top of page

Fortinet's 2026 Cybersecurity Skills Gap Report: What It Means for Team Training

4 hours ago
6 min read
cybersecurity skills gap 2026

Fortinet's 2026 Cybersecurity Skills Gap Global Research Report shows that AI adoption is increasing the need for cybersecurity expertise, oversight, and professional development. In the global survey, 91% of respondents said their organizations were using or experimenting with AI-powered cybersecurity solutions, while 63% expected greater demand for AI oversight and governance roles over the following three years.


For IT and security leaders, the practical question is which skills their teams need to use these tools responsibly and effectively. Source: Fortinet report, pp. 7 and 34.


This article explains the findings and proposes a practical approach to assessing skills and planning training. The action plan is InLearn's editorial analysis, not a framework tested or prescribed by the survey.


What the 2026 report measures - cybersecurity skills gap 2026

The report was published in 2026, but Sapio Research conducted the underlying research in December 2025. It collected responses through online interviews and an email survey from 2,750 IT and cybersecurity decision-makers across 32 locations, including the United States. Source: methodology, p. 3.

Unless explicitly labeled otherwise, the statistics below describe the global survey sample. They are not U.S.-only findings. The research captures respondents' reported experiences, concerns, and expectations; it does not establish that taking a particular course causes a specific security outcome.


Key findings for cybersecurity training decisions

Global survey finding

Result

Report page

Organizations using or experimenting with AI-powered cybersecurity solutions

91%: 49% using and 42% experimenting

7

Respondents reporting that AI-enhanced tools improved team effectiveness and efficiency

84%

7

Respondents identifying difficulty finding candidates with specific AI experience in cybersecurity

60%

34

Respondents expecting greater need for AI oversight and governance roles over the next three years

63%

34

Respondents expecting existing staff to need reskilling or upskilling to work with AI tools

57%

34

IT decision-makers preferring candidates with technology-focused certifications

91%

44

Organizations likely to invest in AI-related cybersecurity training or certifications in the next 12 months

92%: 58% very likely and 34% somewhat likely

46

Source: Fortinet 2026 Cybersecurity Skills Gap Global Research Report, pages shown above. Forward-looking periods are measured from the December 2025 survey, not from the date you read this article.

The investment finding needs particular care: 92% expressed a likelihood of investing. It does not mean that 92% had approved budgets, purchased training, or completed certification programs.


AI adoption makes technical judgment more important

The research combines optimism about AI with concern about implementation. Alongside reported efficiency gains, 45% of respondents worried about insufficient staff expertise in AI, and 50% expressed concerns about data privacy and information security when implementing AI in cybersecurity. Source: p. 7.

Our editorial interpretation: training plans should connect tool proficiency with technical judgment. A team may know how to generate an AI-assisted response without being ready to validate its assumptions, recognize missing context, or decide whether a recommended action is appropriate.

For example, an analyst reviewing an AI-generated incident summary should be able to check the underlying logs, identify evidence that is missing, and explain why an escalation is warranted. A network administrator evaluating a suggested policy change should understand its effect on access and business operations before implementing it.

These are examples of capabilities to assess, not tasks the report directly tested.


Build three complementary capabilities

We recommend assessing three layers of competence:

  • Technical foundations: understanding network behavior, access controls, security policies, and the evidence used in investigations.

  • Tool operation: configuring, monitoring, and troubleshooting the technologies the organization actually deploys.

  • Oversight and accountability: validating AI-assisted outputs, protecting sensitive information, and knowing when human approval is required.

A course may address one or more of these layers. Its fit should be determined by the syllabus and the learner's responsibilities, rather than by the presence of “AI” in its title.


Turn the report into a practical cybersecurity skills assessment

The following approach is an InLearn editorial recommendation. It is designed to help managers turn a broad industry finding into a specific development decision.


1. Start with work the team must perform

Choose a small set of important workflows, such as reviewing firewall policies, investigating suspicious activity, troubleshooting secure connectivity, or validating an automated response.

For each workflow, define the expected outcome, the systems involved, and the person accountable for the decision. This makes the assessment about job performance rather than a general list of technology topics.


2. Assess demonstrated ability

Use a controlled lab exercise, a sanitized incident review, or a walkthrough of an approved procedure. Ask participants to explain both their actions and their reasoning.

A simple internal scale can help: needs guidance, performs independently, or can review and coach others. This is a suggested assessment scale, not a Fortinet certification standard.

