Logo
Cybersecurity

Cybersecurity Training Needs More Room for Failure

Getting everything right in training feels good. Getting something wrong may teach you more, especially when the alternative is learning the same lesson during a real incident.

ITSEC AsiaITSEC Asia
|
Sep 04, 2026
Cybersecurity Training Needs More Room for Failure

A cybersecurity exercise where everything goes according to plan is wonderfully reassuring. It may also be slightly suspicious.

Real incidents rarely arrive with tidy instructions. An alert can look harmless until it isn’t. Evidence can contradict itself. Someone makes an assumption, spends 20 minutes following it and discovers they were looking in entirely the wrong place.

That messy part of cybersecurity deserves a bigger role in how people are trained.

NIST’s National Initiative for Cybersecurity Education (NICE) is putting that idea directly into its workforce discussion. Its upcoming September session on preparing students for cyber careers focuses on realism-based training, including how controlled failure can become useful workforce data rather than something educators simply mark wrong.

That’s a useful distinction. A score tells you whether someone found the answer. Watching how they reached it tells you much more.

A Wrong Answer Can Reveal the Real Skills Gap

Imagine two SOC trainees investigating the same suspicious activity. Both eventually identify the threat. One gets there systematically. The other clicks through five theories, misses a clue and reaches the answer mostly by luck.

On paper, both passed. Operationally, they’re in very different places.

Realistic exercises can reveal things that conventional tests struggle to measure:

  • Whether someone knows what evidence to prioritise
  • How they respond when their first assumption is wrong
  • Whether they can explain a technical decision clearly
  • How effectively they work with other people under pressure
  • When they escalate a problem instead of trying to solve everything alone

These are difficult skills to learn from a slide deck. PowerPoint, despite many years of dedicated service, still can’t simulate a production incident.

Indonesia Is Moving Toward Work-Based Learning

Indonesia’s broader workforce policy is also putting more emphasis on training that connects directly with work.

On 1 September, Coordinating Minister for Economic Affairs Airlangga Hartarto launched the latest National Vocational Training program and stressed the need for competencies that match changing industry requirements.

Some vocational programs are already extending that approach beyond classroom instruction. BBPVP Bandung’s September intake, for example, includes a one-month project-based on-the-job training period after formal training.

Cybersecurity needs the same connection between learning and doing, perhaps even more urgently. A real organization isn’t a good place to discover that someone has never handled an ambiguous incident before.

Practice Should Be Allowed to Get Messy

Cyber ranges and realistic simulations create a useful middle ground. People can investigate, make decisions, get something wrong and understand why, without an actual customer database having a particularly bad afternoon.

For training teams, those mistakes are valuable. They show where knowledge stops and operational judgment begins.

That principle is part of the learning approach at ITSEC Cyber & AI Academy, where practical exercises and realistic scenarios give participants opportunities to apply cybersecurity knowledge rather than simply remember it.

The goal isn’t to create exercises everyone can finish perfectly. It’s to create professionals who’ve already encountered confusion, wrong assumptions and difficult decisions before the stakes become real.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: NIST NICE: Preparing Today’s Students for Tomorrow’s Cyber Careers · Indonesia’s Coordinating Ministry for Economic Affairs: National Vocational Training, 1 September 2026 · BBPVP Bandung: project-based vocational training, September 2026

Share this post

You may also like

Behind the Running Machines: The Cyber Threats Lurking in Your Industrial Systems
Cybersecurity

Behind the Running Machines: The Cyber Threats Lurking in Your Industrial Systems

INTRODUCTION For years, the cybersecurity conversation has revolved almost entirely around the IT world  corporate email, enterprise software, cloud storage. But the threat landscape has shifted. Quietly, and aggressively. Attackers have figured out something that many security teams are only beginning to reckon with: Operational Technology (OT) and Internet of Things (IoT) environments are high-value targets, and by the standards the IT world now takes for granted, they are largely undefended. The numbers don't leave much room for optimism. Ransomware attacks in the industrial sector spiked 87% year-over-year in 2024, making manufacturing the top ransomware target for four consecutive years. In the same period, the number of ransomware groups specifically targeting OT and ICS environments grew by 60%  not because these systems suddenly became more valuable overnight, but because attackers realized how exposed they already were. One in every four penetration tests conducted on industrial environments still finds default credentials in active use. Sixty-five percent of OT environments have insecure remote access conditions. These aren't edge cases. They are the norm. The question,

|
Jun 05, 2026 7 minutes read
This is Why You Should Automate Your Cybersecurity
Cybersecurity

This is Why You Should Automate Your Cybersecurity

DO YOU NEED TO AUTOMATE YOUR CYBERSECURITY OPERATIONS? The answer is likely "yes," and whenever I ask anyone about automation, they unequivocally state that automation will undoubtedly enhance the overall cybersecurity foundation if implemented correctly in their organizations. They say "if" because the organizations I speak with, not many of them have actually implemented automation into their operations, even if they intend to do so. They usually reason that they are too busy to stop and learn how. Here are some of the strongest reasons to automate... We live in a world where launching cyber attacks on an organization is far cheaper than defending it. To make matters worse, the threat landscape is becoming increasingly difficult to cover. You face exponentially growing threats where adversaries are getting the upper hand every day while your security tools incessantly warn you. Business resilience is the ultimate goal of any cybersecurity operation, and the only way to improve the overall resilience of your organization is to improve your overall efficiency in protecting it.

ITSEC AsiaITSEC Asia
|
Jul 20, 2023 4 minutes read
Healthcare Cybersecurity in Southeast Asia: Why Patient Data Systems Are the New Frontline
Cybersecurity

Healthcare Cybersecurity in Southeast Asia: Why Patient Data Systems Are the New Frontline

INTRODUCTION What does it take for an attacker to compromise the personal health records of 1.5 million patients, including a sitting prime minister? At SingHealth in 2018, the answer turned out to be a single unpatched vulnerability, a phishing email, and nearly a year of undetected access before anyone noticed something was wrong. The investigation that followed found no penetration tests had been conducted, no two-factor authentication had been enabled on critical systems, and cybersecurity had been treated as an IT management issue rather than an organizational risk. The Committee of Inquiry described the failures as a catalogue of missed opportunities that a far less skilled attacker could have exploited just as easily. That was 2018. Since then, the threat to healthcare systems across Southeast Asia has not diminished. It has industrialized. Cyberattacks in the region doubled in 2024 compared to the previous year, with healthcare consistently listed alongside finance and government as a primary target. Globally, healthcare accounted for 23% of all data breaches in 2024, overtaking finance for the

ITSEC AsiaITSEC Asia
|
Jun 30, 2026 8 minutes read

Receive weekly
updates on new posts

Subscribe