top of page

Building and Keeping the Cyber Force: The Human Infrastructure of National Security

ICIT Research
11 minutes ago
4 min read

October 2026

Author: Venice Goodwine


I have led cyber and IT workforces on both the civilian and defense sides. As chief information security officer at the U.S. Department of Agriculture, I built teams against the NICE Framework. As chief information officer of the Department of the Air Force, I served as the workforce executive for our civilian cyber and IT professionals and managed the DoD Cyber Workforce Framework. The lexicons differed, but the core problem did not. In both, my hardest and most consequential work was human: finding, developing, and keeping the people who make the technology work. That taught me a lesson the budget process still resists: the cyber workforce is national security infrastructure, and until we resource it as deliberately as any network or platform, modernization will keep outrunning our ability to staff it.


We talk about cyber infrastructure as networks, sensors, and platforms, and we fund it accordingly. The workforce that operates all of it rarely gets the same treatment, even though a control does nothing until a qualified person configures and watches it. Infrastructure earns the name because we plan it over decades, maintain it, and defend it as a national asset. Skilled cyber professionals meet that test. They take years to develop; their capabilities erode without steady training and experience; and their absence can fail the mission as surely as a collapsed bridge. A workforce gap stays invisible until an adversary finds it.


The shortage is well documented: Industry estimates put unfilled U.S. cybersecurity positions above 500,000, with qualified candidates for only about three-quarters of open roles, and government competes for that thin pool at a disadvantage. More than 100,000 federal employees retired this past year, and CISA, the civilian anchor of national cyber defense, shed close to a third of its staff through buyouts, layoffs, and early departures, including senior leaders. The same shortage reaches the private operators of critical infrastructure, where a regional utility or hospital competes for the same scarce people and usually loses, leaving the soft targets an adversary looks for.


Both frameworks I worked under exist to solve the first half of this problem: knowing what you actually have. NICE and the DoD Cyber Workforce Framework (DCWF) give you a common language to code every position to a work role and to see, honestly, where the gaps sit. That discipline is where many organizations fall short, treating the coding of a billet as a box to check for an inspector rather than the management data it is. When we coded positions with rigor at the Air Force, workforce planning stopped being anecdote and became arithmetic.


The tools to close the gap already exist, and the persistent failure is that too few managers use them. The Cyber Excepted Service, authorized under Title 10, allows DoD components to set pay above the standard General Schedule ceiling, promote on demonstrated qualifications rather than time-in-grade, appoint qualified candidates directly, and add local market supplements for hard-to-fill roles. The Department of Homeland Security runs a parallel system, its Cyber Talent Management System. I watched capable managers default to the familiar competitive-service process anyway, because the flexibilities looked like risk. Authorities on paper change nothing until leaders train their people to use them and back them for it.


Recruitment is only the entry point. Cyber skills age quickly, and the organizations that hold their edge treat upskilling as a standing investment. Rotational assignments, tuition tied to work-role qualifications, and deliberate paths from adjacent IT roles into security keep capability current and give people a reason to stay. Growing talent internally almost always costs less than buying it at a premium later.


Retention is the piece leaders most often misread. The people who left rarely left over salary alone. They left because of instability, murky advancement, or a sense that their work no longer mattered. Every contraction I have watched costs years of rebuilding trust and institutional knowledge that no hiring bonus can quickly recover, and the current drawdown is teaching a generation to doubt whether public service is a stable place to build a career.


Congress and policymakers can act on this now. Fund the cyber workforce as a protected, foundational budget line, so it is not the first account raided when budgets tighten. Make the flexible hiring and pay authorities that already exist, from the Cyber Excepted Service to the DHS Cybersecurity Talent Management System, the default across government, and pay for the manager training that turns them into hires. And hold agencies accountable by requiring them to code every position to a work role and report their gaps to oversight.


The cyber workforce is not a support function for national security. Rather, it is national security in and of itself, and the readiness gap will not close until we recruit, pay, and retain its people with the seriousness we reserve for the systems they defend.


Jim Routh

Venice M. Goodwine is a board member and CIO and CISO with over three decades of experience in military and civilian service, including 36 years in the U.S. Air Force. In 2025, she retired as a three-star equivalent after she led the digital transformation of a large, complex organization, oversaw a $17B budget, 2.8K civilian personnel, and provided enterprise-level direction and policy oversight to the more than 65K Air Force and Space Force cyberspace professionals across global portfolios. Venice has transitioned between industry, civilian, and reservist and active duty military roles throughout her career. She is a proven leader in enterprise IT, cloud migration, cybersecurity, data, and AI, with a record of modernizing governance, accelerating digital transformation, and strengthening risk management.


About ICIT

The Institute for Critical Infrastructure Technology (ICIT) is a nonprofit, nonpartisan, 501(c)3think tank with the mission of modernizing, securing, and making resilient critical infrastructure that provides for people’s foundational needs. ICIT takes no institutional positions on policy matters. Rather than advocate, ICIT is dedicated to being a resource for the organizations and communities that share our mission. By applying a people-centric lens to critical infrastructure research and decision making, our work ensures that modernization and security investments have a lasting, positive impact on society.  

Learn more at www.icitech.org.




 
 

The Institute for Critical Infrastructure Technology is a non-partisan 501(c)3 not-for-profit organization. 

EIN #47-5294309

Follow Us

  • LinkedIn
  • Youtube

Important Links

+  Support

+  Privacy Policy

Get the latest news & expert opinions delivered straight to your inbox

Keeping People at the Center of Critical Infrastructure

© 2026 by The Institute for Critical Infrastructure Technology (ICIT)

bottom of page