One Bad Security Decision Can Cost Millions: Why Hiring Matters More Than Ever

Edited June 2026


Lané Venter Resourcer
10 min read Reading Time
9 June 2026 Date Created

Cybersecurity Is Now a Business Risk, Not Just an IT Risk

A decade ago, many organisations viewed cybersecurity as a technical issue handled by specialist teams behind the scenes. Today, it sits much higher on the business agenda.

Every department relies on technology. Customer data, financial systems, supply chains, intellectual property, communications platforms, and operational processes all depend on secure digital environments. When security fails, the impact extends far beyond the IT department.

The financial consequences can be severe. According to IBM’s Cost of a Data Breach Report 2025, the global average cost of a data breach was $4.44 million. Those costs include business disruption, recovery efforts, legal expenses, regulatory penalties, lost revenue, and reputational damage.

For employers, cybersecurity is no longer simply about protecting systems. It is about protecting the organisation itself.

Most Security Problems Start With Human Decisions

Popular culture often portrays cyberattacks as highly sophisticated technical events. While advanced threats certainly exist, many security incidents begin with something much simpler.

Poor access controls, weak governance, misconfigured environments, inadequate oversight, and avoidable human errors remain common contributors to security breaches. Technology can help reduce risk, but people still decide how systems are designed, managed, and maintained.

That reality places hiring firmly at the centre of cybersecurity strategy.

Software developers influence application security. Infrastructure engineers control system configurations. Cloud specialists manage access and governance. Technology leaders make decisions that affect risk across entire organisations.

The quality of security outcomes is often influenced by the experience, judgement, and decision-making of the people responsible for delivering them.

Real-World Breaches Demonstrate the Cost of Getting It Wrong

Recent events across the UK retail sector demonstrate just how costly security failures can become.

In 2025, cyberattacks against major retailers including Marks & Spencer and Co-op caused widespread disruption, affecting online services, supply chains, store operations, and customer data. The UK’s Cyber Monitoring Centre estimated the combined economic impact of these incidents at between £270 million and £440 million, while Co-op alone reported more than £200 million in lost revenue linked to the attack, according to this report by ITpro.

Security experts believe social engineering played a significant role in how the attackers gained access. The incidents highlighted a critical reality of modern cybersecurity: even organisations with substantial technology investments remain vulnerable when attackers can exploit people, processes, or trusted third-party relationships.

For employers, the lesson is difficult to ignore. Cybersecurity is not simply a technology problem. Hiring the right people, establishing strong processes, and creating a security-conscious culture can be just as important as investing in the latest security tools.

The Cost of a Bad Hire Is Increasing

Every hiring decision carries some level of risk. In technology roles, that risk is growing.

An inexperienced engineer may introduce a configuration error. A technology manager may underestimate a critical vulnerability. A project team lacking sufficient expertise may fail to identify weaknesses before systems go live.

As organisations continue investing in cloud platforms, digital transformation programmes, automation, and artificial intelligence, the potential impact of these mistakes increases.

At the same time, businesses face growing expectations from customers, regulators, and stakeholders to demonstrate strong governance and security practices. Meeting those expectations requires capable people who understand both technology and risk.

Technology investments alone cannot deliver security outcomes.

AI Is Creating New Governance Challenges

Artificial intelligence is transforming the way organisations operate. Businesses increasingly use AI to improve productivity, accelerate decision-making, automate routine tasks, and support customer interactions.

However, the rapid adoption of AI also introduces new governance challenges.

IBM’s Cost of a Data Breach Report 2025 found that 97% of organisations that experienced an AI-related security incident lacked proper AI access controls. The same research found that 63% lacked formal AI governance policies.

These findings suggest that many organisations are adopting new technologies faster than they are developing the controls needed to manage them effectively.

As AI becomes more deeply embedded within business operations, demand will continue to grow for professionals who understand security, governance, risk management, and responsible technology deployment.

The Cybersecurity Skills Gap Is Becoming a Business Challenge

At the same time as security risks are increasing, organisations continue to face significant talent shortages.

ISC2’s 2026 analysis of the UK cybersecurity workforce found that 95% of organisations reported at least one cybersecurity skills gap, with 58% describing those shortages as significant or critical. AI skills emerged as the most urgent capability gap, reflecting the growing need for organisations to recruit and develop professionals who can secure increasingly AI-driven environments.

The problem extends beyond dedicated security roles.

Businesses increasingly need cloud professionals with security expertise, infrastructure engineers with governance knowledge, software developers who understand secure coding practices, and technology leaders capable of balancing innovation with risk management.

As digital environments become more complex, competition for these skills is likely to intensify.

Looking Beyond Traditional Security Backgrounds

One response to the skills shortage is to expand the definition of cybersecurity talent.

Many professionals already possess highly transferable skills. Infrastructure engineers understand resilience and availability. Cloud architects manage identity and access controls every day. Network specialists regularly deal with security principles. Senior systems administrators often have extensive experience managing operational risk.

Forward-thinking organisations are increasingly identifying these adjacent skill sets and investing in targeted development rather than focusing exclusively on candidates with traditional cybersecurity titles.

This approach broadens the available talent pool while helping businesses build sustainable long-term capability.

Security Awareness Is Becoming a Core Hiring Requirement

Cybersecurity can no longer sit entirely within a dedicated security function.

Modern organisations expect developers, infrastructure teams, cloud specialists, data professionals, and technology leaders to understand their role in protecting systems and information.

As a result, hiring managers are placing greater emphasis on judgement, accountability, governance awareness, and risk management alongside technical expertise.

Knowledge of a particular platform or technology remains important. However, the ability to make sound decisions in complex environments is becoming equally valuable.

The strongest technology teams recognise that security is everyone’s responsibility.

Prevention Costs Less Than Recovery

Many organisations continue to spend heavily on security tools and platforms. Those investments are important, but technology alone cannot prevent every incident.

The financial impact of breaches such as the M&S attack in 2025 demonstrates how quickly security failures can become business failures. Recovery costs, operational disruption, legal exposure, reputational damage, and customer trust issues often persist long after systems have been restored.

Investing in skilled people helps reduce those risks before they emerge.

Strong hiring decisions do not simply fill vacancies. They strengthen governance, improve resilience, and reduce the likelihood of costly mistakes.

Hiring Has Become a Security Strategy

Cybersecurity is no longer just a technology issue. It is a people issue, a governance issue, and increasingly a hiring issue.

Every organisation depends on individuals to design systems, manage risk, oversee critical infrastructure, and make decisions that influence security outcomes. As technology continues to evolve and AI adoption accelerates, those decisions will become even more important.

Businesses that prioritise cybersecurity capability during hiring place themselves in a stronger position to navigate future challenges. Organisations that treat security as an afterthought may find themselves exposed to risks that technology alone cannot solve.

One poor security decision can cost millions.

One good hiring decision can help prevent it.