Workforce Intelligence

Cybersecurity Skills Assessment: Why Skills Alone Won't Tell You If Your Team Can Execute

A cybersecurity skills assessment tells you what an individual knows. It cannot tell you whether your organization can execute its strategy. Work shifts, contractors come and go, MSPs take on new responsibilities, and AI agents are beginning to perform work that used to belong to people. Here is why capability coverage, capacity, maturity, redundancy, and dependencies have to come before you assess the person.

A professional arranging notes on a wall to lay out the work an organization actually performs

Deidre Diamond · · 8 min read

If you are searching for a cybersecurity skills assessment, you are probably trying to answer an important question:

Does my team have what it needs to execute our cybersecurity strategy?

That is exactly the question you should be asking.

But I don't believe a traditional skills assessment can answer it.

A skills assessment can tell you what an individual knows. It can help identify areas where someone may need training or development. It can be useful for evaluating proficiency in a specific technology or discipline.

But knowing what people know is very different from knowing whether your organization can execute.

And after more than 12 years of working inside cybersecurity organizations and supporting high-volume cyber talent acquisition, I believe that distinction has become critical.

Cybersecurity work changes too quickly. People are rarely doing exactly what they were originally brought in to do. Responsibilities shift constantly. Contractors and consultants come and go. Managed service providers take on new work. Technologies change. Business priorities change. AI is beginning to perform work that previously belonged to people.

Yet we continue to assess our cybersecurity workforce as though roles, responsibilities and work allocation are static.

They aren't.

If the goal is to understand whether your organization has the capability coverage it needs, don't start by assessing the person. Start by understanding the work.

What Does a Cybersecurity Skills Assessment Actually Tell You?

Traditional cybersecurity skills assessments generally focus on the individual.

  • What technologies does this person know?
  • What cybersecurity disciplines are they proficient in?
  • Where are their technical strengths?
  • Where are their skills gaps?
  • What training should they receive?

Those are legitimate questions.

Skills matter.

But there is a much bigger question that has to come first:

What work does the organization actually need to execute, and do we have the capability to execute it?

Those are not the same question.

What Someone Knows Is Not the Same as What They Are Doing

This is one of the biggest lessons I have learned from more than a decade of cybersecurity talent acquisition.

We bring someone into a role.

We give them a title.

We create a job description.

Then reality happens.

Someone brought in as a Cloud Security Engineer starts helping with IAM because there is a need.

Someone in Vulnerability Management becomes heavily involved in Application Security.

A Security Architect gets pulled into an AI initiative.

A manager loses two people and starts personally performing operational work.

A contractor quietly becomes the only person who knows how to execute a critical function.

An MSP begins performing responsibilities leadership still believes are owned internally.

Six months later, the organizational chart may look exactly the same.

The work does not.

And sometimes the work changes much faster than that.

That is why assessing someone's skills without understanding how they are actually being utilized gives leaders an incomplete picture.

Imagine that we assess a Cloud Security Engineer and discover that she has exceptional cloud security skills.

That's useful information.

But what if she is only spending 30% of her time on cloud security because IAM, vulnerability management and a new AI initiative have consumed the rest of her capacity?

Do we have cloud security covered?

Maybe.

Maybe not.

Her skills assessment cannot tell us.

A Highly Skilled Team Can Still Have Major Capability Gaps

This is where I believe the traditional skills-assessment conversation breaks down.

An organization could assess every person on its cybersecurity team and discover that it employs incredibly talented people.

And the organization could still have serious execution risk.

Maybe the people have the required skills but there are not enough hours available to perform the work.

Maybe one person is carrying three critical capabilities.

Maybe a critical function has no redundancy.

Maybe the organization is highly dependent on a contractor whose engagement ends next month.

Maybe an MSP is performing important work without enough internal oversight.

Maybe everyone understands the technology, but the process is immature.

Maybe the process is strong, but the technology is being underutilized.

Maybe the organization believes a capability is fully covered because four people have relevant skills, while none of those four people actually has meaningful capacity allocated to it.

