Purpose

The cybersecurity industry continues to grow and evolve as a consequence of technological advancements. It is, then, imperative for cybersecurity teams to adapt to the dynamic threat landscape. This study aims to examine the future potential for technology-driven adaptations within cyber defence teams. In particular, the authors focus on the changing skill requirements over the next 5–10 years.

Design/methodology/approach

To answer their research questions, they conducted semi-structured interviews with a diverse group of cybersecurity professionals.

Findings

From their analysis they found that future cyber defence teams will have an increased scope of responsibilities and as a consequence, require a wider set of skills to effectively combat cyber threats. Future cyber defence teams will become more intimate with emerging technologies for two reasons. Firstly, to overcome challenges posed by emerging attack vectors. Secondly, to comply with the growing volume of strict legislation and regulations. As such, future cyber defence teams will have an increased emphasis on soft skills – like critical thinking, communication and a commitment to continuous learning.

Originality/value

The goal of their research is to provide insights to guide the continued development of cyber defence teams; to plan talent acquisition, internal development and future cyber education. Their study makes a valuable contribution to a relatively novel space in cybersecurity research, to better position cyber defence teams for future challenges.

In 2022, ISC2 published their Cybersecurity Workforce Study ISC2 (2022), drawing attention to the risks and challenges of emerging technology and their impact on the cybersecurity industry. Among others, the study highlights an ongoing technological transformation in the cybersecurity industry, in conjunction with accompanying organisational changes, and the potential to directly influence the make-up and role of cyber defence teams.

The impact that emerging technologies, in particular around automation, are having on cybersecurity is a matter of fact, as highlighted by numerous articles in this space (Mandt, 2017) (Munoko et al., 2020). Among others, Large-Language Models present the greatest potential to be immediate disruptors in cybersecurity, from both an attacker’s and a defender’s perspective (Motlagh et al., 2024). Frameworks to facilitate cyber defence efforts, such as the MITRE ATT&CK framework, come under question as innovative tools and technology are used, and the threat landscape evolves. As a result, it becomes imperative for organisations to re-examine set-up and composition of their cyber defence teams, to “keep up” with the speed of change and adversarial tactics. Unfortunately, this is no easy task and there is widespread acknowledgment that, generally speaking, cyber-criminals have an edge over defenders (Libicki et al., 2015; National Cyber Security Centre UK, 2024). At a minimum, recruitment and learning strategies are necessary to ensure adequate cyber defence capability that can take on malicious actors.

The present study aims to provide an analysis of the skill composition of current cyber defence teams, and what these teams will look in time, as impacted by technological transformations characterising the current “digital age”. Cyber defence teams are often the first responders to new threats and can be considered the “first line of defence” of an organisation (Valkenburg and Bongiovanni, 2024). Identifiable with the Security Operations Centre (SOC) of an organisation, in either an in-house or outsourced format, a cyber defence team traditionally employs professionals with deep technical knowledge, a penchant for situational awareness and analytical skills (Onwubiko and Ouazzane, 2019). Our study reveals how such teams can evolve in five to ten years, based on emerging and predicted threats and technological trends in cybersecurity. Our analysis hopes to support organisations to plan and resource cyber defence teams appropriately.

In an effort to best approach an understanding of the future of cyber defence teams, we must first begin with an analysis of the current cybersecurity industry. Globally, there are several guiding frameworks that offer best practices and guidelines on the configuration and composition of cyber defence teams.

In 2024, for example, the “Competency in Cybersecurity Education” handbook (Nestler and Fowler, 2024) provided a comprehensive framework for defining and implementing competency-based education in cybersecurity. This approach ensures that students are equipped with the necessary skills to perform specific tasks within the context of their future work roles. Competency is defined as the ability to complete a task effectively, which is crucial for preparing students to handle real-world cybersecurity challenges. The handbook introduces the ABCDE framework, which stands for Actor, Behaviour, Context, Degree and Employability. In the context of cybersecurity, the Actor refers to roles such as security analysts or penetration testers, who require specific knowledge and skills. Behaviour encompasses tasks like threat analysis, incident response and forensic investigations, directly mapping onto roles defined by frameworks such as the NICE Cybersecurity Workforce Framework. Context involves the environments in which these tasks are performed, including corporate networks and cloud infrastructures, along with the tools and resources available. Degree specifies the level of accuracy and thoroughness required, such as the speed and precision of incident resolution or the detail in forensic reports. Employability highlights the importance of professional skills like teamwork, communication and ethics, which are essential for collaborating with IT teams and communicating findings to non-technical stakeholders. Experiential learning is also emphasized as a critical component of cybersecurity education.

In our analysis, however, we decided to focus on the following three frameworks, due to their global prominence and due to the country of the present study, Australia. The National Institute of Standards and Technology (NIST, 2025) has produced the 2017 Workforce Framework for Cybersecurity (NICE Framework) (Peterson et al, 2020). In the European Union, the Agency for Cybersecurity (ENISA) has elaborated in 2022 the Cybersecurity Skills Framework (ECSF) [1]. Finally, in Australia, the Australian Signals Directorate’s (ASD) has created in 2018 their Cyber Skills Framework (CSF). These overarching frameworks function as a means to define roles and enable robust cybersecurity processes. At the foundation of most frameworks are knowledge and skills, which, regardless of the adopted framework, continue to be the essential foundation for any cyber defence team.

The NICE framework revolves around the concepts of Task, Knowledge and Skills (TKS), embedded in progressive iterations. The framework divides cybersecurity functions into seven categories of work: securely provision; operate and maintain; oversee and govern; protect and defend; analyse; collect and operate; and investigate. TKS has become the foundation of NICE and guides the development of the framework. Within the NICE framework, Tasks describes the work or activity done by personnel in an organisation. In this, Knowledge is the set of retrievable concepts that describes expertise; and Skill is the capability and capacity to use tools and resources to complete a task. The application of the NICE framework, then, describes and groups Tasks insofar as the Knowledge and Skills required to carry the task out as a Work Role. The NICE framework is flexible and allows for a fit-for-purpose, context-driven creation of a Work Role. The characteristics of a Work Role then ought to guide the recruitment process, and development of roles. Specifically, the framework provides 52 Work Role templates and describes the TKSs associated. As a prescriptive framework, NICE proposes either a “top down” or a “bottom up” approach to the construction of teams. In either case, similar roles are consolidated by virtue of the necessary knowledge and skills.

The ECSF from ENISA, published in 2022, recognises 12 role profiles in cybersecurity. Each profile has a detailed description that outlines the essential skills, key deliverables and necessary knowledge. The profiles are indicated in Table 1.

Table 1.

Cyber defence roles in ECSF

No.Role profile
1Chief information security officer (CISO)
2Cyber incident responder
3Cyber legal, policy and compliance officer
4Cyber threat intelligence specialist
5Cybersecurity architect
6Cybersecurity auditor
7Cybersecurity educator
8Cybersecurity implementor
9Cybersecurity researcher
10Cybersecurity risk manager
11Digital forensics investigator
12Penetration tester
Source(s): Authors’ own creation

Although described in detailed fashion, each role profile acts as a template, intended to be context-driven and adaptable.

