CyberPath will build a clearer and more trusted cyber profession for Australia
Australia needs an additional 56,000 cyber security professionals, according to ACS Digital Pulse 2026. But where will these people come from, and how will an industry characterised by ambiguity gauge skills and career pathways?
Supported in part by the Australian Department of Home Affairs, CyberPath is an industry-led pilot program that sets out to define what good looks like around cyber security skills, roles and professional recognition.
We spoke to Betsy Gregg, CyberPath Executive Sponsor, about the two-year pilot program and what it could mean for Australia.
ACS: For anyone hearing about it for the first time, what is CyberPath?
BG: CyberPath is an industry-led professionalisation pilot designed to help Australia build a world-class cyber security workforce.
Today, Australia’s cyber security workforce is fragmented. Job titles and expectations vary considerably across organisations and sectors. People develop valuable skills through formal qualifications and informal learning, while employers often struggle to look beyond qualifications and years of experience to understand what someone can actually do. This creates ambiguity for existing practitioners and those aspiring to enter the profession.
CyberPath aims to create greater clarity and consistency. We are bringing industry, government, educators and the wider cyber community together to develop a shared understanding of cyber security roles and the knowledge and skills required, including the many learning and recognition paths that support a dynamic ecosystem.
Ultimately, CyberPath aims to build trust in the cyber profession and help Australia develop the workforce capability and standards needed to respond to an evolving threat environment.
ACS: Why is CyberPath critical to Australia?
BG: Cyber security affects every part of the economy and costs Australia $63 billion a year. A serious incident can disrupt essential services, compromise personal information, damage businesses and weaken public confidence. At the same time, emerging technologies and increasingly complex digital environments continue to change the capabilities Australia needs.
We need a robust cyber security workforce that can demonstrate the right capabilities for the responsibilities they carry in a complex ecosystem supporting and leading legacy and new technologies. What’s more, government and industry need a common language to understand and enable the workforce, identify gaps and demand for future success.
Professionalisation can help provide that foundation. Clear role definitions, measurable capability standards, ethical expectations and continuing professional development give employers and the public greater confidence in the profession. They can also help Australia mobilise trusted practitioners during major incidents and strengthen the international credibility of our cyber capability.
ACS: You used the term ‘professionalisation’; why is that so important?
BG: Professionalisation means creating clear and consistent expectations for capability, conduct and responsibility.
Cyber security remains one of the few high-risk fields in which people can describe themselves as experts without a shared national standard for what that expertise means. That creates uncertainty for employers, practitioners and the people who rely on secure systems.
A professional framework can define what good practice looks like, give people credible ways to demonstrate their capability and set expectations around ethics, accountability and ongoing learning. It can also reduce the reliance on inconsistent job titles or a growing collection of costly credentials that may not show whether someone can apply their knowledge in practice.
Professionalisation must be designed carefully. We do not want to impose unnecessary barriers, disregard existing qualifications or exclude capable people who entered cyber through alternative pathways. CyberPath is exploring a model that strengthens trust while recognising the many ways people develop and demonstrate genuine cyber capability.
ACS: What will CyberPath deliver?
BG: The CyberPath program will develop an interconnected series of frameworks that will provide capability and role definition to support standards and competency through diverse learning and recognition pathways.
Enhanced through international consultation and an inclusive-by-design approach, the frameworks set the foundations for Professional Standards, iteration, harmonisation, and continuing discussion as the pilot moves into activation.
In 2027, CyberPath will commence pilot delivery to test the frameworks’ use, value, and adoption across practitioners and employers. In its first iteration, the pilot will focus on specialist roles, including:
Cyber Security Architect
Governance, Risk, and Compliance (GRC) Analyst
Chief Information Security Officer (CISO)
Security Operations Centre (SOC) Analyst
This is an opportunity for the community to get involved and define solutions and approaches that solve real-world problems. With feedback, the pilot seeks to iterate and support an evolving scope and enable the broader ecosystem, including but not limited to industry, government, education, and HR professionals.
At the conclusion of the pilot, a Durability Plan will evaluate the pilot’s performance and address long-term governance, stewardship, and sustainability. CyberPath must continue to evolve as technologies, threats and workforce requirements change.
ACS: How will employers benefit from CyberPath?
BG: Employers need greater certainty about the capabilities they have and the capabilities they need.
A common framework can help an organisation define roles more clearly, recruit against demonstrated capabilities and identify gaps across teams. It can also support more targeted learning and development by showing where employees are now and what they need to develop to deliver organisational priorities and support effective threat modelling.
That has practical implications for workforce planning, recruitment and retention. Instead of relying on job titles that mean different things in different organisations, employers can use a shared language for roles, tasks, and skills. Instead of overlooking someone because they lack a particular qualification or credential, they can consider credible evidence of prior experience and demonstrated capability.
