Logo
Cybersecurity

Cybersecurity Training Needs More Room for Failure

Getting everything right in training feels good. Getting something wrong may teach you more, especially when the alternative is learning the same lesson during a real incident.

ITSEC AsiaITSEC Asia
|
Sep 04, 2026
Cybersecurity Training Needs More Room for Failure

A cybersecurity exercise where everything goes according to plan is wonderfully reassuring. It may also be slightly suspicious.

Real incidents rarely arrive with tidy instructions. An alert can look harmless until it isn’t. Evidence can contradict itself. Someone makes an assumption, spends 20 minutes following it and discovers they were looking in entirely the wrong place.

That messy part of cybersecurity deserves a bigger role in how people are trained.

NIST’s National Initiative for Cybersecurity Education (NICE) is putting that idea directly into its workforce discussion. Its upcoming September session on preparing students for cyber careers focuses on realism-based training, including how controlled failure can become useful workforce data rather than something educators simply mark wrong.

That’s a useful distinction. A score tells you whether someone found the answer. Watching how they reached it tells you much more.

A Wrong Answer Can Reveal the Real Skills Gap

Imagine two SOC trainees investigating the same suspicious activity. Both eventually identify the threat. One gets there systematically. The other clicks through five theories, misses a clue and reaches the answer mostly by luck.

On paper, both passed. Operationally, they’re in very different places.

Realistic exercises can reveal things that conventional tests struggle to measure:

  • Whether someone knows what evidence to prioritise
  • How they respond when their first assumption is wrong
  • Whether they can explain a technical decision clearly
  • How effectively they work with other people under pressure
  • When they escalate a problem instead of trying to solve everything alone

These are difficult skills to learn from a slide deck. PowerPoint, despite many years of dedicated service, still can’t simulate a production incident.

Indonesia Is Moving Toward Work-Based Learning

Indonesia’s broader workforce policy is also putting more emphasis on training that connects directly with work.

On 1 September, Coordinating Minister for Economic Affairs Airlangga Hartarto launched the latest National Vocational Training program and stressed the need for competencies that match changing industry requirements.

Some vocational programs are already extending that approach beyond classroom instruction. BBPVP Bandung’s September intake, for example, includes a one-month project-based on-the-job training period after formal training.

Cybersecurity needs the same connection between learning and doing, perhaps even more urgently. A real organization isn’t a good place to discover that someone has never handled an ambiguous incident before.

Practice Should Be Allowed to Get Messy

Cyber ranges and realistic simulations create a useful middle ground. People can investigate, make decisions, get something wrong and understand why, without an actual customer database having a particularly bad afternoon.

For training teams, those mistakes are valuable. They show where knowledge stops and operational judgment begins.

That principle is part of the learning approach at ITSEC Cyber & AI Academy, where practical exercises and realistic scenarios give participants opportunities to apply cybersecurity knowledge rather than simply remember it.

The goal isn’t to create exercises everyone can finish perfectly. It’s to create professionals who’ve already encountered confusion, wrong assumptions and difficult decisions before the stakes become real.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: NIST NICE: Preparing Today’s Students for Tomorrow’s Cyber Careers · Indonesia’s Coordinating Ministry for Economic Affairs: National Vocational Training, 1 September 2026 · BBPVP Bandung: project-based vocational training, September 2026

Share this post

You may also like

Cybersecurity Careers Should Start Before University
Cybersecurity

Cybersecurity Careers Should Start Before University

Ask a teenager what jobs exist in technology and you’ll probably hear programmer, software engineer or perhaps data scientist. Ask about cybersecurity and the picture can become considerably fuzzier. Maybe “hacker” makes an appearance, usually wearing an imaginary hoodie. That perception matters because Indonesia needs a much larger pool of people who see cybersecurity as a realistic career before they have to choose one. Komdigi has started pushing cybersecurity education further down the talent pipeline. In May, its Digital Human Resources Development Agency provided Basic Cyber Security training to 124 students at SMKN 2 Depok, covering digital security awareness and preparation for a technology-driven workplace. The direction is also appearing internationally. NIST’s NICE program updated its September webinar on 2 September with a specific focus on preparing students for future cyber careers. One part examines how K–12 education can introduce skills connected to immediate workforce realities such as cloud security and generative AI. Cybersecurity education is moving earlier because the work itself isn’t waiting. EXPOSURE BEFORE SPECIALISATION Starting earlier doesn’t mean asking

ITSEC AsiaITSEC Asia
|
Sep 07, 2026 3 minutes read
Entry-Level Cybersecurity Is Getting a New Job Description
Cybersecurity

Entry-Level Cybersecurity Is Getting a New Job Description

There used to be a fairly predictable starting point for a cybersecurity career. Learn networking. Understand access control. Get comfortable with security operations. Then, after some experience, start tackling the newer and more complicated stuff. AI is messing with that sequence. On 1 September 2026, ISC2 introduced its updated Certified in Cybersecurity exam outline, the first major content revision since the entry-level certification launched in 2022. Foundational AI concepts are now integrated into the material, including identifying AI assets, recognizing automated threats and supporting secure governance of emerging technologies. Its updated AI guidance goes further. Cybersecurity professionals increasingly need competence in AI governance, model security, data integrity, prompt engineering, AI risk management and the security of AI-enabled systems. That’s quite a list for something that was recently considered a specialist topic. AI SECURITY IS MOVING DOWN THE CAREER LADDER There’s a practical reason for this. AI-enabled systems are entering everyday business operations. At the same time, AI can be used for phishing, social engineering and increasingly automated attacks. Indonesia is already preparing for that reality.

ITSEC AsiaITSEC Asia
|
Sep 03, 2026 3 minutes read
Cybersecurity for Financial Institutions: Strengthening Resilience Under OJK Regulations
Cybersecurity

Cybersecurity for Financial Institutions: Strengthening Resilience Under OJK Regulations

Digital transformation is reshaping Indonesia's financial sector. Banks, insurance companies, fintech platforms and other financial institutions are increasingly dependent on digital services to deliver better customer experiences and improve operational efficiency. However, this growing digital ecosystem also expands the attack surface. Cyber threats targeting financial institutions continue to evolve, while regulators are placing greater emphasis on cyber resilience and operational risk management. For financial institutions operating in Indonesia, cybersecurity is no longer simply an IT issue. It is a business imperative and a regulatory requirement. WHY FINANCIAL INSTITUTIONS ARE ATTRACTIVE TARGETS Financial institutions manage some of the most valuable assets in the digital economy. These include: * Customer information. * Financial transactions. * Payment systems. * Personal data. * Sensitive internal information. This makes the sector particularly attractive to cybercriminals. Successful attacks can result in: * Financial losses. * Service disruptions. * Regulatory consequences. * Reputational damage. * Loss of customer trust. Protecting digital assets has therefore become essential to maintaining long-term resilience. THE GROWING ROLE OF OJK IN CYBERSECURITY Indonesia's Financial Services Authority (OJK)

ITSEC AsiaITSEC Asia
|
Jun 15, 2026 4 minutes read

Receive weekly
updates on new posts

Subscribe