Finally in our list, the ASD CSF aims to assess, maintain and monitor ASD’s workforce. The CSF is adapted from the Skills Framework for the Information Age 7 (SFIA 7) (The SFIA Foundation, 2018), and the Chartered Institute for Information Security (CIISec) Framework v.2.4 (CIISec, 2025). As such, the CSF defines the workforce by virtue of roles, capabilities and skill proficiencies. In this, Capability and Skills describe the personnel, with Role to define a specific position. The CSF recognises the following nine roles with distinct capability profiles (Table 2).

Table 2.

Asd csf roles

No.Role
1Cyber threat analyst
2Intrusion analyst
3Malware analyst
4Incident response
5Operations coordinator
6Cyber security advice and assessment
7Vulnerability researcher
8Penetration tester
9Vulnerability assessor
Source(s): Authors’ own creation

In an attempt to describe the levels of skills and knowledge possible in each role, the CSF also recognises the following six proficiency levels, from lower expertise to higher expertise: learner; novice; practitioner; senior practitioner; principal practitioner; expert practitioner. Each proficiency level functions as a way to measure performance, output and ability within a role.

The three frameworks present similarities, but also undeniable differences. This, from the outside, entails challenges in homogenising workforce requirements. It is to the strength of the NICE framework to build a foundation on TKS, as opposed to organisational structure. A TKS foundation enables a more flexible and modular approach, allowing for a more meaningful and context-driven fit. In contrast, the foundation for the CSF is an internal benchmark and it only maps and measures ability relative to position. ECSF is founded in knowledge and skills as a property of a role. That is, what skills and knowledge are appropriate given a specific role. The distinct properties, abilities and functions as characteristics of the workforce, provided by each framework, thus enable a diverse view of the cybersecurity landscape.

To best understand the current state of the cybersecurity workforce, we ought to identify a suitable framework for the conduct of our study. ASD’s CSF is not appropriate as it was intended for internal benchmark exercises and therefore lacks the necessary detail. Moreover, the CSF focuses entirely on an internal cyber defence operation and lacks roles such as Architect and Auditor. While this paper focuses on cyber defence, the lack of consideration of these roles indicates that this framework has not represented how a cyber defence team would fit into and integrate with the wider cybersecurity workforce. The NICE and ECSF framework both have a common foundation and approach to characterise a role with tasks, knowledge and skills. However, it is important to be clear that NICE and ECSF are distinct insofar as the creation of a work role and profile. The NICE framework constructs a role through the necessary tasks, whereas ECSF begins with a role and prescribes the necessary knowledge and skills. Moreover, NICE creates categories of roles relative to the necessary tasks. In contrast, ECSF describes a role independent of tasks or any relation to a wider defence team. For this reason, NICE appears more appropriate for the study of cyber defence teams, and development of tasks relative to roles, in line with the present investigation.

To be clear in our analysis, the NICE framework defines the roles within Protect and Defend as the cyber defence team. Hereafter, in the present study a Cyber Defence team will refer directly to this definition and be understood as the capacity to work on cyber threats on internal networks and systems. To create a meaningful view of future cyber defence teams, we ought to understand how current cyber defence teams operate. There are four specific areas and four roles outlined by the NICE framework, shown in Table 3.

Table 3.

Detailed view of Nice’s definition of cyber defence work roles (Petersen et al., 2020)

NICE specialty areaWork roleWork role description
Cybersecurity defence analysis (CDA)Cyber defence analystUses data collected from a variety of cyber defence tools (e.g. IDS alerts, firewalls, network traffic logs) to analyse events that occur within their environments for the purposes of mitigating threats
Cybersecurity defence infrastructure support (INF)Cyber defence infrastructure support specialistTests, implements, deploys, maintains, and administers the infrastructure hardware and software
Incident response (CIR)Cyber defence incident responderInvestigates, analyses, and responds to cyber incidents within the network environment or enclave
Vulnerability assessment and management (VAM)Vulnerability assessment analystPerforms assessments of systems and networks within the network environment or enclave and identifies where those systems/networks deviate from acceptable configurations, enclave policy, or local policy. Measures effectiveness of defence-in-depth architecture against known vulnerabilities
Source(s): Authors’ own creation

Although the NICE framework provides a detailed view of current cyber defence teams, it is not entirely inclusive, which is expected due to the complicated nature of the cybersecurity industry. SOCs in different industries have different security requirements and legislative obligations, leading to divergent roles and responsibilities within the SOC team. The roles listed in the NICE framework, Defensive Cybersecurity, Digital Forensics, Incident Response, Infrastructure Support, Insider Threat Analysis, Threat Analysis and Vulnerability Analysis are not explicit. However, the list of responsibilities of a cyber defence team is detailed and diverse. In short, some of these are:

  • Policy analysis.

  • Compliance with regulation evaluation.

  • Support authorised penetration testing on enterprise assets.

  • Identify threats from log analysis.

  • Maintenance of audit tools.

  • Relevance of policies and regulations.

  • Incident handling.

  • Forensic analysis.

  • Collection of attack artifacts.

  • Analysis of traffic.

  • Attack signatures construction.

  • Coordination with law enforcement.

  • Monitor threat conditions.

  • Recommendations to leadership.

  • Address disaster recovery and continuity planning.

  • Assess and management of risk and vulnerabilities.

  • Recommendations of security controls.

The rapid growth of the cybersecurity industry is indicative of its dynamic nature. Future cyber defence teams will seemingly need to change structure and grow with the industry. To establish a baseline of the current capability of cyber defence teams, we will analyse the NICE framework and supporting literature.

There are 278 Knowledges and 171 Skills for the seven defence roles in the Protect and Defend section of the framework. For the most part, the skills are technical-focused and involve a particular focus on malware, vulnerabilities, networks, intrusion detection, penetration testing, virtual private networks and operating systems.

The importance of translational skills between a technical setting and an organisational setting cannot be understated. It is critical for the success of an organisation to effectively communicate cybersecurity risks and concerns, and to protect assets. In turn, the use of non-technical skills in conjunction to technical skills enables greater resilience within the NICE framework.

Literature on required technical skills to operate in cyber defence teams is relatively scarce. Švábenský et al., 2021 have analysed Capture The Flag (CTF) [2] competition reports to identify the necessary skills to solve CTF problems. In this, the authors found that the nine most common and important skills are cryptography; reverse engineering; secure programming; penetration testing; malware forensics; web security; network security; authentication; and incident response.

In their work, Dawson and Thomson (2018) underline that there is an overemphasis on technical skills in the cybersecurity industry. The technical proficiency of a person has been directly related to the worthiness of a person. This emphasises a need to understand the personhood and how we are situated, to enable best organisational fit.

Buchler et al. (2018) investigated the effect of intra-team and leadership interaction in cyber defence competitions. The authors have suggested that teamwork can lead to improved performance of some tasks that require shared technical expertise. Tasks that require high concentration may not benefit from teamwork and could be to the detriment of the team. Further, directive leadership can also improve the coordination and effectiveness of team centred work. Hall and Rao (2020) identified that non-technical skills are the most important in the recruitment of cybersecurity graduates. Again, teamwork and leadership also have significant importance, as well as communication skills, adaptability and relationship management. The relevance of communication as the number one soft skill, in particular as the articulate expression of ideas with clients, users, leadership and throughout teams, was also underlined in Jones et al. (2018).

