Cybersecurity Has More Entry Doors Than We Think
The next strong cyber professional may already be working in your organization. Their current job title just doesn’t say “security.”

Picture a cybersecurity team and there’s a good chance you imagine people who studied computing, entered IT and gradually specialised in security.
That route exists. It’s hardly the only one.
ENISA’s 2026 research into cybersecurity investment and workforce challenges found that many employees in cyber-related roles lack formal cybersecurity qualifications and that a substantial share moved into the field from other professions. Upskilling and reskilling already account for part of the workforce organisations rely on today.
NIST is also putting more attention on multiple entry routes. Its cybersecurity career-pathway material, updated on 8 September, focuses on helping people connect their existing interests and strengths with specific work roles in the NICE Workforce Framework.
That matters because a cybersecurity talent strategy based entirely on finding finished cybersecurity professionals is competing for a limited supply. Sometimes it makes more sense to build one.
Cybersecurity Borrows Skills From Everywhere
Someone moving into cybersecurity doesn’t arrive empty-handed.
A network engineer already understands infrastructure and troubleshooting. A software developer knows how applications are assembled. Someone working in audit understands evidence, controls and compliance. A communications professional may be unusually good at translating technical risk during an incident.
Even seemingly distant backgrounds can contribute useful habits.
Career switchers may bring:
- IT operations: systems, networks, troubleshooting and incident handling
- Software development: application architecture, coding and development workflows
- Audit and risk: controls, evidence, governance and regulatory thinking
- Data roles: analysis, pattern recognition and working with large datasets
- Project management: coordination, prioritisation and stakeholder management
The cybersecurity knowledge still has to be learned. Transferable skills simply mean the learner isn’t starting from zero.
A spreadsheet expert becoming a SOC analyst probably still has a few things to learn about malware. The spreadsheet has not been wasted.
Reskilling Changes the Talent Equation
This approach becomes especially useful for organizations trying to build internal capability.
Instead of asking only, “Where can we hire another security specialist?”, companies can also ask which employees already have adjacent skills and the aptitude to move into security.
The process needs more precision than sending everyone to the same introductory course. Organizations need to identify the target role, map existing abilities against it and train the missing competencies.
NIST’s NICE Framework supports exactly this type of thinking by defining cybersecurity work through roles, tasks, knowledge and skills rather than treating “cybersecurity professional” as one giant occupation.
For someone moving from IT operations into SOC work, the gap might include threat analysis and incident investigation. A developer moving toward application security may need deeper knowledge of secure coding, testing and attacker techniques. Someone from risk could move toward cyber governance with a different learning path again.
Build the Bridge, Then Let People Cross It
Practical training becomes valuable because career switchers need to connect what they already know with unfamiliar security situations.
A network engineer can investigate suspicious traffic in a cyber range. A developer can test an intentionally vulnerable application. A risk professional can work through a simulated incident and decide which controls failed.
That’s also where ITSEC Cyber & AI Academy can support workforce development through practical cybersecurity learning built around real tasks and scenarios, helping participants turn adjacent experience into usable cyber capability.
Indonesia needs more cybersecurity talent. Recruiting people already wearing cybersecurity titles will remain part of the answer.
The other part may be sitting two departments away.
Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.
References: ENISA NIS Investments 2025 report, published 2026 · NIST NICE: Unlocking Student Pathways into Cybersecurity Careers, updated 8 September 2026 · NIST NICE Framework
.png)

.png)
