What Everyone Keeps Getting Wrong About the Cyber Gap

The cyber talent gap is misdiagnosed. It’s not a hiring problem—it’s a workforce protection failure. Security teams face rising workloads driven by expanding attack surfaces and AI-driven threats. This session breaks down why talent isn’t the issue—retention is—and outlines how leaders can shift from constant hiring to sustaining and strengthening their teams.


This session deconstructs one of cybersecurity’s most persistent narratives: the talent shortage. While the industry reports millions of unfilled roles, organizations simultaneously experience layoffs, rising burnout, and declining retention, signaling a deeper systemic issue.

We begin by examining the lack of a consistent definition of the cybersecurity workforce and how this undermines measurement, accountability, and progress. Without alignment on who is “in” cybersecurity and what skills are required, workforce planning remains fragmented and ineffective.

Next, we explore the “cyber talent paradox,” a growing workforce alongside continued layoffs—highlighting how this reflects capacity miscalculation rather than a true shortage. We connect this to the rise of AI, which has not reduced labor demand but instead increased cognitive load, alert volume, and decision complexity across security teams.

The session then shifts to a critical but often overlooked driver: workforce experience and belonging. When individuals do not feel valued, supported, or able to contribute effectively, organizations lose talent regardless of hiring efforts. This is positioned not as a culture issue alone, but as a design and leadership challenge that directly impacts retention and performance.

Finally, we move from diagnosis to action. Attendees will leave with a leadership framework focused on:

  • Measuring workforce health beyond headcount
  • Reducing burnout and managing AI-driven workload
  • Designing roles and environments that enable performance and retention
  • Shifting from hiring-centric strategies to sustainable workforce models

The session concludes with a clear call to action: if organizations want to close the cyber gap, they must stop treating it as a pipeline problem and start building teams people can stay in, grow in, and lead within.

Ryan René Rosado

Ryan René Rosado is a recognized cybersecurity leader with nearly 15 years of experience across government, consulting, and enterprise environments. She began her career as an enlisted Cyber Intelligence Analyst in the U.S. Air Force and has since led and supported security initiatives at organizations including EY, Avanade, and Optiv.

Ryan specializes in incident response, threat intelligence, risk management, and compliance, with a focus on translating complex security challenges into actionable business outcomes. She is a Teaching Assistant at Harvard Extension School for Network and Cloud Security and serves as an advisor to the startup Ally Security.

A frequent contributor to the cybersecurity community, Ryan has presented at leading conferences including BSides, Forum InCyber, and RSAC. She has been featured on The Security Happy Hour podcast, contributed to Dark Reading and Signal IT Magazine, and was recently recognized by AFCEA as a 40 Under Forty Emerging Leader.