My thoughts on the CyberPath Professionalisation Pilot Survey
I came here to back up some data and all I got was angry about an accreditation program
At this point it feels like the only time I venture online (outside of doomscrolling Reddit) anymore is because I’m angry about something, or delighted.
I’m disappointed to say today I’m online and updating my blog because I’m angry about something.
Anyway. This post is based on the points I talked through with the survey bot and the follow-up questions it asked me. These are my main concerns. Your concerns might be different.
I’m laying mine out partly because, if you’re unfamiliar with the issue or need something to riff off before completing the survey yourself, at least there’s something here to start from. We might not agree on everything, and that’s okay.
I probably took a more nuanced approach to AI than I would like. Over the past few months, when it comes to professionalism conversations, I’ve found it more helpful to approach things from the point of view of being bouba then kiki. It gives me the ick, because I’d like to see the datacentres burnt to the ground and for the AI bubble to burst. I’m still reconciling how this fits in with my praxis.
But I digress…
There’s currently a survey open for the ACS CyberPath Professionalisation Pilot, and I’d encourage Australian cyber security professionals to complete it1.
1 Not because I’m excited about mandatory accreditation.
I don’t want cyber security professionalisation to become a licensing, accreditation, or role requirement exercise and I suspect a lot of people in the industry feel the same way, and we should say that clearly while feedback is being collected.
I’m not going to lie, I do think cyber security has a professionalism problem in places. We have inconsistent role expectations, unclear career pathways, uneven training, and hiring processes that often fail to understand what the work actually involves. And I think a framework that helps describe cyber security roles, capabilities, development pathways, and expectations could be useful.
But a framework is very different from a gatekeeping mechanism which it feels this accreditation program has the potential to become.
Why you should care? i.e. why the ACS matters more than it might seem
It’s easy to look at the Australian Computing Society (ACS) and think: this probably doesn’t matter much to my day-to-day work.
For a lot of cyber security professionals, that’s probably true in the immediate sense. Most of us aren’t waking up in the morning thinking about ACS membership categories, professional accreditation, or whether our job description maps neatly to a professional framework. Too be honest every time I hear about the ACS I think let out a barely audible groan and think “here we go again”.
But there’s one very important place where the ACS already matters: the Professional Employees Award.
The Professional Employees Award covers, among others, degree-qualified engineers, scientists and information technology employees, as well as information technology employees who have sufficient qualifications and experience to become a Certified Professional of the Australian Computer Society. Fair Work’s guidance on award coverage for information technology employees also says sufficient qualifications for IT employees can include either an ACS-accredited science or IT degree, or qualifications and experience that make someone eligible to be a Certified Professional of the ACS.
That means the ACS isn’t just a professional association sitting somewhere off to the side of the industry. It already has some influence over who falls within parts of the Professional Employees Award.
And I want to be really fucking clear here2.
2 It’s also worth mentioning here I am NOT an employment lawyer, this is just my read on the situation.
I’m not saying the CyberPath framework will definitely change award coverage. I’m not saying ACS accreditation is about to become a hard legal requirement for cyber security workers.
But I am saying that once professional accreditation becomes more formalised, more normalised, and more tied to role definitions, it’s not outside the realm of possibility that it could influence how people understand who is, and isn’t, covered by the award.
That might sound abstract until you connect it to unfair dismissal protections.
The Fair Work Commission says the high income threshold operates as a limit on an employee’s eligibility to be protected from unfair dismissal under the Fair Work Act. If an employee isn’t covered by a modern award, and an enterprise agreement doesn’t apply to them, they generally need to earn less than the high income threshold to access unfair dismissal protections.
For the 1 July 2025 to 30 June 2026 financial year, that threshold is $183,100.
So for higher-paid cyber security professionals, award coverage can matter a lot.
If you earn over the high income threshold, aren’t covered by an enterprise agreement, and don’t meet the definition in the Professional Employees Award, you may not be protected from unfair dismissal under the Fair Work Act.
From a labour point of view this is why I get nervous when accreditation frameworks are treated as harmless professional development exercises.
And for a lot of people, the ACS probably doesn’t feel especially relevant. But if ACS-linked professional definitions already appear in the Professional Employees Award, then any move toward mandatory or semi-mandatory accreditation deserves careful scrutiny. Not because every possible consequence is guaranteed, but because the consequences could be significant if accreditation starts being used to draw lines around who counts as a professional, who’s covered by an award, and who has access to legal protections at work.
