Logo
Cybersecurity

The Cybersecurity Talent Pipeline Needs More Than More Graduates

Getting people interested in cybersecurity is only the first step. They also need access to practical training, mentors and a clear path into the work.

ITSEC AsiaITSEC Asia
|
Okt 09, 2026
The Cybersecurity Talent Pipeline Needs More Than More Graduates

Cybersecurity has no shortage of reasons to attract new talent. There are technical roles, policy roles, incident response, digital forensics, security engineering, governance and an expanding set of jobs around AI.

Yet access to those paths isn’t evenly distributed.

ITU’s Her CyberTracks programme puts a specific number against the problem: women accounted for 22% of the global cybersecurity workforce in 2025. ITU also identifies unequal access to training, a lack of strong female role models and limited awareness of cybersecurity career options among barriers to greater participation. ITU

The programme’s fourth edition, running from May to October 2026, is designed around that gap. It combines technical and policy training with mentorship, networking and practical exercises. Its Asia-Pacific regional training is scheduled for 12–16 October in Bangkok. ITU

The useful lesson for workforce planning is simple: talent development needs an ecosystem around the learner.

Training Gets People Started. Mentorship Helps Them Stay.

A cybersecurity course can teach someone how incident response works. It can’t automatically show them what a career in incident response looks like six months later.

That’s where mentorship matters.

ITU’s Her CyberTracks model includes senior professional mentoring alongside technical education and practical exercises. The 2026 Incident Response CyberTrack, for example, includes cyber drill preparation, incident response, digital forensics, threat intelligence and communication skills, with participants assessed through simulations and group exercises. ITU Academy

That combination addresses several workforce problems at once:

  • Learners gain technical skills they can practise
  • Mentors provide context about how those skills are used at work
  • Participants see different career routes rather than one stereotypical “cyber job”
  • Peer networks can make it easier to ask questions and find opportunities
  • Practical exercises provide evidence of capability beyond a certificate

The last point matters. A CV can say someone studied incident response. A realistic exercise can show how they behave when the evidence is incomplete and the clock is running.

Diversity Also Changes the Talent Pool

A workforce strategy that draws from a narrow section of the population will eventually run into a narrow talent pool.

ITU’s approach treats participation and capability together. Its programme covers technical subjects as well as communication, leadership, policy and networking. The Cyber & AI track also includes AI fundamentals, AI threats, governance, cyber readiness and scenario planning. ITU Academy

That broader model reflects how cybersecurity work is actually done. Security teams need people who can analyse systems, communicate risk, coordinate during incidents and make decisions under pressure.

Different backgrounds don’t automatically produce better security decisions. But a field that gives fewer people access to training and professional networks gives itself fewer chances to find exceptional practitioners.

Make the Path Visible

For educators and employers, the practical question is how to turn interest into progression.

A useful pathway can connect:

  1. Exposure: introduce students and career changers to real cybersecurity roles.
  2. Practice: provide labs, simulations and technical projects.
  3. Mentorship: connect learners with people already doing the work.
  4. Experience: create internships, apprenticeships or supervised assignments.
  5. Progression: map the next skills and responsibilities clearly.

That approach fits the model at ITSEC Cyber & AI Academy, which combines skills assessment, structured learning and practical cyber range environments across cybersecurity and AI. The goal is to help learners see where they are, practise the work and understand what comes next. ITSEC Academy

The cybersecurity workforce doesn’t grow simply because more people hear about cybersecurity.

