Cybersecurity changes too quickly for static skills to stay relevant. New threats, tools, and operating models create constant demand for updated knowledge, so teams should build learning into hiring, onboarding, and promotion plans. Workforce planning works best when organisations fund training, support certifications, and create time for hands-on practice rather than treating skills development as optional.
Why This Matters for Security Teams
Continuous learning is not a soft benefit for cybersecurity teams. It is a core workforce control because attackers, platforms, and operational patterns change faster than static job descriptions. Teams that only train for yesterday’s toolset often miss the shift from perimeter defence to identity-centric abuse, including secrets misuse, OAuth sprawl, and autonomous tool chaining. That is especially visible in NHI-heavy environments, where Ultimate Guide to NHIs — Why NHI Security Matters Now shows how quickly identity risk compounds when credentials, privileges, and visibility all drift at once. For threat awareness, current advisories from CISA cyber threat advisories are useful because they reflect the pace at which real-world tactics evolve, not just formal policy. The workforce-planning issue is that skills gaps rarely appear as a single outage. They surface first as slow detection, inconsistent control tuning, weak incident decisions, and overreliance on a few specialists who already understand the newest attack paths. NHIMG research also shows why this matters operationally: in The State of Non-Human Identity Security, only 1.5 out of 10 organisations were highly confident in securing NHIs, which is a strong signal that knowledge lag is itself a control gap. In practice, many security teams encounter the cost of stale skills only after an incident reveals that the team had not been trained for the way the environment actually changed.How It Works in Practice
Effective workforce planning treats learning as part of operating cadence, not an annual event. The practical model is to map the skills needed for the next 6 to 18 months, then tie training to the controls and technologies the organisation already relies on. That means analysts, engineers, and architects do not just learn new tools. They learn how to investigate identity abuse, validate policy changes, review secrets hygiene, and respond to AI-assisted activity. A workable program usually combines:- role-based skill maps that update with the threat model
- hands-on labs and tabletop exercises for current attack patterns
- certifications or vendor-neutral courses where a formal baseline helps
- time allocated for practice, not only training budgets
- cross-training so knowledge does not sit with one team or one person
Common Variations and Edge Cases
Tighter training requirements often increase time and budget pressure, requiring organisations to balance depth against staffing constraints. Not every role needs the same technical depth, and best practice is evolving on how to segment learning for SOC analysts, cloud engineers, IAM teams, and risk leaders. The current guidance suggests prioritising the skills that map directly to the organisation’s highest-risk assets rather than trying to teach everything to everyone. There are also edge cases where general cyber training is not enough. Teams supporting NHI-heavy platforms need focused instruction on secrets management, workload identity, CI/CD exposure, and delegated access. Teams handling AI-enabled operations need a sharper understanding of agent behaviour, prompt injection, tool misuse, and the limits of static policy models. Where automation is pervasive, training should include failure analysis, not just success paths, because the problem is often not whether a control exists but whether staff know when it silently stopped working. The strongest programs use learning metrics as workforce metrics: time to competence, incident quality, control review accuracy, and the percentage of critical roles with a trained backup. NHIMG’s broader research on identity risk shows why this matters in practice, because the gap is not simply knowledge but execution under pressure. Organisations that treat upskilling as optional usually discover the deficiency during an incident, not during planning.Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10, CSA MAESTRO and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC-03 | Workforce capability must match changing cyber risks and business context. |
| NIST AI RMF | GOVERN | AI-era workforce planning needs governance, accountability, and ongoing competency. |
| OWASP Non-Human Identity Top 10 | NHI-01 | Teams need upskilling to recognise and reduce NHI exposure patterns. |
| CSA MAESTRO | G.4 | Agentic systems require cross-functional learning across security and operations. |
| OWASP Agentic AI Top 10 | A2 | Agentic AI risk changes fast, making continuous upskilling essential. |
Assign owners for cyber learning plans and track whether staff can operate new AI and identity controls safely.
Related resources from NHI Mgmt Group
- What breaks when identity teams do not maintain continuous visibility into machine and AI identities?
- How should security teams prioritise NHI remediation in cloud environments?
- How should security teams govern non-human identities at scale?
- How should security teams govern non-human identities for compliance?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org