Does the Best Cyber Security Candidate Always Have the Right Certifications?

CISSP, CISM, CRISC, CISA and many other certifications matter. But when does a valuable professional credential become an unnecessary hiring filter?

Sean Farrell September 2026 7 minute read

A certification can help someone through a recruitment filter. It can't tell you how they will perform when the situation stops following the textbook.

Cyber Security, Operational Resilience and IT Risk now have professional certifications covering almost every specialist area. CISSP, CISM, CRISC, CISA, CCSP and many others all have their place. They demonstrate knowledge, commitment and a recognised professional standard and for some roles, they are completely relevant. But somewhere along the way, a useful credential can turn into something else: a gate. And that is where organisations get recruitment wrong.

I have seen strong candidates with years of relevant experience miss out on interviews not because they lacked the ability or couldn't do the job, but simply because they didn't tick a specific box on a CV.

The uncomfortable question is whether the employer has screened out a weak candidate, or just screened out someone they should have spoken to.

The certificate isn't the problem

This isn't an argument against professional certifications. Cyber Security, Operational Resilience and IT Risk now have qualifications covering almost every specialist area and many are highly relevant to the roles they support.

In senior Cyber Security searches, certifications such as CISSP, CISM, CRISC, CISA, CCSP and MBCI can all provide useful evidence of professional knowledge and development. Their relevance, however, depends on the role.

CISO & senior leadership CISSP · CISM · CRISC
Security Architecture CISSP-ISSAP · SABSA · CCSP
Operational Resilience MBCI
Technical Security OSCP · GIAC

That distinction matters. A certification can be valuable evidence for one role without being the right measure for another. Its absence shouldn't automatically be treated as evidence that somebody lacks the capability to do the job.

The sensible debate isn't about choosing between certification or experience, since the strongest candidates often have both. The better question is when a valuable credential became an automatic reason to ignore someone who has already proved their capability in the real world.

When preferred quietly becomes essential

A job specification usually starts with good intentions by identifying what an organisation needs before listing technical capabilities and leadership requirements.

Then come the qualifications. CISSP preferred. CISM, CRISC or another relevant certification desirable. And by the time the brief hits an internal talent team or recruitment system, preferred quietly morphs into essential.

A search becomes a rigid checklist. Right acronym? Continue. Missing? Reject.

It is efficient, but it may also be filtering out precisely the people the organisation claims it cannot find.

The people organisations struggle to find are already the experienced ones.

UK Government research continues to show that experienced and senior cyber security professionals are among the people organisations find hardest to recruit, with governance, risk management and cyber security management also presenting recruitment challenges.

Source: Department for Science, Innovation & Technology, Cyber Security Skills in the UK Labour Market 2025.

The market makes this difficult to ignore

The latest UK Government research into the cyber security labour market makes this difficult to ignore because the issue isn't just getting more people into the field. Employers continue to report hard-to-fill vacancies for experienced and senior staff.

Among cyber businesses with hard-to-fill vacancies, 69% reported difficulty recruiting experienced or senior people at roughly the three-to-five-year level. Cyber security governance and risk management and cyber security management were also among the specialist areas where employers reported hard-to-fill vacancies.

If the market is already short of the exact experience you need, making the available pool smaller before you've even spoken to people deserves serious scrutiny.

A CV can confirm a qualification. It can't show you everything else.

At senior level, certifications shouldn't be treated as a proxy for seniority or capability.

For a CISO or senior security leader, evidence of leading security transformation, managing regulatory exposure, influencing boards, handling major incidents and building security organisations can tell you far more about someone's ability to do the job than the number of certifications they hold.

These roles require people who can challenge a board without losing the room, translate technical risk into commercial language and make decisions with incomplete information when pressure is high and consequences are real.

Those qualities are difficult to reduce to a search field and usually emerge through a proper conversation about someone's track record, judgement and reputation.

A certificate can tell you something important about a candidate.

It can't tell you everything important about them.

At senior level, recruitment needs judgement

If someone lacks the experience a role genuinely requires, or if a specific certification is mandatory for regulatory or contractual reasons, that is a legitimate reason not to progress them.

But those situations are very different from automatically excluding somebody because a qualification has migrated from useful to mandatory without anyone questioning why.

At senior level, recruitment should involve judgement rather than just finding the CV that most closely resembles the job description, because the goal is to find the person most capable of doing the job.

Executive Search shouldn't simply automate the filter

One of the main advantages of genuine Executive Search is that you aren't restricted to the people who applied or those who present perfectly against a predetermined list.

Sometimes you know someone whose experience makes them worth a conversation even though their CV doesn't satisfy every line of the brief.

That is when a recruiter has a choice between following the specification blindly or going back to the client to advocate for a strong candidate.

Finding names isn't particularly difficult anymore, but knowing which apparent mismatch is actually worth challenging takes real work.

Useful evidence, not the whole person

There is no reason to diminish the value of respected cyber security qualifications because they provide useful evidence of professional development and validate knowledge.

But a certificate is only one piece of evidence about a person. It is never the person.

When experienced cyber security people are already difficult to find, organisations need to be certain that every supposedly essential requirement really is essential.

The candidate who doesn't tick every box may not be the wrong candidate at all, but rather the one your recruitment process never allowed you to meet.

If you removed the certification requirement from your next senior cyber security search, who would suddenly become worth talking to?

Sean Farrell, Founder of MERCERBRIDGE

Sean Farrell

Founder, MERCERBRIDGE

Sean Farrell founded MERCERBRIDGE in 2006 and has more than three decades of specialist Executive Search experience, working with organisations across Cyber Security, Technology, Risk & Resilience and Data & AI Governance.

Looking beyond the obvious shortlist?

MERCERBRIDGE works with organisations seeking experienced senior and specialist leadership across Cyber Security, Technology, Risk & Resilience and Data & AI Governance.

Start a conversation