Real-World Training for Real-World Threats:...
Go beyond basic training. Cyber ranges give developers hands-on practice in realistic scenarios to build secure code and prevent real-world threats.
Move beyond one-size-fits-all security training with a data-informed strategy built around roles, skill levels, and real-world responsibilities.
Skills gap data becomes useful when an organization connects missing capabilities to job responsibilities, technology exposure, business risk, and measurable learning outcomes. A strong training strategy segments learners by role, assigns focused learning content, reinforces knowledge through hands-on practice, and uses performance data to improve learning paths over time.
Cybersecurity skills gap data is evidence of the difference between the security capabilities a workforce currently has and those it needs to perform its roles effectively. The data may come from internal assessments, learning management system analytics, hands-on labs, cyber range performance, manager observations, vulnerability trends, audit findings, or external workforce research. CMD+CTRL’s Skills Assessment combines knowledge exams with hands-on skills verification to help organizations identify gaps and assign more targeted learning.
The goal is not to collect more training data. The goal is to identify where a lack of knowledge or practice creates risk, then use that evidence to design a more relevant learning experience.
Modern software delivery involves Agile development, DevOps, CI/CD pipelines, APIs, containers, cloud-native architectures, open-source dependencies, infrastructure as code, and automation. Security responsibilities, therefore, extend beyond software developers to cloud architects, site reliability engineers, release managers, product owners, quality teams, and security specialists.
Our guide to moving beyond one-size-fits-all software security training provides a practical framework for aligning modular training with roles throughout the software development lifecycle.
Static, linear training often gives every learner the same generalized material. That approach can build baseline awareness, but it does not account for the systems a person touches, the decisions they make, or the vulnerabilities they are expected to prevent, identify, or remediate.
One-size-fits-all training treats exposure as uniform. Role-based training recognizes that a cloud architect, release manager, product owner, and application security engineer encounter different security decisions during the software development lifecycle.
|
Training model |
How learners are assigned |
Likely result |
|
One-size-fits-all |
The same sequence for broad groups, regardless of role or technology exposure |
Consistent awareness, but uneven relevance and limited evidence of job-specific capability |
|
Role-based |
Content mapped to responsibilities, systems, risks, and current proficiency |
More relevant learning paths and clearer measurement against role expectations |
|
Adaptive and data-informed |
Paths adjusted using assessment, practice, and performance data |
Training can respond as capabilities improve or requirements change |
A role-based approach helps organizations build security capability across every role in the software development lifecycle without wasting learner time on material that does not apply to the job.
The process begins with segmentation and continues through measurement. Each step should connect learning activity to a defined role requirement or security outcome.
Collect evidence from assessments, interviews, learner analytics, hands-on exercises, vulnerability data, audit findings, and manager feedback. Separate knowledge gaps from performance gaps. A learner may recognize a vulnerability in a quiz but still struggle to find or fix it in a realistic application.
Group learners according to the work they perform and the systems they influence. Useful segmentation criteria include job role, seniority, programming language, framework, cloud platform, application type, access level, and exposure to specific security risks. The CMD+CTRL Course Catalog organizes courses, labs, and learning journeys by role, technology, NICE Workforce Framework category, subject matter, and skill level.
|
Role |
Relevant security focus |
Example learning activity |
|
Cloud architect |
Secure architecture, identity and access, configuration, segmentation, and cloud risk |
Review a cloud design and identify insecure trust boundaries or configuration choices |
|
Release manager |
API exposure, dependency risk, build integrity, and release controls |
Evaluate a release workflow for insecure dependencies or missing security gates |
|
Software developer |
Secure coding, vulnerability prevention, and remediation in the languages used at work |
Exploit and fix a vulnerability in a realistic application |
|
Product owner |
Security requirements, risk prioritization, and acceptance criteria |
Translate a security risk into a requirement and measurable acceptance criteria |
|
Application security practitioner |
Testing, threat modeling, vulnerability validation, and developer enablement |
Investigate a realistic application and communicate actionable remediation guidance |
Convert broad findings such as “weak API security” into observable learning objectives. For example, a developer may need to identify broken object-level authorization, explain its business impact, and implement an appropriate authorization check. Clear objectives make it easier to select content and measure improvement.
Use focused modules that can be combined according to role and technology stack. A shared foundation can establish common terminology, while role-specific courses and labs address the decisions each learner makes. This modular structure avoids forcing every person through a long, linear curriculum.
CMD+CTRL Base Camp supports this type of progressive learning through courses, assessments, hands-on labs, and cyber range experiences. Organizations can use these components to build learning paths for different roles, skill levels, and application security use cases.
Short learning modules can introduce or refresh a concept. Hands-on labs and cyber ranges then require learners to apply that concept in a realistic environment. This progression helps teams evaluate whether learners can recognize, exploit, and remediate vulnerabilities rather than only recall definitions.
Knowledge checks show what a learner can recall. Hands-on exercises show how the learner applies that knowledge when facing a realistic security problem.
Review both the learning activity and the evidence of applied capability. Use the results to adjust content, provide additional practice, or advance learners to more complex material. Repeat the process as technologies, responsibilities, and risk priorities change.
Course completion is useful for tracking participation, but it does not prove that a learner can perform a security task. A balanced measurement plan combines leading indicators from the learning environment with operational indicators from software delivery and security programs.
CMD+CTRL’s Application Security at Scale study analyzes results from more than 1,100 cyber range events and shows how performance data can reveal skill gaps, learning patterns, and opportunities to improve AppSec training programs.
|
Measurement category |
Examples |
What it indicates |
|
Participation |
Enrollment, completion, time spent, and return frequency |
Whether learners are engaging with the assigned path |
|
Knowledge |
Pre-training and post-training assessments |
Whether learners understand the concepts being taught |
|
Applied skill |
Lab completion, accuracy, hints used, time to solve, and cyber range performance |
Whether learners can apply knowledge in a realistic task |
|
Workplace behavior |
Quality of remediation, secure design decisions, and adoption of defined practices |
Whether learning is influencing role-specific work |
|
Program outcomes |
Repeat vulnerability trends, remediation time, escape rates, and relevant audit findings |
Whether workforce capability is associated with changes in security and delivery outcomes |
A modular curriculum allows organizations to change one part of a learning path without rebuilding the entire program. Teams can add a course for a new technology, assign extra practice for a recurring vulnerability, or adjust difficulty based on assessment and lab results.
This approach also supports continuous improvement. Skills data should be reviewed throughout the year rather than treated as an annual audit exercise. Regular review helps training keep pace with changes in the software development lifecycle, technology stack, workforce, and threat environment.
One global enterprise technology company used modular training tailored to more than 10 roles to support over 10,000 learners while maintaining relevance across technical and nontechnical job functions.
Skills gap data should function as a blueprint for workforce development. When organizations connect data to roles, technologies, learning objectives, and hands-on practice, training becomes more relevant and easier to measure.
The strongest strategy is iterative. Assess current capability, assign targeted learning, evaluate applied performance, and refine the path as requirements change. This turns training from a static catalog of courses into an ongoing system for building cybersecurity capability at scale.
Go beyond basic training. Cyber ranges give developers hands-on practice in realistic scenarios to build secure code and prevent real-world threats.
Ensure security at every stage of the SDLC with role-based training to prevent vulnerabilities, reduce costs, and build a security-first development...
Ensure security at every stage of the SDLC with role-based training to prevent vulnerabilities, reduce costs, and build a security-first development...
Join our mailing list to get notified first when we post new blogs on cybersecurity training, insights related to secure coding, and updates to our training content — straight to your inbox.