Logo
Cybersecurity

Cybersecurity Has More Entry Doors Than We Think

The next strong cyber professional may already be working in your organization. Their current job title just doesn’t say “security.”

ITSEC AsiaITSEC Asia
|
Sep 11, 2026
Cybersecurity Has More Entry Doors Than We Think

Picture a cybersecurity team and there’s a good chance you imagine people who studied computing, entered IT and gradually specialised in security.

That route exists. It’s hardly the only one.

ENISA’s 2026 research into cybersecurity investment and workforce challenges found that many employees in cyber-related roles lack formal cybersecurity qualifications and that a substantial share moved into the field from other professions. Upskilling and reskilling already account for part of the workforce organisations rely on today.

NIST is also putting more attention on multiple entry routes. Its cybersecurity career-pathway material, updated on 8 September, focuses on helping people connect their existing interests and strengths with specific work roles in the NICE Workforce Framework.

That matters because a cybersecurity talent strategy based entirely on finding finished cybersecurity professionals is competing for a limited supply. Sometimes it makes more sense to build one.

Cybersecurity Borrows Skills From Everywhere

Someone moving into cybersecurity doesn’t arrive empty-handed.

A network engineer already understands infrastructure and troubleshooting. A software developer knows how applications are assembled. Someone working in audit understands evidence, controls and compliance. A communications professional may be unusually good at translating technical risk during an incident.

Even seemingly distant backgrounds can contribute useful habits.

Career switchers may bring:

  • IT operations: systems, networks, troubleshooting and incident handling
  • Software development: application architecture, coding and development workflows
  • Audit and risk: controls, evidence, governance and regulatory thinking
  • Data roles: analysis, pattern recognition and working with large datasets
  • Project management: coordination, prioritisation and stakeholder management

The cybersecurity knowledge still has to be learned. Transferable skills simply mean the learner isn’t starting from zero.

A spreadsheet expert becoming a SOC analyst probably still has a few things to learn about malware. The spreadsheet has not been wasted.

Reskilling Changes the Talent Equation

This approach becomes especially useful for organizations trying to build internal capability.

Instead of asking only, “Where can we hire another security specialist?”, companies can also ask which employees already have adjacent skills and the aptitude to move into security.

The process needs more precision than sending everyone to the same introductory course. Organizations need to identify the target role, map existing abilities against it and train the missing competencies.

NIST’s NICE Framework supports exactly this type of thinking by defining cybersecurity work through roles, tasks, knowledge and skills rather than treating “cybersecurity professional” as one giant occupation.

For someone moving from IT operations into SOC work, the gap might include threat analysis and incident investigation. A developer moving toward application security may need deeper knowledge of secure coding, testing and attacker techniques. Someone from risk could move toward cyber governance with a different learning path again.

Build the Bridge, Then Let People Cross It

Practical training becomes valuable because career switchers need to connect what they already know with unfamiliar security situations.

A network engineer can investigate suspicious traffic in a cyber range. A developer can test an intentionally vulnerable application. A risk professional can work through a simulated incident and decide which controls failed.

That’s also where ITSEC Cyber & AI Academy can support workforce development through practical cybersecurity learning built around real tasks and scenarios, helping participants turn adjacent experience into usable cyber capability.

Indonesia needs more cybersecurity talent. Recruiting people already wearing cybersecurity titles will remain part of the answer.

The other part may be sitting two departments away.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: ENISA NIS Investments 2025 report, published 2026 · NIST NICE: Unlocking Student Pathways into Cybersecurity Careers, updated 8 September 2026 · NIST NICE Framework

Share this post

You may also like

Cybersecurity Network in the Age of AI: Building Resilient, Zero Trust Enterprise Architectures
Cybersecurity

Cybersecurity Network in the Age of AI: Building Resilient, Zero Trust Enterprise Architectures

Artificial intelligence is accelerating digital transformation across industries but it is also accelerating cyber threats. From AI-assisted phishing to automated vulnerability scanning, adversaries are operating faster and more intelligently than ever. In this environment, the cybersecurity network is no longer just an IT safeguard, it is a strategic business asset. According to industry trends, attackers increasingly exploit identity gaps, cloud misconfigurations, and east-west network traffic rather than relying solely on perimeter breaches. For CISOs, CTOs, and enterprise decision-makers, this shift demands a redefinition of how cybersecurity networks are designed, governed, and optimized. The question is no longer whether your network is protected. It is whether your architecture is resilient, adaptive, and aligned with business risk. WHAT IS A CYBERSECURITY NETWORK? A cybersecurity network refers to the integrated framework of technologies, controls, policies, and monitoring capabilities that protect an organization’s digital infrastructure from unauthorized access, disruption, and data compromise. In enterprise environments, it spans: * On-premises infrastructure * Hybrid cloud security environments * Multi-cloud deployments * SaaS platforms * Remote workforce connectivity *

ITSEC AsiaITSEC Asia
|
Feb 20, 2026 6 minutes read
Why Threat Hunting Is the Only Way to Stop Attackers Who Are Already Inside
Cybersecurity

Why Threat Hunting Is the Only Way to Stop Attackers Who Are Already Inside

INTRODUCTION Here is a question every security leader should sit with: if an attacker entered your network six months ago, would you know? According to IBM's Cost of a Data Breach Report 2024, the average time to identify a breach now stands at 194 days, nearly half a year of undetected attacker activity operating freely within enterprise infrastructure. Prevention tools, no matter how sophisticated, have already demonstrated they cannot close that window on their own. Firewalls, antivirus software, and multi-factor authentication are necessary. They are not sufficient. The organizations that understand this distinction are the ones investing in threat hunting: the proactive, intelligence-driven practice of searching for adversaries who have already bypassed the perimeter and are operating in silence. ITSEC Asia, the cybersecurity leader in Indonesia with operations across Singapore, Australia, and the UAE, works with organizations across these regions to build this exact capability before the next breach makes it urgent. Sources: IBM Cost of a Data Breach Report 2024 [https://www.ibm.com/reports/data-breach] THE GAP THAT REACTIVE SECURITY CANNOT CLOSE The fundamental flaw in

|
Mei 12, 2026 5 minutes read
Indonesia Is Buying More Cybersecurity Technology. Are Its People Ready?
Cybersecurity

Indonesia Is Buying More Cybersecurity Technology. Are Its People Ready?

Indonesia is investing more in cybersecurity technology as businesses move deeper into cloud computing, AI and digital services. Security platforms are becoming more sophisticated, but the people operating them have to keep pace. That gap is becoming harder to ignore. The 2025 ISC2 Cybersecurity Workforce Study found that 95% of cybersecurity professionals reported at least one skills need within their organizations. AI was identified as the top skills gap at 41%, followed by cloud security at 36%. The issue, then, isn't simply a shortage of cybersecurity professionals. It's a shortage of people with the specific skills needed to secure increasingly complex technology. NEW TECHNOLOGY CREATES NEW SECURITY SKILLS A company moving its infrastructure to the cloud needs professionals who understand cloud architecture, identity and access management and cloud-specific vulnerabilities. An organization adopting AI needs people who understand how AI systems can be secured and how attackers can exploit them. A security team deploying more automated tools still needs analysts who can investigate alerts and distinguish a genuine attack from a false positive. The

ITSEC AsiaITSEC Asia
|
Agt 27, 2026 4 minutes read

Receive weekly
updates on new posts

Subscribe