Logo
Cybersecurity

Cybersecurity Skills Need Maintenance Too

Cyber professionals don’t finish learning when the course ends. The systems they protect certainly don’t stop changing.

ITSEC AsiaITSEC Asia
|
Sep 14, 2026
Cybersecurity Skills Need Maintenance Too

A cybersecurity professional completes training on Friday. They’ve worked through the material, passed the assessment and returned to their job with a fresh set of skills.

Six months later, the environment looks different.

A cloud service has changed. The team has introduced AI tools. Attack techniques have evolved. Someone redesigned the incident process. Three new systems appeared and one old application that was supposedly retiring is, mysteriously, still alive.

This is why cybersecurity training increasingly needs to behave less like an annual event and more like professional maintenance.

NIST’s FISSEA Fall Forum on 15 September puts that idea into practice. Its agenda includes an interactive session on building a micro training module, followed by examples of cybersecurity learning tied to the NICE Workforce Framework and practical skill application.

The format matters. Learning doesn’t always need another full week away from work.

Small Learning Can Solve Specific Problems

CISA already uses micro learning as part of its cybersecurity training model. Its Continuous Diagnostics and Mitigation program offers short modules of roughly 3 to 10 minutes, designed to build foundational knowledge before deeper demonstrations and hands on activities.

That combination makes sense for cybersecurity.

A short module could refresh one narrow concept before a team practises it:

  • How to interpret a particular security signal
  • What changed in an incident escalation procedure
  • How a new cloud configuration affects access
  • What evidence should be preserved during an investigation
  • How a recent attack technique changes an existing playbook

The goal isn’t to compress an entire cybersecurity discipline into eight cheerful minutes. Some subjects deserve hours, days or considerably longer.

Micro learning works when the learning objective is equally focused.

Skills Have to Stay Close to the Work

Continuous learning becomes more useful when it connects directly to what people actually do.

A SOC analyst could review a new detection technique and immediately test it against a simulated incident. A penetration tester could study one unfamiliar vulnerability class before working through a vulnerable application. A cloud security practitioner could learn a configuration change and then diagnose a deliberately misconfigured environment.

ENISA takes a similar practical view of cybersecurity skills development. Its training and exercise approach centres on testing capabilities, identifying gaps and improving technical and operational competence.

That cycle matters: learn, apply, discover the gap, improve and repeat.

It also changes how organizations should think about training budgets. Sending someone to a substantial course can build capability. Keeping that capability current requires smaller opportunities to practise throughout the year.

Build a Learning Rhythm

A useful cybersecurity development plan might combine deeper structured training with shorter exercises, scenario refreshers and regular practical challenges.

The exact rhythm will vary by role. SOC teams may need frequent incident exercises. Penetration testers need exposure to new techniques and technologies. Managers need recurring practice making decisions during unfamiliar scenarios.

At ITSEC Cyber & AI Academy, hands on environments can support that progression by giving learners opportunities to practise cybersecurity skills against scenarios rather than leaving knowledge parked in course notes.

A certificate can mark the day someone completed training.

It can’t guarantee what they’ll still be able to do next March.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: NIST FISSEA Fall Forum, 15 September 2026 · CISA CDM Micro Learn Training · ENISA Trainings and Exercises

Share this post

You may also like

The Cybersecurity Skills Gap Indonesia Can’t Afford to Ignore
Cybersecurity

The Cybersecurity Skills Gap Indonesia Can’t Afford to Ignore

As businesses, government institutions and other organizations accelerate digital adoption, the need for cybersecurity professionals continues to grow. At the same time, the skills required to protect increasingly complex environments are changing. Cloud security, threat intelligence, security operations, penetration testing and artificial intelligence are becoming part of the modern cybersecurity skill set. The gap between available talent and the capabilities organizations actually need is becoming harder to ignore. CYBERSECURITY NEEDS ARE CHANGING FASTER THAN SKILLS The global cybersecurity workforce is facing a skills shortage alongside its broader talent challenge. The 2025 ISC2 Cybersecurity Workforce Study found that 95% of cybersecurity professionals surveyed reported at least one skills need within their teams, while 59% described those needs as critical or significant. The study also found that 88% had experienced at least one significant cybersecurity consequence because of skills shortages. For Indonesia, the implication is clear: building a cybersecurity team isn't simply about filling vacancies. Organizations need professionals who can apply their knowledge to real security problems. The skills required are also changing rapidly. The World

ITSEC AsiaITSEC Asia
|
Agt 24, 2026 5 minutes read
Cybersecurity Network in the Age of AI: Building Resilient, Zero Trust Enterprise Architectures
Cybersecurity

Cybersecurity Network in the Age of AI: Building Resilient, Zero Trust Enterprise Architectures

Artificial intelligence is accelerating digital transformation across industries but it is also accelerating cyber threats. From AI-assisted phishing to automated vulnerability scanning, adversaries are operating faster and more intelligently than ever. In this environment, the cybersecurity network is no longer just an IT safeguard, it is a strategic business asset. According to industry trends, attackers increasingly exploit identity gaps, cloud misconfigurations, and east-west network traffic rather than relying solely on perimeter breaches. For CISOs, CTOs, and enterprise decision-makers, this shift demands a redefinition of how cybersecurity networks are designed, governed, and optimized. The question is no longer whether your network is protected. It is whether your architecture is resilient, adaptive, and aligned with business risk. WHAT IS A CYBERSECURITY NETWORK? A cybersecurity network refers to the integrated framework of technologies, controls, policies, and monitoring capabilities that protect an organization’s digital infrastructure from unauthorized access, disruption, and data compromise. In enterprise environments, it spans: * On-premises infrastructure * Hybrid cloud security environments * Multi-cloud deployments * SaaS platforms * Remote workforce connectivity *

ITSEC AsiaITSEC Asia
|
Feb 20, 2026 6 minutes read
What Is Continuous Security Validation and Why Does It Matter?
Cybersecurity

What Is Continuous Security Validation and Why Does It Matter?

Cyber threats evolve continuously. New vulnerabilities are discovered every day. Cloud environments change rapidly. Applications are updated frequently. Employees adopt new technologies and attackers constantly search for opportunities to exploit weaknesses. Yet many organizations still rely on periodic security assessments conducted once or twice a year. The challenge is simple: risk does not wait for the next penetration test. This is why more organizations are embracing Continuous Security Validation (CSV) as part of a modern cybersecurity strategy. WHAT IS CONTINUOUS SECURITY VALIDATION? Continuous Security Validation is the practice of continuously evaluating and validating an organization's security posture as environments, threats and attack surfaces evolve. Instead of providing a snapshot at a single point in time, Continuous Security Validation delivers ongoing visibility into security weaknesses and control effectiveness. Its purpose is to answer a critical question: "Are our defenses still working today?" Rather than waiting months between assessments, organizations gain a more dynamic understanding of their exposure. WHY TRADITIONAL ASSESSMENTS ARE NO LONGER ENOUGH Traditional penetration testing remains an important component of cybersecurity. However, most assessments are performed

ITSEC AsiaITSEC Asia
|
Jun 15, 2026 4 minutes read

Receive weekly
updates on new posts

Subscribe