None of those are necessarily skills problems.

And training will not solve them.

A Skills Gap Is Not Always a Training Gap

This distinction matters because one of the most common responses to a perceived cybersecurity skills gap is training.

Identify the gap.

Assess the people.

Build development plans.

Train.

Reassess.

Sometimes that is absolutely the right answer.

But before spending time and money developing people's skills, shouldn't we understand what is actually causing the capability gap?

Suppose Incident Response is struggling.

The assumption might be that the team needs stronger incident-response skills.

But what if the team already has those skills and simply lacks capacity?

What if the process is inconsistent?

What if three people know how to do the work but one person is still handling nearly everything?

What if technology is slowing the team down?

What if the function is dependent on a consultant?

What if people who should be supporting Incident Response have been redirected to other priorities?

You could conduct an excellent skills assessment, invest significantly in training and still have the exact same operational problem later.

Because the problem was never skills.

Start With the Work. Then Assess the Workforce.

I believe we need to reverse the traditional approach.

Instead of beginning with the people and asking what skills they have, begin with the business and ask:

What does this organization need to be capable of doing?

For cybersecurity, those capabilities should be determined by the organization's:

  • Business objectives
  • Risks
  • Regulatory obligations
  • Compliance requirements
  • Technology environment
  • Operating model
  • Strategic priorities

Then determine what is actually required to execute each capability successfully.

  • Who is performing the work?
  • How much capacity is allocated to it?
  • How mature is the process?
  • What technology supports it?
  • How is success measured?
  • Where is the redundancy?
  • Where are the dependencies?
  • Where is the risk?

Only after we understand those things can we intelligently determine whether a people problem exists, and whether that people problem is actually a skills problem.

Start with the work. Then assess the workforce.

Your Workforce Is More Than Your Employees

There is another reason traditional skills assessments are becoming increasingly insufficient.

The cybersecurity workforce is no longer synonymous with cybersecurity employees.

The execution ecosystem now includes:

Full-time employees, contractors, consultants, managed service providers and MSSPs, interns and early-career professionals, and increasingly AI agents.

All of those resources can contribute to the capabilities required to execute cybersecurity strategy, and all of them can create risk within those capabilities.

Consider what happens when a major capability is being executed by an MSP.

Whose employee do you skills-assess?

What happens when a consultant has become the organization's deepest subject-matter expert?

What happens when an AI agent begins performing part of a workflow previously owned by three employees?

What happens when a contractor owns a critical function but isn't included in the organization's talent-management system?

These aren't hypothetical workforce structures anymore.

They are how work gets done.

A workforce assessment that only sees employees, and only sees their skills, can miss a significant portion of the organization's actual capability.

From Skills Intelligence to Workforce Intelligence

This is why I believe cybersecurity leaders need to think beyond skills intelligence.

Skills Intelligence Asks

What does this person know?

Workforce Intelligence Asks

Can the workforce ecosystem execute what the business requires?

To answer the second question, we need visibility into the capabilities the business requires and the workforce actually executing them.

At CyberSN, that means understanding capability:

  • Coverage
  • Capacity
  • Maturity
  • Redundancy
  • Dependencies
  • Workforce risk

And maintaining that visibility as the work changes.

The distinction matters.

If I discover that a capability has a coverage problem, I can determine why.

Perhaps I need to add a role.

Perhaps I need a contractor.

Perhaps I need a consultant.

Perhaps I need to change an MSP engagement.

Perhaps I need to reallocate someone's time.

Perhaps I need to create redundancy.

Perhaps I need better process.

Perhaps I need to optimize technology.

And yes, perhaps I need training.

Training becomes one possible solution instead of the automatic conclusion.

That is a much better workforce decision.

Skills Assessments Are Point-in-Time Data Too

There is another problem with relying heavily on traditional skills assessments: the data ages.

We assess someone's skills today.

Then the work changes.

A new project begins.

The business enters a new market.

A regulation creates new requirements.

