This article was contributed by my good friend, Information Security & IT Risk Leader, Tunde Alade-Bakare and originally published on LinkedIn.
The email arrived on a Tuesday, which is when these things tend to arrive. A hiring manager at a mid-sized financial services firm had just rejected a candidate for a senior security analyst role. The candidate had seven years of hands-on experience, a credible portfolio, and references that checked out. But she did not hold a CISM or CISSP. The job description, buried under seventeen bullet points, listed it as “preferred.” The hiring manager ticked it as “missing” and moved on. Three weeks later, the firm suffered a ransomware incident. The person they eventually hired to lead the response held two ISACA certifications and had never, by his own account, worked a 3 a.m. shift in a SOC. He managed the crisis well. Not because of the certificates, exactly. But not without them either.
This is the conversation the cybersecurity industry keeps having with itself, usually badly.
There is a particular cynicism that lives inside technical communities. The conviction that anyone who holds a certificate instead of raw, hard-won experience is something less than the real thing. In cybersecurity, this runs especially deep. The field was partly built by self-taught operators who learned by breaking things before anyone thought to teach it in a classroom. So when someone walks in with a CISSP, a CISM, or a SABSA badge on their LinkedIn profile, certain rooms go quiet. The verdict, in that silence, has already been delivered.
It is, by and large, the wrong verdict.
The Gatekeepers and Their Grudge
The critics have real grievances. Some certifications are factory-produced, exam-centric, and disconnected from how attacks actually unfold. There are candidates who memorise thousands of practice questions, pass on a second attempt, and cannot configure a firewall rule without a tutorial. The industry has watched this happen, repeatedly, and the resentment it breeds is legitimate.
But this is a critique of implementation, not of the concept. Dismissing certifications because some are poorly designed is the same logic that would close every medical school because some produce mediocre doctors. The flaw is in the execution. The structure, at its best, still holds.
The Number Everyone Argues About
Any serious conversation here has to grapple with a figure that has travelled far and attracted pointed pushback: the cybersecurity workforce gap published annually by ISC2. The 2024 edition of their Cybersecurity Workforce Study placed the global shortfall at approximately 4.8 million professionals, a 19.1% increase from the prior year, with the sharpest rises recorded in Asia-Pacific and Europe. ISC2
The scepticism surrounding that number is worth engaging honestly, because the number itself is frequently misread. The workforce gap measures the difference between how many cybersecurity professionals organisations say they need to properly secure themselves and the number currently working. It is not an estimate of open job postings. ISC2 When critics point out that advertised vacancies do not reflect a 4.8 million shortfall, they are right. They are also answering a different question entirely.
Then in 2025, ISC2 did something quietly significant. They retired the headline gap figure. Respondents to the 2024 and 2025 studies had begun prioritising the need for critical skills over the need for more people. ISC2 therefore chose not to publish a workforce gap estimate in its 2025 report. ISC2
That is not a retraction. It is something more useful, a correction of emphasis. The problem was never purely numerical. For the first time in the study’s history, participants cited lack of budget as the leading cause of staffing shortages, displacing lack of qualified talent, which had held that position in every prior year. ISC2 The crisis shifted from headcount to capability. Which is, again, precisely where certifications become most relevant.
ISACA and the Layer Most People Skip
One of the more persistent blind spots in the anti-certification argument is its tendency to treat cybersecurity as a purely technical field. It has not been that for a long time. Risk governance, audit assurance, regulatory compliance, these are not peripheral activities wrapped around the real work. They are the architecture within which all technical controls either function or fail.
This is the domain ISACA has occupied for more than five decades. The organisation now counts 185,000 members across 188 countries and 225 chapters worldwide. ISACA It is not a testing company. It is a professional community that happens to credential.
ISACA’s Certified Information Systems Auditor (CISA) is built for professionals who audit, control, monitor, and assess an organisation’s information technology and business systems. Its Certified Information Security Manager (CISM) targets those who develop and manage enterprise information security programmes at a strategic level. Training Camp These are not competing credentials. They operate at different altitudes. The external validation of both has grown considerably. CISA and CISM are now approved qualifications under U.S. Department of Defense Manual 8140.03, covering cyberspace workforce qualification for service members, DoD cyber employees, and contractors. ISACA Governments are not known for approving credentials without institutional pressure to do so.
CISM, which has been earned by more than 100,000 professionals since its launch in 2002, was named the Best Professional Certification Programme at the 2025 SC Awards. ISACA ISACA is also not standing still. This year the organisation released the Advanced in AI Security Management credential, the first of its kind, available to professionals who already hold a CISM or CISSP. ISACA That is an institution reading the threat landscape and responding to it, not one collecting fees on stale material.
Structure Is Not the Enemy of Depth
A candidate sitting the Offensive Security Certified Professional exam does not memorise anything useful. They spend months inside a lab, compromising machines, building methodology, developing the kind of pattern recognition that only arrives through repetition and failure. The final exam is a 24-hour live penetration test. Nothing multiple choice about it.