To start hypothesizing what skills will be fundamental in cyber defence teams of the future, we ought to relate the skills to the defensive activities of a cyber defence team. To do so, we will now focus on emerging challenges for cyber defence teams, as illustrated in the literature.

Performance fatigue and stress are a significant challenge for the cybersecurity industry (Dykstra and Paul, 2018). Purpose of this study was to measure fatigue, frustration and cognitive workload of teams, to understand how these impact incident response times. Although it is unclear what the cause of fatigue and stress in cybersecurity is, it is clear that as cyber breaches and incidents continue to grow, so will fatigue and stress. The continued occurrence of high-profile breaches is set to increase workloads and raise attention at the corporate level, and add more pressure onto cyber defence teams.

Another challenge discussed in the literature is the continuous need to meet expectations from management, industry standards and government legislation. In this sense, Onwubiko and Ouazzane (2019) underline the following main issues that cyber defence specialists need to face regularly: lack of quality tools, low maturity with respect to novel technology, lack of skilled labour and lack of standardisation across industry. The authors argue that most SOCs rely on a generalised “all purpose” security monitoring tool, with sub-optimal levels of performance. Moreover, they do not have a structured process to adopt novel technologies and integrate them into everyday operations. As a result, cyber defence teams mainly rely on vendors to recommend them what would work best. In general, also the global shortage of cybersecurity professionals has caused capacity issues in numerous SOCs. In addition, industry standards and government legislation represent further challenges to address. The wide range of challenges experienced by cyber defence team creates an opening for potential trends to make their impact in the future, which we review next.

There is a noticeable tension in the views of cybersecurity trends, between academic and industry literature. Research gravitates around machine learning (ML), artificial intelligence (AI) and Quantum Computing, as the emerging trends (Kaur and Ramkumar, 2022). In slight contrast, industry experts identify AI, automation and outsourcing services as the most compelling trends (Groombridge, 2022). It is also reported that these trends are driven by talent shortages and an increasing demand for cybersecurity services overall. Industry has also moved towards cloud platforms and zero-trust networks; tools and resources to fulfil strict regulatory requirements (Boehm et al., 2022).

Table 4 synthesises emerging trends from scholarly and industry literature, with associated references.

Table 4.

Cyber defence trends discussed in scholarly and industry literature

AcademiaIndustry
Machine learning and artificial intelligence (Gillespie et al., 2021)Artificial intelligence (Groombridge, 2022 and Boehm et al., 2023)
Industrial IoT (Radanliev et al., 2020)Cloud platforms (Groombridge, 2023, Aiyer et al., 2022, Boehm et al., 2023)
State-sponsored cyber attacks (Pandy et al., 2022)Sustainability (Groombridge, 2023)
Ransomware (Pandy et al., 2022)Zero-trust networks (KPMG, 2022a)
Cyber insurance (Pandy et al., 2022)Automated detection and response (KPMG, 2022a and Aiyer et al., 2022)
Quantum computing (Kuar and Ramkumar, 2022)Remote working (Boehm et al., 2023)
Regulatory requirements (Boehm et al., 2023)
Outsourcing services (Aiyer et al., 2022 and Crozier, 2022)
Source(s): Authors’ own creation

Our literature review demonstrated that our understanding of the future of cyber defence teams is still emerging, or incomplete. Future research in this area looks to improve cybersecurity capabilities in a pragmatic and holistic way. As a consequence, we adopted an exploratory approach in our work (Van Puyvelde, 2018), considering this research domain is in a nascent stage (Edmondson and McManus, 2007).

As exploratory, our research was informed by a qualitative approach. We conducted seven in-depth, semi-structured interviews with industry leaders. Questions were informed by our substantial literature review (see  Appendix). We then analysed the contents in an effort to untangle the participant’s viewpoints and gain a meaningful understanding of their position. Our sample was composed by selected industry leaders, equipped with the necessary experience and well-versed in cyber defence. Their expertise and role as key informants in our investigation allowed us to overcome the limitations of our relatively small sample size. The interviewees’ experience spanned across industry, from private sector to higher education, with the aim to gain a wide view of the cybersecurity landscape. A code name was assigned to each interviewee during the data coding process to provide anonymity. Table 5 describes our sample.

Table 5.

Sample

CodeInterviewee background
AManagement at a security software company with a background in both offensive security and defensive security
BBusiness consultant specialising in governance, risk and compliance
CHead of emerging technology and security in a consulting company
DLeader of a cyber defence team
ELeader of an incident response team
FAcademic researcher with focus on blockchain and cloud computing
GSoftware developer in a security services company
Source(s): Authors’ own creation

We obtained ethical approval from the university to conduct our study prior to data collection. Data was de-identified during the transcription process by assigning code names and recordings were deleted after transcription. The semi-structured interviews were carried out online as a way to accommodate all interviewees and consider location and workload. The interview questions were distributed beforehand to enable more valuable insights. We asked open-ended questions and encouraged the participants to follow any tangents or deviations from the original question. This enabled us to explore three main aspects for analysis, as guided by our literature review: first, current challenges faced by cyber defence teams; second, the role of technology; and third, the impact of new technology and how regulatory changes and a dynamic threat environment impact the adoption of new technology.

We used the definition of a cyber defence team as detailed in the Protect and Defend category of the NICE framework. The majority of our respondents highlighted that this picture of a cyber defence team lacks key roles, such as forensics analysts [3], threat intelligence analysts [4], security architects [5], threat detection engineers [6] and cyber instructors [7]. The above roles are indeed included in the NICE framework, but with other categories than Protect and Defend (respectively, Investigate, Analyse, Securely Provision, and Oversee and Govern).

Our respondents also highlighted the emergence of new team structures in and around cyber defence teams, with notable examples including purple teams and Cyber Fusion Centres (CFC). Purple teams (as a mix of traditional blue and red teams) are a combination of defensive and offensive capabilities. The rationale for their creation resides in the positive “contamination” of knowledge and ideas that they foster between defenders and attackers:

Increasingly, I'm seeing purple teams. So you have that mixture of the defense and the offense. And I think that’s a good model because the red team has to be attacking the right and the relevant technology. And the blue team needs to be rapidly adapting to how the attacks change. (A).

CFCs are an organisational structure that combines (the traditionally separated) SOC, incident response team and engineering team. The goal of this fusion is to enhance communication and mitigate threats in a more effective way:

We used to be a cybersecurity operation centre, CSOC, but we are transitioning to a cyber fusion centre, which is more inclusive of all the other teams, like corporate securities, identity access management, and those kinds of things. (D).

Our respondents remarked that neither purple teams, nor CFCs are accounted for in the NICE framework, which they acknowledged is a limitation.

Based on our interviews, we could identify four emerging challenges for cyber defence teams to face. The mostly reported one (5 interviewees) was the increasing number of attack vectors, followed by the challenges presented by automated-threat detection (3), data privacy issues (3) and shortened incident reporting timeframes (2).

Attack vectors.

