Here’s an uncomfortable truth: While 58% of IT decision-makers blame security breaches on skills gaps, most organizations are actively making the problem worse through outdated hiring practices.

Talented candidates get rejected for lacking specific qualifications, while less capable candidates who meet those check-the-box hiring requirements are brought on and struggle to perform in real-world scenarios. The industry needs a fundamental shift in how we identify and develop cybersecurity talent, and learning and development (L&D) professionals are uniquely positioned to lead this transformation.

Checkbox Hiring Versus Training for Cybersecurity Roles

Walk through any cybersecurity job board and you’ll find postings that read like fantasy novels. Entry-level positions demanding five years of experience. Roles requiring expertise in 15 different tools. Certifications that cost thousands of dollars just to apply.

This isn’t just a human resources (HR) problem; it’s an organizational crisis that L&D leaders must help solve. According to IBM, the average data breach costs $5.22 million for organizations with a high shortage of security skills. That’s $1.57 million more than organizations with a low level or no reported skills shortage.

Here’s where L&D becomes critical: When hiring managers insist on impossible requirements, it’s often because they don’t understand that these skills can be developed. L&D leaders need to step up and demonstrate that with the right training architecture, someone with strong foundational skills can become proficient in specific tools and platforms within weeks, not years.

3 Ways L&D Leaders Can Develop Cybersecurity Skills

1. Build Adaptive Learning Systems for Tomorrow’s Threats

The cybersecurity landscape shifts faster than any degree or certification program can keep pace. Five years ago, cloud security was a specialty. Today, it’s table stakes. The hot skill you’re hiring for today might be automated away tomorrow.

L&D leaders must create learning ecosystems that evolve as quickly as the threats do. This means:

  • Microlearning modules that can be updated weekly as new threats emerge
  • Just-in-time training that delivers specific skills when teams need them
  • Artificial intelligence (AI)-powered learning platforms that identify skill gaps in real-time and automatically serve up relevant content

Consider the Department of Defense’s recent shift from DoD 8570 (which mandated specific certifications) to DoD 8140 (which emphasizes continuous skill development). L&D professionals should use this as a model: Build competency frameworks that emphasize continuous learning over point-in-time certifications.

2. Leverage Diverse Backgrounds Through Strategic Skill Transfer

Narrow hiring criteria build teams that think alike: same schools, same certifications, same approaches. This uniformity creates dangerous blind spots that L&D can help eliminate.

L&D leaders should develop “skill transfer programs” that explicitly map broad skills to cybersecurity applications. For example:

  • Former teachers who can communicate complex topics may excel at roles like security awareness training with minimal technical and platform-related upskilling.
  • Military veterans with operational discipline and systematic thinking may excel at procedural-focused careers like incident response or risk management.
  • Artists and musicians with strong pattern recognition may excel in specialized roles like threat hunting with training that builds on their pattern detection abilities.

Consider a supply chain expert who wanted to transition into cybersecurity. Instead of starting her over in entry-level training, we mapped her existing knowledge to security concepts. Supply chain risk assessment became third-party security evaluation. Vendor management became security vendor assessment. Within weeks, she was contributing at an intermediate level because we built on what she knew rather than starting from zero.

3. Develop Character Traits Alongside Technical Skills

Here’s what separates great security teams from mediocre ones: you can teach someone to use a security information and event management (SIEM) platform in weeks, but you can’t easily teach integrity, curiosity or critical thinking. These character traits are the foundation of many cybersecurity roles — and L&D leaders hold the key to unlocking this talent pool.

When L&D builds comprehensive technical training programs, it liberates hiring managers from the checkbox mentality. They can focus on finding people with the right mindset and character, knowing that L&D will handle the technical upskilling.

Here’s how L&D enables this shift:

  • Create “technical bridge” programs that deliver targeted skill development within specific timeframes (e.g., “SOC readiness in 90 days”).
  • Document success metrics showing how quickly non-traditional hires achieve productivity.
  • Build modular training paths that can rapidly fill specific technical gaps while preserving what makes each hire unique.

When hiring managers know there’s a proven pathway to productivity on your tech stack, they stop passing on great candidates who are missing a few technical bullets.

Building a Potential-First Hiring Framework

Assess Abilities, Not Acronyms

While we shouldn’t ignore credentials entirely, we need better ways to evaluate actual capabilities. L&D can get involved by creating practical assessments to aid in hiring.

Give candidates a packet capture and ask them to identify suspicious activity. Present a security scenario and observe their problem-solving approach. Have them explain a technical concept to a non-technical audience. You’re not looking for perfection; you’re evaluating how they think, learn and communicate.

Currently, only half of organizations use practical assessments or other skill verification in hiring. That’s a massive missed opportunity to identify high-potential candidates who might lack traditional credentials but possess the skills that matter.

Design Role-Specific Development Pathways

Organizations succeeding with potential-based hiring must invest in structured development programs led by L&D. This requires a deliberate approach to evaluating cybersecurity skills. Here’s a simple framework:

  • Skill verification using practical exercises and real-world scenarios to establish baseline capabilities
  • Gap analysis comparing current competencies to role requirements
  • Targeted upskilling that fills those gaps with your organization’s needs

With modern learning platforms and AI-driven tools, you can quickly perform that analysis and create hyper-personalized training paths unique to each learner. For example, a security operations center (SOC) analyst with strong analytical skills but no security experience may need a blended approach of self-paced security fundamentals modules, instructor-led tool training, hands-on labs in sandbox environments and mentored on-the-job application. Someone transitioning from network administration would receive a completely different pathway, skipping networking basics but focusing on security-specific applications of their existing knowledge.

This approach requires L&D to work closely with security teams to validate that training translates to job performance, continuously iterate based on learner feedback and performance data and demonstrate ROI through reduced time-to-productivity metrics.

The L&D Opportunity in Building Cybersecurity Talent

This shift requires L&D leaders to become true strategic partners, not just training providers. The organizations that embrace this approach don’t just fill seats — they build stronger, more innovative security teams while tapping into talent pools others ignore. For L&D leaders, this represents a massive opportunity to demonstrate strategic value by enabling organizational resilience and revolutionizing how organizations build capability.

The cybersecurity industry won’t solve its talent crisis by demanding perfect candidates who don’t exist. We’ll solve it by recognizing potential, investing in development and building pathways for talented people to enter and thrive. The question for L&D leaders isn’t whether to make this shift — it’s whether you’ll lead it or watch your organization fall further behind.