Logo
Cybersecurity

Good Cybersecurity Training Should Let People Get Things Wrong

If every training scenario ends successfully, it may be measuring the course more than the learner.

ITSEC AsiaITSEC Asia
|
Sep 16, 2026
Good Cybersecurity Training Should Let People Get Things Wrong

A SOC analyst receives several alerts and investigates the wrong one first. A penetration tester misses a vulnerability. Someone investigating an incident makes an assumption that sends the team in the wrong direction.

In a real environment, those mistakes can become expensive.

Inside a controlled training environment, they’re valuable evidence.

NIST’s NICE webinar on 16 September focuses on preparing students for cyber careers through reality based education and hands on experience. Its agenda explicitly raises an interesting principle: failure can be valuable workforce data. The session examines how educators and employers can introduce controlled realism into cybersecurity learning so participants develop work based capabilities rather than simply completing exercises.

That distinction deserves more attention.

A Correct Answer Doesn’t Explain How Someone Got There

Traditional assessments are good at answering a narrow question: did the participant know the answer?

Operational cybersecurity needs more information.

Suppose two analysts eventually identify the same compromised account. One notices an unusual authentication pattern immediately. The other spends 40 minutes investigating unrelated activity before arriving at the same conclusion.

Both can technically receive a tick beside “incident identified.”

Their capability isn’t identical.

Realistic exercises can reveal things that conventional assessments may miss:

  • Which evidence someone examines first
  • How they prioritise competing signals
  • When they ask for help or escalate
  • Whether they test assumptions before acting
  • How they respond after making a wrong decision
  • Whether they can explain what they learned from the mistake

That last point matters. Cybersecurity professionals won’t always make the correct first call. They need to recognise when the evidence has changed and adjust.

Failure Should Be Designed, Not Manufactured

Useful training doesn’t mean building impossible scenarios and watching participants struggle.

Controlled failure requires a scenario with realistic information, enough room for judgment and consequences that remain safely inside the exercise.

A penetration testing lab might contain several promising attack paths, only one of which leads somewhere meaningful. A SOC exercise could include benign alerts alongside a genuine incident. A cloud security scenario might allow participants to apply a fix that solves one problem while accidentally creating another.

The instructor then has something richer to discuss than a score.

Why did you choose that path? Which evidence changed your mind? At what point should you have escalated?

Those questions turn mistakes into skill development.

Measure the Gap, Then Train It

This approach also helps organizations spend training resources more precisely.

If a team consistently identifies threats but struggles with prioritisation, another introductory security course probably isn’t the answer. If analysts understand investigation but fail during handovers, the gap sits somewhere else.

The NICE Framework supports this task based view of cybersecurity work by describing roles through tasks, knowledge and skills rather than relying solely on job titles.

Practical environments such as cyber ranges can make those gaps visible. At ITSEC Cyber & AI Academy, hands on scenarios can give participants room to test decisions, see consequences and build capability through repeated practice.

Nobody wants employees learning their most expensive cybersecurity lesson for the first time during a real incident.

A training environment is a much cheaper place to be wrong.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: NIST NICE: Preparing Today’s Students for Tomorrow’s Cyber Careers, 16 September 2026 · NIST NICE Webinar Series · NIST NICE Workforce Framework for Cybersecurity

Share this post

You may also like

Is Using a VPN Really Safe? Here’s the Reality Check.
Cybersecurity

Is Using a VPN Really Safe? Here’s the Reality Check.

INTRODUCTION Today, almost everything we do happens online, from working and studying to shopping and banking. While the internet makes life easier, it also comes with certain risks, especially when it comes to privacy and data security. Many people connect to public Wi-Fi in places like cafés, airports, or hotels without realizing that these networks may not always be secure. In some cases, attackers can monitor or intercept data that travels through these connections. This is where VPN apps become useful. A VPN app helps create a safer internet connection by protecting your data and hiding your online identity. Even if you are using an open network, a VPN can help keep your activity more private. This article will explain what a VPN app is, how it works, and why it has become an important tool for safer internet use. Source: pr.norton.com [https://pr.norton.com/blog/privacy/what-is-a-vpn?utm_], security.org [https://www.security.org/vpn/?utm_], fortinet.com [https://www.fortinet.com/resources/cyberglossary/vpn-wifi?utm_] WHAT IS A VPN APP? A VPN app is a tool that helps protect your internet connection and online activity. VPN stands for Virtual Private Network.

ITSEC AsiaITSEC Asia
|
Mar 13, 2026 6 minutes read
Top Five Cybersecurity Threats to Small Business Owners
Cybersecurity

Top Five Cybersecurity Threats to Small Business Owners

According to a recent Verizon Data Breach Investigations Report, over the past two years, small and medium-sized businesses have become the primary target of cybercriminals, and they are now more affected by cyber breaches than large-scale businesses. Cyberattacks on SMEs have increased because cybercriminals have predicted that small and medium-sized enterprises have fewer resources to dedicate to their security. Most SMEs lack dedicated security professionals, and they are too small to afford them. This makes them vulnerable and easy targets for cybercriminals. In this context, neglecting security is no longer an option, and the assumption that your business is too small to attract the interest of cybercriminals is unrealistic. TOP FIVE CYBER THREATS AFFECTING SMALL AND MEDIUM-SIZED ENTERPRISES Incompatible Operating Systems and Software: Ensure that your computers and the software running on them are up to date. This is crucial and forms a solid foundation for good security practices. Hackers exploit vulnerabilities in outdated software and operating systems, often infiltrating organizations. Failing to apply software and operating system updates when they

ITSEC AsiaITSEC Asia
|
Jul 20, 2023 5 minutes read
7 Main Criteria for Quality Managed Security Services Providers That Every Company Must Know
Cybersecurity

7 Main Criteria for Quality Managed Security Services Providers That Every Company Must Know

INTRODUCTION Cyber threats no longer wait for companies to let their guard down. Attacks occur at any time, across sectors, and are increasingly difficult to detect without an integrated monitoring system. According to Gartner, 90% of non-executive board members have no confidence in the value their organizations receive from cybersecurity investments, a gap that continues to widen between leadership expectations and internal team capacity. This is where Managed Security Services (MSS) plays a role. However, not all service providers offer equal protection. Many companies only realize the weaknesses of their vendors when an incident has already occurred. This article discusses seven criteria that should serve as an evaluation reference before you sign a contract with a Managed Security Services provider. Source: gartner.com [http://gartner.com], issglobal.com [https://issglobal.com/perspectives/what-are-managed-security-services/] WHY CHOOSING THE RIGHT MSS IS CRITICALLY IMPORTANT? Throughout 2024 to 2025, companies in the healthcare, automotive, financial, defense, and technology sectors experienced major breaches that cost billions of dollars in losses, exposed millions of data records, and paralyzed operations for months. The pattern found is quite alarming: these

|
Apr 30, 2026 6 minutes read

Receive weekly
updates on new posts

Subscribe