Threat feed liveUpdated — 01.08.2026 10:21 CET72 dossiersMITRE ATT&CK mappingThreat feed liveUpdated — 01.08.2026 10:21 CET72 dossiersMITRE ATT&CK mapping

Editorial explainer · official ENISA framework (ECSF) and ACN statements as reported by the presslow

Who defends: why cybersecurity is not a job only for computer scientists

On 31 July 2026 Italy's National Cybersecurity Agency returned to a point it has made for years: attacks against public administrations, hospitals, businesses and strategic infrastructure are growing, and there are not enough people to counter them. The less obvious part of the statement concerns who can do the work: not only computer scientists and engineers, but also lawyers, economists, communicators and psychologists. That is not rhetorical generosity. It is a description of how the job actually works, and it matches the map ENISA built in its European skills framework, where cybersecurity professional profiles number twelve and most of them do not write code.

The wrong image that keeps the right people away

Ask someone to picture a person who works in cybersecurity. In the vast majority of cases you get the same figure: someone alone in front of a black screen, typing commands. That image has done specific damage, because it carries an implicit message: if you cannot program, this is not for you.

On 31 July 2026 Italy's National Cybersecurity Agency (ACN) returned publicly to the subject. The picture is by now familiar: rising attacks against public administrations, hospitals, companies and strategic infrastructure, and too few professionals to counter them. The part worth picking up, though, is different, and the agency chose to make it explicit: the sector has room for not only computer scientists and engineers, but also lawyers, economists, communicators and psychologists.

One thing about sourcing, because it matters: this statement, attributed to ACN deputy director general Nunzia Ciardi, reaches us through press and news-agency coverage. We did not verify it on an ACN institutional page. We report it as a reported statement, not as an official document — and the rest of this article rests on a framework that is published and consultable.

The map that already exists: the European skills framework

The proof that the sentence is not rhetoric sits in a document nobody outside the field reads: ENISA's European Cybersecurity Skills Framework (ECSF). It is Europe's attempt to answer a simple question — which occupations, exactly, make up cybersecurity? — and the answer is twelve professional profiles, each with its tasks, skills and knowledge described.

What jumps out scanning that list is that most of those profiles do not have writing code as their main activity. Some assess regulatory compliance. Some design and run the security programme. Some deliver training and awareness. Some conduct audits. Some work on threat intelligence, which is largely analysis and writing. Some coordinate incident response, which is managing people under pressure before it is anything technical.

  1. 01
    Technical profiles
    forensics, incident response, penetration testing, architecture
  2. 02
    Governance profiles
    risk management, compliance, audit, chief information security officer
  3. 03
    Relational profiles
    training, awareness, intelligence, crisis coordination

ENISA went a step further in June 2025 by publishing Cybersecurity roles and skills for NIS2 Essential and Important Entities: a document mapping NIS2 obligations onto ECSF profiles. Put plainly: it takes a legal text and answers the question "to do this, what kind of person do you need?". That translation between law and org chart is usually missing.

Why the other disciplines are genuinely needed

This is not about inclusivity: without those skills, certain things cannot be done at all.

Lawyers. A significant incident triggers notification duties with deadlines measured in hours, to different recipients, under different rules — NIS2, GDPR, sector regulation. Whoever decides whether a notification is due, to whom and in what words is making a legal decision under time pressure. Getting it wrong has consequences that excellent technical handling does not offset.

Economists. Security is materially an allocation problem: finite budget, many risks, controls that cost differently and return differently. Someone has to be able to argue for that investment rather than another, in a language the board actually hears. It is a scarce skill, and visibly so.

Communicators. During a serious incident the organisation speaks: to customers, employees, regulators, the press. What is said in the first hours determines much of the reputational damage and, sometimes, the legal exposure. Crisis communication is a profession, and improvising it is a reliable way to make an ongoing incident worse.

Psychologists. Social engineering does not attack systems, it attacks people: it exploits urgency, authority, fear, the wish to be helpful. Understanding why an absurd request gets carried out is behavioural science. And there is a second, less discussed front: the psychological load on the people who handle incidents, with shifts, night alerts and an attrition rate that is high in this field.

The other side, said honestly

It would be dishonest to turn all this into "anyone can work in cybersecurity knowing nothing about technology". That is not true, and telling it that way sets people up for disappointment.

Non-technical roles still require real technical literacy: understanding how a network works, what a digital identity is, how an attack spreads, why a backup can be useless. Without that base, a lawyer writes unenforceable clauses and a communicator states things the facts contradict three days later.

The honest formulation is this: the job requires a domain skill plus a baseline technical skill, and the first is not replaceable by the second. For most organisations, a good compliance lead with solid technical grounding is worth more than an excellent engineer who does not know what the law requires.

What to do with this, concretely

If you are choosing a path: look at the ECSF before deciding this field is not for you. The twelve profiles are described with tasks and skills: it dismantles the black-screen image better than any article can.

If you are hiring: a security post described only through technical certifications selects only one kind of candidate. If the actual role is risk governance, writing it as a technical role is the most effective way not to find the person you need — and then to conclude that "there are no candidates".

If you already work in the organisation in another role: the lateral route is the most travelled and the least advertised. Someone who knows an organisation's processes holds an advantage no course transfers, because most security decisions are process decisions dressed as technical ones.

A note on sources: the skills framework and the NIS2 mapping are published, verifiable ENISA documents. The ACN statements of 31 July 2026 reach us through journalistic coverage: we attributed them as such, without turning them into a documented institutional position.

More dossiers