Our respondents emphasised that the rise of new attack vectors and vulnerabilities brings a number of implications. One participant (B) claimed that the scope and capability of the defence team has necessarily increased because of trends like Internet Protocol Version 6 (IPv6), Internet of Things (IoT) and Bring Your Own Device (BYOD) practices. Another participant (D) claimed that they have dealt with file-less malware created by AI from adversaries; often being difficult to detect. Participant G explained criminals have automated attacks to create a large volume of phishing domains with ease:

[…] the attackers now for these phishing campaigns, you know. It’s all they’ve automated it. The attacks are automated. These attackers can spin up hundreds, thousands of domains with minimal effort all automated and we’re still kind of manually going through (G).

As a consequence, cyber defence teams have needed to change their approach. In this, participant D discussed how organisations have moved to attack surface management from vulnerability management. The aim here is to map the attack surface with the growth of infrastructure. As infrastructure (e.g. cloud) is adopted, the corresponding attack surface can be managed accordingly. Attack surface management allows better asset management and categorisation of vulnerability, our respondents argued; and enables a more transparent and manageable cybersecurity effort. While vulnerability management is still practiced within cybersecurity, it seems that the broader concept of attack surface management will become more popular:

It is moving from vulnerability management to attack surface management. Now attack surface management is considered a new term for the security organizations. […] Being able to monitor them [attack surfaces], patch them, and also see what the threat landscape for them is, who is probably interested to attack them, those kinds of things. I would say that this is something that is missing in some of the defense teams or organizations (D).

Challenges of automated threat detection.

Collected data demonstrated that, generally, a high number of false positives comes from the use of underdeveloped technology and the use of tools that are not fit for the organisation. One participant (D) claimed that User Entity and Behaviour Analytics (UEBA) solutions are still developing. They are based on ML algorithms to power analytics and produce value to the organisation. In the respondent’s opinion, UEBA solutions are often not fine-tuned to the organisation and are not accurate enough to be reliable. More in general, the participant argued, while tools like AI and automation can help alleviate problems around response time and provide accurate analysis, their use has led to a high rate of false positives. Using the example of automating USB notifications, Participant E explained how the unreliability of AI and automation tools may not be conducive for success. The volume of notifications from potential malicious activity can in fact become unmanageable:

Automation helps definitely do some things and not others. So for example, we are attempting to automate USB notifications. So when someone plugs a USB and it’s got a malicious infection on it, we are automatically notifying them. We struggle a lot with automations because if they plug in, plug out, plug in, plug out, plug in, suddenly they’re getting all these emails, right? And so what we find is that we come up with these great ideas for automation, but the actual implementation of them takes months and months and months of hard work. And sometimes all of that hard work is not worth it if it only takes you 30, 40 seconds to actually investigate it (E).

In the same vein, Participant D expressed concerns over automated solutions like Security Orchestration Automation Response (SOAR). They seem promising but are difficult to implement to fit a precise set of needs. Participant G, an automation developer, explained that their company would review work for several weeks before they trusted something generated from a script, despite the improved resolution time (from minutes or hours, to seconds). Other participants (B and C) expressed their hesitancy in using emergent technologies. Participant C also held the view that cultural aspects impact companies’ willingness to invest in new technologies, a perspective shared by five participants in the sample:

Other new technologies, it generally takes people a while to get around to it depending upon how progressive that organisation is. So in Australia we tend to be relatively good adopters of technology but we’re never the first to develop or adopt (C).

Our data demonstrated that this reserved attitude shows the need for continuous work carried out by cyber defence teams. Cyber defence teams need to continue to combat the pressing issues of false positives.

Data Privacy issues.

Respondents’ reflections on data privacy can be categorised in technological and human. Within the technological lens, with increased adoption of cloud hosting, data privacy is a concern cloud service users face because of the multi-tenant characteristics of the cloud and the complexities associated with monitoring the data life cycle. On this topic, Participant F offered confidential computing as a solution. Confidential computing protects data while in use such that information can be encrypted in memory during computation. However, the participant also expressed that this solution is still in development. In addition, he mentioned how confidential computing would likely be brought to attention from the bottom-up, where consumers (e.g. small and medium businesses) are required to satisfy increasingly stringent audit requirements, incentivising technology vendors to imbue the solution into their products. Within the human lens, interviewees noted that an increased number of legislations are in place to raise awareness of data privacy among non-technical personnel. Participant C commented that companies begin launching discussions on governance and strategy to improve their cyber resilience because of the continuously increased demands on data privacy. Participant A mentioned a similar observation, that recent changes in data privacy legislation make board members more aware of cybersecurity:

Most Australians have been impacted in some way by either Optus or Medibank or Latitude or one or more of these breaches. I mean, we’re all kind of feeling that, oh, actually, my data is now out there. So that has obviously prompted the changes in legislation, but it’s also made everyone more aware of it. So I think probably shareholders are asking more questions of the companies, the board are more aware, and there’s nothing like facing, losing your house or freedom to make you more aware. So that those changes have been good (A).

Data privacy becoming a rising topic of discussion places more attention and pressure on cyber defence teams. The nature of the discussions is shifting as non-technical staff such as board members are getting involved, switching from simply considering technical implementations of data privacy to also having to explain in layman’s terms to communicate with senior management. Defence teams also have to keep up to date with constantly changing privacy requirements, leading to new security controls and new technologies:

And so the probably, the biggest change I'm seeing in a regulatory environment is around privacy and privacy information and data. So we’ve seen almost nations and regions just continuously increasing the demands upon privacy, information and privacy, private data (C).

Shorter Timeframes for incident reporting.

Generally speaking, our respondents argued, cyber defence teams have to meet shorter incident reporting timeframes as a consequence of new and updated regulations. While there are many legislative pieces and governing bodies, our interviewees in particular mentioned: the Security of Critical Infrastructure Act (SOCI Act) of Australia, the General Data Protection Regulation (GDPR) of the EU, the US Securities and Exchange Commission, the North American Electric Reliability Corporation (NERC) and the Information Technology Act (IT Act) of India. All of these regulatory regimes call for the reporting of a cyber incident within a specific timeframe, generally ranging from six hours to seventy-two hours of notice, based on the severity and type of incident. Although necessary, these reporting requirements have placed a large burden on organisations attempting to adapt to varying levels of regulations across countries.

As leaders of their cyber defence teams, participants D and E held the view that varying timeframes have caused cyber defence processes to evolve. This includes updating Service Level Agreements with managed security service providers; updating incident response playbooks; hiring new staff; and creating streamlined communication processes with legal or PR teams.

In synthesis, the collected data showed that there are multiple factors affecting the work of a cyber defence team. Challenges that the team faces drive adjustments, such as strengthening vulnerability management with attack surface management, adopting technologies to reduce false positive rates, and adjusting internal processes (e.g. reporting) in response to changing regulations. These changes contribute to the expansion and evolution of the duties of the defence team, as demonstrated by the establishment of new team structures such as purple teams and CFCs. With this expanded scope, cyber defence teams also need to learn new knowledge and skills, which is the topic of the next section.

To look ahead at the future of cyber defence teams, the participants were asked about the necessary skills to come. Five of them directly mentioned the importance of the so-called “soft skills”.

