
Bec McKeown at Immersive Labs explains how high-profile cyber-security threats influence learning behaviours
Developing human cyber-capabilities is critical to ensuring an effective threat response for any workforce. However, with extensive workloads and continuously evolving responsibilities, employees across the organisation often lag behind in developing new cyber skills, knowledge, and judgement. Evidence shows that people often respond to novelty instead of making informed decisions about risk.
The need to balance against time and resource constraints means the proactive development of human cyber capabilities is rare. Employees only receive yearly or occasional one-off sessions, while security professionals only have time to develop skills for the most high-profile threats. Both these scenarios lead to security knowledge stagnating, while frequent, real-time updates are required to keep pace against evolving threats.
In this atmosphere, when a new threat breaks, security teams are left scrambling to ensure a timely and effective response. Unfortunately, this type of frenzied response doesn’t reflect the realities of human learning behaviour, which is often influenced by different cognitive and circumstantial factors that complicate and hinder learning.
Certain threats might require individuals to develop specific cyber capabilities faster based on their risks, potential impact, or even media exposure. But even technical professionals are not immune to chasing the latest “shiny object” at the expense of building well-rounded and adaptable capabilities.
Given this reality, how can security teams consistently accelerate their learning process in real-time when faced with a new threat?
In our 2022 research, we examined how fast security professionals learn and develop cyber knowledge in real-time after a threat or attack was discovered. We found that high-profile threats and vulnerabilities significantly accelerate the security team’s learning process. For instance, while there were many vulnerabilities with a critical impact, four of the five fastest-developed skills identified in our research came around the Log4j vulnerability.
Cyber-security teams took an average of just two days to develop the relevant skills, knowledge, and judgement needed to counter Log4j. This stood in stark contrast to the usual average of three months to acquire new skills against breaking threats, clearly demonstrating the difference a clear motivation and goal can make when developing human cyber capabilities.
Similarly, security teams ramped up SolarWinds knowledge in less than two weeks – nearly eight times faster than the average. Like Log4j, SolarWinds was a highly-publicised vulnerability, this time potentially threatening more than 18,000 companies globally.
Given these statistics, it is evident that high-profile and heavily-publicised threats and vulnerabilities tend to see a significantly faster time to capability, even when compared to less talked-about threats with a similar risk-profile. When faced with such threats, security teams were far more efficient and productive in their learning process, developing human cyber capabilities faster than usual.
While motivation and focus play a strong role in improving skill development, teams also must have the right resources available. Per our research, security teams took an average of five days to develop knowledge about zero-day exploits on Windows servers. This was the only non-Log4j-related threat at the top of the performance list, but because the proof-of-concept around the vulnerability was widely available, it was very accessible.
In addition to vulnerabilities that pose an imminent business risk, we also found that security teams were keen to prioritise threats and attacks that were associated with well-known malicious groups. For instance, knowledge regarding UN2452 (SolarWinds), Iranian threats groups, and Russia-based FIN7 group was developed faster than other malicious actors. These groups are well-known in the public domain, and receive significant interest from the media, research teams, and other mainstream sources.
Similarly, we observed that knowledge and skills development were significantly faster around familiar and widely-used malware groups. When faced with prominent ransomware strains such as Maze, Annabelle, and WastedLocker, security teams developed defensive skills and incident response capabilities faster than other ransomware groups.
These instances demonstrate how the recognition and profile of certain threat groups and malicious programs influence the security team’s motivation to learn, as well as why working against known examples may help teams establish a sense of focus and a clear set of learning objectives.
To effectively keep ahead of threats, teams must be able to apply this focused, accelerated approach to learning to any new skills, not just infamous examples that pique their interest.
Threat intelligence is one of the most effective ways of accelerating the learning process. By subscribing to threat intelligence feeds or using OSINT platforms, security teams can quickly learn about new threats, rather than reacting to the latest headlines. Armed with this knowledge, teams must determine how these threats may impact their organisation, and develop strategies and learning plans to match.
Establishing specific incident response plans in advance will also help expedite learning processes when faced with a new threat. This means that security teams have specific procedures and resources in place for how to respond to different types of risks and threat incidents, and defining who is responsible for what tasks. Teams can quickly and efficiently respond to a new threat without wasting valuable time determining next steps.
In addition, security teams can also accelerate their learning process by conducting regular threat-hunting exercises, the process of proactively searching for indicators of compromise on a network.
Finally, regular exercising and simulation-driven programmes will accelerate the learning process of security professionals. Workforces that are equipped with crisis simulation programmes, incident response, and threat detection training will likely produce faster time-to-cyber capabilities, enabling them to draw on practical experience rather than a purely theoretical approach.
Collectively, these measures ensure security teams achieve a regular cadence of learning, which not only keeps skills up-to-date, but helps teams develop the cognitive agility needed to recognise and respond to threats faster and more effectively.
By drawing on an understanding of adult learning behaviours, organisations can more effectively prepare teams for new threats, as well as the rapid development of skills for specific evolving threats, ultimately creating a more cyber-resilient workforce.
Bec McKeown is Director of Human Science at Immersive Labs
Main image courtesy of iStockPhoto.com
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543