Logo
Cybersecurity

Stop Treating the Cybersecurity Skills Gap as One Big Gap

The people a SOC needs, the people securing cloud infrastructure and the people testing applications may all work in cybersecurity. Their missing skills aren’t necessarily the same.

ITSEC AsiaITSEC Asia
|
Sep 21, 2026
Stop Treating the Cybersecurity Skills Gap as One Big Gap

“Cybersecurity talent shortage” is a useful phrase until someone has to decide what to do about it.

Hire more people. Train more graduates. Upskill employees.

Fine. Train them in what?

NIST’s latest cybersecurity workforce investment takes that question seriously. On 18 September, it announced more than $1.7 million for nine Regional Alliances and Multistakeholder Partnerships to Stimulate Cybersecurity Education and Workforce Development, or RAMPS, projects across eight U.S. states.

The interesting part isn’t the funding figure. It’s the design.

Each project is expected to connect the specific workforce needs of local businesses and nonprofit organizations with learning objectives based on the NICE Workforce Framework. The projects then translate those requirements into curriculum development, internships, apprenticeships, hands-on projects and other learning opportunities.

In other words, training starts with the capability that’s missing.

One Shortage Can Hide Several Gaps

Consider three organizations hiring cybersecurity talent.

A financial institution may need people who can investigate identity abuse and respond to incidents. A cloud-heavy technology business may be struggling to find people who understand cloud configurations, IAM and security automation. An organization developing digital services may need application security and penetration testing capability.

All three can report a “cybersecurity skills gap.”

Solving them with the same training program would be convenient. It would also miss the point.

A better workforce assessment asks:

  • Which cybersecurity tasks are currently difficult to perform?
  • Which roles depend too heavily on one or two specialists?
  • What capabilities will new technology create demand for?
  • Where do employees have theoretical knowledge but little practical experience?
  • Which skills are needed often enough to justify developing internally?

These questions turn an abstract talent shortage into something that can actually be trained.

Start With the Work, Then Design the Learning

The NICE Framework is useful here because it describes cybersecurity through work roles, tasks, knowledge and skills. That allows employers and educators to discuss capability with more precision than a job title such as “cybersecurity specialist.”

The new RAMPS projects build around that principle. NIST says participating communities bring together employers, educators and economic development organizations so training reflects regional workforce requirements.

There’s a lesson for corporate training too.

Before booking another broad cybersecurity course, map the work. If SOC analysts struggle with cloud investigations, train that gap. If penetration testers need stronger API testing capability, build practice around APIs. If managers struggle during incidents, another technical certification probably won’t rescue the meeting.

Specific gaps deserve specific practice.

Training Should End Closer to the Job

Once the capability is defined, practical learning becomes easier to design.

A learner preparing for SOC work can investigate simulated incidents. Someone developing penetration testing capability can work against realistic applications. Cloud security learners can diagnose misconfigured environments rather than simply identify the correct answer on a slide.

That approach fits the work of ITSEC Cyber & AI Academy, where hands-on environments can be used to connect training objectives with the tasks people will actually perform.

The cybersecurity skills gap is real. Treating it as one enormous empty space makes it harder to solve.

Name the missing capability first. Then train for it.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: NIST: $1.7 Million for Cybersecurity Workforce Development, 18 September 2026 · NIST NICE · ENISA European Cybersecurity Skills Conference 2026

Share this post

You may also like

What Makes AI-Powered Penetration Testing Different From Automated Scanners?
Cybersecurity

What Makes AI-Powered Penetration Testing Different From Automated Scanners?

INTRODUCTION How much of what a vulnerability scanner flags every week actually turns out to be real? Research from OWASP puts the false positive rate for common vulnerability types somewhere between 15% and 30%, and separate research from Snyk found that security teams now spend roughly 70% of their time chasing alerts that end up being nothing at all. That gap between what a tool reports and what is actually exploitable is not a minor inconvenience. It is the reason a third of companies surveyed admitted they responded late to a genuine attack because their team was buried in phantom threats instead. ITSEC Asia, Indonesia's leading cybersecurity company, works with organizations across the region that have learned this the hard way, and the question that keeps coming up is simple. If a scanner already checks the boxes, why does AI-powered penetration testing exist at all, and what does it actually do differently? Source: OWASP false positive research via DEV Community [https://dev.to/kuboidsecurelayer/why-automated-vulnerability-scanners-miss-most-real-security-vulnerabilities-2p96] · Snyk: Minimizing False Positives [https://snyk.io/blog/minimizing-false-positives-enhancing-security-efficiency/] THE FUNDAMENTAL DIFFERENCE: FOLLOWING RULES

ITSEC AsiaITSEC Asia
|
Jul 03, 2026 — 5 minutes read
Think Your System Is Secure? Penetration Testing Can Prove It
Cybersecurity

Think Your System Is Secure? Penetration Testing Can Prove It

INTRODUCTION Today, almost every organization relies on digital systems to run daily operations, from websites and cloud applications to payment systems and internal databases.  However, as digital infrastructure grows, so do cybersecurity risks. Attackers constantly look for vulnerabilities in applications, networks, and systems that they can exploit to gain unauthorized access or steal sensitive data (Cloudflare, 2024). Because of this growing threat landscape, organizations need ways to test their defenses before real attackers attempt to breach them. One of the most effective methods is penetration testing, often called pen testing, where cybersecurity professionals simulate attacks to identify security weaknesses before malicious actors do (IBM, 2024). In simple terms, penetration testing is authorized hacking designed to improve security rather than cause damage. Source: Cloudflare.com [https://www.cloudflare.com/learning/security/glossary/what-is-penetration-testing/], ibm.com [https://www.ibm.com/think/topics/penetration-testing] WHAT IS PENETRATION TESTING? Penetration testing is a cybersecurity assessment where security experts simulate cyberattacks on systems to identify vulnerabilities that attackers could exploit. These experts that are often known as penetration testers or ethical hackers use techniques similar to real attackers, but with permission from the organization and with the goal

ITSEC AsiaITSEC Asia
|
Apr 02, 2026 — 6 minutes read
The AI Talent Gap Is Still the Weakest Link in Indonesia's Digital Transformation
Cybersecurity

The AI Talent Gap Is Still the Weakest Link in Indonesia's Digital Transformation

Introduction How many people on your team truly understand how to build, secure, and govern AI-based systems today. For most organizations, the honest answer is far fewer than what's actually needed. The World Economic Forum's Future of Jobs Report 2025 found that nearly 39 percent of workers' core skills are expected to change significantly by 2030, with AI and big data sitting at the top of the list of skills most in demand and hardest to fill. ITSEC Asia, which works with organizations across Indonesia, Singapore, Australia, and the UAE, sees the same pattern play out almost everywhere. AI adoption is moving far faster than organizations' ability to build, secure, and responsibly govern the technology. Source: World Economic Forum, Future of Jobs Report 2025 Demand for AI Talent Is Growing Faster Than the Supply This isn't simply a headcount problem, it's a widening gap between how fast technology is being adopted and how fast organizations can produce people genuinely capable of handling it. * ISC2's workforce study puts the

ITSEC AsiaITSEC Asia
|
Agu 14, 2026 — 4 minutes read

Receive weekly
updates on new posts

Subscribe