Logo
Cybersecurity

Cybersecurity Training Needs More Room for Failure

Getting everything right in training feels good. Getting something wrong may teach you more, especially when the alternative is learning the same lesson during a real incident.

ITSEC AsiaITSEC Asia
|
Sep 04, 2026
Cybersecurity Training Needs More Room for Failure

A cybersecurity exercise where everything goes according to plan is wonderfully reassuring. It may also be slightly suspicious.

Real incidents rarely arrive with tidy instructions. An alert can look harmless until it isn’t. Evidence can contradict itself. Someone makes an assumption, spends 20 minutes following it and discovers they were looking in entirely the wrong place.

That messy part of cybersecurity deserves a bigger role in how people are trained.

NIST’s National Initiative for Cybersecurity Education (NICE) is putting that idea directly into its workforce discussion. Its upcoming September session on preparing students for cyber careers focuses on realism-based training, including how controlled failure can become useful workforce data rather than something educators simply mark wrong.

That’s a useful distinction. A score tells you whether someone found the answer. Watching how they reached it tells you much more.

A Wrong Answer Can Reveal the Real Skills Gap

Imagine two SOC trainees investigating the same suspicious activity. Both eventually identify the threat. One gets there systematically. The other clicks through five theories, misses a clue and reaches the answer mostly by luck.

On paper, both passed. Operationally, they’re in very different places.

Realistic exercises can reveal things that conventional tests struggle to measure:

  • Whether someone knows what evidence to prioritise
  • How they respond when their first assumption is wrong
  • Whether they can explain a technical decision clearly
  • How effectively they work with other people under pressure
  • When they escalate a problem instead of trying to solve everything alone

These are difficult skills to learn from a slide deck. PowerPoint, despite many years of dedicated service, still can’t simulate a production incident.

Indonesia Is Moving Toward Work-Based Learning

Indonesia’s broader workforce policy is also putting more emphasis on training that connects directly with work.

On 1 September, Coordinating Minister for Economic Affairs Airlangga Hartarto launched the latest National Vocational Training program and stressed the need for competencies that match changing industry requirements.

Some vocational programs are already extending that approach beyond classroom instruction. BBPVP Bandung’s September intake, for example, includes a one-month project-based on-the-job training period after formal training.

Cybersecurity needs the same connection between learning and doing, perhaps even more urgently. A real organization isn’t a good place to discover that someone has never handled an ambiguous incident before.

Practice Should Be Allowed to Get Messy

Cyber ranges and realistic simulations create a useful middle ground. People can investigate, make decisions, get something wrong and understand why, without an actual customer database having a particularly bad afternoon.

For training teams, those mistakes are valuable. They show where knowledge stops and operational judgment begins.

That principle is part of the learning approach at ITSEC Cyber & AI Academy, where practical exercises and realistic scenarios give participants opportunities to apply cybersecurity knowledge rather than simply remember it.

The goal isn’t to create exercises everyone can finish perfectly. It’s to create professionals who’ve already encountered confusion, wrong assumptions and difficult decisions before the stakes become real.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: NIST NICE: Preparing Today’s Students for Tomorrow’s Cyber Careers · Indonesia’s Coordinating Ministry for Economic Affairs: National Vocational Training, 1 September 2026 · BBPVP Bandung: project-based vocational training, September 2026

Share this post

You may also like

Why Annual Penetration Testing Is No Longer Enough in Today's Threat Landscape
Cybersecurity

Why Annual Penetration Testing Is No Longer Enough in Today's Threat Landscape

If you only went to the doctor once a year, you probably would not assume you were perfectly healthy for the other 364 days. Health changes over time. New conditions can develop, existing issues can worsen, and unexpected problems may arise between checkups. That is why people increasingly rely on regular monitoring and preventive care rather than waiting for an annual appointment to discover something has gone wrong. Cybersecurity works in much the same way. For many years, annual penetration testing has been considered a cybersecurity best practice. Organizations schedule an assessment, receive a report, address the findings, and repeat the process the following year. In relatively static environments, this approach provided a reasonable level of assurance. Modern organizations, however, no longer operate in static environments. Cloud adoption has accelerated. APIs have become essential to digital services. Development teams deploy updates continuously, and third-party integrations have become increasingly common. As organizations move faster, their attack surfaces evolve just as quickly. A system that was secure six months ago may look very

ITSEC AsiaITSEC Asia
|
Jan 09, 2026 — 7 minutes read
Teaching People to Use AI Without Security Is Half a Lesson
Cybersecurity

Teaching People to Use AI Without Security Is Half a Lesson

Seven hundred and fifty government employees across Kalimantan started AI training this week. The program, run by BLSDM Komdigi Banjarmasin with ASEAN Foundation, covers AI fundamentals, ethics, implementation and something that deserves to sit comfortably beside all three: data security. That combination makes sense. Organizations are teaching more people how to use AI because AI is becoming part of ordinary work. Employees can summarize documents, analyse information, draft material and automate routine tasks without writing a line of code. Every new capability also creates a new question: what exactly are we giving the AI? THE AI SKILL GAP HAS A SECURITY SIDE An employee can be perfectly competent at prompting an AI system while making poor security decisions around it. Imagine someone needs to summarize a lengthy internal report. Uploading the document may produce an excellent summary. Whether the document should have been uploaded in the first place is an entirely different test. As AI becomes commonplace, workers need enough security literacy to ask questions such as: * What information am I

ITSEC AsiaITSEC Asia
|
Sep 08, 2026 — 3 minutes read
Calculating the Cost of Securing Your Business
Cybersecurity

Calculating the Cost of Securing Your Business

Tips

As the strategic importance of information security continues to grow for organizations of all sizes, and the complexity of information security increases across industries, business decisions are increasingly driven by the need to protect their intellectual assets and safeguard their IT infrastructure from evolving cybersecurity threats. Securing customer records, protecting sensitive financial information, and complying with regulatory requirements can create significant pressures on IT decision-makers and their resources. While many organizations have traditionally outsourced critical elements of their IT operations to managed service providers, more and more businesses are proactively outsourcing their security functions to specialized information security service providers. This has led to a need for evaluating the benefits of outsourcing security elements and comparing them to managing these processes internally. I wrote this article to help business leaders understand the best way to approach Managed Security Service Providers (MSSPs) in the context of Total Cost Ownership (TCO), a subject that is frequently discussed and of interest to both technical and non-technical leaders. INTERNAL SOLUTIONS OR OUTSOURCING? The key to evaluating

ITSEC AsiaITSEC Asia
|
Jul 10, 2023 — 8 minutes read

Receive weekly
updates on new posts

Subscribe