Logo
Cybersecurity

Cybersecurity Talent Needs to Understand How Things Get Built

The security team can’t inspect every finished product at the door. More cyber professionals need to understand what happens on the assembly line.

ITSEC AsiaITSEC Asia
|
Sep 09, 2026
Cybersecurity Talent Needs to Understand How Things Get Built

For years, cybersecurity careers have often been imagined around defense: monitor systems, detect suspicious activity, investigate incidents and fix vulnerabilities.

That work remains essential. But security is increasingly moving upstream.

ENISA’s current revision of the European Cybersecurity Skills Framework is explicitly aligning cybersecurity roles with the secure digital product lifecycle, emerging technologies such as AI and new regulatory requirements. The framework itself maps cybersecurity into 12 professional profiles with defined responsibilities, knowledge and competencies.

NIST has made an equally telling change. Version 2.2.0 of the NICE Framework Components added Cybersecurity Supply Chain Risk Management as a work role and DevSecOps as a competency area.

Those aren’t cosmetic additions. They reflect where cybersecurity work is going.

Security Is Becoming Part of the Build Process

Modern digital services rarely come from one neat stack of code written entirely inside one organization. They may depend on cloud infrastructure, open-source packages, APIs, external services, automated development pipelines and software supplied by third parties.

Every dependency creates another place where security decisions can be made well or badly.

That means cyber professionals increasingly benefit from understanding questions such as:

  • Where do software dependencies come from and how are they verified?
  • How are secrets and credentials handled during development?
  • Can security testing become part of the development pipeline?
  • What happens when a third-party component develops a vulnerability?
  • Who owns the risk when several suppliers contribute to one digital service?

These questions sit somewhere between traditional security, software engineering, cloud operations and risk management. Job descriptions, as usual, have failed to respect departmental boundaries.

DevSecOps Changes What “Cyber Skills” Look Like

A SOC analyst and a DevSecOps practitioner may both work in cybersecurity, but their daily environments can look very different.

DevSecOps requires security thinking inside software delivery. A practitioner may need to understand development workflows, CI/CD pipelines, cloud configurations, automated testing and how developers actually work.

Supply chain security adds another dimension. NIST describes its new NICE work role around identifying, assessing and mitigating cybersecurity risks throughout supply chains.

For workforce development, this means cybersecurity training can’t stay isolated from the systems and processes learners will eventually protect.

Someone studying application security should see how software is assembled. Someone learning cloud security should work with configurations and deployment processes. Someone preparing for supply chain risk should understand how dependencies move through an organization.

Build It, Break It, Fix It

Practical training becomes especially useful here because the skills are procedural.

Give learners an application pipeline with an insecure dependency. Let them identify the problem, modify the process and test whether their control actually works. Introduce a cloud configuration mistake midway through deployment and see whether it gets caught before production.

The exercise becomes less about remembering security advice and more about applying it while something is being built.

That connection between technical knowledge and operational practice is central to ITSEC Cyber & AI Academy, where hands-on environments can help learners develop capabilities closer to the systems, workflows and security decisions they’ll encounter professionally.

Cybersecurity will always need people watching what comes through the door. Increasingly, it also needs people standing much closer to the factory floor.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: ENISA: European Cybersecurity Skills Framework, updated 7 September 2026 · ENISA: European Cybersecurity Skills Conference 2026 · NIST NICE Framework Components v2.2.0

Share this post

You may also like

Think Your System Is Secure? Penetration Testing Can Prove It
Cybersecurity

Think Your System Is Secure? Penetration Testing Can Prove It

INTRODUCTION Today, almost every organization relies on digital systems to run daily operations, from websites and cloud applications to payment systems and internal databases.  However, as digital infrastructure grows, so do cybersecurity risks. Attackers constantly look for vulnerabilities in applications, networks, and systems that they can exploit to gain unauthorized access or steal sensitive data (Cloudflare, 2024). Because of this growing threat landscape, organizations need ways to test their defenses before real attackers attempt to breach them. One of the most effective methods is penetration testing, often called pen testing, where cybersecurity professionals simulate attacks to identify security weaknesses before malicious actors do (IBM, 2024). In simple terms, penetration testing is authorized hacking designed to improve security rather than cause damage. Source: Cloudflare.com [https://www.cloudflare.com/learning/security/glossary/what-is-penetration-testing/], ibm.com [https://www.ibm.com/think/topics/penetration-testing] WHAT IS PENETRATION TESTING? Penetration testing is a cybersecurity assessment where security experts simulate cyberattacks on systems to identify vulnerabilities that attackers could exploit. These experts that are often known as penetration testers or ethical hackers use techniques similar to real attackers, but with permission from the organization and with the goal

ITSEC AsiaITSEC Asia
|
Apr 02, 2026 6 minutes read
Post-Quantum Cryptography Readiness with ITSEC
Cybersecurity

Post-Quantum Cryptography Readiness with ITSEC

For decades, public-key cryptography has been the backbone of protecting sensitive information, such as financial transactions, personal data, corporate communications, and government secrets. Whether logging into a secure banking app, shopping online, or browsing encrypted websites (like HTTPS), public key infrastructure (PKI) protects your data from cybercriminals. However, the rise of quantum computing introduces transformative and potentially disruptive challenge to this foundation of digital trust. THE QUANTUM REVOLUTION Quantum computers can perform complex computations faster than even the most advanced current supercomputers. While this capability promises breakthroughs in drug discovery and healthcare, materials science or Artificial Intelligence (AI), it also poses a significant threat to current cryptographic systems. Quantum computers could break widely used publickey cryptographic systems (e.g., RSA, ECC), compromising critical infrastructure security such as energy grids, financial systems, and sensitive government communication networks. Compromised public-key cryptography could lead to forged digital certificates or signatures, undermining trust in banking, healthcare, and government services. Quantum cryptography attacks could also compromise billions of connected devices, from smart homes to Industrial Control Systems (ICS), by

ITSEC AsiaITSEC Asia
|
Jul 11, 2025 4 minutes read
A SOC Can’t Detect What It Never Learned to See
Cybersecurity

A SOC Can’t Detect What It Never Learned to See

A security alert arrives. An analyst opens it, checks the surrounding activity and begins reconstructing what happened. That sounds like the beginning of detection work. In reality, a considerable amount of work happened earlier. Someone decided which events should be logged, configured the systems to produce them, collected those records centrally and made sure the data contained enough detail to support an investigation. If that work is poor, even an excellent analyst is starting with missing pages. An upcoming ITU cybersecurity exercise in Dushanbe makes this dependency unusually explicit. During the three day program from 21 to 23 September 2026, teams will configure centralized monitoring and telemetry collection before responding to simulated ransomware, data exfiltration, server compromise and command and control traffic. The methodology has a catch: performance against attacks on Day 3 depends on the monitoring participants configured on Day 2. That’s a useful model for SOC training. VISIBILITY IS A SKILL SOC development often concentrates on the visible part of the job: analysing alerts, threat hunting and incident response. Those capabilities

ITSEC AsiaITSEC Asia
|
Sep 17, 2026 3 minutes read

Receive weekly
updates on new posts

Subscribe