Career Overlap Transition record Edition 1 · ESCO v1.2.1
Table 1Transition record

cyber incident respondertochief ICT security officer

A cyber incident responder already meets 42% of what the chief ICT security officer role asks for. The move turns on 27 required skills not yet in the profile.

From cyber incident responder
42%
Overlap1
To chief ICT security officer
34 Skills carried over
27 Required, not held
71.5 Difficulty2
Career overlap Partial match

42%

Learning distance Substantial retraining

71.5/ 100

1 Share of the chief ICT security officer role’s weighted skill requirement already met by the cyber incident responder profile. Required skills count in full, supplementary skills at 0.35. Directional: the figure for the reverse move differs. 2 Combines what is missing with how specialised it is, so a gap of general skills scores easier than the same number of narrow ones.

Why

Why this move works

A chief ICT security officer role treats 20 of its required skills as things a cyber incident responder already does. These are the ones it depends on most.

  • ICT network security risks
  • ICT process quality models
  • ICT project management methodologies
  • ICT safety
  • ICT security legislation
  • ICT security standards

What stands in the way is 27 required skills the profile does not yet cover. Table 3 groups them; Table 4 says which to take first.

Table 2

Table 2 · What you already bring

Of the 34 skills that carry over, these are the ones fewest other occupations ask for. A chief ICT security officer role needs them, and most people applying for one will not have them already. This is the part of a cyber incident responder background worth leading with.

Skill the target role also needs Area
  • already held manage digital identity core skills and competences
  • already held engage with stakeholders communication, collaboration and creativity
  • already held lead disaster recovery exercises management skills
  • already held web application security threats information and communication technologies (icts)
  • already held ICT safety working with computers
  • already held ethical hacking principles information and communication technologies (icts)

All 34 carried skills, including the 20 the chief ICT security officer role treats as required.

Table 3

Table 3 · What you would need to learn

The 47 missing skills fall into 10 areas of the ESCO skill hierarchy, numbered below in the order worth working in: the areas carrying the most required skills come first, and inside each one the required skills sit above the supplementary ones.

Skill to acquire Tier
01 information skills 5 required, 4 supplementary
  • required, not held advice on security risk management required
  • required, not held identify ICT security risks required
  • required, not held forecast organisational risks required
  • required, not held monitor developments in field of expertise required
  • required, not held monitor technology trends required
  • optional, not held execute ICT audits optional
  • optional, not held implement cloud security and compliance optional
  • optional, not held conduct impact evaluation of ICT processes on business optional
  • optional, not held identify legal requirements optional
02 assisting and caring 5 required, 1 supplementary
  • required, not held ensure adherence to organisational ICT standards required
  • required, not held ensure information privacy required
  • required, not held establish an Information Security Management System required
  • required, not held comply with legal regulations required
  • required, not held ensure compliance with legal requirements required
  • optional, not held apply operations for an ITIL-based environment optional
03 information and communication technologies (icts) 4 required, 6 supplementary
  • required, not held data protection required
  • required, not held decision support systems required
  • required, not held information confidentiality required
  • required, not held assessment of risks and threats required
  • optional, not held ICT recovery techniques optional
  • optional, not held ICT system user requirements optional
  • optional, not held computer forensics optional
  • optional, not held software anomalies optional
  • optional, not held World Wide Web Consortium standards optional
  • optional, not held computer programming optional
04 business, administration and law 4 required
  • required, not held ICT project management required
  • required, not held internal risk management policy required
  • required, not held organisational resilience required
  • required, not held audit techniques required
05 communication, collaboration and creativity 3 required, 3 supplementary
  • required, not held implement corporate governance required
  • required, not held educate on data confidentiality required
  • required, not held ensure cross-department cooperation required
  • optional, not held create solutions to problems optional
  • optional, not held train employees optional
  • optional, not held use different communication channels optional
06 management skills 3 required, 3 supplementary
  • required, not held establish an ICT security prevention plan required
  • required, not held maintain plan for continuity of operations required
  • required, not held manage disaster recovery plans required
  • optional, not held assess ICT knowledge optional
  • optional, not held coordinate technological activities optional
  • optional, not held manage staff optional

4 further areas in the appendix

Table 4

Table 4 · Where to start

The 3 entries a chief ICT security officer role is least likely to hire without. The ordering is computed from the skill data, not from what pays.

Each entry opens a course search for that skill. Career Overlap earns nothing from these links.

