Live · Thu, Sep 10, 2026 · 01:01 UTC Block 843,917 Fees 14 sat/vB Fear & Greed 72 · Greed
Newsletter Pro Terminal Sign in
ITop Field News.
Subscribe →
Live · 01:01 UTC Block 843,917 F&G 72
Cybersecurity Cybersecurity desk

Cyber security skills assessments: how to evaluate your team honestly

Most Australian IT teams have a rough sense of where their cyber security skills are thin, but a rough sense isn't enough. Here is how to run a skills assessment that surfaces real gaps rather than comfortable answers.

Professional setting with hands pointing at a colorful business chart on paper.

Photo by RDNE Stock project on Pexels

Cyber security skills assessments are one of the most underused tools in Australian IT management. Teams invest heavily in training platforms, certifications, and awareness programs, yet most organisations don't know with any precision which controls their people can actually operate under pressure. The gap between what's on a résumé and what happens during an incident is where breaches get worse.

Why most assessments produce flattering results

The problem isn't that organisations skip assessments entirely. It's that most run them in a way that signals the right answer before anyone is tested. A scheduled phishing simulation where staff received a reminder email last week isn't measuring real readiness. A written quiz on the Essential Eight maturity model tells you whether people have read the framework, not whether they can apply it under load.

Three design mistakes produce the flattery:

  • Assessments are announced in advance, giving staff time to prepare specifically for the test format rather than the skill being measured.
  • Questions are drawn from training materials already distributed, so familiarity with the content is being measured rather than transferable skill.
  • Results are tied to performance reviews, which changes what people are willing to disclose.

The last point is particularly corrosive. If admitting a skills gap carries career risk, people don't admit it. You get a skills map that looks stronger than reality, and you don't find out until the wrong moment.

What a credible skills assessment actually covers

A useful assessment maps against the roles on your team, not against a generic framework. A SOC analyst and a cloud infrastructure engineer have overlapping cyber responsibilities in some areas and completely distinct ones in others. A single assessment instrument applied to both produces noise.

For each role, the assessment should cover four distinct layers. First, conceptual knowledge: does the person understand the threat they're being asked to defend against? Second, tool proficiency: can they operate the specific platforms your organisation uses (not generic product categories)? Third, process execution: can they follow your incident response procedure accurately under time pressure? Fourth, judgement: can they escalate appropriately, identify ambiguity, and know when to call for help?

Most off-the-shelf assessments only test the first layer. That's the cheapest layer to fake, and it's the least predictive of actual performance during an incident.

Practical methods that produce honest data

Scenario-based exercises are the most reliable signal for process and judgement. Present your team with a realistic incident scenario, give them access to actual tooling (or a sandboxed replica), and observe. You don't need to simulate a full breach. A contained scenario, like a suspicious authentication event in your SIEM that needs to be triaged and escalated correctly, tells you whether the process exists in practice or only on paper.

This is closely related to how cyber security tabletop exercises surface gaps that written policies miss. The difference is that a skills assessment is narrower: it focuses on individual capability rather than team coordination.

For tool proficiency, give practitioners a constrained task in a test environment and time them. Can a SOC analyst run a specific threat hunt in your EDR platform without looking up the documentation? If not, that's a training need, not a hiring problem. It's worth knowing before an alert fires at 2am.

For conceptual knowledge, open-ended questions outperform multiple choice. Ask someone to explain how a credential stuffing attack works and what controls would reduce its impact on your environment. The answer reveals far more than a tick on a five-option quiz.

Building a skills matrix without demoralising the team

The output of a skills assessment should be a matrix that maps each person's current proficiency against the skills their role requires. Most CISO teams find it useful to rate proficiency on a four-point scale: not yet demonstrated, developing, proficient, and subject matter expert. Avoid five-point scales because assessors cluster around the middle and the data becomes useless.

How you communicate the exercise matters as much as how you design it. Frame it as an investment in the team, not an audit of individuals. Make it explicit that results feed training budgets rather than performance reviews. If your organisation's culture makes that promise hard to keep, fix that problem before running the assessment.

Some Australian organisations bring in external assessors for this work. The advantage is objectivity and a reference point against peer organisations. The disadvantage is cost and the risk that the external benchmark doesn't reflect your specific environment or threat profile. A hybrid approach, internal design with external validation of the method, often produces the most usable output.

Connecting gaps to action

A skills matrix has no value unless it drives a decision. The most common failure is producing a clear picture of capability gaps and then doing nothing specific about them. Gaps get added to a training plan, training plans become annual tick-box exercises, and twelve months later the matrix looks identical.

Effective skills development after an assessment involves three things: targeted training matched to the specific gap (not a general cyber awareness module), a defined timeline with a follow-up assessment date, and visible support from leadership. That last one is harder to programme than a training module, but it's the factor that determines whether the skill actually gets built.

It's also worth distinguishing between gaps that training can close and gaps that indicate a structural resourcing problem. If your team lacks the head count to cover a critical function at all, no amount of upskilling changes that equation. Honest skills assessments sometimes surface the need for a hire or a managed service, and that's a legitimate outcome. Understanding your actual threat intelligence posture and who can act on it is foundational to every other security investment your organisation makes.

Run the assessment. Be honest about what it shows. Then do something specific with the result.

→ The Confirmations · Daily newsletter

One email at 06:00 UTC. Six minutes. The only digest written for desks, not for retail.