Logo
Cybersecurity

“Knows Cybersecurity” Is Too Vague to Be Useful

Two people can understand the same security topic at very different depths. Workforce planning gets better when organizations can describe that difference.

ITSEC AsiaITSEC Asia
|
Okt 07, 2026
“Knows Cybersecurity” Is Too Vague to Be Useful

Imagine two SOC analysts who both list incident response as a skill.

One can follow a documented investigation procedure, collect evidence and escalate a suspicious event. The other can investigate an unfamiliar attack, correlate evidence across systems, challenge the initial hypothesis and guide colleagues through containment.

Both legitimately have incident response skills.

They clearly shouldn’t be described as having the same level of capability.

ENISA is addressing exactly this problem in its ongoing revision of the European Cybersecurity Skills Framework. The current ECSF organizes cybersecurity work into 12 professional role profiles, covering responsibilities, skills, knowledge and relationships between roles. The revised framework will add proficiency levels to support workforce assessment, career development and training pathways. ENISA

That seemingly small addition could change how organizations think about the skills gap.

A Skill List Tells You What. A Level Tells You How Far.

Consider penetration testing.

A beginner might understand reconnaissance, use established testing methods and reproduce common vulnerabilities in a controlled environment.

Someone further along should be able to choose an appropriate methodology, adapt testing to unfamiliar architecture, interpret ambiguous results and explain the business relevance of a finding.

An advanced practitioner may design complex assessments, evaluate unusual attack paths and mentor other testers.

Writing “penetration testing” beside all three names hides most of the useful information.

The same problem appears across cybersecurity roles. Organizations need ways to distinguish between people who can:

  • Explain a concept with guidance
  • Perform a defined task independently
  • Handle unfamiliar or ambiguous situations
  • Design approaches for complex environments
  • Review other practitioners’ work
  • Teach or mentor others

Those distinctions make training needs much easier to see.

The Skills Gap Can Hide Inside the Team

A company may have five incident responders and still have an incident response capability gap.

Perhaps everyone can perform initial triage, while only one person can lead a complex investigation. Maybe several cloud security practitioners understand configuration reviews but nobody can design security architecture across multiple environments.

Headcount alone won’t show that.

ENISA says the ECSF is intended to give employers, professionals, educators and HR teams a shared language for cybersecurity roles and competencies. Its 12 profiles already help define what different cyber professionals do. Adding proficiency levels should make it easier to describe how independently and deeply those tasks can be performed. ENISA

That also gives managers a more useful question than “Do we have this skill?”

Ask: At what level do we have it, and how many people can perform it there?

Training Should Move People Between Levels

Once capability has levels, training can become more precise.

A learner who understands vulnerability assessment but struggles to interpret findings doesn’t need the same program as someone already running assessments independently. One may need structured labs. The other may benefit from complex scenarios with incomplete information and fewer instructions.

That principle fits hands-on development at ITSEC Cyber & AI Academy. Practical environments can help organizations observe how people perform tasks, identify where guidance is still required and create training paths that progressively increase difficulty and independence.

Cybersecurity careers aren’t collections of boxes waiting to be ticked.

A better workforce model asks how well someone can actually do the work.

Explore practical cybersecurity and AI learning at ITSEC Cyber & AI Academy.

References

  1. ENISA, “European Cybersecurity Skills Framework (ECSF),” updated 28 September 2026
  2. ENISA, “European Cybersecurity Skills Framework,” current framework and revision information, accessed October 2026
  3. ENISA, “European Cybersecurity Skills Conference 2026,” 4–5 November 2026
  4. ENISA, “European Cybersecurity Skills Framework Role Profiles,” 19 September 2022
Share this post

You may also like

This is Why You Should Automate Your Cybersecurity
Cybersecurity

This is Why You Should Automate Your Cybersecurity

DO YOU NEED TO AUTOMATE YOUR CYBERSECURITY OPERATIONS? The answer is likely "yes," and whenever I ask anyone about automation, they unequivocally state that automation will undoubtedly enhance the overall cybersecurity foundation if implemented correctly in their organizations. They say "if" because the organizations I speak with, not many of them have actually implemented automation into their operations, even if they intend to do so. They usually reason that they are too busy to stop and learn how. Here are some of the strongest reasons to automate... We live in a world where launching cyber attacks on an organization is far cheaper than defending it. To make matters worse, the threat landscape is becoming increasingly difficult to cover. You face exponentially growing threats where adversaries are getting the upper hand every day while your security tools incessantly warn you. Business resilience is the ultimate goal of any cybersecurity operation, and the only way to improve the overall resilience of your organization is to improve your overall efficiency in protecting it.

ITSEC AsiaITSEC Asia
|
Jul 20, 2023 — 4 minutes read
How AI Helps Reduce False Positives in Security Assessments
Cybersecurity

How AI Helps Reduce False Positives in Security Assessments

Modern security teams are drowning in alerts. Vulnerability scanners, SIEM platforms, threat detection tools and security assessments generate thousands of findings every day. While visibility is essential, not every finding represents a genuine threat. Many turn out to be false positives. As organizations expand their attack surfaces and adopt increasingly complex environments, managing false positives has become one of the biggest operational challenges in cybersecurity. Because ultimately, cybersecurity is not about generating more alerts. It is about identifying the risks that truly matter. WHAT ARE FALSE POSITIVES IN CYBERSECURITY? A false positive occurs when a security tool or assessment identifies something as a vulnerability or threat, even though it poses little or no actual risk. In other words, a finding appears dangerous but cannot realistically be exploited or does not have meaningful impact. False positives can originate from: * Vulnerability scanners. * Automated security assessments. * Threat detection systems. * SIEM platforms. * Security monitoring tools. * Misconfigured rules and signatures. Although these tools are designed to maximize detection, excessive false positives

ITSEC AsiaITSEC Asia
|
Jun 15, 2026 — 5 minutes read
Why Annual Penetration Testing Is No Longer Enough in Today's Threat Landscape
Cybersecurity

Why Annual Penetration Testing Is No Longer Enough in Today's Threat Landscape

If you only went to the doctor once a year, you probably would not assume you were perfectly healthy for the other 364 days. Health changes over time. New conditions can develop, existing issues can worsen, and unexpected problems may arise between checkups. That is why people increasingly rely on regular monitoring and preventive care rather than waiting for an annual appointment to discover something has gone wrong. Cybersecurity works in much the same way. For many years, annual penetration testing has been considered a cybersecurity best practice. Organizations schedule an assessment, receive a report, address the findings, and repeat the process the following year. In relatively static environments, this approach provided a reasonable level of assurance. Modern organizations, however, no longer operate in static environments. Cloud adoption has accelerated. APIs have become essential to digital services. Development teams deploy updates continuously, and third-party integrations have become increasingly common. As organizations move faster, their attack surfaces evolve just as quickly. A system that was secure six months ago may look very

ITSEC AsiaITSEC Asia
|
Jan 09, 2026 — 7 minutes read

Receive weekly
updates on new posts

Subscribe