Record observable evidence. “Completed the lab with two prompts” is more useful than “needs better cybersecurity skills.”


3. Separate training gaps from operational problems

If a task fails, determine why. The cause could be missing knowledge, unclear ownership, insufficient access, incomplete documentation, or excessive workload.

Training is appropriate when the missing capability can be developed through instruction and practice. A staffing shortage or an undefined approval process also needs an operational response.


4. Prioritize a specific learning outcome

Rank gaps by business impact, frequency of the task, upcoming changes, and the availability of experienced reviewers. Then write a concrete outcome, such as:

“After training and supervised practice, the administrator will be able to review a proposed firewall policy change, explain its access implications, and document the validation steps.”

Assign an owner, protected learning time, and a date for reassessment. Avoid sending an entire team to the same course simply because it is available.


5. Match training to the environment

For teams operating Fortinet technologies, compare the identified gap with the objectives and prerequisites of relevant official courses. Confirm the product version, technical level, and practical exercises before selecting a class.

Explore InLearn US's official Fortinet courses to review options against your team's responsibilities and learning needs.


A 90-day plan to connect learning with practice

This suggested timeline is a planning example, not a research finding or a promise that a skills gap can be closed in 90 days. Adjust it to course availability, prerequisites, workload, and the depth of the gap.

Days 1–30: establish the baseline. Select one priority workflow, assess current performance, and identify whether the main issue is knowledge, process, or capacity. Choose a learning objective and an appropriate course or development activity.

Days 31–60: learn and practice. Protect time for instruction and hands-on exercises. Pair learners with an experienced reviewer and document questions that need follow-up. Use approved lab environments for practice that could affect security or availability.

Days 61–90: reassess and apply. Repeat a comparable exercise, review the reasoning behind decisions, and update the relevant procedure. Decide whether the learner is ready for supervised application or needs further practice.

Track evidence of capability: accuracy during a policy review, quality of incident documentation, or the ability to troubleshoot without unnecessary escalation. Course attendance and exam results can contribute to the picture, but they should not be the only measures.


Where certifications fit into professional development

The survey found that 91% of IT decision-makers preferred candidates with technology-focused certifications. Separately, 92% expressed willingness to pay for an employee to obtain a certification. These findings indicate employer interest; willingness to pay does not establish that funding was actually provided. Source: p. 44.

For an individual professional, a certification goal can help organize study around a defined body of knowledge. For a manager, it can be one input into a development plan alongside practical assessments and observed performance.

Course completion and certification are separate outcomes. Before enrolling, confirm the current requirements for the intended credential. Training does not guarantee an exam result, employment, or the elimination of security risk.


Frequently asked questions

Is the Fortinet 2026 report based only on U.S. organizations?

No. It is a global survey of 2,750 IT and cybersecurity decision-makers across 32 locations, including the United States. Global results should not be presented as U.S.-specific statistics, and North America findings should retain their regional label. Methodology, p. 3.

When was the research conducted?

Sapio Research conducted it in December 2025. The report's publication year is 2026. References to the “next 12 months” describe expectations at the time of the survey. Pages 3 and 46.

Does the report show that AI removes the need for cybersecurity training?

No. While respondents reported benefits from AI-enhanced tools, 57% expected existing employees to require reskilling or upskilling to work with AI tools. That is an expectation reported by respondents, not a measurement of completed training. Page 34.

How should a manager choose a Fortinet course for a team?

Start with the tasks employees need to perform and the gaps demonstrated in an assessment. Compare those needs with course objectives, prerequisites, and the product versions in use. InLearn recommends selecting a course around a defined capability and planning time to practice afterward.

Does official training automatically lead to certification?

No. Completing training and earning a certification are distinct steps. Review the current requirements for the credential you are pursuing and treat instruction as part of preparation, alongside practice and any required assessments.


Plan your next step with InLearn US

Use the report to start a focused conversation: which security task does your team need to perform more confidently, and what evidence would show that capability has improved?

Bring that objective to your training decision. Explore official Fortinet training with InLearn US and identify options that match your team's responsibilities, experience, and development priorities.


Research source: Fortinet, 2026 Cybersecurity Skills Gap Global Research Report. Fieldwork: Sapio Research, December 2025. Page references use the report's printed page numbers, which match the PDF page count. The skills-assessment approach and 90-day plan are InLearn editorial recommendations; they were not evaluated by the survey.

 
 
 

Comments


bottom of page