Alexia Pedersen, SVP International at O’Reilly, explores how Chief Information Security Officers (CISOs) can cultivate long-lasting and effective security teams by prioritising the right skills from the outset.
CISOs today are stuck between a rock and a hard place. As cyber threats grow in complexity and scale, they’re being asked to protect the enterprise while navigating a widening cybersecurity skills gap, shrinking budgets, and rising burnout. How do you build – and keep – a capable security team under those conditions? The short answer: it’s incredibly difficult.

The pressure to secure the enterprise isn’t going anywhere – but neither is the widening talent gap. CISOs will have to get creative. According to the ISC2’s latest Cybersecurity Workforce Study, an additional 10.2 million security professionals are required to meet the current global demand. In the UK, the first Skills England report highlighted that the nationwide skills gap continues to grow, with the NCSC warning of a widening gap between cyber threats and defence capabilities due to talent shortages.
Many CISOs still rely on traditional security training methods like annual courses, in-person workshops, or outdated e-learning, but in today’s fast-evolving threat landscape, these approaches leave teams underprepared for emerging vulnerabilities and sophisticated attack vectors. What’s often overlooked is just how advanced and accessible modern learning platforms have become. For example, gamified activities like “capture the flag” challenges are now common in cybersecurity upskilling, offering real-time threat simulations that engage and educate. Live sessions with world-leading practitioners, deep technical content for IT certifications, and hands-on labs help practitioners learn faster and apply knowledge immediately, all while saving organisations time and money compared to legacy methods.
As daunting as this sounds, it also opens the door to a smarter solution. Amid headcount and salary freezes, our research discovered that over the past twelve months, more than half (53%) of UK employers have seen an uptick in requests from nontechnical staff for cybersecurity reskilling opportunities. Encouragingly, four in five (81%) see digital reskilling more cost-effective than acquiring new headcount — particularly for the 48% of employers looking to enhance skills in cybersecurity.
Upskilling existing employees is not as crazy as it might sound. Many non-technical staff data analysts, IT-adjacent roles, even ops folks already have transferable skills like risk awareness, systems thinking, or compliance experience. These individuals can take ownership of ensuring security practices in their departments to bolster cyber security across an organisation without the need for additional resources.
Despite the demand, many employees do not feel empowered to drive forward their own learning, with more than a third (34%) pointing to a lack of time as a barrier to pursuing new security-focused learning opportunities. Almost one in five (19%) employees also cited a lack of access to relevant learning materials at their point of need. Unsurprisingly, businesses must develop their internal cyber training systems, with robust methodology, training modules and even in-house certification and remuneration offers.
Indeed, while hiring new talent may seem like the fastest fix, the reality is that we cannot recruit our way out of this talent shortage. Cyber talent simply doesn’t exist in the volumes required. Instead, we should turn inwards and consider whether we are creating an environment where existing team members can grow and build the advanced capabilities we so urgently need. With the threat landscape changing daily, the ability to continuously learn through an ‘in-the-flow-of-work’ approach will be essential.
Building a continuous learning programme
Continuous learning is the key – a culture that fosters curiosity, adaptability, and ongoing skill development in employees. It’s about more than just formal training; it involves encouraging individuals to seek new challenges, share knowledge, and continuously learn to stay relevant. It’s about embedding learning into the day-to-day, not reserving it for annual workshops or reactive upskilling after incidents.
It’s easy to focus on the upfront cost of learning and development (L&D), particularly in a budget-constrained environment. What is often overlooked, however, is the cost of underinvestment. Unaddressed skills gaps can lead to increased incident response times, higher risk exposure, and ultimately, greater financial losses from breaches or compliance failures. A blanket upskilling of employees helps to mitigate some of these risks, headed by non-technical leaders.
Burnout is also a growing issue in the cybersecurity industry, driven in part by the sense that teams are constantly fighting fires without time to build the tools or knowledge they need to keep pace. Without meaningful growth opportunities, top talent is more likely to leave, contributing further to the talent churn that so many organisations are already experiencing. The 2024 ISC2 report found that 66% of cybersecurity professionals experience significant stress at work, with nearly half (49%) reporting that stress has increased over the past year. A major contributor: insufficiently trained staff, cited by 45% of respondents.
In contrast, when organisations support continuous learning, the benefits are wide-reaching. In fact, our research found that access to continuous learning and being part of a highly skilled team are among their top priorities when considering a new role. In other words, investing in L&D doesn’t just build internal capability, it improves retention, attracts ambitious new talent and creates a culture of shared accountability for staying ahead of threats.
CISOs must treat continuous learning as a strategic lever rather than an isolated HR function, embedding it into team structures, team culture and success metrics. Here are a few principles to developing a culture of continuous learning:
1. Align learning strategies with business and security goals. CISOs should partner with department leads to ensure learning objectives map to the broader business strategy. For example, if your organisation is undergoing a major cloud migration, your L&D programme should focus on cloud security training. Similarly, if your business is expanding its digital services or handling larger volumes of sensitive customer data, focus areas should include data protection, threat detection and secure development practices. Training must be closely tied to the specific risks and technologies driving the business forward.
2. Integrate in-the-flow-of-work learning. Rather than sending teams off-site for generic training courses, provide access to high-quality, contextually relevant content that can be accessed in real-time, whether during a security audit, or post-mortem analysis. A learning platform – ideally one that has been designed specifically for technology professionals – would make it possible to integrate learning into daily workflows, turning real-world challenges into learning moments. This could mean incorporating time for skill-building into sprint planning, aligning training with real-world threat scenarios, or creating visible pathways for internal mobility. When learning is integrated, rather than imposed, it becomes part of how people work, not a burden on top of it.
3. Set measurable expectations. Too often, employees want to upskill but aren’t sure where to start or if their learning will be recognised. In fact, our research revealed that nearly one in three (30%) UK employees say learning and development (L&D) is not discussed or measured as part of their performance reviews. Meanwhile, 27% report no clear expectations or structured support for leveraging available learning tools. CISOs can change this by setting clear learning goals, incorporating L&D into regular performance reviews, to recognise skill development as much as project delivery.
4. Cultivate a culture of shared responsibility. Ultimately, developing a future-ready security team requires commitment from both employer and employee. CISOs must create the right conditions for learning, but team members must also take ownership of their growth. Empowerment is key, when people feel trusted to explore and develop their skills, they’re more likely to step up and stay.
Looking ahead
The cybersecurity skills gap is only getting worse, putting CISOs in a critical position. To protect their organisations effectively, they must also become champions of talent development. Bridging the gap requires more than just recruitment, it needs a new approach to training that keeps teams working while integrating learning into the day-to-day. In-the-flow-of-work training, tailored to real-world threats and aligned with both business and security priorities, is key to building a resilient, adaptable security team.


