Logo
Cybersecurity

Cybersecurity Talent Needs to Understand How Things Get Built

The security team can’t inspect every finished product at the door. More cyber professionals need to understand what happens on the assembly line.

ITSEC AsiaITSEC Asia
|
Sep 09, 2026
Cybersecurity Talent Needs to Understand How Things Get Built

For years, cybersecurity careers have often been imagined around defense: monitor systems, detect suspicious activity, investigate incidents and fix vulnerabilities.

That work remains essential. But security is increasingly moving upstream.

ENISA’s current revision of the European Cybersecurity Skills Framework is explicitly aligning cybersecurity roles with the secure digital product lifecycle, emerging technologies such as AI and new regulatory requirements. The framework itself maps cybersecurity into 12 professional profiles with defined responsibilities, knowledge and competencies.

NIST has made an equally telling change. Version 2.2.0 of the NICE Framework Components added Cybersecurity Supply Chain Risk Management as a work role and DevSecOps as a competency area.

Those aren’t cosmetic additions. They reflect where cybersecurity work is going.

Security Is Becoming Part of the Build Process

Modern digital services rarely come from one neat stack of code written entirely inside one organization. They may depend on cloud infrastructure, open-source packages, APIs, external services, automated development pipelines and software supplied by third parties.

Every dependency creates another place where security decisions can be made well or badly.

That means cyber professionals increasingly benefit from understanding questions such as:

  • Where do software dependencies come from and how are they verified?
  • How are secrets and credentials handled during development?
  • Can security testing become part of the development pipeline?
  • What happens when a third-party component develops a vulnerability?
  • Who owns the risk when several suppliers contribute to one digital service?

These questions sit somewhere between traditional security, software engineering, cloud operations and risk management. Job descriptions, as usual, have failed to respect departmental boundaries.

DevSecOps Changes What “Cyber Skills” Look Like

A SOC analyst and a DevSecOps practitioner may both work in cybersecurity, but their daily environments can look very different.

DevSecOps requires security thinking inside software delivery. A practitioner may need to understand development workflows, CI/CD pipelines, cloud configurations, automated testing and how developers actually work.

Supply chain security adds another dimension. NIST describes its new NICE work role around identifying, assessing and mitigating cybersecurity risks throughout supply chains.

For workforce development, this means cybersecurity training can’t stay isolated from the systems and processes learners will eventually protect.

Someone studying application security should see how software is assembled. Someone learning cloud security should work with configurations and deployment processes. Someone preparing for supply chain risk should understand how dependencies move through an organization.

Build It, Break It, Fix It

Practical training becomes especially useful here because the skills are procedural.

Give learners an application pipeline with an insecure dependency. Let them identify the problem, modify the process and test whether their control actually works. Introduce a cloud configuration mistake midway through deployment and see whether it gets caught before production.

The exercise becomes less about remembering security advice and more about applying it while something is being built.

That connection between technical knowledge and operational practice is central to ITSEC Cyber & AI Academy, where hands-on environments can help learners develop capabilities closer to the systems, workflows and security decisions they’ll encounter professionally.

Cybersecurity will always need people watching what comes through the door. Increasingly, it also needs people standing much closer to the factory floor.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: ENISA: European Cybersecurity Skills Framework, updated 7 September 2026 · ENISA: European Cybersecurity Skills Conference 2026 · NIST NICE Framework Components v2.2.0

Share this post

You may also like

What CISOs Should Ask Before Choosing a Penetration Testing Provider in 2026
Cybersecurity

What CISOs Should Ask Before Choosing a Penetration Testing Provider in 2026

INTRODUCTION What percentage of your last penetration test report was actually proven exploitable, and what percentage was a list of things a scanner flagged and nobody validated? Most CISOs cannot answer that question with confidence, and that is exactly the problem. Buyers guides published this year point to a pattern worth sitting with. If a quoted penetration test comes in at four to five thousand dollars or less, it is very likely an automated vulnerability scan wearing a pen test label, not manual work performed by a skilled tester. That gap between what is sold as a penetration test and what is actually delivered is why the selection conversation matters so much more than most procurement teams treat it. ITSEC Asia, Indonesia's leading cybersecurity company, works with organizations across Indonesia, Singapore, Australia, and the UAE that have gone through this exact evaluation, and the questions that separate a genuinely useful engagement from an expensive checkbox exercise are more specific than most RFPs ever ask. Source: Six Questions to Ask a

ITSEC AsiaITSEC Asia
|
Jul 17, 2026 5 minutes read
Is Using a VPN Really Safe? Here’s the Reality Check.
Cybersecurity

Is Using a VPN Really Safe? Here’s the Reality Check.

INTRODUCTION Today, almost everything we do happens online, from working and studying to shopping and banking. While the internet makes life easier, it also comes with certain risks, especially when it comes to privacy and data security. Many people connect to public Wi-Fi in places like cafés, airports, or hotels without realizing that these networks may not always be secure. In some cases, attackers can monitor or intercept data that travels through these connections. This is where VPN apps become useful. A VPN app helps create a safer internet connection by protecting your data and hiding your online identity. Even if you are using an open network, a VPN can help keep your activity more private. This article will explain what a VPN app is, how it works, and why it has become an important tool for safer internet use. Source: pr.norton.com [https://pr.norton.com/blog/privacy/what-is-a-vpn?utm_], security.org [https://www.security.org/vpn/?utm_], fortinet.com [https://www.fortinet.com/resources/cyberglossary/vpn-wifi?utm_] WHAT IS A VPN APP? A VPN app is a tool that helps protect your internet connection and online activity. VPN stands for Virtual Private Network.

ITSEC AsiaITSEC Asia
|
Mar 13, 2026 6 minutes read
What Makes AI-Powered Penetration Testing Different From Automated Scanners?
Cybersecurity

What Makes AI-Powered Penetration Testing Different From Automated Scanners?

INTRODUCTION How much of what a vulnerability scanner flags every week actually turns out to be real? Research from OWASP puts the false positive rate for common vulnerability types somewhere between 15% and 30%, and separate research from Snyk found that security teams now spend roughly 70% of their time chasing alerts that end up being nothing at all. That gap between what a tool reports and what is actually exploitable is not a minor inconvenience. It is the reason a third of companies surveyed admitted they responded late to a genuine attack because their team was buried in phantom threats instead. ITSEC Asia, Indonesia's leading cybersecurity company, works with organizations across the region that have learned this the hard way, and the question that keeps coming up is simple. If a scanner already checks the boxes, why does AI-powered penetration testing exist at all, and what does it actually do differently? Source: OWASP false positive research via DEV Community [https://dev.to/kuboidsecurelayer/why-automated-vulnerability-scanners-miss-most-real-security-vulnerabilities-2p96] · Snyk: Minimizing False Positives [https://snyk.io/blog/minimizing-false-positives-enhancing-security-efficiency/] THE FUNDAMENTAL DIFFERENCE: FOLLOWING RULES

ITSEC AsiaITSEC Asia
|
Jul 03, 2026 5 minutes read

Receive weekly
updates on new posts

Subscribe