Unclear career pathways, inconsistent job definitions, and high barriers to entry are holding back Australia’s cyber security workforce, according to new research from the Australian Computer Society’s CyberPath Professionalisation Pilot.
The findings have informed the release of the CyberPath Occupations Framework Discussion Paper, which proposes a nationally consistent framework for defining roles and creating clearer career pathways across the industry.
The qualitative study, conducted with research consultancy Evolved Group, gathered feedback from more than 300 participants across Australia’s cyber security sector, including industry professionals, students, and career changers.
Researchers found a growing disconnect between demand for talent and the industry’s ability to attract newcomers. Participants identified confusing job descriptions, expensive professional certifications, and entry-level positions requiring years of prior experience as key obstacles to entering the profession.
“We would never build a hospital, declare a health crisis, and then require every nurse applicant to have already worked in one,” cyber security leader and Australian CISO advisory board member Maryam Shoraka (pictured) said in a statement.
“Yet that is precisely what we are doing with cyber security. The threat is not waiting for us to sort out our credentialing philosophy.”
Certification costs ranging from $3,000 to $4,000, ongoing maintenance requirements, and job advertisements demanding two or three years’ experience for entry-level roles were common concerns among aspiring cyber security professionals.
The report also highlights the growing complexity of the profession, noting that cyber security now encompasses more than 60 distinct job types without a nationally recognised framework to help employers, educators, or jobseekers understand the skills required for each role.
Dean Wunder, lead developer at finao, said greater collaboration and practical skills development would be essential to addressing the workforce challenge.
“Cyber security requires continuous learning, and collaboration is critical,” Wunder said.
“No individual can keep pace with every emerging threat, technology, or security tool.”
CyberPath said it will now begin developing a complementary Capabilities Framework that will define the skills, knowledge, and behaviours required across cyber security roles.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.
David Hollingworth
David Hollingworth has been writing about technology for over 20 years, and has worked for a range of print and online titles in his career. He is enjoying getting to grips with cyber security, especially when it lets him talk about Lego.