Security News

National CyberPath Initiative Seeks to Redefine How Cyber Skills Are Measured

Key Takeaway When hiring or assessing cyber staff, small businesses should look beyond certificates and consider real-world experience, references and demonstrated performance under pressure.

The CyberPath pilot, led by the Australian Computer Society with the Australian Information Security Association and the Australian Cyber Collaboration Centre, has released a draft Capability Framework Discussion Paper for public feedback. The proposal argues that qualifications and certifications remain useful evidence of ability but should not be treated as proof of proficiency on their own. Instead, capability could be shown through workplace performance, simulations, incident records, vulnerability disclosures, code commits, governance documentation and independently validated work.

The framework also aims to clarify which cyber tasks can reasonably be handled by AI tools and where human accountability must remain, as AI-enabled attacks add pressure to cyber teams. It builds on CyberPath's earlier Occupations Framework, which standardised how cyber roles are described.

The consultation comes amid workforce shortages, with ACS estimating Australia's cyber workforce at around 137,500 people and a need for 54,000 more by 2030. ACS chief executive Dr Prins Ralston said certificates and job titles are not proof someone can protect critical systems during an incident, noting that judgement, experience and performance under pressure matter more.

cyber workforce CyberPath skills framework Australia cybersecurity policy
Answering for this at board level? Our cyber governance framework ->

Summarised by CISO AI from Australian Cyber Security Magazine. We link back to every original so you can read it yourself.