Security Think Tank: Getting the training and development mix right

Rob Dartnall, CEO at SecAlliance and chair of Crest’s UK Council, describes the need for formal, varied and continuous development in the cyber security sector

Rob Dartnall

By

Published: 02 Feb 2023

What training do we need to provide to cyber security professionals to keep them ahead of the bad guys? And how do we retain talented security professionals in such a competitive recruitment market? These two important questions may seem different, but they are intrinsically linked. Both are connected to the statement we always hear at the start of a vendor pitch: “The cyber threat landscape is continuously evolving.”

The truth is, we rely on the fact that we work in an industry where a significant percentage of the workforce comprises highly driven, motivated individuals who finish work and then often sit and create, or try out, new tools. They investigate new sources, compete in ‘capture the flag’ events and debate in online forums. But this is not possible for all due to a myriad of reasons.

This level of dedication and constant casual learning can also make the career transition path pretty scary for some. Keeping up with innovations, technology and the ever-changing threat landscape is certainly daunting. However, there are now some fantastic resources available, many free, for cyber security professionals to train more easily and hone their skills, with certified proof.

One of the most important things we need to do as an industry is create the time, space, environment and budget to enable talent to continuously improve. Where some industries push continuous development for people to become more senior or certified, we in cyber security must also do this – because “the cyber threat landscape is continuously evolving.”

Personally, I love resources like Immersive Labs and Hack the Box. Why? Because they can quickly reflect the real threat landscape, with practical labs that can test both defensive and offensive skills against the newest techniques, quickly aligning an individual’s skills with real life situations.

Many of these platforms also align to career development and certification pathways – so the work is mostly done for us. That said, variety is the spice of life. There will always be a place for classroom-based, tutor-led, intensive training.

It is about getting the right recipe for the individual, which also helps with retention.

The psychological construct of the average cyber security professional means they put a lot of weight on their employers caring about their training, knowing they have a dedicated training budget and a detailed training plan set out for them. The more effort we put into our talent’s training and development plans, the more effort they will put into the role and our companies.

This does not have to cost the earth.

A training plan should not just contain big, expensive courses, but subscriptions to platforms, academies and even free online tutorials and webcasts, for example. Training offerings should not be a ‘one-type-suits-all’ scenario, we must be mindful that different people learn in different ways, and everyone benefits from variety.

While lab-based training, such as HTB and Immersive, has driven cyber security skills of late, and certification bodies such as Crest have made sure these skills are used in a safe, professional, ethical and legal manner, for the future, I am excited to see what virtual and mixed reality can bring to cyber security training.

Some of us are highly visual or auditory learners. Labs where we can learn with the help and support of friends or strangers, pointing at visual representations of networks and network traffic, will bring a whole new understanding and possibly even new people to our industry. This will also fuse the separation between classroom, tutor-led training and practical labs.

Also interesting is the evolution of AI-based chatbots, many of which have hit the news recently. There is the opportunity for these bots to act as tutors and ‘sounding boards’. This allows for students to ask questions, clarifications and seek advice, for example with script and ruleset development.

Overall, the training environment in cyber security is strong and continues to develop. What is more important is making sure individuals have the time, support, plan and budget to make it happen. Want to retain staff? Do the above. Want to be ahead of an evolving threat? Do the above.  Want to do the right thing about the individual and the industry? Then do the above.

Read more on Security policy and user awareness

Read More
Arden Center

Latest

FCS Draft Surge: The Rise of Small-School Prospects in Modern NFL Conversations

FCS Draft Surge: The Rise of Small-School Prospects in Modern NFL Conversations Every spring, draft chatter once focused almost entirely on blue-blood programs such as Alabama or Ohio State. Today that narrative feels outdated. Championship rosters increasingly feature players who sharpened skills on modest Football Championship Subdivision (FCS) fields, developing technique rather than basking in

