Australia needs to fix its cyber workforce constraints: Report

A government-funded industry study has found major impediments to growing the cyber workforce.

Image:
Clint Thomson, director, TechConnect

Unclear career pathways, inconsistent role definitions and high costs to enter the profession are constraining the cybersecurity workforce pipeline, new research from the CyberPath Professionalisation Pilot has found.

The research, conducted in partnership with Evolved Group, surveyed 300 people and found the profession has a major disconnect. Cybersecurity now spans more than 60 job types, but there is no simple, nationally consistent structure to help people understand where they fit, what skills they need or how they can progress.

This also creates challenges for employers trying to assess capability with confidence, and for educators and training providers working to align programs with industry needs. Clint Thomson, director, TechConnect, has seen first-hand the gap between education and employment.

“Our own graduate and work-experience programs show the talent is there; what's missing is a structured pathway to bring it in,” Thomson said.

“It needs clearer career pathways, stronger links between education providers and employers, and more chances for graduates to get hands-on experience in live customer environments,” he added.

Balancing education and experience

The research found strong support for a more practical, skills- and capability-based approach to professional recognition, backed by clearer role definitions, stronger links between education and industry, and more accessible entry pathways.

Many employers find candidates have a strong theoretical knowledge but haven't yet had the chance to apply it in production environments. Certifications set a useful baseline but other attributes are also important.

“Cybersecurity demands a mix of technical skill, problem-solving, communication and a security mindset that's hard to assess from a resume alone,” Thomson said.

“We've found aptitude and attitude are often better predictors of success than years on the job. Curiosity, a willingness to keep learning, and the ability to work through real problems tend to matter more than a tick-box list of prior study or basic experience,” he said.

How to improve the cyber workforce squeeze

CyberPath is a government-funded pilot program led by a consortium of industry organisations, including Australian Computer Society (ACS), Australian Information Security Association (AISA) and the Australian Women in Security Network (AWSN).

It’s now moving to develop a capabilities framework that defines the skills, knowledge and behaviours required across cybersecurity roles to address the key constraints.

To make it easier for partners to build the cybersecurity workforce Australia needs, Thomson nominated three initiatives.

Closer collaboration between education providers and industry, so graduates leave with practical, job-ready exposure rather than theory alone.

Wider recognition of skills-based pathways alongside traditional certifications, so capable people can prove themselves through practical assessment rather than being filtered out on paper.

And more support for internships, graduate programs, apprenticeships and work-integrated learning to bridge the experience gap.

“Australia isn't short on people who want to work in cybersecurity; it's short on accessible, structured ways for them to get in, develop and stay,” he said.

Thomson also highlighted another challenge for smaller, partner businesses: graduates that meet the investable grade are too talented for the sector and move into defence/government or dedicated security consultancies lured by attractive opportunities and salaries.

“The large consultancies and government have the financial means to invest in these candidates; smaller businesses like ours will struggle to compete for talent at this level so we have to build it internally and risk losing them to the market,” he said.

Highlights