Logo
Cybersecurity

Cybersecurity Has More Entry Doors Than We Think

The next strong cyber professional may already be working in your organization. Their current job title just doesn’t say “security.”

ITSEC AsiaITSEC Asia
|
Sep 11, 2026
Cybersecurity Has More Entry Doors Than We Think

Picture a cybersecurity team and there’s a good chance you imagine people who studied computing, entered IT and gradually specialised in security.

That route exists. It’s hardly the only one.

ENISA’s 2026 research into cybersecurity investment and workforce challenges found that many employees in cyber-related roles lack formal cybersecurity qualifications and that a substantial share moved into the field from other professions. Upskilling and reskilling already account for part of the workforce organisations rely on today.

NIST is also putting more attention on multiple entry routes. Its cybersecurity career-pathway material, updated on 8 September, focuses on helping people connect their existing interests and strengths with specific work roles in the NICE Workforce Framework.

That matters because a cybersecurity talent strategy based entirely on finding finished cybersecurity professionals is competing for a limited supply. Sometimes it makes more sense to build one.

Cybersecurity Borrows Skills From Everywhere

Someone moving into cybersecurity doesn’t arrive empty-handed.

A network engineer already understands infrastructure and troubleshooting. A software developer knows how applications are assembled. Someone working in audit understands evidence, controls and compliance. A communications professional may be unusually good at translating technical risk during an incident.

Even seemingly distant backgrounds can contribute useful habits.

Career switchers may bring:

  • IT operations: systems, networks, troubleshooting and incident handling
  • Software development: application architecture, coding and development workflows
  • Audit and risk: controls, evidence, governance and regulatory thinking
  • Data roles: analysis, pattern recognition and working with large datasets
  • Project management: coordination, prioritisation and stakeholder management

The cybersecurity knowledge still has to be learned. Transferable skills simply mean the learner isn’t starting from zero.

A spreadsheet expert becoming a SOC analyst probably still has a few things to learn about malware. The spreadsheet has not been wasted.

Reskilling Changes the Talent Equation

This approach becomes especially useful for organizations trying to build internal capability.

Instead of asking only, “Where can we hire another security specialist?”, companies can also ask which employees already have adjacent skills and the aptitude to move into security.

The process needs more precision than sending everyone to the same introductory course. Organizations need to identify the target role, map existing abilities against it and train the missing competencies.

NIST’s NICE Framework supports exactly this type of thinking by defining cybersecurity work through roles, tasks, knowledge and skills rather than treating “cybersecurity professional” as one giant occupation.

For someone moving from IT operations into SOC work, the gap might include threat analysis and incident investigation. A developer moving toward application security may need deeper knowledge of secure coding, testing and attacker techniques. Someone from risk could move toward cyber governance with a different learning path again.

Build the Bridge, Then Let People Cross It

Practical training becomes valuable because career switchers need to connect what they already know with unfamiliar security situations.

A network engineer can investigate suspicious traffic in a cyber range. A developer can test an intentionally vulnerable application. A risk professional can work through a simulated incident and decide which controls failed.

That’s also where ITSEC Cyber & AI Academy can support workforce development through practical cybersecurity learning built around real tasks and scenarios, helping participants turn adjacent experience into usable cyber capability.

Indonesia needs more cybersecurity talent. Recruiting people already wearing cybersecurity titles will remain part of the answer.

The other part may be sitting two departments away.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: ENISA NIS Investments 2025 report, published 2026 · NIST NICE: Unlocking Student Pathways into Cybersecurity Careers, updated 8 September 2026 · NIST NICE Framework

Share this post

You may also like

Top Five Cybersecurity Threats to Small Business Owners
Cybersecurity

Top Five Cybersecurity Threats to Small Business Owners

According to a recent Verizon Data Breach Investigations Report, over the past two years, small and medium-sized businesses have become the primary target of cybercriminals, and they are now more affected by cyber breaches than large-scale businesses. Cyberattacks on SMEs have increased because cybercriminals have predicted that small and medium-sized enterprises have fewer resources to dedicate to their security. Most SMEs lack dedicated security professionals, and they are too small to afford them. This makes them vulnerable and easy targets for cybercriminals. In this context, neglecting security is no longer an option, and the assumption that your business is too small to attract the interest of cybercriminals is unrealistic. TOP FIVE CYBER THREATS AFFECTING SMALL AND MEDIUM-SIZED ENTERPRISES Incompatible Operating Systems and Software: Ensure that your computers and the software running on them are up to date. This is crucial and forms a solid foundation for good security practices. Hackers exploit vulnerabilities in outdated software and operating systems, often infiltrating organizations. Failing to apply software and operating system updates when they

ITSEC AsiaITSEC Asia
|
Jul 20, 2023 5 minutes read
Healthcare Cybersecurity in Southeast Asia: Why Patient Data Systems Are the New Frontline
Cybersecurity

Healthcare Cybersecurity in Southeast Asia: Why Patient Data Systems Are the New Frontline

INTRODUCTION What does it take for an attacker to compromise the personal health records of 1.5 million patients, including a sitting prime minister? At SingHealth in 2018, the answer turned out to be a single unpatched vulnerability, a phishing email, and nearly a year of undetected access before anyone noticed something was wrong. The investigation that followed found no penetration tests had been conducted, no two-factor authentication had been enabled on critical systems, and cybersecurity had been treated as an IT management issue rather than an organizational risk. The Committee of Inquiry described the failures as a catalogue of missed opportunities that a far less skilled attacker could have exploited just as easily. That was 2018. Since then, the threat to healthcare systems across Southeast Asia has not diminished. It has industrialized. Cyberattacks in the region doubled in 2024 compared to the previous year, with healthcare consistently listed alongside finance and government as a primary target. Globally, healthcare accounted for 23% of all data breaches in 2024, overtaking finance for the

ITSEC AsiaITSEC Asia
|
Jun 30, 2026 8 minutes read
Human + AI: Why the Future of Offensive Security Isn't Human vs Machine
Cybersecurity

Human + AI: Why the Future of Offensive Security Isn't Human vs Machine

Artificial intelligence is transforming cybersecurity. From threat detection and vulnerability management to attack simulations and security operations, AI is enabling organizations to process information faster and automate tasks that once required significant manual effort. As AI adoption accelerates, a common question continues to emerge: Will AI replace cybersecurity professionals? The short answer is no. In reality, the future of offensive security is not about humans competing against machines. It is about combining the strengths of both to create a more effective and sustainable approach to cybersecurity. WHY OFFENSIVE SECURITY IS BECOMING MORE CHALLENGING Modern environments are more complex than ever. Organizations are embracing cloud computing, APIs, remote work and AI-driven applications. At the same time, threat actors are leveraging automation and AI to identify and exploit vulnerabilities faster. Security teams face several challenges: * Expanding attack surfaces. * Increasing volumes of vulnerabilities. * Limited cybersecurity resources. * Alert fatigue. * Time-consuming manual processes. * Growing compliance requirements. As environments continue to evolve, relying exclusively on traditional approaches becomes increasingly difficult. This is where

ITSEC AsiaITSEC Asia
|
Jun 15, 2026 4 minutes read

Receive weekly
updates on new posts

Subscribe