“Knows Cybersecurity” Is Too Vague to Be Useful
Two people can understand the same security topic at very different depths. Workforce planning gets better when organizations can describe that difference.

Imagine two SOC analysts who both list incident response as a skill.
One can follow a documented investigation procedure, collect evidence and escalate a suspicious event. The other can investigate an unfamiliar attack, correlate evidence across systems, challenge the initial hypothesis and guide colleagues through containment.
Both legitimately have incident response skills.
They clearly shouldn’t be described as having the same level of capability.
ENISA is addressing exactly this problem in its ongoing revision of the European Cybersecurity Skills Framework. The current ECSF organizes cybersecurity work into 12 professional role profiles, covering responsibilities, skills, knowledge and relationships between roles. The revised framework will add proficiency levels to support workforce assessment, career development and training pathways. ENISA
That seemingly small addition could change how organizations think about the skills gap.
A Skill List Tells You What. A Level Tells You How Far.
Consider penetration testing.
A beginner might understand reconnaissance, use established testing methods and reproduce common vulnerabilities in a controlled environment.
Someone further along should be able to choose an appropriate methodology, adapt testing to unfamiliar architecture, interpret ambiguous results and explain the business relevance of a finding.
An advanced practitioner may design complex assessments, evaluate unusual attack paths and mentor other testers.
Writing “penetration testing” beside all three names hides most of the useful information.
The same problem appears across cybersecurity roles. Organizations need ways to distinguish between people who can:
- Explain a concept with guidance
- Perform a defined task independently
- Handle unfamiliar or ambiguous situations
- Design approaches for complex environments
- Review other practitioners’ work
- Teach or mentor others
Those distinctions make training needs much easier to see.
The Skills Gap Can Hide Inside the Team
A company may have five incident responders and still have an incident response capability gap.
Perhaps everyone can perform initial triage, while only one person can lead a complex investigation. Maybe several cloud security practitioners understand configuration reviews but nobody can design security architecture across multiple environments.
Headcount alone won’t show that.
ENISA says the ECSF is intended to give employers, professionals, educators and HR teams a shared language for cybersecurity roles and competencies. Its 12 profiles already help define what different cyber professionals do. Adding proficiency levels should make it easier to describe how independently and deeply those tasks can be performed. ENISA
That also gives managers a more useful question than “Do we have this skill?”
Ask: At what level do we have it, and how many people can perform it there?
Training Should Move People Between Levels
Once capability has levels, training can become more precise.
A learner who understands vulnerability assessment but struggles to interpret findings doesn’t need the same program as someone already running assessments independently. One may need structured labs. The other may benefit from complex scenarios with incomplete information and fewer instructions.
That principle fits hands-on development at ITSEC Cyber & AI Academy. Practical environments can help organizations observe how people perform tasks, identify where guidance is still required and create training paths that progressively increase difficulty and independence.
Cybersecurity careers aren’t collections of boxes waiting to be ticked.
A better workforce model asks how well someone can actually do the work.
Explore practical cybersecurity and AI learning at ITSEC Cyber & AI Academy.
References
- ENISA, “European Cybersecurity Skills Framework (ECSF),” updated 28 September 2026
- ENISA, “European Cybersecurity Skills Framework,” current framework and revision information, accessed October 2026
- ENISA, “European Cybersecurity Skills Conference 2026,” 4–5 November 2026
- ENISA, “European Cybersecurity Skills Framework Role Profiles,” 19 September 2022
.png)


