We may be solving the wrong problem
For years, cybersecurity has been described as an industry with a skills shortage.
So we’ve responded logically.
Train more people.
Create more courses.
Encourage more graduates.
Promote certifications.
Attract career changers.
Yet something doesn’t quite add up.
People are completing cybersecurity qualifications and still struggling to secure their first opportunity.
Career changers are investing in certifications but remain unsure where they fit.
Graduates are applying for supposedly entry-level positions that ask for previous experience.
Meanwhile, employers continue telling us they can’t find the cybersecurity capability they need.
Perhaps both sides are telling us something important.
Cybersecurity doesn’t only have a skills problem.
It has an employability problem.
We have become increasingly good at helping people learn cybersecurity.
Now we need to become much better at helping them demonstrate they can do cybersecurity work.
What is the cybersecurity employability gap?
The employability gap sits between knowledge and workplace capability.
Imagine someone completes a cybersecurity qualification.
They can explain risk management.
They understand incident response.
They know common frameworks.
They’ve studied security controls.
Then an employer asks:
“Tell me about a time you’ve actually applied this.”
That’s where many candidates struggle.
Not because they haven’t worked hard.
But because our development pathways don’t always provide enough opportunities to move from:
Learning → Applying → Being challenged → Demonstrating
Employers aren’t simply purchasing knowledge.
They’re trying to reduce hiring risk.
They want evidence that someone can take what they know and use it appropriately.
1. More qualifications won’t automatically solve employability
I believe strongly in education.
I also believe qualifications should have a purpose.
The problem begins when every career obstacle results in the same response:
Get another certification.
A candidate applies.
They’re rejected.
They assume they’re underqualified.
So they complete another course.
They apply again.
Still no success.
Eventually, they have considerable theoretical knowledge but the original problem hasn’t changed.
Perhaps the missing piece wasn’t knowledge.
Perhaps it was:
- Practical experience.
- Evidence.
- Professional positioning.
- Communication.
- Mentoring.
- Commercial awareness.
- Interview capability.
Or clarity about which cybersecurity career actually fits.
Before recommending more education, we should diagnose the gap properly.
2. Cybersecurity experience needs somewhere to begin
Employers are justified in wanting capable people.
Cybersecurity carries significant consequences.
But if every organisation requires experience before providing an opportunity, where does experience begin?
Someone has to provide the first project.
The first mentor.
The first realistic problem.
The first opportunity to make a recommendation.
The first piece of feedback.
The first chance to discover that the textbook answer doesn’t always survive contact with the business.
That doesn’t always need to begin with permanent employment.
We can create development through:
- Practical projects.
- Industry mentoring.
- Workplace simulations.
- Internships and apprenticeships.
- Employer challenges.
- University partnerships.
- Structured programmes.
These shouldn’t be misrepresented as years of employment.
But they can help someone start developing demonstrable capability.
3. We are overlooking experienced professionals
The employability problem looks different for career changers.
Someone with 12 years in procurement isn’t professionally inexperienced.
They may already understand suppliers, contracts, negotiation, due diligence and commercial risk.
An auditor may understand evidence, controls and assurance.
A project manager may understand complex delivery and stakeholders.
A finance professional may understand governance and commercial decision-making.
They still need cybersecurity-specific knowledge.
But asking them to disregard everything they’ve already built makes little sense.
This is one of the principles behind our approach at Lateral Connect:
New to cybersecurity doesn’t mean new to professional value.
A stronger transition identifies:
- What transfers.
- What doesn’t.
- What’s missing.
- What needs proving.
Then development becomes targeted rather than generic.
4. Work-ready doesn’t mean finished
We also need a more realistic definition of “work-ready.”
An entry-level professional shouldn’t be expected to operate like someone with five years’ experience.
Work-readiness isn’t perfection.
It’s having enough knowledge, practical capability and professional behaviour to begin contributing at an appropriate level while continuing to develop.
