Logo
Cybersecurity

Cybersecurity Has a People Skills Gap Too

Knowing what happened is valuable. Explaining it clearly enough for someone else to make the right decision is another capability entirely.

ITSEC AsiaITSEC Asia
|
Sep 25, 2026
Cybersecurity Has a People Skills Gap Too

An analyst has spent two hours investigating suspicious activity. They understand the sequence, know which systems may be affected and have a reasonable hypothesis about what the attacker did.

Then the incident manager asks a simple question: “What do we need to do now?”

The answer suddenly requires more than technical knowledge.

Cybersecurity work is full of moments like this. Findings need to be explained. Assumptions need to be challenged. Teams need to disagree without losing time. Technical specialists have to communicate with executives, engineers, auditors and people who would prefer never to hear the phrase “lateral movement” before their first coffee.

NIST’s NICE program treats these capabilities as part of cybersecurity work itself. Its workplace skills resources include communication, collaboration, critical thinking, conflict management, resilience, strategic thinking and relationship building.

That matters for how organizations train cybersecurity professionals.

Communication Changes the Value of Technical Skill

Consider a penetration tester who discovers a serious vulnerability.

Finding it requires technical skill. Explaining why it matters requires another set of abilities.

The tester needs to describe the attack path accurately, separate evidence from assumptions and give developers enough detail to reproduce the problem. Someone may also need to explain the business impact to management without turning the discussion into either a catastrophe or a lecture on protocol internals.

NICE describes cybersecurity communication broadly, from working with teammates and writing reports to creating presentations and engaging leadership and external stakeholders. It also emphasizes listening, because communication fails rather efficiently when everyone is only waiting for their turn to speak.

Pressure Makes Workplace Skills Visible

These capabilities become even easier to see during incidents.

A responder may have incomplete evidence and several teams asking for answers simultaneously. An engineer may disagree with a containment decision because it could disrupt production. Management may want certainty that simply doesn’t exist yet.

Technical knowledge still matters. So does the ability to:

  • Explain what is known, unknown and assumed
  • Ask precise questions under time pressure
  • Challenge a decision without derailing the response
  • Adapt technical detail to different audiences
  • Document decisions so another person can continue the work
  • Recognize when a disagreement needs escalation

NICE specifically includes conflict management because cybersecurity professionals regularly work in situations where the consequences of a poor decision can be substantial.

These Skills Can Be Practised

Communication shouldn’t be left to personality.

A cyber range exercise can require analysts to brief an incident manager after investigating an attack. Penetration testing learners can present findings to a simulated development team. A cloud security exercise can require participants to defend a remediation decision when another team raises operational concerns.

The technical problem remains central. The exercise simply continues until participants have transferred their understanding to someone else.

That approach fits practical development at ITSEC Cyber & AI Academy. Realistic scenarios can train technical capability while also requiring participants to explain findings, coordinate decisions and work through uncertainty.

Cybersecurity teams need people who can find difficult problems.

They also need people who can make those problems understandable to everyone responsible for fixing them.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: NIST NICE: Workplace Skills and the NICE Framework · NIST: Cyber Career Realities Revealed, announced September 2026 · NIST NICE Workforce Framework

Share this post

You may also like

AI Is Raising the Bar for Cybersecurity Talent
Cybersecurity

AI Is Raising the Bar for Cybersecurity Talent

For cybersecurity teams, AI is quickly moving from something experimental to something people actually use. The World Economic Forum’s Global Cybersecurity Outlook 2026 found that 77% of surveyed organizations had adopted AI for cybersecurity. It is already being used for tasks such as phishing detection, intrusion response and user-behaviour analysis. That sounds like good news for teams struggling with workload. And mostly, it is. But AI doesn’t remove the need for skilled cybersecurity professionals. It changes what those professionals need to be good at. AUTOMATION CAN DO MORE. SO HUMANS HAVE TO DO MORE TOO. The same WEF research found that 54% of organizations considered insufficient knowledge or skills a barrier to using AI effectively in cybersecurity. Another 41% pointed to the need for human oversight. That second number matters. AI can analyse enormous amounts of information quickly. What it still struggles with is context: whether an unusual event is genuinely dangerous, how a technical issue affects the business and what action makes sense when the available information is incomplete. Cybersecurity professionals increasingly need

ITSEC AsiaITSEC Asia
|
Sep 02, 2026 — 3 minutes read
Cybersecurity Has More Entry Doors Than We Think
Cybersecurity

Cybersecurity Has More Entry Doors Than We Think

Picture a cybersecurity team and there’s a good chance you imagine people who studied computing, entered IT and gradually specialised in security. That route exists. It’s hardly the only one. ENISA’s 2026 research into cybersecurity investment and workforce challenges found that many employees in cyber-related roles lack formal cybersecurity qualifications and that a substantial share moved into the field from other professions. Upskilling and reskilling already account for part of the workforce organisations rely on today. NIST is also putting more attention on multiple entry routes. Its cybersecurity career-pathway material, updated on 8 September, focuses on helping people connect their existing interests and strengths with specific work roles in the NICE Workforce Framework. That matters because a cybersecurity talent strategy based entirely on finding finished cybersecurity professionals is competing for a limited supply. Sometimes it makes more sense to build one. CYBERSECURITY BORROWS SKILLS FROM EVERYWHERE Someone moving into cybersecurity doesn’t arrive empty-handed. A network engineer already understands infrastructure and troubleshooting. A software developer knows how applications are assembled. Someone working in audit understands

ITSEC AsiaITSEC Asia
|
Sep 11, 2026 — 3 minutes read
OWASP Top 10 Explained: The Risks Every Organization Should Understand
Cybersecurity

OWASP Top 10 Explained: The Risks Every Organization Should Understand

Modern applications have become increasingly interconnected and complex. Organizations rely on web applications, APIs and cloud services to support critical business operations and deliver digital experiences. Unfortunately, attackers are evolving just as quickly. As cyber threats continue to grow, understanding common application security risks has become essential. This is where the OWASP Top 10 plays an important role. Widely regarded as one of the most influential resources in application security, the OWASP Top 10 provides organizations with a practical framework for understanding and prioritizing the most critical risks affecting web applications. Whether you are a developer, security professional or business leader, understanding these risks is essential for building stronger cyber resilience. WHAT IS OWASP? OWASP, or the Open Worldwide Application Security Project, is a global non-profit organization focused on improving software security. Among its many initiatives, the OWASP Top 10 is perhaps the most widely recognized. It highlights the most significant security risks affecting modern web applications based on industry data and expert consensus. The list is not intended to be a compliance checklist. Instead,

ITSEC AsiaITSEC Asia
|
Jun 15, 2026 — 5 minutes read

Receive weekly
updates on new posts

Subscribe