And like that’s a very different conversation from “wouldn’t it be nice to have clearer career pathways?” And like, too be honest, clearer career pathways are good. Better role definitions can be good. Shared language across the industry can be useful. But tying professional legitimacy to accreditation can have downstream effects beyond hiring, promotion, or status. It can interact with employment law, and workplace protections in ways that many cyber security workers may not realise until it matters.
That’s why I think the safest position is to be very clear now: cyber security professionalisation should be descriptive and supportive, not mandatory, exclusionary, or tied to whether someone gets to be recognised as a legitimate professional under workplace systems.
Accreditation risks excluding good people
My biggest concern is that accreditation often rewards the people who are already best positioned to access it: people with spare time, money, confidence, organisational support, and the ability to perform well in formal assessment environments.
Some people don’t test well. Some people are neurodivergent. Some people have caring responsibilities. Some people are already carrying a disproportionate amount of domestic labour outside work. Some people are underrepresented in the industry and already dealing with additional barriers to progression.
For those people, mandatory accreditation becomes another burden placed between them and career progression.
And the 2024 ABS Time Use Survey makes labour disparity pretty clear.3 Women spent more time on unpaid work, at 4 hours and 53 minutes on average per day, compared with 3 hours and 52 minutes for men. For parents of children under 15 who reported doing unpaid work, the gap was even larger: women spent an average of 7 hours and 29 minutes a day doing unpaid work, compared with 5 hours and 2 minutes for men4.
3 I didn’t cite the ABS in my actual survey responses. That was a follow-up activity for this blog post… apparently my coping mechanism is adding references after the fact.
4 If the distribution of unpaid work in your home looks different, that’s genuinely great. I’m not going to argue with you about your household. The point is that, at a population level, unpaid work is not evenly distributed, and extra professional requirements land on top of that existing imbalance.
Even on workdays, women reported an average of 3 hours and 2 minutes on unpaid work. On days they didn’t work, that increased to 5 hours and 50 minutes. Men reported an average of 2 hours and 27 minutes on unpaid work on workdays, and 4 hours and 56 minutes on days they didn’t work.
So when we talk about accreditation as “just” professional development, we need to be honest about who has the time, energy, and support to absorb that extra work. Mandatory accreditation doesn’t land evenly across the workforce. It lands on top of existing inequalities in paid work, unpaid work, care, and time pressure.
And it’s important because professionalisation frameworks often talk about fairness and consistency, but if they become mandatory credentials, they can easily increase disparity rather than reduce it.
Cyber security capability isn’t just technical knowledge
Another problem is that accreditation tends to measure the things that are easiest to assess, not necessarily the things that matter most. So, in cyber security, technical skills are important. Of course they are. But they’re not the whole job.
A lot of the most valuable work in my opinion involves judgement, communication, prioritisation, strategic thinking, influence, and the ability to guide people toward secure outcomes that actually get delivered.
I work in appsec, which is effectively a customer-facing role. I talk to software engineers all day. I need to explain risks, understand constraints, influence roadmaps, negotiate trade-offs, and help teams land practical solutions. While technical skills are critical, the people skills aren’t optional in my role. I value them, and I expect to see them in people on my team.
Like, I can teach many people what server-side request forgery is and how to exploit it. What’s much harder is educating a whole group of software engineers about why SSRF matters in their environment, helping them understand the risk, and guiding them toward a solution that actually lands on their roadmap, and enabling them to solve similar problems themselves in the future.
Every security speciality will have examples like this. The hardest and most valuable work is often not the thing that fits neatly into an exam.
Judgement and communication are deeply contextual
In 2021, I presented a conference talk called “Collapsology: Why Exposed RDP Isn’t Your Biggest Threat”. In that talk, I talked about security culture, how to identify cultural threats, and how modern tools can help us detect those threats before they lead to security culture collapse.
So I have big thoughts about one of the follow-up questions the stupid bot asked me about measuring and assessing so-called “soft skills” like judgement and communication.
As most are probably aware, some certification programs try to assess practical capability through reports or scenario-based work. OSCP, for example, requires a written report. That’s better than a purely multiple-choice assessment, but it still only captures a narrow version of the work.
And the bit that I rambled on about is that in reality judgement and communication depend heavily on context. Communicating risk in a process-driven culture is different from communicating risk in a high-autonomy culture. Both are different again from working in a process-driven culture that believes it’s an autonomy culture.
