

As cybersecurity evolves, governments need confidence not only in technology, but in the people responsible for using it. CREST’s Chief Product Officer Sebastian Madden and Senior Product Manager, Leanne Sperry, reflected on the recent GISEC conference, and the latest developments with the International Coalition on Cyber Security Workforces (ICCSW).
I sat down with them both to discuss CREST’s collaboration with ICCSW. In this interview, we talked about the involvement of CyberForce – the cybersecurity certification of the Dubai Electronic Security Center (DESC) – and how together, by putting the ICCSW’s principles into practice, we are professionalising the cyber workforce. Finally, we discussed what other countries can learn from the programmes already in operation, and why greater international alignment matters. Read the full interview below.
Sebastian: Because however sophisticated the technology becomes, people are still making consequential decisions.
AI can assist detection, response and testing. It can enable attacks at greater speed and scale. It also introduces new questions around governance and accountability. Who authorised a machine-assisted decision? Who was supervising it? Who steps in when something goes wrong?
There is still a person somewhere in that chain.
So alongside asking whether our tools can be trusted, governments and employers need to know whether the professionals using them are competent, accountable and keeping pace with a rapidly changing environment.
Leanne: The International Coalition on Cyber Security Workforces brings governments together to share their experience of developing capable, trusted cyber workforces.
One of the advantages of the Coalition is that countries are at different stages. Some already have established approaches to professional recognition or licensing; others are exploring what an appropriate national model might look like.
That gives members an opportunity to learn from one another rather than every country beginning with a blank sheet of paper.
Importantly, ICCSW is government-led and participation is voluntary. It provides a collaborative forum for sharing expertise and experience, enabling stakeholders to shape and support agreed priorities, exchange best practice, and work towards greater mutual recognition, facilitating the mobilisation of cyber professionals across borders.
Sebastian: Technical certifications remain extremely valuable. But there is a difference between demonstrating a technical skill at a point in time, and demonstrating professional fitness to practise.
Cyber professionals operate in situations where experience, judgement, integrity and communication can matter just as much as technical knowledge.
They also work in a field that changes extraordinarily quickly. A qualification somebody originally achieved several years ago and kept up to date cannot, on its own, tell an employer or regulator whether that person has continued developing their capabilities.
That’s why professional approaches increasingly consider relevant experience, broader competences, levels of ongoing project delivery and continuing professional development alongside technical skills.
For governments, that can provide greater assurance over who is protecting critical systems. Employers gain a more consistent language around recruitment, progression and capability. And professionals gain recognition and a clearer career pathway.
“As AI changes how cybersecurity work is performed, trust in the people responsible for that work becomes more important, not less. Technical certification alone cannot provide that trust. Professional competence needs to encompass experience, judgement, integrity, communication, leadership and continual development – and increasingly needs to be recognisable across borders.”
– Sebastian Madden, Chief Product Officer, CREST
Leanne: It’s designed primarily for governments considering whether and how to professionalise their cybersecurity workforce.
It brings together international experience so that policymakers can understand some of the choices involved before designing their own approach.
The guidance makes the case for professionalisation, explores different design options and trade-offs, explains how professional titles differ from certifications alone, and starts to identify areas where international alignment might be possible.
Crucially, it isn’t a blueprint saying every country should build the same system. It gives governments a framework through which they can consider what will work in their own national context.
Read the ICCSW Professional Titles Framework Guidance
Sebastian: CyberForce is useful because it shows what professionalisation looks like when you move from theory into implementation as part of an industry certification.
The approach looks beyond whether the employees who carry out the projects for CyberForce-certified companies hold an accepted technical qualification. At Team Member and Team Leader level, there is also evidence relating to wider professional competence.
The next generation of CyberForce builds on that approach, including broader recognition of qualifications alongside areas such as integrity, communication, leadership, personal commitment and continuing professional development. Assessment happens at initial application and is revisited annually.
That ongoing element is important. Professional competence shouldn’t be viewed as something you prove once and then carry indefinitely.
Leanne: The UK Cyber Security Council has also developed a professional recognition model, and CREST acts as one of its licensing bodies.
Looking across approaches such as the UK and Dubai gives ICCSW members practical evidence about what works, where models differ and where requirements can potentially become better aligned.
The other ICCSW members bring their own experiences too, whether they are operating professional recognition schemes already or considering how such an approach could work nationally.
The framework distils that collective experience into something other governments can use.
Sebastian: Countries have different regulatory structures, workforce needs and cyber ecosystems. There will continue to be legitimate differences in how professionalisation is implemented.
The near-term opportunity here, is interoperability.
If national programmes increasingly understand and recognise comparable requirements for professional competence, it becomes easier for trusted cyber professionals to work across organisations, projects and borders.
That won’t happen overnight. As we said at GISEC; interoperability is built through one aligned requirement at a time.
Leanne: That there is already a growing body of international experience to draw upon.
Governments considering professionalisation don’t need to solve every question independently. ICCSW provides a forum to share that learning and develop approaches which work nationally while becoming easier to understand internationally.
Sebastian: And I’d come back to trust.
Technology will change, so will the skills required of practitioners continue to evolve. AI will accelerate both.
What remains constant is the need for trusted professionals behind the technology.
Ultimately, standards make trust visible, whereas certifications such as CyberForce make it real and practical. ICCSW and CREST are making it globally portable.
Useful resources to learn more: