Logo
Cybersecurity

Cybersecurity Skills Need Maintenance Too

Cyber professionals don’t finish learning when the course ends. The systems they protect certainly don’t stop changing.

ITSEC AsiaITSEC Asia
|
Sep 14, 2026
Cybersecurity Skills Need Maintenance Too

A cybersecurity professional completes training on Friday. They’ve worked through the material, passed the assessment and returned to their job with a fresh set of skills.

Six months later, the environment looks different.

A cloud service has changed. The team has introduced AI tools. Attack techniques have evolved. Someone redesigned the incident process. Three new systems appeared and one old application that was supposedly retiring is, mysteriously, still alive.

This is why cybersecurity training increasingly needs to behave less like an annual event and more like professional maintenance.

NIST’s FISSEA Fall Forum on 15 September puts that idea into practice. Its agenda includes an interactive session on building a micro training module, followed by examples of cybersecurity learning tied to the NICE Workforce Framework and practical skill application.

The format matters. Learning doesn’t always need another full week away from work.

Small Learning Can Solve Specific Problems

CISA already uses micro learning as part of its cybersecurity training model. Its Continuous Diagnostics and Mitigation program offers short modules of roughly 3 to 10 minutes, designed to build foundational knowledge before deeper demonstrations and hands on activities.

That combination makes sense for cybersecurity.

A short module could refresh one narrow concept before a team practises it:

  • How to interpret a particular security signal
  • What changed in an incident escalation procedure
  • How a new cloud configuration affects access
  • What evidence should be preserved during an investigation
  • How a recent attack technique changes an existing playbook

The goal isn’t to compress an entire cybersecurity discipline into eight cheerful minutes. Some subjects deserve hours, days or considerably longer.

Micro learning works when the learning objective is equally focused.

Skills Have to Stay Close to the Work

Continuous learning becomes more useful when it connects directly to what people actually do.

A SOC analyst could review a new detection technique and immediately test it against a simulated incident. A penetration tester could study one unfamiliar vulnerability class before working through a vulnerable application. A cloud security practitioner could learn a configuration change and then diagnose a deliberately misconfigured environment.

ENISA takes a similar practical view of cybersecurity skills development. Its training and exercise approach centres on testing capabilities, identifying gaps and improving technical and operational competence.

That cycle matters: learn, apply, discover the gap, improve and repeat.

It also changes how organizations should think about training budgets. Sending someone to a substantial course can build capability. Keeping that capability current requires smaller opportunities to practise throughout the year.

Build a Learning Rhythm

A useful cybersecurity development plan might combine deeper structured training with shorter exercises, scenario refreshers and regular practical challenges.

The exact rhythm will vary by role. SOC teams may need frequent incident exercises. Penetration testers need exposure to new techniques and technologies. Managers need recurring practice making decisions during unfamiliar scenarios.

At ITSEC Cyber & AI Academy, hands on environments can support that progression by giving learners opportunities to practise cybersecurity skills against scenarios rather than leaving knowledge parked in course notes.

A certificate can mark the day someone completed training.

It can’t guarantee what they’ll still be able to do next March.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: NIST FISSEA Fall Forum, 15 September 2026 · CISA CDM Micro Learn Training · ENISA Trainings and Exercises

Share this post

You may also like

Cloud Misconfigurations Are Still the Leading Cause of Breaches: Here Is How to Stay Ahead
Cybersecurity

Cloud Misconfigurations Are Still the Leading Cause of Breaches: Here Is How to Stay Ahead

Introduction How many storage buckets, IAM roles, or API endpoints in your organization's cloud environment could you confidently say are configured correctly right now. Most security leaders cannot answer that with certainty, and that uncertainty is precisely what attackers count on. Recent industry research puts the picture in sharp focus. Verizon's Data Breach Investigations Report ties fifteen percent of breaches directly to cloud misconfiguration, while separate analysis from SentinelOne finds that ninety five percent of cloud security failures trace back to human error rather than a flaw in the platform itself. Gartner has been saying the same thing for years, projecting that through 2026, ninety nine percent of cloud security failures will be the customer's fault, not the provider's. ITSEC Asia, Indonesia's leading cybersecurity company, works with organizations across Indonesia, Singapore, Australia, and the UAE that are racing to modernize their infrastructure, and the pattern is consistent everywhere. Teams move fast to ship to the cloud, and the governance needed to secure that environment quietly falls behind. Source: Cloud Security Statistics

ITSEC AsiaITSEC Asia
|
Agt 07, 2026 5 minutes read
What Information Security Process Manager Actually Does and Why Most Organizations Getting It Wrong
Cybersecurity

What Information Security Process Manager Actually Does and Why Most Organizations Getting It Wrong

INTRODUCTION Here is a number worth sitting with: organizations that detect breaches with a security AI and automation program save an average of USD 2.2 million compared to those that do not. Yet the operational role responsible for building, owning, and continuously improving those detection and response processes, the Information Security Process Manager, remains one of the least formally defined positions in enterprise security. Most organizations have the tools. Very few have the structured ownership that makes those tools work together as a system. ITSEC Asia, the cybersecurity leader in Indonesia with operations across Singapore, Australia, and the UAE, works directly with organizations to fill exactly this gap: turning fragmented security investments into managed, measurable, and genuinely effective programs. Sources: IBM Cost of a Data Breach Report 2024 [https://www.ibm.com/reports/data-breach] WHAT THE ROLE ACTUALLY OWNS An Information Security Process Manager is the operational architect of a security program. Where a CISO sets direction and a security analyst executes individual tasks, the Process Manager is responsible for defining, documenting, improving, and governing the processes that

|
Mei 25, 2026 5 minutes read
Entry-Level Cybersecurity Is Getting a New Job Description
Cybersecurity

Entry-Level Cybersecurity Is Getting a New Job Description

There used to be a fairly predictable starting point for a cybersecurity career. Learn networking. Understand access control. Get comfortable with security operations. Then, after some experience, start tackling the newer and more complicated stuff. AI is messing with that sequence. On 1 September 2026, ISC2 introduced its updated Certified in Cybersecurity exam outline, the first major content revision since the entry-level certification launched in 2022. Foundational AI concepts are now integrated into the material, including identifying AI assets, recognizing automated threats and supporting secure governance of emerging technologies. Its updated AI guidance goes further. Cybersecurity professionals increasingly need competence in AI governance, model security, data integrity, prompt engineering, AI risk management and the security of AI-enabled systems. That’s quite a list for something that was recently considered a specialist topic. AI SECURITY IS MOVING DOWN THE CAREER LADDER There’s a practical reason for this. AI-enabled systems are entering everyday business operations. At the same time, AI can be used for phishing, social engineering and increasingly automated attacks. Indonesia is already preparing for that reality.

ITSEC AsiaITSEC Asia
|
Sep 03, 2026 3 minutes read

Receive weekly
updates on new posts

Subscribe