Preloader

The Missing Link in Europe’s Cybersecurity Skills Agenda

Cybersecurity is a critical condition to Europe’s competitiveness, resilience and preparedness. Yet the policy conversation often stops at a familiar conclusion: Europe needs more cyber skills.

That conclusion is true, but also incomplete. A stronger cybersecurity workforce will not be built through training courses alone. It requires clearer career pathways, stronger links between research and industry, more mobility between sectors, and targeted support for groups still underrepresented in the field — especially women. 

This is one of the practical takeaways from the European Commission’s 2026 European Semester – Spring Package. While not a cybersecurity strategy, the document shows that cybersecurity is increasingly linked to Europe’s broader priorities: protecting critical systems, leading in strategic technologies, and developing the talent needed to support both. The policy direction is already visible. The harder question is how these priorities are translated into sustainable careers and stronger institutional capacity.

The issue is not only cyber skills, it is cyber capacity

The Commission places cybersecurity within Europe’s wider economic security concerns. Member States face risks linked to strategic dependencies, including in energy, critical raw materials and key technologies. These dependencies expose European economies to disruption and external pressure. In that context, it calls on Member States to fast-track investments in “technological sovereignty and cybersecurity, infrastructure resilience, and crisis preparedness” (COM(2026) 200 final, p. 3).

The key point is not simply that cybersecurity matters. It is that cybersecurity is part of Europe’s ability to keep essential systems functioning: industry, infrastructure, research, public services. A cyber incident affecting a hospital or an energy provider is a technical problem that quickly transforms into an operational and societal incident.

This shifts the question from “how many people have completed cybersecurity training?” to “does Europe have enough people, in the right places, with the right experience?”

That is a different policy challenge. It requires not only entry-level skills, but also applied experience, cross-sector understanding, leadership, and the ability to translate cyber risks into organisational decisions. It also requires people who can operate across professional boundaries — connecting technical expertise with governance, procurement, research, regulation and management.

Cybersecurity capacity needs to reach beyond cyber teams

The Commission calls for more digital public services and underlines the need to invest in the digital skills of civil servants. This matters because cyber resilience increasingly depends on people who are not cybersecurity specialists. Managers, project leads, researchers, educators and administrators may all influence an organisation’s cyber resilience without working in a dedicated cyber role.

This is where mentoring, mobility and cross-sector exposure become especially valuable: they help cybersecurity knowledge circulate beyond narrow technical environments and into the institutions that depend on it. They also help professionals understand how cyber risks change across sectors, organisational cultures and levels of responsibility.

The skills gap is also a pipeline problem

The Commission identifies labour and skills shortages as particularly acute in strategic sectors including cybersecurity, quantum, artificial intelligence and semiconductors (COM(2026) 200 final, p. 18). It also calls for better alignment between education and labour market needs, more STEM participation, stronger upskilling and reskilling, and better use of skills intelligence tools.

This is where the policy response needs more precision. “More skills” is not a strategy by itself, because cybersecurity is not a single profession with a single pathway. Some roles require deep technical expertise; others require the ability to manage risk. A serious cybersecurity skills agenda therefore needs to distinguish between different profiles, career stages and sectors, rather than treating the workforce gap as a generic shortage that can be solved with more training courses.

It also needs better bridges between education, research and employment. Many initiatives understandably focus on attracting people into the field, but recruitment is only the beginning. Greater attention is needed on what happens next: whether participants find opportunities, gain practical experience, build networks and progress into leadership roles. Without these next steps, Europe risks increasing the number of people trained in cybersecurity without achieving an equivalent increase in experienced professionals able to take on complex or senior responsibilities.

Progress should therefore be measured not only through enrolment and course completion, but also through employment, retention, mobility and access to leadership. These indicators provide a clearer picture of whether skills investment is translating into lasting capacity.

Women in STEM is not a side objective

The Spring Package refers to shortages in STEM and ICT fields and notes the need to incentivise female enrolment in these disciplines. For cybersecurity, however, the gender question should not stop at entry. Encouraging more women to study or enter cybersecurity matters, but entry alone does not build lasting careers. Women must also have access to professional networks, visible role models, applied experience and credible routes towards greater responsibility.

WEM Cyber is particularly relevant in this context, because it is designed to address part of this post-entry challenge. We support women after they have entered the field, and aim to help them move through it with mentoring, funded secondments and cross-sector knowledge exchange. WEM Cyber focuses not only on skills development, but on the conditions that allow women researchers and professionals to build confidence, expand their networks and progress in cybersecurity careers.

A secondment can expose a researcher to real operational constraints; mentoring can help a professional navigate career decisions; and cross-sector exchange can create relationships that continue beyond a single training activity.

In this sense, WEM Cyber offers one practical model for responding to the priorities identified by the Commission. If Europe wants to address cybersecurity skills shortages, strengthen its cyber capacity and make better use of its STEM talent, it needs more than enrolment targets or one-off training initiatives. It needs structured pathways that connect women to opportunities, and help them advance in one of Europe’s most strategic fields.

The challenge for Europe is therefore not simply to attract more people into cybersecurity, but to create the conditions that allow them to gain experience, remain in the field and progress.