To excel in a field like basketball, aspiring stars don’t just study the game; they actively participate. So why do we approach cybersecurity training with a purely theoretical mindset? The current narrative in the cybersecurity sector often focuses on a “skills gap,” highlighting the supposed lack of qualified professionals. However, I propose we recognize an underlying issue: a validation gap.
Recent findings from the World Economic Forum’s Global Cybersecurity Outlook report emphasize the role of insufficient skills and budget constraints in achieving cyber resilience. But the framing of a skills gap neglects a paradox—how can we claim a skills shortage while also facing significant graduate unemployment? Blaming AI feels more like a scapegoat than a viable explanation. If AI were the root cause of our breaches, wouldn’t the scale of attacks have diminished?
Organizations remain hesitant to entrust AI with critical security tasks, and understandably so. The production risks associated with deploying AI solutions are non-trivial. Despite fewer organizations reporting breaches specifically linked to AI models, there’s a disconcerting trend: many are ramping up AI deployments without appropriate governance frameworks. According to IBM, between March 2024 and February 2025, a mere 13% of 600 polled organizations experienced breaches involving AI. Alarmingly, 63% of those had inadequate AI governance policies at the time of the breach, which underscores significant vulnerabilities still present in our security practices.
Addressing the skills gap isn’t just about HR metrics; it's about proving readiness before incidents occur. Current discussions often fixate on training and hiring rather than answering a vital question: how do we verify readiness proactively? The threats posed by AI are not theoretical; they manifest in the form of emergent vulnerabilities that the industry hasn’t prepared for adequately. Organizations find it increasingly difficult to keep pace with an evolving threat model traditionally ignored in training programs.
Standard ups-killing methods don’t cut it anymore, either. Companies invest heavily in certifications, courses, and boot camps, yet these often lag behind the rapid pace of change and shifting techniques employed by attackers. What’s needed is not just theoretical knowledge; cybersecurity professionals require continuous, hands-on experience that mirrors their actual work environments. Existing training cannot replicate the chaos of a real attack or highlight weaknesses in incident response protocols.
Rather than viewing technology as the sole solution, the industry must acknowledge that more tools often just lead to alert fatigue and burnout among teams. With human errors remaining the primary drivers of breaches, a systemic focus on people and their development is essential. Dynamic cyber ranges can make a tangible difference, allowing for practical learning opportunities that embody real-world scenarios.
Building Effective Cyber Ranges
To be truly effective, cyber ranges must feature an AI Proving Ground, characterized by high customization and realistic simulations. Post-exercise analysis is critical for refining skills and confirming readiness, providing invaluable insights to see how individuals can improve their responses under pressure.
- Customization is Key: Tailor environments to replicate your unique tech stack while introducing live-fire scenarios that challenge participants. This prepares teams for quick decision-making in real situations.
- Analyze Outcomes: Ranges must focus on data analysis post-exercise. This information is instrumental for executives pushing for tech consolidation or additional funding and can validate the efficiency and impact of the training.
- Nurture Existing Talent: Rather than solely hiring experienced analysts, organizations should invest in developing their talent from within. Training junior analysts to become high-performers can be far quicker and less expensive than seeking external hires, creating a pipeline of skilled workers tailored to the organization’s needs.
The advantages of on-the-job training in relieving pressure on overstretched teams can be significant, yielding returns that often exceed tenfold on the initial investment. Some clients have reported saving over $400,000 in training expenses while enhancing their resilience against emerging threats. The focus should shift from viewing practical training as an occasional event to integrating it into daily operations and security culture.
Ultimately, fostering a team-centric learning environment proves far more rewarding than traditional classroom training. Validate skills and allow talent to flourish in a way that feels organic, which not only elevates individual capabilities but enhances the overall security posture of the organization.
This article is published as part of the Foundry Expert Contributor Network.
Want to join?