According to recent research, there are approximately 4.8 million cybersecurity-related vacancies globally—and over 3 million of them are in the Asia-Pacific (APAC) region. This significant gap of talent is particularly impacting operational technology (OT) environments, where the convergence of information technology (IT) and OT introduces unique vulnerabilities and additional risks.
Beyond just the sheer numbers of people needed to fill critical cybersecurity roles, there is also the challenge of finding candidates with the right skill sets. The skills shortage is amplified by the ongoing adoption of artificial intelligence (AI), which is causing greater complexity and driving an increased need for interdisciplinary expertise. Besides OT and IT skills, ideal candidates would now also have knowledge of product security, cyber compliance and governance, and AI, which, unfortunately, is a rare combination today.
Building a talent pool beyond cyber-only roles
To combat the talent and skills gap, companies can broaden the definition of cybersecurity roles and look for unique ways to build local talent pools that are skilled enough to protect critical infrastructures.
It’s also important to recognize that the talent needed today may already exist within a company’s workforce. A strong strategy is needed for bridging cybersecurity talent and skills gaps—for example, by providing internal platforms for training and career development so that employees can begin or enhance their cybersecurity career paths.
Key talent practices include:
- Cross-training for versatility: We recognize cybersecurity is no longer a siloed discipline—it intersects with engineering, data science and governance. Through cross-training opportunities, people can combine OT, IT and AI technical skills with soft skills such as critical thinking, risk assessment and AI ethics.
- Reskilling mid-career professionals: Organizations may encourage longer-term employees to consider career shifts where they can become valuable cybersecurity assets through structured upskilling programs.
- Demystify cybersecurity careers: Cybersecurity is a multidisciplinary field with a societal impact. Consider the impact of offering diverse career paths that may begin in many different areas, such as critical infrastructure management, legal and project security roles.
Designing a clear talent architecture for OT security
To support the need for hybrid expertise in professionals who understand OT systems, cybersecurity principles and AI governance, build a structured talent architecture that defines:
- Skill pathways and competency frameworks: While we did this internally on our own, in the APAC region, Singapore’s OT Cybersecurity Competency Framework (OTCCF) provides a model with clear career development tracks for OT cybersecurity professionals. Our model encourages people to combine formal education with on-the-job training, ensuring alignment with global standards like the ISA/IEC 62443 series of standards and the National Institute of Standards and Technology’s (NIST) AI Risk Management Framework.
- Inclusive talent strategies: Because the talent gap has broadened recruitment beyond traditional cyber profiles, focus has expanded to characteristics such as adaptability, critical thinking and the ability to handle emergencies, as well as other skills that can be nurtured through reskilling programs.
- Retention mechanisms: Keep talent engaged and growing by providing mentoring programs, grants for advanced degrees and talent mobility platforms for internal hiring and recruiting.
- Cross-border education and certification: Cybersecurity credentials lack standardization across geographies, which can hinder the recruitment process with foreign nationals. It can be beneficial to be aware of local cybersecurity certifications when hiring people from other countries is an option.
Embedding trust in any use of AI, including within cybersecurity roles
When considering the role of AI for cybersecurity, governance is a topic that can’t be ignored. There is no doubt that AI offers transformative benefits that can improve operational resilience and reduce risk—and that it will play an important role for today’s cybersecurity talent.
In fact, a recent study found that 97% of organizations are either already using or plan to implement AI-enabled cybersecurity solutions, with threat detection and prevention cited as the top areas of interest for applying AI in cybersecurity. AI is also being used to educate and improve overall cyber skills and knowledge to support both protect and defend mechanisms. The study found that 87% of cybersecurity professionals expect AI to enhance their roles, rather than replace them, offering efficiency and relief amid skills shortages.
While AI can be highly effective in cybersecurity, organizations should embrace its benefits without trusting it blindly and set up some guardrails. Building trust in AI requires human oversight for AI outputs, particularly in critical infrastructure, training that enables employees to use these technologies responsibly, and assurance mechanisms embedded throughout deployment that are guided by frameworks such as the NIST Framework, the U.S. National Security Agency’s Artificial Intelligence Security Center (AISC) guidance and relevant government regulations and publications.
Most importantly, AI must be considered as a strategic tool, not as a skilled decision-making machine that can be trusted to protect human lives.
Creating a strong security posture
Closing the OT cybersecurity talent and skills gap in APAC will not be achieved by incremental hires or isolated training programs alone. It requires a deliberate shift in how organizations design roles, develop people and govern the use of technologies such as AI.
Leaders across industry, government and academia must collaborate to rethink talent pipelines, embrace nontraditional career pathways and invest in structured reskilling at scale while embedding strong governance and trust in every AI deployment.
Now is the time to act: to modernize OT cybersecurity talent strategies, participate in local and regional ecosystems and help shape standards, frameworks and partnerships that will secure critical infrastructure for decades to come. The future resilience of our digital and industrial economy depends on it.
