Preloader

The Missing Link in Europe’s Cybersecurity Skills Agenda

Cybersecurity is a critical condition to Europe’s competitiveness, resilience and preparedness. Yet the policy conversation often stops at a familiar conclusion: Europe needs more cyber skills.

That conclusion is true, but also incomplete. A stronger cybersecurity workforce will not be built through training courses alone. It requires clearer career pathways, stronger links between research and industry, more mobility between sectors, and targeted support for groups still underrepresented in the field — especially women.

This is one of the practical takeaways from the European Commission’s 2026 European Semester – Spring Package. While not a cybersecurity strategy, the document shows that cybersecurity is increasingly linked to Europe’s broader priorities: protecting critical systems, leading in strategic technologies, and developing the talent needed to support both.

The issue is not only cyber skills, it is cyber capacity

The Commission places cybersecurity within Europe’s wider economic security concerns. Member States face risks linked to strategic dependencies, including in energy, critical raw materials and key technologies. These dependencies expose European economies to disruption and external pressure. In that context, it calls on Member States to fast-track investments in “technological sovereignty and cybersecurity, infrastructure resilience, and crisis preparedness” (COM(2026) 200 final, p. 3).

The key point is not simply that cybersecurity matters. It is that cybersecurity is part of Europe’s ability to keep essential systems functioning: industry, infrastructure, research, public services.

This shifts the question from “how many people have completed cybersecurity training?” to “does Europe have enough people, in the right places, with the right experience?”

That is a different policy challenge. It requires not only entry-level skills, but also applied experience, cross-sector understanding, leadership, and the ability to translate cyber risks into organisational decisions.

Cybersecurity capacity needs to reach beyond cyber teams

The Commission calls for more digital public services and underlines the need to invest in the digital skills of civil servants. This matters because cyber resilience increasingly depends on people who are not cybersecurity specialists: public managers, procurement officers, project leads, researchers, educators and administrators who make decisions about digital systems every day.

For cybersecurity policy, this widens the challenge. Europe does not only need more technical experts; it also needs more professionals who can understand cyber risks, work with specialists and integrate security into organisational decisions. This is where mentoring, mobility and cross-sector exposure become especially valuable: they help cybersecurity knowledge circulate beyond narrow technical environments and into the institutions that depend on it.

The skills gap is also a pipeline problem

The Commission identifies labour and skills shortages as particularly acute in strategic sectors including cybersecurity, quantum, artificial intelligence and semiconductors (COM(2026) 200 final, p. 18). It also calls for better alignment between education and labour market needs, more STEM participation, stronger upskilling and reskilling, and better use of skills intelligence tools.

This is where the policy response needs more precision. “More skills” is not a strategy by itself, because cybersecurity is not a single profession with a single pathway. Some roles require deep technical expertise; others require the ability to manage risk. A serious cybersecurity skills agenda therefore needs to distinguish between different profiles, career stages and sectors, rather than treating the workforce gap as a generic shortage that can be solved with more training courses.

It also needs better bridges between education, research and employment. Too many initiatives focus on attracting people into the field, without enough attention to what happens next: whether they find opportunities, gain experience, build networks and progress into leadership roles.

Women in STEM is not a side objective

The Spring Package refers to shortages in STEM and ICT fields and notes the need to incentivise female enrolment in these disciplines. For cybersecurity, however, the gender question should not stop at entry. Encouraging more women to study or enter cybersecurity matters, but entry alone does not build lasting careers.

WEM Cyber is particularly relevant in this context, because we are filling the gap. We support women after they have entered the field, and help them move through it with mentoring, funded secondments and cross-sector knowledge exchange. WEM Cyber focuses not only on skills development, but on the conditions that allow women researchers and professionals to build confidence, expand their networks and progress in cybersecurity careers.

In this sense, WEM Cyber offers a practical response to the priorities identified by the Commission. If Europe wants to address cybersecurity skills shortages, strengthen its cyber capacity and make better use of its STEM talent, it needs more than enrolment targets or one-off training initiatives. It needs structured pathways that connect women to opportunities, and help them advance in one of Europe’s most strategic fields.