Logo
Cybersecurity

Employees Want Better Cybersecurity Skills. The Training Has to Keep Up.

Most employees don’t need to become security analysts. They do need to know what a suspicious situation looks like in the work they actually perform.

ITSEC AsiaITSEC Asia
|
Okt 02, 2026
Employees Want Better Cybersecurity Skills. The Training Has to Keep Up.

Cybersecurity training has an awkward reputation.

For many employees, it arrives as an annual module, a collection of familiar warnings and a quiz that strongly encourages remembering whatever appeared on the previous screen.

Meanwhile, the workplace has become considerably less predictable.

ENISA’s latest Cybersecurity Month data shows that 74% of surveyed employees had received suspicious emails, messages, voice communications or links at work during the previous six months. Phishing remained the most common example, but employees also encountered attempts to steal personal information, passwords, AI-generated scams, malware and ransomware. ENISA

Yet only 45% said their organization regularly sends cybersecurity awareness information or updates.

The interesting part is that employees don’t appear uninterested. Eighty-five percent said they wanted to improve their cybersecurity skills. ENISA

The gap is partly about how training is delivered.

The Biggest Training Problem May Be the Calendar

Among employees who identified obstacles to developing cyber skills, 26% cited finding time during work, ahead of cost at 16%, followed by limited information about training and insufficient employer support. ENISA

That matters because cybersecurity training often competes with everything else people are expected to finish that day.

A better program has to respect that reality.

Useful workforce training can focus on specific decisions employees regularly face:

  • Whether an unusual request should be independently verified
  • What information is safe to enter into an AI tool
  • How to report suspicious activity quickly
  • What to do when a familiar login process suddenly behaves differently
  • How to handle customer or confidential information outside normal workflows
  • When an unusual request from a manager should still trigger a second check

These aren’t abstract cybersecurity concepts. They’re moments that can happen between two ordinary meetings.

Different Jobs Create Different Risks

A finance employee, software developer and communications manager don’t necessarily need identical cybersecurity training.

Finance teams may face payment fraud and impersonation. Developers need secure handling of code, credentials and dependencies. Communications teams can encounter compromised social accounts, fraudulent media requests or suspicious files arriving from external contacts.

The basics overlap, but the scenarios should feel familiar to the learner.

NIST’s FISSEA program takes a similar direction. Its 2026 training forums emphasize employee behaviour and practical learning, including short micro-training modules and methods that move users from passive awareness toward verification habits they can use in real situations. NIST

That’s a more useful objective than asking whether everyone remembers the definition of phishing.

Train the Decision, Not Just the Definition

Cybersecurity readiness improves when employees practise what to do.

Give a finance team a realistic payment-change request. Let employees inspect it, verify it through another channel and decide when to escalate. Give another group an AI tool and several documents with different sensitivity levels, then ask what can safely be uploaded.

The learning becomes a decision rather than a lecture.

For dedicated cyber professionals, the same principle can continue into deeper practical environments. ITSEC Cyber & AI Academy connects cybersecurity and AI learning with hands-on exercises where participants can investigate, test and respond rather than simply consume material.

Most employees already know cybersecurity matters.

The more useful training question is whether they’ll know what to do when something slightly strange appears at 3:47 on a busy afternoon.

Explore practical cybersecurity and AI learning at ITSEC Cyber & AI Academy.

References: ENISA: Cybersecurity Month @ Work, 30 September 2026 · NIST FISSEA Spring Forum 2026 · NIST FISSEA Fall Forum 2026

Share this post

You may also like

Indonesia Is Buying More Cybersecurity Technology. Are Its People Ready?
Cybersecurity

Indonesia Is Buying More Cybersecurity Technology. Are Its People Ready?

Indonesia is investing more in cybersecurity technology as businesses move deeper into cloud computing, AI and digital services. Security platforms are becoming more sophisticated, but the people operating them have to keep pace. That gap is becoming harder to ignore. The 2025 ISC2 Cybersecurity Workforce Study found that 95% of cybersecurity professionals reported at least one skills need within their organizations. AI was identified as the top skills gap at 41%, followed by cloud security at 36%. The issue, then, isn't simply a shortage of cybersecurity professionals. It's a shortage of people with the specific skills needed to secure increasingly complex technology. NEW TECHNOLOGY CREATES NEW SECURITY SKILLS A company moving its infrastructure to the cloud needs professionals who understand cloud architecture, identity and access management and cloud-specific vulnerabilities. An organization adopting AI needs people who understand how AI systems can be secured and how attackers can exploit them. A security team deploying more automated tools still needs analysts who can investigate alerts and distinguish a genuine attack from a false positive. The

ITSEC AsiaITSEC Asia
|
Agu 27, 2026 — 4 minutes read
Why Annual Penetration Testing Is No Longer Enough in Today's Threat Landscape
Cybersecurity

Why Annual Penetration Testing Is No Longer Enough in Today's Threat Landscape

If you only went to the doctor once a year, you probably would not assume you were perfectly healthy for the other 364 days. Health changes over time. New conditions can develop, existing issues can worsen, and unexpected problems may arise between checkups. That is why people increasingly rely on regular monitoring and preventive care rather than waiting for an annual appointment to discover something has gone wrong. Cybersecurity works in much the same way. For many years, annual penetration testing has been considered a cybersecurity best practice. Organizations schedule an assessment, receive a report, address the findings, and repeat the process the following year. In relatively static environments, this approach provided a reasonable level of assurance. Modern organizations, however, no longer operate in static environments. Cloud adoption has accelerated. APIs have become essential to digital services. Development teams deploy updates continuously, and third-party integrations have become increasingly common. As organizations move faster, their attack surfaces evolve just as quickly. A system that was secure six months ago may look very

ITSEC AsiaITSEC Asia
|
Jan 09, 2026 — 7 minutes read
Top Five Cybersecurity Threats to Small Business Owners
Cybersecurity

Top Five Cybersecurity Threats to Small Business Owners

According to a recent Verizon Data Breach Investigations Report, over the past two years, small and medium-sized businesses have become the primary target of cybercriminals, and they are now more affected by cyber breaches than large-scale businesses. Cyberattacks on SMEs have increased because cybercriminals have predicted that small and medium-sized enterprises have fewer resources to dedicate to their security. Most SMEs lack dedicated security professionals, and they are too small to afford them. This makes them vulnerable and easy targets for cybercriminals. In this context, neglecting security is no longer an option, and the assumption that your business is too small to attract the interest of cybercriminals is unrealistic. TOP FIVE CYBER THREATS AFFECTING SMALL AND MEDIUM-SIZED ENTERPRISES Incompatible Operating Systems and Software: Ensure that your computers and the software running on them are up to date. This is crucial and forms a solid foundation for good security practices. Hackers exploit vulnerabilities in outdated software and operating systems, often infiltrating organizations. Failing to apply software and operating system updates when they

ITSEC AsiaITSEC Asia
|
Jul 20, 2023 — 5 minutes read

Receive weekly
updates on new posts

Subscribe