Stop Treating the Cybersecurity Skills Gap as One Big Gap
The people a SOC needs, the people securing cloud infrastructure and the people testing applications may all work in cybersecurity. Their missing skills aren’t necessarily the same.

“Cybersecurity talent shortage” is a useful phrase until someone has to decide what to do about it.
Hire more people. Train more graduates. Upskill employees.
Fine. Train them in what?
NIST’s latest cybersecurity workforce investment takes that question seriously. On 18 September, it announced more than $1.7 million for nine Regional Alliances and Multistakeholder Partnerships to Stimulate Cybersecurity Education and Workforce Development, or RAMPS, projects across eight U.S. states.
The interesting part isn’t the funding figure. It’s the design.
Each project is expected to connect the specific workforce needs of local businesses and nonprofit organizations with learning objectives based on the NICE Workforce Framework. The projects then translate those requirements into curriculum development, internships, apprenticeships, hands-on projects and other learning opportunities.
In other words, training starts with the capability that’s missing.
One Shortage Can Hide Several Gaps
Consider three organizations hiring cybersecurity talent.
A financial institution may need people who can investigate identity abuse and respond to incidents. A cloud-heavy technology business may be struggling to find people who understand cloud configurations, IAM and security automation. An organization developing digital services may need application security and penetration testing capability.
All three can report a “cybersecurity skills gap.”
Solving them with the same training program would be convenient. It would also miss the point.
A better workforce assessment asks:
- Which cybersecurity tasks are currently difficult to perform?
- Which roles depend too heavily on one or two specialists?
- What capabilities will new technology create demand for?
- Where do employees have theoretical knowledge but little practical experience?
- Which skills are needed often enough to justify developing internally?
These questions turn an abstract talent shortage into something that can actually be trained.
Start With the Work, Then Design the Learning
The NICE Framework is useful here because it describes cybersecurity through work roles, tasks, knowledge and skills. That allows employers and educators to discuss capability with more precision than a job title such as “cybersecurity specialist.”
The new RAMPS projects build around that principle. NIST says participating communities bring together employers, educators and economic development organizations so training reflects regional workforce requirements.
There’s a lesson for corporate training too.
Before booking another broad cybersecurity course, map the work. If SOC analysts struggle with cloud investigations, train that gap. If penetration testers need stronger API testing capability, build practice around APIs. If managers struggle during incidents, another technical certification probably won’t rescue the meeting.
Specific gaps deserve specific practice.
Training Should End Closer to the Job
Once the capability is defined, practical learning becomes easier to design.
A learner preparing for SOC work can investigate simulated incidents. Someone developing penetration testing capability can work against realistic applications. Cloud security learners can diagnose misconfigured environments rather than simply identify the correct answer on a slide.
That approach fits the work of ITSEC Cyber & AI Academy, where hands-on environments can be used to connect training objectives with the tasks people will actually perform.
The cybersecurity skills gap is real. Treating it as one enormous empty space makes it harder to solve.
Name the missing capability first. Then train for it.
Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.
References: NIST: $1.7 Million for Cybersecurity Workforce Development, 18 September 2026 · NIST NICE · ENISA European Cybersecurity Skills Conference 2026
.png)


