Key Takeaways

  • Work experience that produces proof. This is the thinking behind the work experience packages Securus runs for school and early-career students. Each one is built around a real task with a real outcome, not a tour or a talk.
  • There is a line that circulates among people trying to land their first job in cyber security. You need experience to get a job, and you need a job to get experience. It gets a laugh because it is true, and it describes a trap the field has built for itself.
  • The experience gap is usually described as a supply problem, as though the people are simply not out there.
  • A large part of it is a gate problem. Entry is filtered on certificates, and a certificate is treated as the gate rather than the floor.

By Jake Dew – Securus Consulting Group

There is a line that circulates among people trying to land their first job in cyber security. You need experience to get a job, and you need a job to get experience. It gets a laugh because it is true, and it describes a trap the field has built for itself.

Australia says, repeatedly, that it does not have enough cyber security people. At the same time, the usual way into the field asks new entrants to prove experience they have had no way to get. Those two positions cannot both be served by the same hiring habit, and the habit is winning.

How the gap gets manufactured

The experience gap is usually described as a supply problem, as though the people are simply not out there. A large part of it is a gate problem. Entry is filtered on certificates, and a certificate is treated as the gate rather than the floor.

A certificate shows that someone sat a course and passed. That is worth something. It does not show what they do when a system falls over in a way the course never mentioned, which is most of the actual job. So, employers ask for experience instead. But the only place to get that experience is a job, and the job asks for the experience first. The loop closes, and the people best placed to open it, the ones already hiring, are the ones holding it shut.

It stays shut because it is the safe choice. Filtering on a certificate is quick and easy to defend. Backing someone who can show what they have built is slower and feels riskier, even when it is the better bet. The cost lands on the people least able to carry it, and on a workforce that keeps coming up short.

The effect compounds. Capable people who cannot get the first role move to adjacent fields that will take them, and the experience they would have built is lost to cyber security altogether. The gate does more than delay entry. It quietly removes people from the pipeline the country says it needs.

What actually builds capability

The thing a certificate cannot supply is what happens after something breaks. Take the Essential Eight. A person can read the ASD guidance cover to cover and hold the whole model in their head, patching, application control, multi-factor, backups. Standing a system up, hardening it, and watching it hold or fall over when pushed is a different skill entirely. The reading is necessary. It is nowhere near enough.

Good training builds this in by teaching people to attack as well as defend, because a system nobody has tried to break is a system nobody really understands. That lesson does not survive being told. It has to be done, got wrong, and understood in hindsight. The moment something breaks and the cause is not yet obvious is not a gap in the learning. It is the learning.

The same holds across the field. An incident responder learns triage by working real alerts, not by memorising a playbook. A tester learns where systems bend by bending them. In every case the knowledge that separates a competent practitioner from a certified one is the knowledge of what goes wrong, and that is only available on the far side of having watched it go wrong.

Work experience that produces proof

This is the thinking behind the work experience packages Securus runs for school and early-career students. Each one is built around a real task with a real outcome, not a tour or a talk. Students crack a historical cipher, build an interactive piece of electronics that only works when two of them integrate their halves, or defend and attack a system in a supervised lab. The work is genuine, the environment is contained and getting it wrong is part of the design rather than a failure of it.

The point of each package is the same. A student finishes with something they can show: a working build, a solved problem, a write-up in their own words. That is experience produced before anyone is paying for it, in a setting where a mistake teaches instead of costs. It is the rung most people never get handed, put there on purpose.

The fair objection

There is an honest counter, and it is a good one. A serious assurance firm cannot run on people who simply enjoy breaking things. Clearances, standards, and client trust demand rigour, and rigour is what structured certification exists to prove. A junior cannot be turned loose on a live client system with the wreckage called a learning experience. Not every employer can stand up a lab or carry the risk of teaching on the job.

All of that is true, and none of it is an argument against hands-on learning. The question is what sits alongside the certificate. A certificate is a floor to build on, not a wall to hide behind. A lab works precisely because it is supervised and safe to fail, with the mess contained by design. Hands-on and rigour are not opposites. The rigour is in building an environment where getting it wrong teaches something and costs nothing.

What to do about it

If the gap is built rather than inevitable, it can be unbuilt. Build environments where people can fail safely, because that is where the capability a certificate cannot give is actually formed. Hire for what someone can demonstrate, then test it, rather than filtering on paperwork and hoping the ability sits behind it. Treat certificates as the starting line that they are.

None of this needs a budget. The gate is expensive to keep shut and cheap to open. A few virtual machines on a laptop is enough for anyone to start.

At scale, the same principle looks like graduated exposure. Apprenticeship-style pathways, supervised placements, and training that pairs coursework with real work put people on live problems with a mentor and a safety net, rather than behind a gap they were never given a way to close. The lab is the small version of this. Structured on-the-job pathways are the large one, and they are what a workforce short of people should be building.