Can someone apply what they’ve learned?
Can they explain their reasoning?
Can they communicate with stakeholders?
Can they produce useful work?
Can they recognise when they don’t know something?
Can they receive feedback?
Can they connect cybersecurity decisions to business impact?
Those are better questions than simply counting certificates.
5. Employers need to become talent developers too
The cybersecurity talent pipeline cannot be somebody else’s responsibility.
If employers only compete for experienced talent, we’re redistributing existing capability rather than creating enough new capability.
Employers don’t need to become training providers.
But they can contribute.
Security professionals can mentor.
Organisations can provide sanitised industry scenarios.
Businesses can sponsor programme places.
Teams can participate in practical projects.
Employers can create internships, apprenticeships and internal transition routes.
Universities and organisations can collaborate on real-world challenges.
This isn’t simply goodwill.
It’s workforce strategy.
Organisations participating earlier in talent development can build relationships with emerging professionals before everyone else is competing to hire them.
6. Education and industry need a stronger bridge
Universities and training providers have an equally important role.
Instead of measuring success only through:
- Attendance.
- Completion.
- Qualifications.
I’d add another question:
What can someone demonstrate at the end that they couldn’t demonstrate at the beginning?
Can they assess?
Analyse?
Challenge?
Recommend?
Present?
Build?
Explain?
That’s where education begins connecting to employability.
And it’s why partnerships matter.
Universities bring academic development.
Employers bring workplace context.
Industry mentors bring experience.
Specialist programmes can help create the practical bridge between them.
No single part of that ecosystem needs to solve the entire problem.
But we do need to stop passing the problem between us.
What does better cybersecurity employability look like?
I would build it around five stages:
LEARN – Develop credible cybersecurity knowledge.
APPLY – Use that knowledge against realistic problems.
CHALLENGE – Receive feedback from experienced professionals.
PROVE – Build evidence of capability.
CONNECT – Create meaningful pathways towards opportunity.
That’s a much stronger proposition than:
Learn → Certify → Apply → Hope.
It’s also central to what we’re building through Lateral Connect.
Because the goal shouldn’t simply be helping someone say:
“I’m cybersecurity qualified.”
It should be helping them confidently demonstrate:
“Here’s what I know, here’s how I’ve applied it, and here’s the professional value I can bring.”
Conclusion: Skills are only part of the equation
Cybersecurity still needs skills.
It needs education.
It needs technical expertise.
It needs certifications.
But if people continue learning while struggling to enter the profession, and employers continue struggling to find suitable talent, we need to look at what happens between education and employment.
The missing piece may be employability.
That means building stronger connections between:
- Knowledge and application.
- Qualifications and evidence.
- Education and employers.
- Potential and opportunity.
And importantly, it means recognising that cybersecurity talent doesn’t arrive fully formed.
It has to be developed.
If we want more work-ready cybersecurity professionals tomorrow, we need better ways to build them today.
Don’t just learn cybersecurity. Build capability.
I’m Victoria Coker, Founder of Lateral Connect. We help professionals turn cybersecurity learning and existing career experience into practical, demonstrable capability through mentoring, real-world projects and structured career development.
For professionals: If you’ve completed courses, earned certifications or spent months trying to enter cybersecurity but still aren’t getting traction, don’t automatically assume you need another qualification. Our 5-Week Accelerator and 5-Month Lateral Connect Programme offer different pathways depending on the practical development, mentoring and career support you need.
Applications for our next cohort are open. Apply to Lateral Connect or book a Career Fit Call to explore which pathway is right for you.
For employers, universities, colleges and workforce organisations: we’re actively looking for partners who want to create stronger cybersecurity talent pathways through industry mentoring, practical projects, sponsored programme places, employability initiatives and talent-development programmes.
If you’re asking where the work-ready cybersecurity talent is, perhaps there’s a bigger opportunity:
Let’s build it together.
Responses