Cybersecurity professionals least impacted by layoffs, Singapore prioritises investments in Cybersecurity

(ISC)² – the world’s largest nonprofit association of certified cybersecurity professionals – today published its How the Cybersecurity Workforce Will Weather a Recession research report. The study found that despite looming recession concerns, cybersecurity teams will be least impacted by staffing cuts in 2023. The research highlights how C-suite executives view cybersecurity as an essential, valuable asset that is a strategic priority.

To assess the impact of a potential economic downturn on cybersecurity teams, (ISC)2 polled 1,000 C-suite executives in December 2022 across five countries: Germany, Japan, Singapore, the U.K. and U.S.       

85% of respondents expect layoffs will be necessary at their organizations, but cybersecurity roles are expected to be the least affected by staff reductions. Only 10% of organizations are likely to cut jobs in cybersecurity compared to other business areas, such as human resources (30%), finance (24%), operations (24%), marketing (22%) and sales (22%). This is because 87% of respondents believe that a reduction in cybersecurity staff will lead to greater risks against cyberattacks, as well as recognition of the challenges associated with building their cybersecurity team when skilled workers are in short supply.

“The importance placed on cybersecurity professionals, even during uncertain economic times, suggests that top executives understand the critical need for a strong cybersecurity team now more than ever,” said Clar Rosso, CEO, (ISC)². “This is not surprising given the upward trend in recent years where a weakening economy combined with global political tensions has led to increased cyber threats. A key test for executives in 2023 will be their ability to sustain their commitment toward strengthening their organizations’ resilience against evolving cyberthreats amid emerging budgetary pressures.”

Findings from the study also indicated that business leaders in Singapore have a bigger appetite for bolstering their cybersecurity teams, compared to their global counterparts.

Over the past two to three years, 98% of Singapore firms have increased their investments in cybersecurity staffing, above the global average of 90%. Compared to the global average of 74%, 88% of Singapore executives surveyed also indicated that they are likely to recruit cybersecurity talent that may be or have been impacted by layoffs at other companies in 2023.

Figure 1

This is likely due to a higher risk assessment of cybersecurity threats in Singapore compared to the rest of the world, with 96% of Singapore respondents – the highest among the countries surveyed – concerned about increased risk if staff cuts are necessary.

Figure 2

Once economic conditions improve, 54% of organizations in Singapore would prioritize rehiring and reinvesting in cybersecurity professionals. The willingness to keep hiring cybersecurity personnel is also for a practical reason – professionals in this field have always been in short supply and this is evident in Asia Pacific where the cybersecurity workforce gap stands at 2.2 million.

Key report findings include:

●   86% of Singapore respondents believe that cybersecurity threats will rise as a result of worsening economic conditions in 2023 (versus 80% globally)

●   29% of Singapore respondents cited cybersecurity as the least likely to be impacted in a first round of layoffs

●   Seniority (31%) was the least important factor when determining which staff would be impacted by layoffs compared to other factors such as performance (56%) and expertise/skill set (53%)

●   Junior staff in Singapore are expected to be affected at a higher rate (76%) than cybersecurity employees at other levels in the event of staff reductions

  • Cybersecurity professionals in Singapore may face promotion freezes, staff reductions in other teams, and longer hours due to economic conditions

To learn more, read the full “How the Cybersecurity Workforce Will Weather a Recession” report here.

Study Methodology

(ISC)² surveyed a total of 1,000 business executives in December 2022 from Germany (200), Japan (200), Singapore (200), the U.S. (200) and U.K. (200). Respondents were screened to allow only non-tech/security C-suite professionals to participate. Respondents were also limited to those working within an organization with a cybersecurity team of at least two (2) employees and anticipating economic challenges in 2023. The margin of error for the global descriptive statistics in this research is +/- 3.1 at a 95% confidence level.

About (ISC)²

(ISC)² is an international nonprofit membership association focused on inspiring a safe and secure cyber world. Best known for the acclaimed Certified Information Systems Security Professional (CISSP®) certification, (ISC)² offers a portfolio of credentials that are part of a holistic, pragmatic approach to security. Our association of candidates, associates, and members, nearly 330,000 strong, is made up of certified cyber, information, software, and infrastructure security professionals who are making a difference and helping to advance the industry. Our vision is supported by our commitment to educate and reach the general public through our charitable foundation –The Center for Cyber Safety and Education™. For more information on (ISC)², visit, follow us on Twitter, or connect with us on Facebook and LinkedIn.