A recent study from the CyberPath Professionalisation Pilot has highlighted significant barriers to expanding the cybersecurity workforce in Australia. Conducted in partnership with Evolved Group, the research surveyed 300 individuals and revealed a disconnect within the profession, which now encompasses over 60 job types. The findings underscore the absence of a clear, nationally consistent framework that helps individuals understand their roles, required skills, and career progression. This lack of clarity poses challenges for employers assessing capabilities and for educators aligning training programs with industry needs. For more details, visit CRN Australia.
Identifying the Gaps in Cybersecurity Education
Unclear career pathways, inconsistent role definitions, and high entry costs are constraining the cybersecurity workforce pipeline. Clint Thomson, director of TechConnect, noted that while talent exists, a structured pathway is missing to guide individuals into the profession. He emphasized the need for clearer career pathways and stronger connections between educational institutions and employers, as well as more opportunities for graduates to gain hands-on experience in real-world environments.
Balancing Education and Experience
The research advocates for a more practical, skills-based approach to professional recognition. Many employers report that candidates possess strong theoretical knowledge but lack practical experience in production environments. While certifications provide a baseline, other attributes such as problem-solving skills and a security mindset are equally important. Thomson pointed out that curiosity and a willingness to learn often predict success better than years of experience alone.
Strategies to Address Workforce Constraints
CyberPath is a government-funded initiative led by a consortium of industry organizations, including the Australian Computer Society (ACS) and the Australian Information Security Association (AISA). The program aims to develop a capabilities framework that defines the necessary skills, knowledge, and behaviors across cybersecurity roles. To facilitate workforce development, Thomson proposed three key initiatives:
- Enhancing collaboration between educational institutions and industry to ensure graduates are job-ready.
- Recognizing skills-based pathways alongside traditional certifications, allowing capable individuals to demonstrate their abilities through practical assessments.
- Increasing support for internships, graduate programs, and apprenticeships to bridge the experience gap.
Thomson also highlighted a challenge faced by smaller businesses: graduates who meet the required standards often leave for more lucrative opportunities in government or larger consultancies. This trend makes it difficult for smaller firms to compete for talent, forcing them to invest in internal development while risking losing those employees to the market.
In summary, while Australia has a wealth of individuals eager to enter the cybersecurity field, the lack of accessible and structured pathways hinders their entry and retention. Addressing these issues is crucial for building a robust cybersecurity workforce capable of meeting the demands of the future.


