Logo
Cybersecurity

Cybersecurity Skills Need Maintenance Too

Cyber professionals don’t finish learning when the course ends. The systems they protect certainly don’t stop changing.

ITSEC AsiaITSEC Asia
|
Sep 14, 2026
Cybersecurity Skills Need Maintenance Too

A cybersecurity professional completes training on Friday. They’ve worked through the material, passed the assessment and returned to their job with a fresh set of skills.

Six months later, the environment looks different.

A cloud service has changed. The team has introduced AI tools. Attack techniques have evolved. Someone redesigned the incident process. Three new systems appeared and one old application that was supposedly retiring is, mysteriously, still alive.

This is why cybersecurity training increasingly needs to behave less like an annual event and more like professional maintenance.

NIST’s FISSEA Fall Forum on 15 September puts that idea into practice. Its agenda includes an interactive session on building a micro training module, followed by examples of cybersecurity learning tied to the NICE Workforce Framework and practical skill application.

The format matters. Learning doesn’t always need another full week away from work.

Small Learning Can Solve Specific Problems

CISA already uses micro learning as part of its cybersecurity training model. Its Continuous Diagnostics and Mitigation program offers short modules of roughly 3 to 10 minutes, designed to build foundational knowledge before deeper demonstrations and hands on activities.

That combination makes sense for cybersecurity.

A short module could refresh one narrow concept before a team practises it:

  • How to interpret a particular security signal
  • What changed in an incident escalation procedure
  • How a new cloud configuration affects access
  • What evidence should be preserved during an investigation
  • How a recent attack technique changes an existing playbook

The goal isn’t to compress an entire cybersecurity discipline into eight cheerful minutes. Some subjects deserve hours, days or considerably longer.

Micro learning works when the learning objective is equally focused.

Skills Have to Stay Close to the Work

Continuous learning becomes more useful when it connects directly to what people actually do.

A SOC analyst could review a new detection technique and immediately test it against a simulated incident. A penetration tester could study one unfamiliar vulnerability class before working through a vulnerable application. A cloud security practitioner could learn a configuration change and then diagnose a deliberately misconfigured environment.

ENISA takes a similar practical view of cybersecurity skills development. Its training and exercise approach centres on testing capabilities, identifying gaps and improving technical and operational competence.

That cycle matters: learn, apply, discover the gap, improve and repeat.

It also changes how organizations should think about training budgets. Sending someone to a substantial course can build capability. Keeping that capability current requires smaller opportunities to practise throughout the year.

Build a Learning Rhythm

A useful cybersecurity development plan might combine deeper structured training with shorter exercises, scenario refreshers and regular practical challenges.

The exact rhythm will vary by role. SOC teams may need frequent incident exercises. Penetration testers need exposure to new techniques and technologies. Managers need recurring practice making decisions during unfamiliar scenarios.

At ITSEC Cyber & AI Academy, hands on environments can support that progression by giving learners opportunities to practise cybersecurity skills against scenarios rather than leaving knowledge parked in course notes.

A certificate can mark the day someone completed training.

It can’t guarantee what they’ll still be able to do next March.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: NIST FISSEA Fall Forum, 15 September 2026 · CISA CDM Micro Learn Training · ENISA Trainings and Exercises

Share this post

You may also like

Cybersecurity Has a People Skills Gap Too
Cybersecurity

Cybersecurity Has a People Skills Gap Too

An analyst has spent two hours investigating suspicious activity. They understand the sequence, know which systems may be affected and have a reasonable hypothesis about what the attacker did. Then the incident manager asks a simple question: “What do we need to do now?” The answer suddenly requires more than technical knowledge. Cybersecurity work is full of moments like this. Findings need to be explained. Assumptions need to be challenged. Teams need to disagree without losing time. Technical specialists have to communicate with executives, engineers, auditors and people who would prefer never to hear the phrase “lateral movement” before their first coffee. NIST’s NICE program treats these capabilities as part of cybersecurity work itself. Its workplace skills resources include communication, collaboration, critical thinking, conflict management, resilience, strategic thinking and relationship building. That matters for how organizations train cybersecurity professionals. COMMUNICATION CHANGES THE VALUE OF TECHNICAL SKILL Consider a penetration tester who discovers a serious vulnerability. Finding it requires technical skill. Explaining why it matters requires another set of abilities. The tester needs to describe

ITSEC AsiaITSEC Asia
|
Sep 25, 2026 — 3 minutes read
Cybersecurity Training Needs More Room for Failure
Cybersecurity

Cybersecurity Training Needs More Room for Failure

A cybersecurity exercise where everything goes according to plan is wonderfully reassuring. It may also be slightly suspicious. Real incidents rarely arrive with tidy instructions. An alert can look harmless until it isn’t. Evidence can contradict itself. Someone makes an assumption, spends 20 minutes following it and discovers they were looking in entirely the wrong place. That messy part of cybersecurity deserves a bigger role in how people are trained. NIST’s National Initiative for Cybersecurity Education (NICE) is putting that idea directly into its workforce discussion. Its upcoming September session on preparing students for cyber careers focuses on realism-based training, including how controlled failure can become useful workforce data rather than something educators simply mark wrong. That’s a useful distinction. A score tells you whether someone found the answer. Watching how they reached it tells you much more. A WRONG ANSWER CAN REVEAL THE REAL SKILLS GAP Imagine two SOC trainees investigating the same suspicious activity. Both eventually identify the threat. One gets there systematically. The other clicks through five theories, misses a

ITSEC AsiaITSEC Asia
|
Sep 04, 2026 — 3 minutes read
This is Why You Should Automate Your Cybersecurity
Cybersecurity

This is Why You Should Automate Your Cybersecurity

DO YOU NEED TO AUTOMATE YOUR CYBERSECURITY OPERATIONS? The answer is likely "yes," and whenever I ask anyone about automation, they unequivocally state that automation will undoubtedly enhance the overall cybersecurity foundation if implemented correctly in their organizations. They say "if" because the organizations I speak with, not many of them have actually implemented automation into their operations, even if they intend to do so. They usually reason that they are too busy to stop and learn how. Here are some of the strongest reasons to automate... We live in a world where launching cyber attacks on an organization is far cheaper than defending it. To make matters worse, the threat landscape is becoming increasingly difficult to cover. You face exponentially growing threats where adversaries are getting the upper hand every day while your security tools incessantly warn you. Business resilience is the ultimate goal of any cybersecurity operation, and the only way to improve the overall resilience of your organization is to improve your overall efficiency in protecting it.

ITSEC AsiaITSEC Asia
|
Jul 20, 2023 — 4 minutes read

Receive weekly
updates on new posts

Subscribe