How to Close Cybersecurity Workforce Gaps

TL;DR
Cybersecurity workforce gaps can be reduced by aligning job expectations with actual work roles, providing practical training, and documenting achievement through certifications or badges. Employers should reconsider inflated degree and experience requirements, recognize related experience and soft skills, and give entry-level candidates opportunities. Shared standards, workforce data, lab-based education, and performance assessments can strengthen confidence in workers’ demonstrated abilities.
Transcript
Everybody, thank you for joining in. Uh, as president of something called the C3, which is a group of, uh, certification providers, uh, you're ta- you're gonna be hearing from each of them. And I just wanna, uh, thank them for taking the time, and thank you for joining in, 'cause we're talking today about kind of fixing the gaps in the cyber workfo... Read More
Key Insights
- The cybersecurity workforce problem is a confidence gap as well as a skills gap. Institutions may hesitate to move forward because they lack workers with suitable capabilities, while learners may doubt whether they can enter technology without credentials such as a four-year degree.
- Indicators of achievement are documented signs of learning and capability, including certifications and badges. Capturing a person’s learning behavior and accomplishments can help address gaps involving education, compliance, and employer confidence by making achievement visible and easier to evaluate.
- The Cybersecurity Credentials Collaborative is a group of certification providers that includes ISACA, ISC squared, SANS GIAC, CompTIA, IAPP, FITSI, and CertNexus. Its members cooperate with governments and standards bodies even though they also compete within the cybersecurity credentialing market.
- ISO 17024 certification supports processes intended to create fairness and equity. C3 members use defined processes to help ensure that training and certification provide consistent opportunities, including opportunities that support workforce diversity.
- Practical cybersecurity education is strengthened by hands-on laboratories and performance-based testing. These approaches assess whether learners can apply knowledge at scale and develop practiced capability, rather than merely demonstrating that they know facts or concepts.
- Cybersecurity career pathways can begin with learners of different ages and backgrounds. CompTIA described K–12 efforts, its TestOut acquisition, CompTIA Spark, and Tech Girls, while examples of professionals from varied countries and previous careers illustrated how certification can document career development.
- Cybersecurity workforce data can help organizations understand regional employment conditions and industry priorities. CyberSeek, Cyber States, CompTIA’s monthly tech jobs report, and its industry research were presented as resources shaped partly through contributions from C3 members.
- Cybersecurity job descriptions are often overspecified through demands for four-year degrees, certifications, and excessive experience. Employers can widen the talent pool by defining genuine role needs, considering related experience and soft skills, and remaining open to career changers and motivated entry-level candidates.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: What is the cybersecurity workforce confidence gap?
The cybersecurity workforce confidence gap is the uncertainty experienced by both organizations and learners. Institutions may lack confidence to proceed because they cannot identify workers with the right capabilities or because communication is inadequate. Learners may question whether they need a four-year degree or whether they can enter technology at all. Documented achievement, practical training, and clearer expectations can help reduce this uncertainty.
Q: How can certifications help close cybersecurity workforce gaps?
Certifications can document a person’s achievement and give organizations evidence that learning has occurred. The presentation calls these credentials indicators of achievement, a category that can also include badges. When supported by hands-on education and performance-based assessments, certification can demonstrate practical capability, strengthen employer confidence, and help address education, compliance, communication, and workforce qualification gaps.
Q: Why are performance-based cybersecurity assessments important?
Performance-based assessments are important because they evaluate whether learners can apply knowledge through practical activity. CompTIA combines these assessments with hands-on education and laboratory work so candidates demonstrate more than factual recall. The stated goal is to build practiced ability into a learner’s muscle memory while providing organizations with scalable evidence that workers have genuinely developed relevant capabilities.
Q: How should employers improve cybersecurity job descriptions?
Employers should work with the cybersecurity industry to identify what a role truly requires and remove demands that do not match the work. The presenters criticize postings that request five years of experience for a job requiring only two years, as well as unnecessary combinations of four-year degrees, certifications, and experience. More realistic descriptions can make qualified candidates easier to identify.
Q: How can organizations expand the cybersecurity talent pool?
Organizations can expand the talent pool by remaining open to entry-level candidates, career changers, and existing employees with related work experience. Employers should also evaluate drive, determination, eagerness, soft skills, and cultural fit instead of relying exclusively on degrees or long experience histories. Reassessing inflated hiring expectations can reveal capable candidates who would otherwise be overlooked.
Q: What workforce gaps exist beyond cybersecurity skills?
The presentation identifies gaps in confidence, communication, diversity, information sharing, education, compliance, and employer expectations in addition to technical skills. These gaps affect institutions as well as individual learners. Closing them requires cooperation among credential providers, clearer work-role definitions, practical learning, visible documentation of achievement, fair certification processes, and job requirements that reflect actual organizational needs.
Q: What does the Cybersecurity Credentials Collaborative do?
The Cybersecurity Credentials Collaborative brings together certification providers including ISACA, ISC squared, SANS GIAC, CompTIA, IAPP, FITSI, and CertNexus. Members work with governments and standards bodies, contribute to workforce resources, and collaborate on projects such as mapping credentials to NICE. Their shared purpose includes documenting achievement and improving confidence in cybersecurity education, assessment, and credentials.
Q: What organizational changes can address cybersecurity staffing needs?
Organizations can reassess the effectiveness and structure of their IT departments while considering consulting, managed services, outsourcing, and greater automation. They can also improve hiring by defining work roles accurately, training existing employees, recognizing related experience, and opening positions to entry-level talent. These changes address both workforce capability and the expectations that make cybersecurity positions unnecessarily difficult or expensive to fill.
Summary & Key Takeaways
-
Cybersecurity organizations face more than a shortage of technical skills. Employers, workers, and learners also experience gaps in confidence, communication, diversity, education, compliance, and information sharing. The Cybersecurity Credentials Collaborative brings certification providers together to document achievement, cooperate with governments and standards bodies, and improve trust in workforce qualifications.
-
Certifications and badges can function as indicators of achievement by making learning and demonstrated ability visible to employers. CompTIA emphasizes pathway-based education, hands-on laboratories, immersive learning, and performance-based assessments. These methods are intended to show that candidates can apply knowledge practically, not merely recall information during a conventional knowledge-based evaluation.
-
Employers can expand the cybersecurity talent pool by writing realistic job descriptions, understanding work roles, and avoiding unnecessary combinations of degrees, certifications, and extensive experience. Organizations should also consider entry-level applicants, existing employees with related experience, career changers, soft skills, cultural fit, automation, managed services, consulting, and outsourcing when addressing workforce needs.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator