
The Cybersecurity Skills Shortage Is a Design Problem, Not a Pipeline Problem
The cybersecurity skills shortage is not just a supply problem. It is a design problem. Many hiring and training systems inadvertently filter out neurodivergent candidates who possess the core skills cybersecurity demands: pattern recognition, sustained attention, and persistence, by prioritizing neurotypical communication styles over actual job performance.
Take one hiring artifact you use right now: a job description, a timed quiz, a first-round interview script, and ask a rude question about it: does this measure security work, or comfort with neurotypical performance?
The question stings because many teams already know the numbers game is failing. Open roles stay open. Threats do not pause out of politeness. Training programs keep graduating people who can talk fluently about security and still struggle with the work itself, while other candidates who can spot patterns, persist through messy evidence, and stay locked on a problem keep getting screened out before anyone sees them.
The usual story says the cybersecurity skills gap comes from a thin pipeline. Not enough people. Not enough credentials. Not enough years of experience. That story feels practical, and it justifies the usual fixes: post more jobs, add more certificates, widen university recruiting, automate the funnel. But the story breaks the moment you look closely at what cybersecurity actually asks a person to do.
A lot of cyber work is not polished presentation. It is anomaly detection. It is sustained attention. It is noticing that one event in a sea of normal events feels wrong. It is persistence when the answer does not appear in the first ten minutes. It is rapid task-switching when an incident suddenly changes shape. Those are not fringe demands. They sit in the middle of the field. Research notes from ISC2 and the SIGCSE 2026 poster session on neurodiverse talent describe the same alignment plainly: cybersecurity demands creativity, persistence, and pattern recognition, and neurodivergent people often bring deep focus, persistence, and strong pattern recognition to exactly those kinds of tasks.
Why the Pipeline Story Fails
That is the turn. The shortage is not only a supply problem. It is a design problem.
The strongest objection comes quickly, and it deserves a straight answer. Security jobs involve teamwork, pressure, ambiguity, and communication. You cannot fill a security team by romanticizing neurodivergence or pretending every autistic person is a brilliant threat hunter, every person with ADHD a perfect incident responder, every dyslexic learner a hidden genius. Fair enough. Stereotypes dressed up as compliments are still stereotypes. Hyperfocus can become tunnel vision. Rapid task-switching can become distraction. Communication differences can matter, especially in roles that involve clients, executives, or cross-team coordination.
None of that rescues the current system. It indicts it.
A good hiring or training system does not assume one cognitive style is universally superior. It asks which tasks matter in which roles, then measures those tasks directly. If incident response really needs fast context-switching under pressure, test that. If threat hunting really depends on patient pattern recognition across noisy data, test that. If a role requires briefing nontechnical leaders during an active incident, test that too. The problem is that many systems never get this far. They use proxies that happen to reward one social style: smooth eye contact, crisp small talk, quick answers in a timed setting, confidence under vague questioning, resumes written in the standard corporate dialect. Those are cheap to screen for. They are not the job.
This is where the field quietly loses people it says it cannot find.
How AI Screens Out the Wrong Things
AI-driven hiring pipelines make the problem worse because they scale the proxy problem. A rigid screener cannot easily tell the difference between weak security thinking and non-normative communication. If an applicant answers literally, structures experience differently, omits the expected self-promotional phrasing, or struggles with conventional interview rhythm, an automated system can read that as poor fit. The candidate may still be excellent at tracing a suspicious pattern across logs or sticking with a tedious investigation until the signal appears. The system never finds out.
The same mistake starts earlier, in training. Many cyber courses still assume one ideal learner: comfortable with dense text, broad lectures, fixed pacing, noisy group settings, and frequent context-switching that serves the course schedule rather than the learner's comprehension. Research notes point out that access to cyber training is not always designed with neurodiverse learners in mind. That sounds abstract until you picture what it means in practice. A learner who needs visual structure gets a wall of text. A learner who understands best through repeated pattern exposure gets a broad survey. A learner with ADHD gets long passive instruction followed by a high-stakes assessment. A learner who can do the work but processes language differently gets graded on how fluently they explain it in the approved style.
Then employers look at the resulting completion rates or confidence levels and conclude the candidate pool is thin. It is a neat trick. The system creates friction, then treats the bruises as evidence of individual deficit.
Designing Training for Real Learners
A better way is already visible. At the University of Missouri, researchers are building USucceed, a platform designed to teach cybersecurity to people with autism, dyslexia, attention-deficit disorders, and other neurodevelopmental differences. The point here is larger than one platform. It proves something many teams still treat as speculative: alternative training methods are viable enough to build on purpose. Noah Glaser, an assistant professor and director of the Information Experience Laboratory in Mizzou's College of Education and Human Development, is involved in that work. The stated aim is direct and practical: to address the growing need for a skilled cybersecurity workforce.
