The perceived shortage of skilled cybersecurity professionals is symptomatic of organizational and strategic deficiencies, not primarily a personnel recruitment problem.
NIS2 obligates operators of critical infrastructures and essential services to comply with enhanced cybersecurity standards by 3 October 2026; non-compliance carries penalties of up to €10 million.
Companies must implement NIS2, EU AI Act and business continuity in parallel — a requirement profile that demands systematic competency building in compliance and IT security teams.