Critical thinking, problem-solving and analytical skills emerged as top amongst them. Participant B said that whilst technical skills can help with the collection of data, critical thinking and problem-solving can help with analysing the data and creating the information used to form a coherent story. Participants A and G both argued that critical thinking can help an individual challenge themselves and achieve better results. Such reflections, the collected data revealed, mirrored the technological evolution that cyber defence teams are experiencing.

As described in the previous subsection, defence teams tend to be suspicious of new technologies, but are willing to adopt them when they are proven reliable. A critical mindset is needed to question the technology in its effectiveness and how it can be fitted within the existing processes. In addition, automation and AI are designed to become integrated into the data compilation and analytic process, making the human decision, which is more capable of critically analysing human and organisational context, more valuable and significant:

So I think that those soft skills like critical thinking, understanding why you’re doing a certain thing, why an automation might need to be in place or how you could implement an automation where there isn’t currently one and people haven’t kind of thought at a deeper level. I think that those soft skills will become more and they already are in demand (G).

As Participant A mentioned, “asking why, not just how and what” is difficult because with how fast technology is changing, workers in the field gravitate towards learning the facts about the technology instead of questioning why things are done in a specific way.

Curiosity was another skill mentioned by three of the participants. The terms used were “continuous learning” and “willingness to learn”. Participant C quoted from another person, “I need someone who is capable of un-learning and re-learning”. He described that with technological changes, the skillset required in the next few years will change. Some long-lived information may even be proven wrong. As a consequence, cyber defence teams should be open to understanding that certain knowledge will be replaced with newer knowledge and be willing to gain relevant expertise. The skill of curiosity links back to the observations in the previous subsection. As the scope of work of a defence team expands, the team will take up more tasks and will become multi-talented, for example in managing and operating solutions powered by ML and AI and developing and maintaining automation.

Communication skills were mentioned by two participants as needed to “future-proof” cyber defence teams. Our data revealed that business communication is considered important to convey information to the wider non-technical teams in layman’s terms. This is increasingly important as defence teams have to work with a more diverse group of personnel for incident response and reporting (e.g. board members, lawyers, media team, auditors).

Other soft skills listed by participants included strategic skills, emotional intelligence, teamwork, creativity and situational awareness. Participant A described situational awareness as being able to “look at one piece of the puzzle and imagine how big the puzzle is and where you are in the puzzle”.

When asked about necessary technical skills for cyber defence teams, our interviewees emphasised their fundamental importance. The majority of respondents argued that ability to operate new tools is a fundamental skill for cyber defence teams. Amongst them, a minority even mentioned ability to code as an important skill. The latter is likely associated with smaller cyber defence and, overall, cybersecurity teams, requiring analysts to be able to find coded workarounds, for example, to facilitate automation.

As previously discussed, cyber defence teams are set to work with an increasing number of solutions and changing technologies. Participant D mentioned as an example the prominence of cloud computing, and the dominance of the cloud infrastructure. In this, the participant argued, knowledge of varying solutions holds value to cyber defence and broadens the team’s capability.

In addition, according to participant D the use of automation as a way to improve efficiency can also be a point of failure in the defensive workflow. In cases like this, it is then necessary for the defence team to understand how to manually operate all defensive processes, independent of technology. The technical skills here enable a more mature cybersecurity posture, and stronger defensive teams:

One technical skill explicitly mentioned was the ability to write secure code and scripts, contribute to development operations, and maintain automation scripts. Participant A said “Security is a subset of reliability”, that is to say that programs ought to operate as designed, if reliable, with consistent and secure code such that is not exploited. Although this seems like a tall order and more aligned to software development, there is a need for defensive teams to develop internal software. One example was the development of customised ML to automate defensive tasks and reduce the workload burden. In conjunction, the ability to develop scripts was described by participants D and G as the maintenance and optimisation of automation tools. Secure code development and script maintenance look to become a necessary quality in defensive cyber teams.

And then yes, I guess in terms of a lot of that skillset, I think, would transition to more of maintaining these automation tools, refining and optimizing them as opposed to just, you know, manually handling the data and having, you know, a lot of data entry. It would be more about, yeah, optimizing automation. As simple as basic scripting and stuff, but also, you know, more technical things. So I think a higher level of technical aptitude. Probably in future. But that and that would enable you to handle a lot more at scale, I think, for a lot more (G).

Importantly, participants also reiterated the role of situational awareness in parallel with technical ability. Participant E, for example, held the view that “if a playbook is well-defined and has very few forks in the decision-making process, that be automated.” However, the participant continued, this is not the case for complex problems like data leakage; technology cannot create a meaningful solution for a specific scenario in a specific organisation. It is up to the cybersecurity professionals to use situational awareness in conjunction with technical skills to overcome these sorts of problems. Further, although ML and AI will lead the automation process and investigation, the final decision will still be made by a human. As summarised by participant C “we will still need a human in the loop as an oversight role.” This role, for example, will require critical thinking and problem-solving in addition to technical understanding. The future of cyber defensive teams necessarily calls for a multi-skilled workforce with technical foundation and openness to learn.

As it is a common concern that AI could “eliminate jobs”, in our interviews we also set to probe whether the participants thought certain skills would be diminishing in future cyber defence teams.

Our interviews revealed that there will not be any diminishing skills due to AI or automation, but there will be the likely creation of better opportunities for beginners to get into the cybersecurity industry. Participant D expressed that cyber defence teams will still need to understand how a task is performed without the technology, such that there will not be a point of failure dependent on the availability and trustworthiness of technology. Participant F said that workers will have to coexist with AI to improve productivity. Participant G argued that automation will create more entry-level positions because it lowers the bar of skills required in those roles. In summary, participants in our study generally thought that technology will not “steal” jobs from cyber-professionals.

A slightly opposing view was held by participant E (an incident response leader) who noted that some skills will indeed become less important in the future. He mentioned the example of forensic skills: forensic tasks will be more and more performed through automation (e.g. by antivirus and EDR tools) and associated tasks such as penetration testing through outsourcing. As a result, in this participant’s view, forensic skills will be in lesser demand for cyber defence teams:

[on the question of what skills will be diminishing] Forensic skills. So the cybersecurity tooling is getting so much better now that we’re not doing a lot of the manual forensic skills that are involved. Those sort of jobs still exist at like the antivirus and the EDR firms. But I see, you know, you may have had those skills in each incident response team. Now we don’t need those skills in the incident response team because the tooling does a lot of that automatically for us (E).

Our study highlighted the importance and emergence of new cyber defence teams and cyber defence team structures. The composition of cyber defence teams was seen as particularly compelling because of its impact on communication and threat mitigation. The interviewees emphasised the notability of purple teams and Cyber Fusion Centres, as offering enhanced communication and effective threat mitigation (see Figure 1). As argued in similar research (Kneip, 2021), teams ought to approach threats proactively and reactively. This approach requires a diverse team built on effective communication and dissemination of knowledge. Our research has offered novel contributions to cybersecurity practitioners and hiring managers/recruitment agencies in defining the skills and competencies necessary for the cyber workforce of the future. In slight contrast with the recommendations contained in frameworks like NICE, our investigation stressed that the growing threat landscape calls for innovation and creativity, as opposed to a rigid set of technical skills and team structure.

