Logo
Cybersecurity

Cybersecurity Has More Entry Doors Than We Think

The next strong cyber professional may already be working in your organization. Their current job title just doesn’t say “security.”

ITSEC AsiaITSEC Asia
|
Sep 11, 2026
Cybersecurity Has More Entry Doors Than We Think

Picture a cybersecurity team and there’s a good chance you imagine people who studied computing, entered IT and gradually specialised in security.

That route exists. It’s hardly the only one.

ENISA’s 2026 research into cybersecurity investment and workforce challenges found that many employees in cyber-related roles lack formal cybersecurity qualifications and that a substantial share moved into the field from other professions. Upskilling and reskilling already account for part of the workforce organisations rely on today.

NIST is also putting more attention on multiple entry routes. Its cybersecurity career-pathway material, updated on 8 September, focuses on helping people connect their existing interests and strengths with specific work roles in the NICE Workforce Framework.

That matters because a cybersecurity talent strategy based entirely on finding finished cybersecurity professionals is competing for a limited supply. Sometimes it makes more sense to build one.

Cybersecurity Borrows Skills From Everywhere

Someone moving into cybersecurity doesn’t arrive empty-handed.

A network engineer already understands infrastructure and troubleshooting. A software developer knows how applications are assembled. Someone working in audit understands evidence, controls and compliance. A communications professional may be unusually good at translating technical risk during an incident.

Even seemingly distant backgrounds can contribute useful habits.

Career switchers may bring:

  • IT operations: systems, networks, troubleshooting and incident handling
  • Software development: application architecture, coding and development workflows
  • Audit and risk: controls, evidence, governance and regulatory thinking
  • Data roles: analysis, pattern recognition and working with large datasets
  • Project management: coordination, prioritisation and stakeholder management

The cybersecurity knowledge still has to be learned. Transferable skills simply mean the learner isn’t starting from zero.

A spreadsheet expert becoming a SOC analyst probably still has a few things to learn about malware. The spreadsheet has not been wasted.

Reskilling Changes the Talent Equation

This approach becomes especially useful for organizations trying to build internal capability.

Instead of asking only, “Where can we hire another security specialist?”, companies can also ask which employees already have adjacent skills and the aptitude to move into security.

The process needs more precision than sending everyone to the same introductory course. Organizations need to identify the target role, map existing abilities against it and train the missing competencies.

NIST’s NICE Framework supports exactly this type of thinking by defining cybersecurity work through roles, tasks, knowledge and skills rather than treating “cybersecurity professional” as one giant occupation.

For someone moving from IT operations into SOC work, the gap might include threat analysis and incident investigation. A developer moving toward application security may need deeper knowledge of secure coding, testing and attacker techniques. Someone from risk could move toward cyber governance with a different learning path again.

Build the Bridge, Then Let People Cross It

Practical training becomes valuable because career switchers need to connect what they already know with unfamiliar security situations.

A network engineer can investigate suspicious traffic in a cyber range. A developer can test an intentionally vulnerable application. A risk professional can work through a simulated incident and decide which controls failed.

That’s also where ITSEC Cyber & AI Academy can support workforce development through practical cybersecurity learning built around real tasks and scenarios, helping participants turn adjacent experience into usable cyber capability.

Indonesia needs more cybersecurity talent. Recruiting people already wearing cybersecurity titles will remain part of the answer.

The other part may be sitting two departments away.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: ENISA NIS Investments 2025 report, published 2026 · NIST NICE: Unlocking Student Pathways into Cybersecurity Careers, updated 8 September 2026 · NIST NICE Framework

Share this post

You may also like

What Information Security Process Manager Actually Does and Why Most Organizations Getting It Wrong
Cybersecurity

What Information Security Process Manager Actually Does and Why Most Organizations Getting It Wrong

INTRODUCTION Here is a number worth sitting with: organizations that detect breaches with a security AI and automation program save an average of USD 2.2 million compared to those that do not. Yet the operational role responsible for building, owning, and continuously improving those detection and response processes, the Information Security Process Manager, remains one of the least formally defined positions in enterprise security. Most organizations have the tools. Very few have the structured ownership that makes those tools work together as a system. ITSEC Asia, the cybersecurity leader in Indonesia with operations across Singapore, Australia, and the UAE, works directly with organizations to fill exactly this gap: turning fragmented security investments into managed, measurable, and genuinely effective programs. Sources: IBM Cost of a Data Breach Report 2024 [https://www.ibm.com/reports/data-breach] WHAT THE ROLE ACTUALLY OWNS An Information Security Process Manager is the operational architect of a security program. Where a CISO sets direction and a security analyst executes individual tasks, the Process Manager is responsible for defining, documenting, improving, and governing the processes that

|
Mei 25, 2026 — 5 minutes read
How to Protect Your Personal Data: A Practical Guide for Individuals and Organizations
Cybersecurity

How to Protect Your Personal Data: A Practical Guide for Individuals and Organizations

Your personal data is more valuable than you might think, and cybercriminals know it. From your email address and phone number to your banking credentials and health records, every piece of information you share online can be stolen, sold, or weaponized against you. But here is the uncomfortable truth: most people underestimate how vulnerable they are, and most organizations still treat data protection as an afterthought rather than a priority. This guide breaks down exactly how personal data gets compromised, what the real-world consequences look like, and, most importantly, what you can do about it right now. According to the IBM Cost of a Data Breach Report 2025, the global average cost reached USD 4.4 million. Behind every statistic is a real person whose identity was stolen, whose bank account was drained, or whose private records were exposed to strangers. WHY PERSONAL DATA PROTECTION IS A GLOBAL EMERGENCY We are living through a data breach epidemic. Every week, news breaks about a new company, government agency, or institution that has

ITSEC AsiaITSEC Asia
|
Apr 27, 2026 — 8 minutes read
Cybersecurity for Financial Institutions: Strengthening Resilience Under OJK Regulations
Cybersecurity

Cybersecurity for Financial Institutions: Strengthening Resilience Under OJK Regulations

Digital transformation is reshaping Indonesia's financial sector. Banks, insurance companies, fintech platforms and other financial institutions are increasingly dependent on digital services to deliver better customer experiences and improve operational efficiency. However, this growing digital ecosystem also expands the attack surface. Cyber threats targeting financial institutions continue to evolve, while regulators are placing greater emphasis on cyber resilience and operational risk management. For financial institutions operating in Indonesia, cybersecurity is no longer simply an IT issue. It is a business imperative and a regulatory requirement. WHY FINANCIAL INSTITUTIONS ARE ATTRACTIVE TARGETS Financial institutions manage some of the most valuable assets in the digital economy. These include: * Customer information. * Financial transactions. * Payment systems. * Personal data. * Sensitive internal information. This makes the sector particularly attractive to cybercriminals. Successful attacks can result in: * Financial losses. * Service disruptions. * Regulatory consequences. * Reputational damage. * Loss of customer trust. Protecting digital assets has therefore become essential to maintaining long-term resilience. THE GROWING ROLE OF OJK IN CYBERSECURITY Indonesia's Financial Services Authority (OJK)

ITSEC AsiaITSEC Asia
|
Jun 15, 2026 — 4 minutes read

Receive weekly
updates on new posts

Subscribe