Logo
Cybersecurity

Cybersecurity Training Needs More Room for Failure

Getting everything right in training feels good. Getting something wrong may teach you more, especially when the alternative is learning the same lesson during a real incident.

ITSEC AsiaITSEC Asia
|
Sep 04, 2026
Cybersecurity Training Needs More Room for Failure

A cybersecurity exercise where everything goes according to plan is wonderfully reassuring. It may also be slightly suspicious.

Real incidents rarely arrive with tidy instructions. An alert can look harmless until it isn’t. Evidence can contradict itself. Someone makes an assumption, spends 20 minutes following it and discovers they were looking in entirely the wrong place.

That messy part of cybersecurity deserves a bigger role in how people are trained.

NIST’s National Initiative for Cybersecurity Education (NICE) is putting that idea directly into its workforce discussion. Its upcoming September session on preparing students for cyber careers focuses on realism-based training, including how controlled failure can become useful workforce data rather than something educators simply mark wrong.

That’s a useful distinction. A score tells you whether someone found the answer. Watching how they reached it tells you much more.

A Wrong Answer Can Reveal the Real Skills Gap

Imagine two SOC trainees investigating the same suspicious activity. Both eventually identify the threat. One gets there systematically. The other clicks through five theories, misses a clue and reaches the answer mostly by luck.

On paper, both passed. Operationally, they’re in very different places.

Realistic exercises can reveal things that conventional tests struggle to measure:

  • Whether someone knows what evidence to prioritise
  • How they respond when their first assumption is wrong
  • Whether they can explain a technical decision clearly
  • How effectively they work with other people under pressure
  • When they escalate a problem instead of trying to solve everything alone

These are difficult skills to learn from a slide deck. PowerPoint, despite many years of dedicated service, still can’t simulate a production incident.

Indonesia Is Moving Toward Work-Based Learning

Indonesia’s broader workforce policy is also putting more emphasis on training that connects directly with work.

On 1 September, Coordinating Minister for Economic Affairs Airlangga Hartarto launched the latest National Vocational Training program and stressed the need for competencies that match changing industry requirements.

Some vocational programs are already extending that approach beyond classroom instruction. BBPVP Bandung’s September intake, for example, includes a one-month project-based on-the-job training period after formal training.

Cybersecurity needs the same connection between learning and doing, perhaps even more urgently. A real organization isn’t a good place to discover that someone has never handled an ambiguous incident before.

Practice Should Be Allowed to Get Messy

Cyber ranges and realistic simulations create a useful middle ground. People can investigate, make decisions, get something wrong and understand why, without an actual customer database having a particularly bad afternoon.

For training teams, those mistakes are valuable. They show where knowledge stops and operational judgment begins.

That principle is part of the learning approach at ITSEC Cyber & AI Academy, where practical exercises and realistic scenarios give participants opportunities to apply cybersecurity knowledge rather than simply remember it.

The goal isn’t to create exercises everyone can finish perfectly. It’s to create professionals who’ve already encountered confusion, wrong assumptions and difficult decisions before the stakes become real.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: NIST NICE: Preparing Today’s Students for Tomorrow’s Cyber Careers · Indonesia’s Coordinating Ministry for Economic Affairs: National Vocational Training, 1 September 2026 · BBPVP Bandung: project-based vocational training, September 2026

Share this post

You may also like

How Continuous Pentesting Supports PCI DSS Compliance
Cybersecurity

How Continuous Pentesting Supports PCI DSS Compliance

Organizations that process, store or transmit payment card information face increasing pressure to protect sensitive data and comply with industry standards. Among the most widely recognized requirements is the Payment Card Industry Data Security Standard (PCI DSS). While many organizations view PCI DSS as a compliance exercise, the reality is that the framework is designed to strengthen security and reduce the risk of data breaches. As cyber threats continue to evolve, organizations are also recognizing that point-in-time assessments may no longer provide sufficient visibility. This is where Continuous Pentesting and Continuous Security Validation can help. WHAT IS PCI DSS? PCI DSS is a security framework developed to help organizations protect cardholder data and maintain secure payment environments. It applies to merchants, financial institutions, payment processors and service providers that handle payment card information. The standard covers multiple areas, including: * Network security. * Access control. * Vulnerability management. * Monitoring and logging. * Security testing. * Incident response. The objective is not simply compliance but the protection of sensitive payment information. WHY PENETRATION TESTING

ITSEC AsiaITSEC Asia
|
Jun 15, 2026 — 4 minutes read
Your SOC Can’t Handle a Cyber Crisis Alone
Cybersecurity

Your SOC Can’t Handle a Cyber Crisis Alone

Imagine a ransomware incident at 10:30 on a Tuesday morning. The SOC detects suspicious activity and starts investigating. Soon IT needs to isolate systems. Management wants to know whether operations should continue. Legal needs facts. Communications may need to prepare a response. Someone has to decide whether customers or authorities need to be informed. By lunch, cybersecurity has become an organizational exercise. That reality is reflected in current training from the International Telecommunication Union. An ITU Academy incident response course currently open for applications uses three scenarios: a ransomware attack, a data breach and an attack affecting a national education system. Participants work through the incident response lifecycle using collaborative tabletop exercises. The lesson is useful far beyond education. Incident response capability depends on how well different people can make decisions together. TECHNICAL SKILL IS ONLY ONE LAYER A strong SOC can identify malicious activity, analyse evidence and recommend containment. It still needs an organization around it that knows what happens next. Useful incident response capability therefore spreads across several functions: *

ITSEC AsiaITSEC Asia
|
Sep 15, 2026 — 3 minutes read
Stop Treating the Cybersecurity Skills Gap as One Big Gap
Cybersecurity

Stop Treating the Cybersecurity Skills Gap as One Big Gap

“Cybersecurity talent shortage” is a useful phrase until someone has to decide what to do about it. Hire more people. Train more graduates. Upskill employees. Fine. Train them in what? NIST’s latest cybersecurity workforce investment takes that question seriously. On 18 September, it announced more than $1.7 million for nine Regional Alliances and Multistakeholder Partnerships to Stimulate Cybersecurity Education and Workforce Development, or RAMPS, projects across eight U.S. states. The interesting part isn’t the funding figure. It’s the design. Each project is expected to connect the specific workforce needs of local businesses and nonprofit organizations with learning objectives based on the NICE Workforce Framework. The projects then translate those requirements into curriculum development, internships, apprenticeships, hands-on projects and other learning opportunities. In other words, training starts with the capability that’s missing. ONE SHORTAGE CAN HIDE SEVERAL GAPS Consider three organizations hiring cybersecurity talent. A financial institution may need people who can investigate identity abuse and respond to incidents. A cloud-heavy technology business may be struggling to find people who understand cloud configurations, IAM and

ITSEC AsiaITSEC Asia
|
Sep 21, 2026 — 3 minutes read

Receive weekly
updates on new posts

Subscribe