To beat a hacker, you have to think like a hacker: Fast. Adept. Pervasive. IT-savvy. Cybersecurity skills are difficult but imperative to develop in order to meet the ever-changing ways hackers challenge, penetrate and crack network systems – methods that IT professionals need to anticipate and defeat if they want to do their jobs right.

The cost of these infiltrations is staggering and increasing; global estimates are between $375 billion and $575 billion each year. The reach of cybercrime is far and wide, and its intent is ominous, ranging from stealing secrets about military operations to influencing foreign election outcomes. Only recently, security researchers confirmed that Russian operatives hacked the email account of John Podesta, chair of Hilary Clinton’s U.S. presidential campaign, leaking private campaign correspondence leading up to the 2016 election.

The bottom line for IT professionals is to keep the system safe from harm. It’s a tall order to maintain security when you consider the size and speed of change in the field and the overwhelming enthusiasm and commitment of those who seek to harm it. Security and protection seem counterintuitive to a system that was built to be open and accessible.

So how do training professionals prepare IT staff for the demands of system protection? Cybersecurity is a growing field and not suited to everyone, but if you can commit your IT professionals to an ongoing learning process, they will be prepared to meet the demands of your network’s security.

Education is key. Be sure your IT professionals have appropriate training. There are several certifications that might be useful for your team. For example, Certified Penetration Testing (CPT) and Certified Expert Penetration Testing (CEPT) are certifications in two “big-picture” areas that can help IT professionals learn about potential attacks on networks as well as software and computer systems. These certifications are often offered bootcamp-style as focused training sessions over a short period of time, and they often include real-life simulations to ensure that your IT professionals can hit the ground running when they return from training.

Specialize your team. Today’s technology is complex. No single person can fully understand all the aspects and issues of such a large and fluid system, so it’s a good idea for different employees to master one or a few specific cybersecurity skill areas. You can build on these specializations as your organization gains experience. For example, is your business using wireless technology? Train your IT professionals in a wireless system, such as GIAC or GIAC GAWN, to learn how to think through and evaluate weaknesses that affect it. Sometimes you can piggyback specialties by encouraging employees to gain expertise in areas that complement each other, resulting in better protection for the enterprise.

Get experienced help, and get your help experience. Being a cybersecurity expert requires both education and extensive experience. Look for opportunities that help employees develop good analytical and policy skills in addition to technical knowledge. They need to be able to think about policies that support your network security and do not hinder your capacity to do business.

Think system-wide. Today, infiltrators are improving in the quality as well as the quantity of their attacks, and attacks on network systems are the biggest threat to security (about 80 percent of risk). Your IT people must be able to think broadly about network issues, a skill that only comes with education, focused training and experience.

There are still surprisingly few international protocols or policies to guide cybersecurity professionals, so it’s important that they develop a sixth sense for the problems they may encounter and work to create organizational policies and practical tactics to meet them. Make sure that cybersecurity employees are plugged in to government departments, roundtables and discussion groups that develop policies that may affect your bottom line.

The capacity of your network to provide secure yet flexible services is a balancing act of policy and legislation, applied technologies, and know-how. Preparing cybersecurity professionals to understand network complexities that include theory, policy and application means ensuring they are excellent critical thinkers; aware of legislative and legal issues; and supported by plenty of training to anticipate, detect and resolve challenges in the “wild, wild west” of network security.