Two Trap Games that Georgia Tech Football Cannot Overlook This Season

While Georgia Tech Football did not face its usual gauntlet of a schedule last season, the Yellow Jackets are no strangers to playing tough schedules, usually among the toughest in the country. Georgia Tech is going to be playing 11 power conference opponents this season, with eight ACC opponents and a non-conference schedule that includes

“I cannot divorce the two”: How Star Wars is blending technology, creativity, and products into the experience itself

(Image credit: Disney) “It’s like a community, right? And it’s a global community that people really love and identify with.” That’s how Bobby Kim, Global Creative Director at Disney Consumer Products, describes Star Wars fandom. And it’s a framing that feels especially fitting as another May the 4th is behind us and we’re weeks out

Trump administration defends right to ban content moderation experts from US

The Trump administration is fighting for the right to keep some social media moderation advocates out of the US. On Wednesday, US District Court Judge James Boasberg heard arguments in a lawsuit between the nonprofit Coalition for Independent Technology Research (CITR) and Secretary of State Marco Rubio and other Trump administration officials. The suit concerns

Newsletter

Don't miss

FCS Draft Surge: The Rise of Small-School Prospects in Modern NFL Conversations

FCS Draft Surge: The Rise of Small-School Prospects in Modern NFL Conversations Every spring, draft chatter once focused almost entirely on blue-blood programs such as Alabama or Ohio State. Today that narrative feels outdated. Championship rosters increasingly feature players who sharpened skills on modest Football Championship Subdivision (FCS) fields, developing technique rather than basking in

Two Trap Games that Georgia Tech Football Cannot Overlook This Season

While Georgia Tech Football did not face its usual gauntlet of a schedule last season, the Yellow Jackets are no strangers to playing tough schedules, usually among the toughest in the country. Georgia Tech is going to be playing 11 power conference opponents this season, with eight ACC opponents and a non-conference schedule that includes

“I cannot divorce the two”: How Star Wars is blending technology, creativity, and products into the experience itself

(Image credit: Disney) “It’s like a community, right? And it’s a global community that people really love and identify with.” That’s how Bobby Kim, Global Creative Director at Disney Consumer Products, describes Star Wars fandom. And it’s a framing that feels especially fitting as another May the 4th is behind us and we’re weeks out

Trump administration defends right to ban content moderation experts from US

The Trump administration is fighting for the right to keep some social media moderation advocates out of the US. On Wednesday, US District Court Judge James Boasberg heard arguments in a lawsuit between the nonprofit Coalition for Independent Technology Research (CITR) and Secretary of State Marco Rubio and other Trump administration officials. The suit concerns

Apple’s 2028 iPhone display sounds impossible, but Samsung and LG are scrambling to build it

Android phones have had curved displays for years and accepted the distortion as the price of aesthetics. Apple is spending two years and billions of supplier dollars to not accept it. Apple's all-screen iPhone 20 mockup Ice Universe / X Apple doesn’t ask its suppliers to build things. It tells them to, hands them a

WD sees sustainability as key business driver in an ‘AI economy’

Hard drive company WD promoted long-term operations and sustainability executive Jackie Jung to become its first chief sustainability officer in February, as it steps up sales to companies building AI data centers. Her vision: Turn sustainability into a “brand” for WD, a strategy that reduces risk for the $6 billion company (formerly known as Western

5 Business Ideas Worth Starting in 2026

If there is one thing Nigerians understand well, it is how to spot opportunity inside hardship. In 2026, that mindset will matter more than ever. The economy is tough, competition is rising, and many people are looking for smarter ways to earn, build, and survive. But even in a difficult environment, some businesses still stand

Getting a business loan now comes with a frequent flyer upside

Australian fintech Prospa has partnered with Qantas Business Rewards, letting eligible SMEs earn up to 500,000 points per loan. What’s happening: Australian fintech lender Prospa has partnered with Qantas Business Rewards to allow eligible small and medium business owners to earn up to 500,000 Qantas Points per loan when taking out a Prospa Small Business