The same behaviour can be interpreted differently depending on the organisation. In one environment, challenging a design early is seen as valuable risk management. In another, it’s seen as being difficult or slowing delivery. In one team, a short written recommendation is enough. In another, the work is in building trust over months so security advice is actually accepted.
And it makes me sceptical that a central framework can objectively assess judgement and communication across the entire profession for the purposes of accreditation or saying someone is suitable for a particular role.
It also shouldn’t assume every cyber security role needs the same balance of skills. Some roles are deeply collaborative and influence-heavy. Others are more research-focused, technical, operational, or specialist. A useful framework should describe different role expectations, not force everyone into the same model of what a “good cyber professional” looks like.
And now we’re talking about AI…
The survey also asked a bunch of questions about AI, which felt a bit disjointed in the flow of the whole thing. So, because apparently we’re doing this too: here are the things I talked about regarding AI.
AI makes this conversation more urgent, not less
This debate is happening at the same time as organisations are rapidly adopting state-of-the-art AI models and agentic AI tools.
I do think AI has some useful applications in cyber security. It can help summarise large volumes of information, triage alerts, draft documentation, identify known patterns, and make security knowledge more accessible to engineers. In incident analysis, it may help organise logs, alerts, tickets, timelines, and reports so analysts can spend less time on administrative work.
But I see the opportunities as more limited and operational than the hype suggests.
To me, security is a forward-looking discipline. We’re constantly trying to anticipate emerging risks, new attack paths, new technologies, and changes in attacker behaviour. AI models are largely trained on the past. They can summarise known patterns well, but that doesn’t mean they can reliably identify what’s novel, what’s missing, or what’ll matter next.
Yesterday’s best practice isn’t always enough for tomorrow’s threat model.
My bigger concern is over-reliance. AI-generated content can look polished and plausible even when the underlying thinking is weak. Software engineers can use a generic prompt to generate system designs, threat models, security recommendations, or implementation plans, and then hand over whatever the model produces with little review or thought.
That’s already a problem in environments where businesses are pushing teams to move faster and focus more on delivery.
It becomes a Brandolini’s law problem: the amount of energy required to refute low-quality AI-generated work is much greater than the energy required to produce it. Security teams can quickly become overwhelmed reviewing large volumes of plausible-looking documents that were generated in minutes but require serious effort to validate.
And so to me one of the biggest risks isn’t just that AI gives bad answers. The risk is that people stop noticing when the answers are incomplete.
AI-generated work can also blur accountability
Over-reliance on AI-generated content can interact badly with insider threats.5
5 The bot asked me about how AI can enable insider threats. IDK man, I’m just putting my answers here so readers can riff off them if they want.
Careless insiders may use AI tools to make mistakes at scale. A person might generate a design for an admin function that recommends overly broad access, weak logging, or limited approval controls, then implement it without questioning the assumptions.
Malicious insiders may use AI-generated content as cover. They could deliberately steer a prompt toward a design that creates future opportunities for abuse, then present the result as a reasonable AI-assisted recommendation.
In both cases, the output looks professional enough to move through a busy review process. Security teams, already under pressure, may miss subtle weaknesses. The organisation then has a harder time understanding who made the decision, why it was accepted, and whether anyone properly challenged it.
To me, strong cyber security depends on traceability, ownership, and scepticism. AI can weaken all three if organisations treat model output as authority rather than input.
Don’t use professionalisation to make the same mistake
We’re already at risk of mistaking polished output for real capability. AI can generate documents that look like security thinking. Accreditation can create credentials that look like proof of security capability.
Neither is enough on its own.
Cyber security needs people who can think critically, work through ambiguity, challenge assumptions, communicate with different audiences, and make judgement calls in messy real-world environments. Those capabilities are hard to measure, but they’re central to the work.
A framework shouldn’t pretend otherwise.
What I’d like to see instead
My advice to those designing the framework was simple: make it supportive, not punitive.
Use it to describe skills, role types, career pathways, and development opportunities. Use it to help employers understand what different cyber security roles actually involve. Use it to support better hiring, mentoring, training, and progression.
But don’t make it a mandatory credential for employment, promotion, or legitimacy in the field.
If practical capabilities like judgement and communication are included, describe them as role-dependent expectations rather than universal pass-or-fail requirements. Provide examples of what they can look like in different environments. Acknowledge that application security, red teaming, governance, detection engineering, incident response, security architecture, research, and leadership may all require different balances of capability.
Most importantly, don’t build a framework that excludes people who are already carrying additional burdens, or that rewards people simply because they’re good at navigating accreditation systems.