Good Cybersecurity Training Should Let People Get Things Wrong
If every training scenario ends successfully, it may be measuring the course more than the learner.

A SOC analyst receives several alerts and investigates the wrong one first. A penetration tester misses a vulnerability. Someone investigating an incident makes an assumption that sends the team in the wrong direction.
In a real environment, those mistakes can become expensive.
Inside a controlled training environment, they’re valuable evidence.
NIST’s NICE webinar on 16 September focuses on preparing students for cyber careers through reality based education and hands on experience. Its agenda explicitly raises an interesting principle: failure can be valuable workforce data. The session examines how educators and employers can introduce controlled realism into cybersecurity learning so participants develop work based capabilities rather than simply completing exercises.
That distinction deserves more attention.
A Correct Answer Doesn’t Explain How Someone Got There
Traditional assessments are good at answering a narrow question: did the participant know the answer?
Operational cybersecurity needs more information.
Suppose two analysts eventually identify the same compromised account. One notices an unusual authentication pattern immediately. The other spends 40 minutes investigating unrelated activity before arriving at the same conclusion.
Both can technically receive a tick beside “incident identified.”
Their capability isn’t identical.
Realistic exercises can reveal things that conventional assessments may miss:
- Which evidence someone examines first
- How they prioritise competing signals
- When they ask for help or escalate
- Whether they test assumptions before acting
- How they respond after making a wrong decision
- Whether they can explain what they learned from the mistake
That last point matters. Cybersecurity professionals won’t always make the correct first call. They need to recognise when the evidence has changed and adjust.
Failure Should Be Designed, Not Manufactured
Useful training doesn’t mean building impossible scenarios and watching participants struggle.
Controlled failure requires a scenario with realistic information, enough room for judgment and consequences that remain safely inside the exercise.
A penetration testing lab might contain several promising attack paths, only one of which leads somewhere meaningful. A SOC exercise could include benign alerts alongside a genuine incident. A cloud security scenario might allow participants to apply a fix that solves one problem while accidentally creating another.
The instructor then has something richer to discuss than a score.
Why did you choose that path? Which evidence changed your mind? At what point should you have escalated?
Those questions turn mistakes into skill development.
Measure the Gap, Then Train It
This approach also helps organizations spend training resources more precisely.
If a team consistently identifies threats but struggles with prioritisation, another introductory security course probably isn’t the answer. If analysts understand investigation but fail during handovers, the gap sits somewhere else.
The NICE Framework supports this task based view of cybersecurity work by describing roles through tasks, knowledge and skills rather than relying solely on job titles.
Practical environments such as cyber ranges can make those gaps visible. At ITSEC Cyber & AI Academy, hands on scenarios can give participants room to test decisions, see consequences and build capability through repeated practice.
Nobody wants employees learning their most expensive cybersecurity lesson for the first time during a real incident.
A training environment is a much cheaper place to be wrong.
Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.
References: NIST NICE: Preparing Today’s Students for Tomorrow’s Cyber Careers, 16 September 2026 · NIST NICE Webinar Series · NIST NICE Workforce Framework for Cybersecurity
.png)


