
Max Vetter at Immersive Labs explains how to build a cyber-resilient workforce
Boardroom discussions on cyber-security are often focused on tech tools and processes, yet they frequently overlook a crucial component: the workforce. This leads to a concerning disconnect, as nearly 80% of leaders express doubt about their teams’ ability to respond effectively to cyber-attacks.
This gap exposes a significant vulnerability in organisations’ approach to cyber-security. It’s not just about the technology; the human element plays an increasingly pivotal role. People, unlike systems, cannot be simply patched or upgraded.
Addressing this issue demands a fundamental shift in strategy, placing the emphasis on cultivating a workforce that is resilient and prepared to face the dynamic challenges of cyber-threats. Investing in advanced technical defences is important, but it’s equally, if not more important, to invest in building a resilient and well-trained team.
The concept of cyber-security training is as old as the internet itself. Yet, as modern threats and technologies have evolved rapidly, the traditional approach to training hasn’t embraced the same pace. Such programmes are still often restricted to dull lectures, one-directional exercises, and tick-box activities. So, how can organisations change their approach and build a robust and cyber-resilient workforce?
The first step is addressing the complacency issue. Immersive Labs’ study revealed that junior staff members routinely tackle training content that is approximately 5% more challenging than that handled by their senior counterparts. This discrepancy points to a dangerous trend: as individuals climb the professional ladder, there’s a tendency to become complacent in one’s skills and not keep pace with new threats.
This complacency is not just a matter of personal skills attainment; it has real and potentially severe implications for organisational security. Senior staff, often in decision-making roles, are integral to the cyber-security posture of a company. When they do not continually upskill and improve their capabilities, their ability to respond effectively to threats lags and sets a concerning precedent for the entire team.
This environment can lead to a false sense of security, where the most experienced members of the team are the least prepared for emerging cyber-threats.
Organisations must recognise and address this issue head-on. This involves not only acknowledging the existence of the problem but also implementing targeted strategies to re-engage senior team members. All members of the team should be expected to regularly build and prove their capabilities using exercises tailored to their roles and responsibilities.
Leadership plays a crucial role in shaping a cyber-resilient workforce. A common misconception in many organisations is that cyber-security is the sole responsibility of the CISO. However, this narrow view undermines the broader need for a comprehensive and inclusive approach to cyber-security.
Alarmingly, 65% of directors anticipate a major cyber-attack within the next year, yet nearly half of these leaders consider their organisations unprepared.
Building a strong cyber-security culture means embedding cyber-accountability and cyber-exercising across every level of the organisation.
Ongoing cyber-exercising should be implemented to keep pace with the evolving threat landscape. Programmes need to be engaging, challenging, hands-on, and simulation-driven, ensuring that even the most experienced staff are continually updating their skills and knowledge. This approach prevents overconfidence and ensures preparedness for new and emerging threats at all levels.
One of the most important steps in building a cyber-resilient workforce is to ensure preparedness across all stages of the attack lifecycle. A technical analysis of an industry framework reveals that many organisations are well-equipped to handle the initial phases of an attack ("before the boom"), but their capabilities significantly diminish in the later stages ("after the boom").
The "before the boom" phase involves identifying and protecting against potential threats. This stage is characterised by activities such as threat hunting, vulnerability management, and implementing preventive controls.
However, the "after the boom" phase, which includes response and recovery after an attack has occurred, often reveals significant gaps in preparedness. This phase demands different skill sets and technologies, such as forensic analysis, incident response, and system restoration. The challenges here are complex, requiring not only technical skills but also effective communication, decision-making under pressure, and strategic planning for business continuity.
To address this imbalance, organisations must adopt a more holistic approach to cyber-security that tests employees knowledge, skills, and judgement for both preventative measures but also how they will respond after an attack has occurred.
To conclude, businesses can never achieve true cyber-resilience without a people-centric approach to cyber-security. By addressing complacency and cultivating a culture of continuous learning led by proactive leadership, organisations can develop a well-trained, adaptable, and prepared workforce.
The aim is to balance technological defences with a robust, well-trained team, recognising that true resilience is achieved when both elements work in harmony.
Max Vetter is VP of Cyber at Immersive Labs
Main image courtesy of iStockPhoto.com
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543