ve invested closely in safety however nonetheless battle to deal with the threats.
Additionally: AI is quietly poisoning itself and pushing fashions towards collapse – however there is a remedy
Some trade consultants are involved that present fears concerning the tempo of AI-enabled change are simply the place to begin. Anand acknowledges that the hype surrounding Anthropic’s Mythos mannequin is justified, with the potential for this mannequin and different AI-powered improvements to disrupt the entire trade.
“These developments present how AI can uncover all these sleeping vulnerabilities in techniques,” he stated.
“Anthropic, as a accountable group, is making an attempt to make sure that the important thing platforms are addressing these vulnerabilities. Nonetheless, you additionally should take into consideration whether or not different non-responsible risk actors will create related instruments.”
Taking a proactive strategy
In brief, the trade is correct to be involved about Mythos, and the ramifications may imply extra strain for cyber professionals. Nonetheless, it isn’t all unhealthy information, and the analysis means that AI may assist to cut back the pressure on safety employees.
Cybersecurity professionals (48%) are the third-most seemingly IT employees to not really feel threatened by AI taking their jobs, behind firmware/{hardware} engineers (55%) and know-how leaders (58%). Anand stated safety specialists perceive that AI creates new dangers but additionally generates new alternatives.
“AI is just not eradicating the necessity for safety; it’s growing it, and that is the place a cyber skilled provides worth — they may outline what attractiveness like,” he stated. “It’s essential suppose, ‘Okay, how do I contribute to the AI technique of our group and guarantee what we do is inside the guardrails of the laws and knowledge safety legal guidelines?'”
Additionally: 5 safety techniques your online business cannot get improper within the age of AI – and why they’re crucial
With the analysis suggesting that just about half (49%) of cybersecurity professionals wish to transfer jobs within the subsequent 12 months, safety specialists are more likely to discover themselves preventing for alternatives in a aggressive labor market. Anand inspired cyber specialists to hone their AI capabilities and to develop expertise in different areas, together with technique and communication.
“The strongest cyber professionals right now mix the technical depth of the area with the enterprise context,” he stated. “They will clarify a safety situation with out the jargon, with none drama, however by being very sensible concerning the enterprise impression and the way the agency manages it.”
Fairly than burdening the management with technical particulars, essentially the most in-demand cyber employees are conscious of how specialist instruments, reminiscent of AI, can be utilized to cut back dangers, not enhance them. These cyber professionals clarify how good safety apply is essential to the general enterprise technique.
“This focus is just not about audits, findings, and so forth,” stated Anand. “It is a few progressive thought course of — it is speaking about cyber strategically when it comes to enterprise wants, enterprise dangers, and enterprise readiness for the long run.”