Figure 1.
Diagram illustrating the structure of the Security Operations Centre, detailing its subdivisions into Purple Team and Cyber Fusion Centre.The diagram presents the structure of the Security Operations Centre (S O C), centrally placed, connecting to two subdivisions: the Purple Team and the Cyber Fusion Centre (C F C). Arrows link the SOC to these branches, highlighting the division of responsibilities. Below the diagram, a note states that S O C teams are required to take on more responsibilities, diverging into Purple Teams and C F Cs. This visual representation helps convey the hierarchical relationship among these components.

SOC teams are required to take on more responsibilities, diverging into Purple Teams and CFCs

Source: Authors’ own creation

Figure 1.
Diagram illustrating the structure of the Security Operations Centre, detailing its subdivisions into Purple Team and Cyber Fusion Centre.The diagram presents the structure of the Security Operations Centre (S O C), centrally placed, connecting to two subdivisions: the Purple Team and the Cyber Fusion Centre (C F C). Arrows link the SOC to these branches, highlighting the division of responsibilities. Below the diagram, a note states that S O C teams are required to take on more responsibilities, diverging into Purple Teams and C F Cs. This visual representation helps convey the hierarchical relationship among these components.

SOC teams are required to take on more responsibilities, diverging into Purple Teams and CFCs

Source: Authors’ own creation

Close Figure 1.

While this paper does not propose a new integrated framework, our findings suggest meaningful ways in which existing models such as NICE and ECSF could evolve. Firstly, our interviews revealed that several roles central to cyber defence operations, such as threat detection engineers, cyber instructors and security architects (within defence contexts), are either underrepresented or misclassified within current frameworks. These or similar roles are present in NICE, but are placed outside the “Protect and Defend” category, despite their operational relevance. We also observed that new team structures, like Purple Teams and Cyber Fusion Centres, are becoming more common. These setups combine offensive, defensive and strategic functions. However, they are not reflected in existing frameworks, which limits their relevance for today’s cybersecurity landscape. In addition, soft skills like critical thinking, curiosity and communication are no longer just “nice to have”, they are becoming essential. As automation and AI become more embedded in cyber defence work, professionals need to be able to manage and fine-tune these technologies, write secure scripts and critically evaluate automated outputs. Frameworks should evolve to reflect these realities. Together, these extensions would help existing frameworks remain responsive to the evolving threat landscape and the dynamic nature of cyber defence work.

From our investigation, it is unclear what a perfect cyber defence team composition looks like, but the problems that cyber defence teams typically face are shared. Our interviews highlighted the need for future cyber defence teams to closely monitor four problematic areas: an increased number of attack vectors, automated threat detection and high false positive rates, data privacy and short incident report timeframes. The increase in volume of attack vectors has widened the scope and capability of cyber defence teams and led to a change in how defensive cybersecurity is approached (Pandey et al., 2022). One common strategy adopted in practice has been to map the attack surface with the growth of an infrastructure. This approach corroborates the view of our interviewees insofar as the changing dynamic and composition of cyber defence teams. Threat detection as a primary concern is centred on the high number of false positive alerts from underdeveloped technology and tools that are not fit for purpose. From our data, it is clear that these tools, like automation, have undeniable utility, but are still underdeveloped insofar as functionality (Onwubiko and Ouazzane, 2019). On another note, data privacy as an ongoing problem has two parts, a technology aspect and a human aspect. Simply put, the technological challenge is the increasing adoption of tools, like cloud hosting, and the complexities that are entailed with monitoring the data life cycle. On the other hand, the human aspect is associated with the increased number of competing legislations concerned with data privacy (Chen and Zhao, 2012). Finally, our data also indicated that reporting timeframes are an area of concern for cyber defence teams. In short, our respondents held the view that new and updated regulations continually shorten incident reporting times. While strict reporting times are necessary, it is becoming an increasing burden to adapt and satisfy legislation across regions (Toulas, 2022).

From a theoretical standpoint, our research demonstrated that critical thinking is more and more a necessary skill for emerging cyber defence teams. In both a practical and theoretical sense, critical thinking can guide the use of automated tools in threat detection and reporting to ease the burden in cyber defence teams. In existing literature, the more closely associated skill has been indicated as “systematic thinking”. In describing systematic thinking, (Dawson and Thomson, 2018) argue that, with the complexity of physical layers, systems and networks, the mental agility needed to grasp one piece of information and understand the whole of the network is a skill needed in cyber defence teams. Arguably, systematic thinking is the method for an individual to come to conclusions methodically when given related information, and is different from critical thinking, which requires an individual to raise questions objectively and be analytical. While valuable, systematic thinking does not enable flexibility and innovation in the same way critical thinking does. This finding aligns with publication from the National Center of Academic Excellence – Cybersecurity (NCAE-C) (Nestler and Fowler, 2024): competency in a cybersecurity workplace requires professional skills, such as critical thinking and problem-solving skills. It is clear from our interviews that both industry practitioners and academia have found an increasing demand to critically think rather than systematically think.

In the 2022 Cyber Workforce Study by (ISC)2 (ISC2, 2022), strong problem-solving is listed as the second most important qualifying factor when cyber-professionals are seeking employment. Problem-solving skills refer to the ability to find solutions and is used in conjunction with critical thinking. In a practical sense, problem-solving as a property of emerging cyber teams can enable a more meaningful solution, as opposed to an ad hoc, process-based solution; to better meet the challenges represented by novel attack vectors, threat detection, data privacy and reporting timeframes.

Similar to critical thinking, curiosity was not a common skill discussed throughout the literature. However, our data indicated that curiosity ought to be a highly desirable skill in emerging cyber defence teams. Once more, existing literature emphasises technical skills and offers minimal mention of curiosity, a notable exception being the Cybersecurity Workforce Study from ISC2 (2021). With the support of our findings, we can expect curiosity to become more important for cyber defence teams in the future as organisations adopt novel technologies. Insofar as cyber defence teams, an understanding of the reasons behind potential solutions, is invaluable to problem-solving in cyber-defensive process.

Our study underlines the importance that critical thinking, problem-solving and curiosity have for cyber defence teams. It is then a logical consequence that the “glue” that keeps them all together, communication skills, acquire a fundamental role too. Effective communication, our respondents argued, is the way ideas, thoughts and solutions are successfully articulated in the world. Given the increasing (internal and external) interconnectedness of cyber defence teams, effective communication is paramount.

The data collected also indicated a set of “migrating” skills in cyber defence teams. With the need to reduce operational costs, more and more organisations outsource cyber defence functions. This translates into the migration of specific skills (e.g. technological expertise; understanding of best practices; etc.) to solution and service providers (e.g. MSPs). It should also be noted that different teams, based on their organisation’s governance, policy and regulatory requirements, may have a different frequency of use of certain skill sets, leading to a decision to outsource those processes, solidifying the diminishment of the skill in an organizational context. Once more, the phenomenon of “migrating cyber-skills” is not a result of technological change, but rather a consequence of the need to reduce operational costs.