ACS: What does CyberPath mean for people already working in cyber?
BG: For practitioners, it offers greater clarity, recognition and mobility.
Many people working in cyber struggle to communicate the depth of their capabilities, particularly when their experience crosses role boundaries or does not align neatly with existing qualifications or certifications. CyberPath is exploring how practical evidence, workplace experience and prior learning can contribute to professional recognition.
A shared framework can help practitioners benchmark their capability, understand employers’ expectations and identify their next development priorities. Portable recognition could also make it easier to move between roles, organisations and sectors.
There is an important psychological benefit as well. Cyber security can be an ambiguous field, and that ambiguity can contribute to imposter syndrome. When expectations are clear, and capability can be independently recognised, people gain greater confidence in what they know, what they can do and where they can go next.
ACS: Will CyberPath recognise people who entered cyber through non-traditional pathways?
BG: Recognition for people on alternative career pathways is fundamental to the CyberPath pilot program.
Some of Australia’s most capable practitioners have developed their expertise through hands-on experience, self-directed learning, open-source contributions, community participation or work in adjacent fields. Their capability may not appear on a university transcript, but it is real and valuable.
CyberPath intends to recognise multiple forms of evidence, including prior learning and professional experience. The aim is to validate knowledge, skills, and competencies without forcing everyone through the same pathway or simply adding another certificate to those already available.
This approach can make the profession more accessible to career changers, skilled migrants, self-taught practitioners and those underrepresented in cyber. It also helps employers reach a wider talent pool.
ACS: How will students and educators benefit from CyberPath?
BG: Students need to see where their learning can take them. Educators need clearer signals from industry about the capabilities employers require.
CyberPath seeks to connect learning with real cyber security roles. Students should be able to understand the different kinds of work available, the skills and knowledge each role requires and the routes they can take to enter and progress through the profession.
For universities, TAFE and other education providers, CyberPath can provide a reference point for mapping curricula against industry needs without prescribing a single education model. Better alignment should help graduates enter the workforce with more relevant capabilities and reduce the gap between completing a course and becoming effective in a role.
It can also make cyber careers visible to people who may never have considered the field, including those whose strengths or experiences do not fit traditional perceptions of a cyber professional.
ACS: You describe CyberPath as industry-led. What does that mean in practice?
BG: It means the people who work in, employ, educate and support the cyber workforce must shape the outcome.
A framework and pilot developed without these groups would struggle to reflect the variety of cyber roles and dynamic operating environments across Australia. It would also lack the trust required for widespread adoption and practical use.
Industry ownership also needs to continue beyond the pilot. The Durability Plan will consider how CyberPath is governed, maintained and updated so that the Framework remains responsive to changes in technology, threats, and professional practice.
ACS: How and when will the CyberPath pilot be delivered?
BG: The two-year CyberPath pilot program follows a staged process.
Discovery and early consultation took place from January to March 2026, followed by framework design and co-design work from March to November 2026. The program has been working concurrently on pilot development and consultation through late 2026 to identify models that deliver value for employers, practitioners, and learners.
Pilot delivery will kick off in February 2027. This phase will engage employers and practitioners to explore workforce planning, skills benchmarking, and practitioner recognition to capture feedback and workforce insights for further iteration and durability consideration.
Through 2027, the program will evaluate the pilot and consult on future scaling. That work will inform an evaluation report and durability plan to support long-term sustainability in December 2027.
The staged approach is deliberate. CyberPath needs enough structure to establish trusted standards, but it must also remain flexible enough to respond to evidence. Each phase gives the community a chance to challenge assumptions, identify unintended barriers, and improve the model.
ACS: Come the end of the CyberPath pilot program, what would success look like?
BG: Success would mean Australia and the global cyber security community has a framework that people understand, trust, and can use.
Employers will have a clearer way to define roles, assess capability and plan their workforce. Practitioners will demonstrate their skills and knowledge to navigate their career. Students and career changers will see alignment and opportunity to transition from learning to workforce.
While the pilot won’t capture every success, it offers an opportunity to consider how the model could drive value in broadening contexts like generalist technology roles and micro-businesses, supporting Australia’s cyber resilience and human firewall.
Most importantly, the CyberPath framework would belong to the sector. CyberPath will have lasting value only if collaborators continue to shape, adopt and improve it.
ACS: How can people contribute to CyberPath?
BG: CyberPath is still inviting people and organisations to register their interest, receive updates and become an early adopter.
We want to hear from practitioners at every career stage, employers in different sectors, educators, learners and people considering a move into cyber security. We are particularly keen to include regional voices and groups that remain underrepresented in the sector.
CyberPath is an opportunity to build a profession on the most precious of things: trust. Achieving that will take the whole cyber community.
Discover CyberPath and register your interest. Join the conversation on LinkedIn