The CISM operates with similar rigour in a different register. ISACA requires five years of professional experience in information security, with at least three years spent in information security management spanning three or more CISM domains, before certification is awarded. DestCert That is not a box-ticking exercise. It is a gate. And gates, when properly maintained, keep the wrong people out and let the right ones in with something to show for the journey.
SABSA: The Credential Most Boards Have Never Heard Of
If ISACA speaks to governance and ISC2 to operational security management, SABSA, the Sherwood Applied Business Security Architecture, occupies a third layer that most certification debates never reach: enterprise security architecture itself. The layer where a security decision either traces back to a business outcome or it does not, and if it does not, it probably should not have been made. SABSA is a model and methodology for developing risk-driven enterprise information security architecture and service management. Its defining characteristic is that everything must be derived from an analysis of business requirements for security, especially where security functions as a business enabler rather than a constraint. Wikipedia
Those framing matters. Most certification programmes teach practitioners to implement controls. SABSA teaches them to justify controls in terms a board will understand and a regulator will accept. SABSA certification is a mandatory requirement for Security Architects and Enterprise Architects in numerous large-scale national financial sector bodies globally. The SABSA Institute In industries where accountability has teeth, that distinction is not academic.
SABSA Chartered Architects are now present in 84 countries. Flashgenius The advanced examinations are assignment-based. Candidates must produce original work applied to real environments. There is no shortcut through memorisation at that level, because the exam is not asking what you know. It is asking whether you can build something that works.
The Compounding Effect Nobody Mentions
The anti-certification argument consistently underweights one thing: credentials do not operate alone. They sit inside a professional trajectory. A practitioner who earns a Security+ and stops there has made a different career choice than one who uses it as a foundation for ISACA’s CRISC, builds toward CISM, then pursues SABSA Foundation to connect security design to demonstrable business outcomes. The certificate is not the destination. It is a checkpoint with evidence attached. What happens next depends entirely on the person holding it, and that ambition is not diminished by the fact that a formal credential started the journey.
The field rewards compounding. A practitioner who studies formally, applies the knowledge, identifies where theory met reality badly, returns to structured learning to close that gap, then earns the next credential, that person is not diluting expertise. They are building it in layers. And layers hold better than instinct alone when something goes wrong at 2 a.m. and you need more than muscle memory.
The Thing Raw Talent Cannot Fix
There is a version of cybersecurity expertise that lives entirely inside one person’s head and cannot be transmitted under pressure. The brilliant self-taught operator who has never been required to articulate reasoning within a shared framework can be extraordinary as an individual contributor and genuinely dangerous as a team lead in a crisis, when communication and shared methodology matter as much as technical instinct, sometimes more. Certifications solve something experience alone does not. They create common language. When a CISO references ISO 27001 alignment or an audit committee asks about COBIT governance, everyone in the room who holds relevant ISACA credentials understands not just the words but the architecture beneath them. Almost 60% of respondents in ISC2’s 2024 study agreed that skills gaps had significantly impacted their organisation’s ability to maintain security posture. ISC2 That gap is not just in bodies. It is in shared frameworks. And shared frameworks are one of the few things you can actually teach at scale.
The Ceiling Keeps Moving. So Should the Profession.
The dilution argument assumes cybersecurity has a fixed ceiling. It does not, and the ceiling keeps moving. Cloud infrastructure, AI-driven threat detection, zero-trust architecture, operational technology security, quantum-resistant cryptography, these are not incremental additions to a stable discipline. They are entire new domains, each demanding specialised knowledge, each producing its own credentialling pathways. Addressing skills shortages within existing teams is now considered more critical than simply adding more people. ISC2 That shift in priority is not an argument against certification. It is the argument for it, made by the professionals inside the field.
More people entering the field with verifiable, structured knowledge is not dilution. It is a profession finally meeting the scale of the problem it was always supposed to solve.
What This Is Actually About
Back to that Tuesday email. The hiring manager who passed on the experienced candidate because of a missing CISM or CISSP was not wrong to value the credential. She may have been wrong in how she weighted it against seven years of demonstrated competence. That tension, between verified knowledge and lived experience, is real, and anyone who pretends it resolves cleanly in one direction is selling something. The honest position is this: certifications are not a substitute for experience. They are not a talent guarantee. What they are, at their best, is evidence that someone understood what this field demands, engaged with it seriously, and submitted themselves to external verification, often while working full-time, often at personal cost, and always with their name attached to the result.
That is not the behaviour of someone watering down a profession.
It is the behaviour of someone who decided the profession was worth the effort.
And in an industry where the cost of getting it wrong looks like Change Healthcare in February 2024, a single ransomware attack on a payment processing subsidiary that disrupted claims across 900,000 physicians, 33,000 pharmacies, and 5,500 hospitals, touching roughly one in three patient records across the United States, BlackFog that effort is not a minor thing.
It is, in fact, the whole point.
#Cybersecurity #CISM #ISACA #CISSP #ISC2 #SABSA #CyberCareers #CISOmindset