In this study we have investigated some of the trends that will likely impact cyber defence teams. In this, we discussed the changes in how work is done, and the skills required to carry out the work. It is important to illustrate the limitations of our study. The first limitation is associated with the generalisability of our findings. Although our sample included participants from differing cybersecurity roles and backgrounds, their overall number was limited. A larger number of participants would enable a more balanced set of findings and results. A large group can lead to a more diverse set of responses and perspectives, and as a consequence provide further depth to our study. Further research should be carried out and continue to investigate trends and needs in the cybersecurity industry. For example, by increasing the sample size and adopting research methods to enhance generalisability (e.g. quantitative methods) across different countries and contexts, a novel skills and competencies framework that takes into account the impact of future technologies could be elaborated. We invite other researchers to join us in this future research project.

A second limitation is the potential for sampling bias (Patton, 1999). It is because of the intentional sample that we selected, and people who were able to participate were selected. Further, there was also the potential for bias in the recruitment process, with a preference for participants based on experience and expertise. In future studies, this can be overcome through a broader and more diverse group of cybersecurity professionals.

Further research should also be conducted on the wider cybersecurity teams. This study is limited to only cyber defence teams and is only reflective of a small portion of the entire cybersecurity capability. The cybersecurity industry is likely impacted by the trends, changes and needs discussed in this study, which however offers a partial view, focused on cyber defence teams. The cybersecurity industry as a whole can benefit from pragmatic and practical understanding of cybersecurity trends.

Our study represents one of the first attempts in the scholarly literature to hypothesise how, in the face of technological change and shifting human dynamics (e.g. adaptation to technology, modifying organisational processes, etc.), cyber defence teams will need to be composed in the near future. Our investigation focused on required emerging skills and whether existing capability frameworks (in particular, the NICE framework) are “future-proof”: do they offer valuable recommendations on how cyber defence teams should be composed and operated moving forward? The judgement is suspended. Capability frameworks offer a solid starting point for organisations to setup and expand their cyber defence teams. On the other hand, novel working structures (e.g. cyber fusion centres and purple teams) are showing promise. However, emerging challenges such as increasing number of attack vectors, automated-threat detection and increase in the number of false positives, data privacy issues and shortened incident reporting timeframes are likely to require more flexibility in definition, composition and operation of cyber defence teams. In this sense, skills such as critical thinking, problem-solving and curiosity will play the lion’s share in the portfolio of desirable skills for future cyber-defenders.

[2.]

In short, to play and win CTF players must breach networks and compromise passwords to “capture” the flag.

[3.]

Forensic analysts analyse evidence collected from an incident to identify the attacker and provide intelligence to the cyber defence analysts to enable the prevention and mitigation of further exploitations.

[4.]

Threat intelligence analysts assess the activities of cyber criminals within the sector and analyse the geopolitics and organisational politics to identify the threats that an organisation faces.

[5.]

Security architects oversee that during the system and software development lifecycle, security requirements are built into the end product to support the cybersecurity of the networks and systems of the organisation.

[6.]

Threat detection engineers create the content for and maintain the detection capability of the Security Information and Event Management (SIEM) solutions to support the users of the solution.

[7.]

Cyber instructors uplift awareness and spread knowledge about cybersecurity culture among the organisations.