A technology is implemented.

Someone leaves the organization.

A team restructures.

AI takes over part of a workflow.

The person's skills may not have changed at all.

But the organization's capability needs did.

This is why I believe point-in-time workforce assessments, whether they measure skills, roles or headcount, are no longer enough.

Cybersecurity leaders need current visibility into what work is being performed and whether the workforce ecosystem has the capacity and maturity to execute it.

The assessment creates a baseline.

The intelligence comes from keeping that baseline true as the organization changes.

The Cybersecurity Workforce Conversation Is Already Changing

The industry is already beginning to move away from the old headcount conversation.

The discussion is increasingly about having the right skills, not simply more people.

That is progress.

But I believe we need to take the conversation one step further.

The answer isn't simply:

Do we have enough people?

And it isn't simply:

Do our people have the right skills?

The question is:

Do we have the capability to execute the work our business requires?

That requires understanding skills, but also capacity, utilization, process, technology, KPIs, redundancy, external dependencies and risk.

That's why I believe capability visibility is the next evolution of the cybersecurity workforce conversation.

Before You Buy a Cybersecurity Skills Assessment, Ask What You Really Need to Know

If your objective is specifically to test someone's technical knowledge, a skills assessment may be exactly what you need.

Use it.

If you want to determine which course someone should take, identify a specific technical development opportunity or validate proficiency in a particular area, skills assessments can provide valuable information.

But if you are searching for a cybersecurity skills assessment because you are really trying to determine whether your team can execute your cybersecurity strategy, I would stop before beginning with individual skills.

Ask a different question first:

What capabilities does my business require, and can my current workforce ecosystem execute them?

Then ask:

  • Where are we covered?
  • Where do we lack capacity?
  • Where are we dependent on one person?
  • Where are we dependent on outside resources?
  • Where is the work actually happening?
  • Where is maturity insufficient?
  • Where does the operating model need to change?

And once those answers are visible:

Where do we truly have a skills gap?

Now a skills assessment has context.

Now training has a purpose.

Now hiring has a business case.

Now workforce decisions are based on operating reality instead of titles, job descriptions and assumptions.

Don't Assess the Person Until You Understand the Work

For years, cybersecurity organizations have tried to solve workforce problems by looking harder at people.

More recruiting.

More certifications.

More training.

More skills assessments.

Those tools all have value.

But after more than 12 years of watching how cybersecurity organizations actually operate, I believe we have been starting too far downstream.

Before we assess the person, we need to understand the work.

What does the business require?

What capabilities deliver it?

Who and what are actually executing those capabilities today?

Do they have enough capacity?

How mature are people, process, technology and KPIs?

Where are the dependencies and risks?

And if something changes tomorrow, will leadership see it?

That is the visibility cybersecurity leaders need.

A traditional cybersecurity skills assessment can tell you what someone knows. Workforce Intelligence tells you whether your organization can execute.

Start with the capabilities.

Understand the work.

See the workforce as it actually operates.

Then determine where skills assessment, training, hiring or other workforce decisions are truly needed.

Start with the work. Then assess the workforce.


About CyberSN Workforce Intelligence

CyberSN's Workforce Intelligence Engagement gives cybersecurity and IT leaders a living view of capability coverage, capacity, maturity, redundancy, and dependencies across employees, contractors, consultants, MSPs, and AI agents. That is what separates Workforce Intelligence from a point-in-time assessment: it stays true as the work changes.

The result is workforce decisions grounded in operating reality, training that has a defined purpose, and budget requests leadership can defend.

Your Cyber & IT Workforce Risk Partner

Start with the work, then assess the workforce

CyberSN's Workforce Intelligence Engagement gives cybersecurity and IT leaders visibility into capability coverage, capacity, maturity, redundancy, and dependencies across employees, contractors, consultants, and MSPs, so workforce decisions are based on operating reality rather than titles and job descriptions.

Request a Workforce Intelligence Briefing
© 2026 CyberSN · All rights reservedworkforce intelligence · est. 2014