Logo
Cybersecurity

Good Cybersecurity Training Should Let People Get Things Wrong

If every training scenario ends successfully, it may be measuring the course more than the learner.

ITSEC AsiaITSEC Asia
|
Sep 16, 2026
Good Cybersecurity Training Should Let People Get Things Wrong

A SOC analyst receives several alerts and investigates the wrong one first. A penetration tester misses a vulnerability. Someone investigating an incident makes an assumption that sends the team in the wrong direction.

In a real environment, those mistakes can become expensive.

Inside a controlled training environment, they’re valuable evidence.

NIST’s NICE webinar on 16 September focuses on preparing students for cyber careers through reality based education and hands on experience. Its agenda explicitly raises an interesting principle: failure can be valuable workforce data. The session examines how educators and employers can introduce controlled realism into cybersecurity learning so participants develop work based capabilities rather than simply completing exercises.

That distinction deserves more attention.

A Correct Answer Doesn’t Explain How Someone Got There

Traditional assessments are good at answering a narrow question: did the participant know the answer?

Operational cybersecurity needs more information.

Suppose two analysts eventually identify the same compromised account. One notices an unusual authentication pattern immediately. The other spends 40 minutes investigating unrelated activity before arriving at the same conclusion.

Both can technically receive a tick beside “incident identified.”

Their capability isn’t identical.

Realistic exercises can reveal things that conventional assessments may miss:

  • Which evidence someone examines first
  • How they prioritise competing signals
  • When they ask for help or escalate
  • Whether they test assumptions before acting
  • How they respond after making a wrong decision
  • Whether they can explain what they learned from the mistake

That last point matters. Cybersecurity professionals won’t always make the correct first call. They need to recognise when the evidence has changed and adjust.

Failure Should Be Designed, Not Manufactured

Useful training doesn’t mean building impossible scenarios and watching participants struggle.

Controlled failure requires a scenario with realistic information, enough room for judgment and consequences that remain safely inside the exercise.

A penetration testing lab might contain several promising attack paths, only one of which leads somewhere meaningful. A SOC exercise could include benign alerts alongside a genuine incident. A cloud security scenario might allow participants to apply a fix that solves one problem while accidentally creating another.

The instructor then has something richer to discuss than a score.

Why did you choose that path? Which evidence changed your mind? At what point should you have escalated?

Those questions turn mistakes into skill development.

Measure the Gap, Then Train It

This approach also helps organizations spend training resources more precisely.

If a team consistently identifies threats but struggles with prioritisation, another introductory security course probably isn’t the answer. If analysts understand investigation but fail during handovers, the gap sits somewhere else.

The NICE Framework supports this task based view of cybersecurity work by describing roles through tasks, knowledge and skills rather than relying solely on job titles.

Practical environments such as cyber ranges can make those gaps visible. At ITSEC Cyber & AI Academy, hands on scenarios can give participants room to test decisions, see consequences and build capability through repeated practice.

Nobody wants employees learning their most expensive cybersecurity lesson for the first time during a real incident.

A training environment is a much cheaper place to be wrong.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: NIST NICE: Preparing Today’s Students for Tomorrow’s Cyber Careers, 16 September 2026 · NIST NICE Webinar Series · NIST NICE Workforce Framework for Cybersecurity

Share this post

You may also like

Cybersecurity for Financial Institutions: Strengthening Resilience Under OJK Regulations
Cybersecurity

Cybersecurity for Financial Institutions: Strengthening Resilience Under OJK Regulations

Digital transformation is reshaping Indonesia's financial sector. Banks, insurance companies, fintech platforms and other financial institutions are increasingly dependent on digital services to deliver better customer experiences and improve operational efficiency. However, this growing digital ecosystem also expands the attack surface. Cyber threats targeting financial institutions continue to evolve, while regulators are placing greater emphasis on cyber resilience and operational risk management. For financial institutions operating in Indonesia, cybersecurity is no longer simply an IT issue. It is a business imperative and a regulatory requirement. WHY FINANCIAL INSTITUTIONS ARE ATTRACTIVE TARGETS Financial institutions manage some of the most valuable assets in the digital economy. These include: * Customer information. * Financial transactions. * Payment systems. * Personal data. * Sensitive internal information. This makes the sector particularly attractive to cybercriminals. Successful attacks can result in: * Financial losses. * Service disruptions. * Regulatory consequences. * Reputational damage. * Loss of customer trust. Protecting digital assets has therefore become essential to maintaining long-term resilience. THE GROWING ROLE OF OJK IN CYBERSECURITY Indonesia's Financial Services Authority (OJK)

ITSEC AsiaITSEC Asia
|
Jun 15, 2026 4 minutes read
Why Threat Hunting Is the Only Way to Stop Attackers Who Are Already Inside
Cybersecurity

Why Threat Hunting Is the Only Way to Stop Attackers Who Are Already Inside

INTRODUCTION Here is a question every security leader should sit with: if an attacker entered your network six months ago, would you know? According to IBM's Cost of a Data Breach Report 2024, the average time to identify a breach now stands at 194 days, nearly half a year of undetected attacker activity operating freely within enterprise infrastructure. Prevention tools, no matter how sophisticated, have already demonstrated they cannot close that window on their own. Firewalls, antivirus software, and multi-factor authentication are necessary. They are not sufficient. The organizations that understand this distinction are the ones investing in threat hunting: the proactive, intelligence-driven practice of searching for adversaries who have already bypassed the perimeter and are operating in silence. ITSEC Asia, the cybersecurity leader in Indonesia with operations across Singapore, Australia, and the UAE, works with organizations across these regions to build this exact capability before the next breach makes it urgent. Sources: IBM Cost of a Data Breach Report 2024 [https://www.ibm.com/reports/data-breach] THE GAP THAT REACTIVE SECURITY CANNOT CLOSE The fundamental flaw in

|
Mei 12, 2026 5 minutes read
Cloud Misconfigurations Are Still the Leading Cause of Breaches: Here Is How to Stay Ahead
Cybersecurity

Cloud Misconfigurations Are Still the Leading Cause of Breaches: Here Is How to Stay Ahead

Introduction How many storage buckets, IAM roles, or API endpoints in your organization's cloud environment could you confidently say are configured correctly right now. Most security leaders cannot answer that with certainty, and that uncertainty is precisely what attackers count on. Recent industry research puts the picture in sharp focus. Verizon's Data Breach Investigations Report ties fifteen percent of breaches directly to cloud misconfiguration, while separate analysis from SentinelOne finds that ninety five percent of cloud security failures trace back to human error rather than a flaw in the platform itself. Gartner has been saying the same thing for years, projecting that through 2026, ninety nine percent of cloud security failures will be the customer's fault, not the provider's. ITSEC Asia, Indonesia's leading cybersecurity company, works with organizations across Indonesia, Singapore, Australia, and the UAE that are racing to modernize their infrastructure, and the pattern is consistent everywhere. Teams move fast to ship to the cloud, and the governance needed to secure that environment quietly falls behind. Source: Cloud Security Statistics

ITSEC AsiaITSEC Asia
|
Agt 07, 2026 5 minutes read

Receive weekly
updates on new posts

Subscribe