Aiyer
,
B.
,
Caso
,
J.
,
Russell
,
P.
and
Sorel
,
M.
(
2022
), “
New survey reveals $2 trillion market opportunity for cybersecurity technology and service providers
”,
McKinsey and Company
,
27 October
,
available at:
Link to New survey reveals $2 trillion market opportunity for cybersecurity technology and service providersLink to the cited article.
Boehm
,
J.
,
Lewis
,
C.
,
Li
,
K.
,
Wallance
,
D.
and
Dias
,
D.
(
2022
), “
Cybersecurity trends: looking over the horizon’, McKinsey and company
”,
10 March
,
available at:
Link to Cybersecurity trends: looking over the horizon’, McKinsey and companyLink to the cited article.
Buchler
,
N.
,
Rajivan
,
P.
,
Marusich
,
L.R.
,
Lightner
,
L.
and
Gonzalez
,
C.
(
2018
), “
Sociometrics and observational assessment of teaming and leadership in a cyber security defense competition
”,
Computers and Security
, Vol.
73
, pp.
114
-
136
, doi: .
Chen
,
D.
, and
Zhao
,
H.
(
2012
), “
'Data security and privacy protection issues in cloud computing
”, in
2012 International Conference on Computer Science and Electronics Engineering, IEEE
, pp.
647
-
651
.
CIISec
(
2025
), “
Skills framework
”,
available at:
Link to Skills frameworkLink to the cited article.
Crozier
,
R.
(
2022
), “
ATO, AFP and DFAT outsourced IT deals screened on security grounds
”, in CRN,
available at:
Link to ATO, AFP and DFAT outsourced IT deals screened on security groundsLink to the cited article.
Dawson
,
J.
and
Thomson
,
R.
(
2018
), “
The future cybersecurity workforce: going beyond technical skills for successful cyber performance
”,
Frontiers in Psychology
, Vol.
9
, doi: .
Dykstra
,
J.
, and
Paul
,
C.L.
(
2018
), “Cyber operations stress survey (COSS): studying fatigue, frustration, and cognitive workload in cybersecurity operations”, in
11th USENIX Workshop on Cyber Security Experimentation and Test
, (
CSET 18
).
Edmondson
,
A.
, and
McManus
,
S.
(
2007
), '
Methodological Fit in Management Field Research’
,
Academy of Management Review
,
32
, pp.
1155
-
1179
, doi: .
Gillespie
,
N.
,
Lockey
,
S.
, and
Curtis
,
C.
(
2021
),
'Trust in Artificial Intelligence: A Five Country Study’
,
The University of Queensland and KPMG Australia
. doi: .
Groombridge
,
D.
(
2022
), “
Gartner top 10 strategic technology trends for 2023
”,
available at:
Link to Gartner top 10 strategic technology trends for 2023Link to the cited article.
Hall
,
J.L.
and
Rao
,
A.
(
2020
), “
Non-technical skills needed by cyber security graduates
”, in,
2020 IEEE Global Engineering Education Conference (EDUCON), IEEE
, pp.
354
-
358
, doi: .
ISC2
(
2021
), “
Cybersecurity workforce study, 2021
”,
(ISC)2
,
available at:
Link to Cybersecurity workforce study, 2021Link to a PDF of the cited article.
ISC2
(
2022
), “
(ISC)2 cybersecurity workforce study, 2022
”,
available at:
Link to (ISC)2 cybersecurity workforce study, 2022Link to the cited article.
Jones
,
K.S.
,
Namin
,
A.S.
and
Armstrong
,
M.E.
(
2018
), “
The core cyber-defense knowledge, skills, and abilities that cybersecurity students should learn in school: results from interviews with cybersecurity professionals
”,
ACM Transactions on Computing Education (TOCE)
, Vol.
18
No.
3
, pp.
1
-
12
, doi: .
Kaur
,
J.
and
Ramkumar
,
K.
(
2022
), “
The recent trends in cyber security: a review
”,
Journal of King Saud University - Computer and Information Sciences
, Vol.
34
No.
8
, pp.
5766
-
5781
.
Kneip
,
F.
(
2021
), “
Why cybersecurity requires a fusion center approach
”,
Forbes
,
available at:
Link to Why cybersecurity requires a fusion center approachLink to the cited article.
KPMG
(
2022
), “
KPMG’s Australia cyber security insights 2022
”,
available at:
Link to KPMG’s Australia cyber security insights 2022Link to the cited article. (
accessed
13 May 2023).
KPMG
(
2022
), “
Cyber security considerations 2022
”,
available at:
Link to Cyber security considerations 2022Link to a PDF of the cited article.
Libicki
,
M.C.
,
Ablon
,
L.
, and
Webb
,
T.
(
2015
),
'The Defender’s Dilemma: Charting a Course toward Cybersecurity’
,
RAND Corporation
,
Santa Monica, CA
, doi: ,
available at:
Link to the cited article.Link to a PDF of the cited article.
Mandt
,
E.J.
(
2017
), “
Integrating cyber-intelligence analysis and active cyber-defence opera-tions
”,
Journal of Information Warfare
, Vol.
16
No.
1
, pp.
31
-
48
.
Motlagh
,
F.N.
,
Hajizadeh
,
M.
,
Majd
,
M.
,
Najafi
,
P.
,
Cheng
,
F.
and
Meinel
,
C.
(
2024
), “
Large language models in cybersecurity: state-of-the-art
”,
available at:
Link to Large language models in cybersecurity: state-of-the-artLink to the cited article.
Munoko
,
I.
,
Brown-Liburd
,
H.L.
and
Vasarhelyi
,
M.
(
2020
), “
The ethical implications of using artificial intelligence in auditing
”,
Journal of Business Ethics
, Vol.
167
No.
2
, pp.
209
-
234
, available at: Link to The ethical implications of using artificial intelligence in auditingLink to the cited article.
National Cyber Security Centre UK
(
2024
), “
The near-term impact of AI on the cyber threat
”,
available at:
Link to The near-term impact of AI on the cyber threatLink to the cited article.
Nestler
,
V.
and
Fowler
,
Z.
(
2024
), “
Competency in cybersecurity education: a handbook for educators at NCAE-C designated institutions
”,
available at:
Link to Competency in cybersecurity education: a handbook for educators at NCAE-C designated institutionsLink to a PDF of the cited article.
NIST
(
2025
), “
NICE framework history
”,
available at:
Link to NICE framework historyLink to the cited article.
Onwubiko
,
C.
and
Ouazzane
,
K.
(
2019
), “
Challenges towards building an effective cyber security operations Centre
”,
International Journal on Cyber Situational Awareness
, Vol.
4
No.
1
, pp.
11
-
39
.
Pandey
,
A.B.
,
Tripathi
,
A.
, and
Vashist
,
P.C.
(
2022
), “'A survey of cyber security trends, emerging technologies and threats”, in
Cyber Security in Intelligent Computing and Communications
, pp.
19
-
33
.
Patton
,
M.Q.
(
1999
), “
Enhancing the quality and credibility of qualitative analysis
”,
Health Services Research
, Vol.
34
No.
5 Pt 2
, p.
1189
.
Petersen
,
R.
,
Santos
,
D.
,
Smith
,
M.
,
Wetzel
,
K.
and
Witte
,
G.
(
2020
), “
Workforce framework for cybersecurity (NICE framework)
”,
NIST Special Publication 800-181, Revision 1
, available at: Link to Workforce framework for cybersecurity (NICE framework)Link to a PDF of the cited article.
Radanliev
,
P.
,
De Roure
,
D.
,
Page
,
K.
,
Nurse
,
J.R.
,
Mantilla Montalvo
,
R.
,
Santos
,
O.
,
Maddox
,
L.T.
and
Burnap
,
P.
(
2020
), “
Cyber risk at the edge: current and future trends on cyber risk analytics and artificial intelligence in the industrial internet of things and industry 4.0 supply chains
”,
Cybersecurity
, Vol.
3
No.
1
, pp.
1
-
21
.
Švábenský
,
V.
,
Čeleda
,
P.
,
Vykopal
,
J.
and
Brišáková
,
S.
(
2021
), “
Cybersecurity knowledge and skills taught in capture the flag challenges
”,
Computers and Security
, Vol.
102
, p.
102154
, doi: .
The SFIA Foundation
(
2018
), “
Sfia 7
”,
available at:
Link to Sfia 7Link to the cited article.
Toulas
,
B.
(
2022
), “
India to require cybersecurity incident reporting within six hours
”,
Bleeping Computer
,
available at:
Link to India to require cybersecurity incident reporting within six hoursLink to the cited article.
Valkenburg
,
B.
and
Bongiovanni
,
I.
(
2024
), “
Unravelling the three lines model in cybersecurity: a systematic literature review
”,
Computers and Security
, Vol.
139
, p.
103708
.
Van Puyvelde
,
D.
(
2018
), “
Qualitative research interviews and the study of national security intelligence
”,
International Studies Perspectives
, Vol.
19
No.
4
, pp.
375
-
391
, available at: Link to Qualitative research interviews and the study of national security intelligenceLink to the cited article.
Ahmad
,
A.
,
Maynard
,
S.B.
,
Desouza
,
K.C.
,
Kotsias
,
J.
,
Whitty
,
M.T.
and
Baskerville
,
R.L.
(
2021
), “
How can organizations develop situation awareness for incident response: a case study of management practice
”,
Computers and Security
, Vol.
101
, pp.
102
-
122
.
ASD Cyber Skills Framework
(
2022
),
available at:
Link to the cited article.Link to a PDF of the cited article.
Dreibelbis
,
E.
(
2023
), “
The best AI chatbots for 2023
”,
available at:
Link to The best AI chatbots for 2023Link to the cited article.
European Union Agency for Cybersecurity
(
2022
), “
ECSF, European Cybersecurity Skills Framework
”,
available at:
Link to ECSF, European Cybersecurity Skills FrameworkLink to the cited article.
Rashid
,
F.Y.
(
2020
), “
The rise of confidential computing: big tech companies are adopting a new security model to protect data while it’s in use-[news]
”,
IEEE Spectrum
, Vol.
57
No.
6
, pp.
8
-
9
.
Reddy
,
G.N.
and
Reddy
,
G.
(
2014
), “
A study of cyber security challenges and its emerging trends on latest technologies
”,
available at:
Link to A study of cyber security challenges and its emerging trends on latest technologiesLink to the cited article.
Scriven
,
M.
and
Paul
,
R.
Defining critical thinking
”,
available at:
Link to Defining critical thinkingLink to the cited article.

A form records general details of an interview for a cyber security defence team study, including date, time, location, interview type, and procedures.The study purpose, consent procedures, data treatment, and the first introductory interview question are displayed in a structured form.A continuation of the interview guide presents question 2 on cyber defence team formation, question 3 on processes and technical skills, and question 4 on current challenges and emerging technologies.The final section of the guide includes question 8 on future skills required for cyber defence teams, question 9 on concluding remarks, and a thank-you note for participation.A form records general details of an interview for a cyber security defence team study, including date, time, location, interview type, and procedures.

Published by Emerald Publishing Limited. This article is published under the Creative Commons Attribution (CC BY 4.0) licence. Anyone may reproduce, distribute, translate and create derivative works of this article (for both commercial and non-commercial purposes), subject to full attribution to the original publication and authors. The full terms of this licence may be seen at Link to the terms of the CC BY 4.0 licenceLink to the terms of the CC BY 4.0 licence.

or Create an Account

Close subscription notice
Close access options