Logo
Cybersecurity

Stop Treating the Cybersecurity Skills Gap as One Big Gap

The people a SOC needs, the people securing cloud infrastructure and the people testing applications may all work in cybersecurity. Their missing skills aren’t necessarily the same.

ITSEC AsiaITSEC Asia
|
Sep 21, 2026
Stop Treating the Cybersecurity Skills Gap as One Big Gap

“Cybersecurity talent shortage” is a useful phrase until someone has to decide what to do about it.

Hire more people. Train more graduates. Upskill employees.

Fine. Train them in what?

NIST’s latest cybersecurity workforce investment takes that question seriously. On 18 September, it announced more than $1.7 million for nine Regional Alliances and Multistakeholder Partnerships to Stimulate Cybersecurity Education and Workforce Development, or RAMPS, projects across eight U.S. states.

The interesting part isn’t the funding figure. It’s the design.

Each project is expected to connect the specific workforce needs of local businesses and nonprofit organizations with learning objectives based on the NICE Workforce Framework. The projects then translate those requirements into curriculum development, internships, apprenticeships, hands-on projects and other learning opportunities.

In other words, training starts with the capability that’s missing.

One Shortage Can Hide Several Gaps

Consider three organizations hiring cybersecurity talent.

A financial institution may need people who can investigate identity abuse and respond to incidents. A cloud-heavy technology business may be struggling to find people who understand cloud configurations, IAM and security automation. An organization developing digital services may need application security and penetration testing capability.

All three can report a “cybersecurity skills gap.”

Solving them with the same training program would be convenient. It would also miss the point.

A better workforce assessment asks:

  • Which cybersecurity tasks are currently difficult to perform?
  • Which roles depend too heavily on one or two specialists?
  • What capabilities will new technology create demand for?
  • Where do employees have theoretical knowledge but little practical experience?
  • Which skills are needed often enough to justify developing internally?

These questions turn an abstract talent shortage into something that can actually be trained.

Start With the Work, Then Design the Learning

The NICE Framework is useful here because it describes cybersecurity through work roles, tasks, knowledge and skills. That allows employers and educators to discuss capability with more precision than a job title such as “cybersecurity specialist.”

The new RAMPS projects build around that principle. NIST says participating communities bring together employers, educators and economic development organizations so training reflects regional workforce requirements.

There’s a lesson for corporate training too.

Before booking another broad cybersecurity course, map the work. If SOC analysts struggle with cloud investigations, train that gap. If penetration testers need stronger API testing capability, build practice around APIs. If managers struggle during incidents, another technical certification probably won’t rescue the meeting.

Specific gaps deserve specific practice.

Training Should End Closer to the Job

Once the capability is defined, practical learning becomes easier to design.

A learner preparing for SOC work can investigate simulated incidents. Someone developing penetration testing capability can work against realistic applications. Cloud security learners can diagnose misconfigured environments rather than simply identify the correct answer on a slide.

That approach fits the work of ITSEC Cyber & AI Academy, where hands-on environments can be used to connect training objectives with the tasks people will actually perform.

The cybersecurity skills gap is real. Treating it as one enormous empty space makes it harder to solve.

Name the missing capability first. Then train for it.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: NIST: $1.7 Million for Cybersecurity Workforce Development, 18 September 2026 · NIST NICE · ENISA European Cybersecurity Skills Conference 2026

Share this post

You may also like

API Security Testing: Why APIs Have Become a Prime Target for Attackers
Cybersecurity

API Security Testing: Why APIs Have Become a Prime Target for Attackers

Modern applications rarely operate in isolation. From mobile apps and cloud platforms to payment gateways and third-party integrations, APIs (Application Programming Interfaces) have become the invisible backbone of digital services. Organizations rely on APIs to connect systems, exchange data and accelerate innovation. Unfortunately, attackers rely on them too. As API adoption continues to grow, APIs have emerged as one of the fastest-growing attack surfaces in cybersecurity. Misconfigured or vulnerable APIs can expose sensitive information, disrupt business operations and provide attackers with a direct path into critical systems. This is why API Security Testing has become an essential part of modern application security. WHAT IS API SECURITY TESTING? API Security Testing is the process of identifying and validating vulnerabilities within APIs before they can be exploited by malicious actors. Unlike traditional web application testing, API security assessments focus on how applications communicate with each other and whether those interactions can be manipulated or abused. The objective is not simply to find vulnerabilities but to understand how weaknesses within APIs could impact business operations and data security. WHY

ITSEC AsiaITSEC Asia
|
Jun 15, 2026 5 minutes read
What Is Cloud Security? A First Introduction for Modern Enterprises
Cybersecurity

What Is Cloud Security? A First Introduction for Modern Enterprises

INTRODUCTION: CLOUD ADOPTION IS ACCELERATING, SO ARE THE RISKS Cloud computing has been part of enterprise IT for years, but the risk landscape around it is changing faster than ever. As organizations embrace AI, remote work, and digital transformation, cloud environments have become the backbone of business operations and a prime target for attackers. Today, breaches are no longer limited to traditional data centers. Misconfigured cloud resources, stolen credentials, and unmanaged identities are now among the most common root causes of security incidents. This is why understanding what cloud security is and what it is not matters deeply for enterprises today. At its core, cloud security refers to the policies, technologies, configurations, and responsibilities that protect cloud-based systems, data, and services. This concept is inseparable from how cloud computing itself is defined:an on demand, shared,and externally managed computing model, as outlined in the NIST [https://csrc.nist.gov/pubs/sp/800/145/final]Cloud Computing Definition (SP 800-145), where responsibility is inherently distributed between the provider and the user. WHAT IS CLOUD COMPUTING? A SIMPLE ENTERPRISE PERSPECTIVE Cloud computing is not

ITSEC AsiaITSEC Asia
|
Feb 12, 2026 7 minutes read
Post-Quantum Cryptography Readiness with ITSEC
Cybersecurity

Post-Quantum Cryptography Readiness with ITSEC

For decades, public-key cryptography has been the backbone of protecting sensitive information, such as financial transactions, personal data, corporate communications, and government secrets. Whether logging into a secure banking app, shopping online, or browsing encrypted websites (like HTTPS), public key infrastructure (PKI) protects your data from cybercriminals. However, the rise of quantum computing introduces transformative and potentially disruptive challenge to this foundation of digital trust. THE QUANTUM REVOLUTION Quantum computers can perform complex computations faster than even the most advanced current supercomputers. While this capability promises breakthroughs in drug discovery and healthcare, materials science or Artificial Intelligence (AI), it also poses a significant threat to current cryptographic systems. Quantum computers could break widely used publickey cryptographic systems (e.g., RSA, ECC), compromising critical infrastructure security such as energy grids, financial systems, and sensitive government communication networks. Compromised public-key cryptography could lead to forged digital certificates or signatures, undermining trust in banking, healthcare, and government services. Quantum cryptography attacks could also compromise billions of connected devices, from smart homes to Industrial Control Systems (ICS), by

ITSEC AsiaITSEC Asia
|
Jul 11, 2025 4 minutes read

Receive weekly
updates on new posts

Subscribe