Cybersecurity Has a People Skills Gap Too
Knowing what happened is valuable. Explaining it clearly enough for someone else to make the right decision is another capability entirely.

An analyst has spent two hours investigating suspicious activity. They understand the sequence, know which systems may be affected and have a reasonable hypothesis about what the attacker did.
Then the incident manager asks a simple question: “What do we need to do now?”
The answer suddenly requires more than technical knowledge.
Cybersecurity work is full of moments like this. Findings need to be explained. Assumptions need to be challenged. Teams need to disagree without losing time. Technical specialists have to communicate with executives, engineers, auditors and people who would prefer never to hear the phrase “lateral movement” before their first coffee.
NIST’s NICE program treats these capabilities as part of cybersecurity work itself. Its workplace skills resources include communication, collaboration, critical thinking, conflict management, resilience, strategic thinking and relationship building.
That matters for how organizations train cybersecurity professionals.
Communication Changes the Value of Technical Skill
Consider a penetration tester who discovers a serious vulnerability.
Finding it requires technical skill. Explaining why it matters requires another set of abilities.
The tester needs to describe the attack path accurately, separate evidence from assumptions and give developers enough detail to reproduce the problem. Someone may also need to explain the business impact to management without turning the discussion into either a catastrophe or a lecture on protocol internals.
NICE describes cybersecurity communication broadly, from working with teammates and writing reports to creating presentations and engaging leadership and external stakeholders. It also emphasizes listening, because communication fails rather efficiently when everyone is only waiting for their turn to speak.
Pressure Makes Workplace Skills Visible
These capabilities become even easier to see during incidents.
A responder may have incomplete evidence and several teams asking for answers simultaneously. An engineer may disagree with a containment decision because it could disrupt production. Management may want certainty that simply doesn’t exist yet.
Technical knowledge still matters. So does the ability to:
- Explain what is known, unknown and assumed
- Ask precise questions under time pressure
- Challenge a decision without derailing the response
- Adapt technical detail to different audiences
- Document decisions so another person can continue the work
- Recognize when a disagreement needs escalation
NICE specifically includes conflict management because cybersecurity professionals regularly work in situations where the consequences of a poor decision can be substantial.
These Skills Can Be Practised
Communication shouldn’t be left to personality.
A cyber range exercise can require analysts to brief an incident manager after investigating an attack. Penetration testing learners can present findings to a simulated development team. A cloud security exercise can require participants to defend a remediation decision when another team raises operational concerns.
The technical problem remains central. The exercise simply continues until participants have transferred their understanding to someone else.
That approach fits practical development at ITSEC Cyber & AI Academy. Realistic scenarios can train technical capability while also requiring participants to explain findings, coordinate decisions and work through uncertainty.
Cybersecurity teams need people who can find difficult problems.
They also need people who can make those problems understandable to everyone responsible for fixing them.
Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.
References: NIST NICE: Workplace Skills and the NICE Framework · NIST: Cyber Career Realities Revealed, announced September 2026 · NIST NICE Workforce Framework
.png)