Notice what changes when you take that seriously. The conversation moves from charity to systems design. The question stops being, "How do we accommodate unusual learners after the fact?" The better question is, "Why was the default design so narrow in the first place?" Security already accepts that systems fail when they are built around brittle assumptions. Yet many training and hiring processes still assume one clean user profile, as if every capable analyst learns, speaks, and interviews in the same rhythm.
This is also why the "pipeline" story keeps flattering the people in charge. A pipeline problem sounds external. Schools did not produce enough people. Candidates did not prepare well enough. The market is tight. A design problem points inward. It asks who wrote the job description, who chose the interview loop, who decided that a timed verbal answer predicts investigative skill, who bought the screener, who accepted a training format that selects for lecture endurance rather than security aptitude.
Once you see that, familiar practices start to look strange.
Take the common entry-level job post that asks for polished communication, comfort in fast-paced environments, the ability to wear many hats, and a long list of tools. On paper it sounds normal. In effect it often tells candidates that style comes first, context-switching must look socially graceful, and broad familiarity matters more than deep capability in the tasks that actually consume the day. A person with strong pattern recognition and sustained attention may read that post and self-select out. Another may apply and get filtered by an AI screener that prizes keyword symmetry and conventional phrasing. The team then says it cannot find enough talent.
Or take the standard interview. One candidate gets a vague prompt and talks smoothly for five minutes. Another pauses, asks clarifying questions, gives a precise but less socially polished answer, and maybe misses the expected conversational dance. If the role is threat hunting, which response should impress you more? The field often rewards the first. The work often rewards the second.
This does not mean every cyber role should be redesigned around every cognitive profile. It means roles should stop pretending they already are well designed. Some work genuinely requires frequent live communication. Some work benefits from long, quiet concentration. Some roles need both, but at different stages. Good design starts with that granularity. Bad design uses one interview ritual for all of it.
Friction at the Doorway
The same principle applies to learning from zero. If you are neurodivergent and trying to enter cybersecurity, the most demoralizing experience is often not the material itself. It is the feeling that you understand the pattern but keep failing the wrapper. You may grasp network behavior, threat analysis, or investigative logic, yet stall on pacing, format, noise, or assessment style. That does not mean you are unsuited to the field. It often means the field has attached avoidable friction to the doorway.
This is why tailored teaching matters so much. A learner with autism may benefit from stable structure, explicit rules, and repeated exposure to patterns. A learner with ADHD may do better with shorter cycles, clearer milestones, and tasks that channel hyperfocus rather than punish it. A learner with dyslexia may need visual supports and different ways to process technical material. Those are not indulgences. They are design choices that let the actual skill emerge. USucceed matters because it treats that premise as buildable, not theoretical.
The broader culture is inching toward this recognition. A SIGCSE 2026 poster session is dedicated to empowering neurodiverse talent in cybersecurity, scheduled for February 18 through 21, 2026 in St. Louis. A conference poster will not fix your hiring funnel, and it will not rewrite your training modules. But it does signal that the idea has moved past private frustration. The field is beginning to name the waste.
The Anomaly Detection Test
Here is the specific instance where the whole argument comes into focus: anomaly detection.
Lots of cyber work boils down to noticing the one wrong thing that does not announce itself. A login pattern that almost fits. A sequence of events that is normal until the fourth step. A piece of traffic that resembles the rest until one detail breaks the shape. This kind of work rewards people who enjoy patterns, tolerate repetition, and can stay with ambiguity long enough for a meaningful deviation to surface. If your hiring process filters heavily on conversational smoothness before it ever tests for that capacity, you are screening for the wrapper and missing the gift.
And then you call it a shortage.
One Honest Edit
So what should you do first, without launching a grand reform program you will never finish?
Audit one step. Just one. Pick the first obstacle a real person meets in your system: a job description, a screening question, a timed exercise, a training module. Then ask the question from the opening and answer it honestly. Does this test the skill, or the ability to perform neurotypical communication?
If it is a job description, cut one vague social demand and replace it with one concrete task. If it is an interview prompt, rewrite it so the candidate can show reasoning rather than charm. If it is a training module, remove one avoidable source of friction: dense text with no visual structure, a pacing assumption, an assessment format that confuses recall speed with competence. One step is enough to reveal the pattern.
Try this within seven days. Pick one artifact in your process and mark every line that rewards presentation more than security ability. Then change one of those lines before the week ends.
You do not need a manifesto. You need one honest edit.
The field keeps talking as if talent were a resource hidden somewhere upstream, waiting to be mined. Much of it is already at the gate, failing a test for the wrong thing. The shortage may look like an empty pipeline from a distance. Up close, it looks more like a locked door with the wrong label on it.