It grows when more people can see a path into it and have a realistic opportunity to walk that path.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References

  1. International Telecommunication Union, “Her CyberTracks,” updated 2026
  2. ITU Academy, “Her CyberTracks – Incident Response CyberTrack 2026,” 11 May–31 October 2026
  3. ITU, “Her CyberTracks Regional Asia-Pacific Training,” 12–16 October 2026
  4. ITU Academy, “Her CyberTracks – Cyber and AI CyberTrack 2026,” 11 May–31 October 2026
  5. ITSEC Cyber & AI Academy, “ITSEC Cyber & AI Academy,” accessed October 2026
Share this post

You may also like

Entry-Level Cybersecurity Is Getting a New Job Description
Cybersecurity

Entry-Level Cybersecurity Is Getting a New Job Description

There used to be a fairly predictable starting point for a cybersecurity career. Learn networking. Understand access control. Get comfortable with security operations. Then, after some experience, start tackling the newer and more complicated stuff. AI is messing with that sequence. On 1 September 2026, ISC2 introduced its updated Certified in Cybersecurity exam outline, the first major content revision since the entry-level certification launched in 2022. Foundational AI concepts are now integrated into the material, including identifying AI assets, recognizing automated threats and supporting secure governance of emerging technologies. Its updated AI guidance goes further. Cybersecurity professionals increasingly need competence in AI governance, model security, data integrity, prompt engineering, AI risk management and the security of AI-enabled systems. That’s quite a list for something that was recently considered a specialist topic. AI SECURITY IS MOVING DOWN THE CAREER LADDER There’s a practical reason for this. AI-enabled systems are entering everyday business operations. At the same time, AI can be used for phishing, social engineering and increasingly automated attacks. Indonesia is already preparing for that reality.

ITSEC AsiaITSEC Asia
|
Sep 03, 2026 — 3 minutes read
The AI Talent Gap Is Still the Weakest Link in Indonesia's Digital Transformation
Cybersecurity

The AI Talent Gap Is Still the Weakest Link in Indonesia's Digital Transformation

Introduction How many people on your team truly understand how to build, secure, and govern AI-based systems today. For most organizations, the honest answer is far fewer than what's actually needed. The World Economic Forum's Future of Jobs Report 2025 found that nearly 39 percent of workers' core skills are expected to change significantly by 2030, with AI and big data sitting at the top of the list of skills most in demand and hardest to fill. ITSEC Asia, which works with organizations across Indonesia, Singapore, Australia, and the UAE, sees the same pattern play out almost everywhere. AI adoption is moving far faster than organizations' ability to build, secure, and responsibly govern the technology. Source: World Economic Forum, Future of Jobs Report 2025 Demand for AI Talent Is Growing Faster Than the Supply This isn't simply a headcount problem, it's a widening gap between how fast technology is being adopted and how fast organizations can produce people genuinely capable of handling it. * ISC2's workforce study puts the

ITSEC AsiaITSEC Asia
|
Agu 14, 2026 — 4 minutes read
Vulnerability Assessment vs Penetration Testing: What's the Difference and Why Does It Matter?
Cybersecurity

Vulnerability Assessment vs Penetration Testing: What's the Difference and Why Does It Matter?

When discussing cybersecurity assessments, two terms are often used interchangeably: Vulnerability Assessment and Penetration Testing. While both approaches aim to improve an organization's security posture, they serve different purposes and provide different types of insights. Understanding the distinction between the two is important for organizations looking to prioritize risks, strengthen defenses and make better security decisions. Rather than asking which one is better, the more relevant question is: When should you use each approach, and how can they work together? WHAT IS A VULNERABILITY ASSESSMENT? A Vulnerability Assessment is the process of identifying and evaluating security weaknesses across systems, networks, applications and other digital assets. The primary objective is to discover vulnerabilities before attackers do. WHAT HAPPENS DURING A VULNERABILITY ASSESSMENT? A typical Vulnerability Assessment may include: * Asset discovery. * Automated vulnerability scanning. * Risk classification and prioritization. * Identification of outdated software and misconfigurations. * Reporting and remediation recommendations. The result is a broad view of potential weaknesses that require attention. STRENGTHS OF VULNERABILITY ASSESSMENTS Organizations often conduct Vulnerability Assessments

ITSEC AsiaITSEC Asia
|
Jun 15, 2026 — 4 minutes read

Receive weekly
updates on new posts

Subscribe