Appendix

Appendix · The rest of the record

All 34 skills that carry over
Skill Type
  • already held ICT network security risks knowledge
  • already held ICT process quality models knowledge
  • already held ICT project management methodologies knowledge
  • already held ICT safety skill
  • already held ICT security legislation knowledge
  • already held ICT security standards knowledge
  • already held attack vectors knowledge
  • already held communicate with stakeholders skill
  • already held cyber attack counter-measures knowledge
  • already held cyber security knowledge
  • already held develop information security strategy skill
  • already held engage with stakeholders skill
  • already held ethical hacking principles knowledge
  • already held implement ICT risk management skill
  • already held implement ICT security policies skill
  • already held information security strategy knowledge
  • already held lead disaster recovery exercises skill
  • already held manage IT security compliances skill
  • already held risk management knowledge
  • already held security engineering knowledge
  • already held ICT encryption knowledge
  • already held Internet of Things knowledge
  • already held cloud monitoring and reporting knowledge
  • already held cloud security and compliance knowledge
  • already held cloud technologies knowledge
  • already held implement a firewall skill
  • already held implement a virtual private network skill
  • already held implement anti-virus software skill
  • already held internet governance knowledge
  • already held manage digital identity skill
  • already held manage keys for data protection skill
  • already held optimise choice of ICT solution skill
  • already held protect personal data and privacy skill
  • already held web application security threats knowledge
The 4 learning areas not shown above
Skill to acquire Tier
07 working with computers 2 required
  • required, not held manage system security required
  • required, not held utilise decision support system required
08 arts and humanities 1 required
  • required, not held ethics required
09 engineering, manufacturing and construction 2 supplementary
  • optional, not held ICT communications protocols optional
  • optional, not held ICT infrastructure optional
10 social sciences, journalism and information 1 supplementary
  • optional, not held control objectives for information and related technology optional
20 supplementary skills, helpful but not required
Skill to acquire Tier
  • optional, not held apply operations for an ITIL-based environment optional
  • optional, not held control objectives for information and related technology optional
  • optional, not held ICT communications protocols optional
  • optional, not held ICT infrastructure optional
  • optional, not held ICT recovery techniques optional
  • optional, not held ICT system user requirements optional
  • optional, not held assess ICT knowledge optional
  • optional, not held computer forensics optional
  • optional, not held coordinate technological activities optional
  • optional, not held execute ICT audits optional
  • optional, not held implement cloud security and compliance optional
  • optional, not held software anomalies optional
  • optional, not held World Wide Web Consortium standards optional
  • optional, not held computer programming optional
  • optional, not held conduct impact evaluation of ICT processes on business optional
  • optional, not held create solutions to problems optional
  • optional, not held identify legal requirements optional
  • optional, not held manage staff optional
  • optional, not held train employees optional
  • optional, not held use different communication channels optional
41 held skills the chief ICT security officer role does not ask for
Skill Type
  • not needed by the target role C++ knowledge
  • not needed by the target role GDPR knowledge
  • not needed by the target role Process-based management knowledge
  • not needed by the target role Python (computer programming) knowledge
  • not needed by the target role building systems monitoring technology knowledge
  • not needed by the target role business intelligence knowledge
  • not needed by the target role collect cyber defence data skill
  • not needed by the target role consult with business clients skill
  • not needed by the target role copyright legislation knowledge
  • not needed by the target role create incident reports skill
  • not needed by the target role create project specifications skill
  • not needed by the target role defence standard procedures knowledge
  • not needed by the target role define quality standards skill
  • not needed by the target role embedded systems knowledge
  • not needed by the target role ensure information security skill
  • not needed by the target role ensure proper document management skill
  • not needed by the target role give live presentation skill
  • not needed by the target role handle cybersecurity incidents skill
  • not needed by the target role implement spam protection skill
  • not needed by the target role incidents and accidents recording knowledge
  • not needed by the target role leadership principles knowledge
  • not needed by the target role lean project management knowledge
  • not needed by the target role manage ICT change request process skill
  • not needed by the target role manage a team skill
  • not needed by the target role manage changes in ICT system skill
  • not needed by the target role monitor system performance skill
  • not needed by the target role operating systems knowledge
  • not needed by the target role operational tactics for emergency responses knowledge
  • not needed by the target role perform project management skill
  • not needed by the target role perform risk analysis skill
  • not needed by the target role perform scientific research skill
  • not needed by the target role project management knowledge
  • not needed by the target role protect ICT devices skill
  • not needed by the target role provide ICT consulting advice skill
  • not needed by the target role provide information skill
  • not needed by the target role provide user documentation skill
  • not needed by the target role remove computer virus or malware from a computer skill
  • not needed by the target role safety engineering knowledge
  • not needed by the target role security threats knowledge
  • not needed by the target role track key performance indicators skill

1 further entry not listed here

18 gaps that are knowledge rather than practice

Knowledge gaps usually close through study. Practical skill gaps usually need something you can point at.

Skill to acquire Tier
  • required, not held ICT project management required
  • required, not held data protection required
  • required, not held decision support systems required
  • required, not held information confidentiality required
  • required, not held internal risk management policy required
  • required, not held organisational resilience required
  • required, not held assessment of risks and threats required
  • required, not held audit techniques required
  • required, not held ethics required
  • optional, not held control objectives for information and related technology optional
  • optional, not held ICT communications protocols optional
  • optional, not held ICT infrastructure optional
  • optional, not held ICT recovery techniques optional
  • optional, not held ICT system user requirements optional
  • optional, not held computer forensics optional
  • optional, not held software anomalies optional
  • optional, not held World Wide Web Consortium standards optional
  • optional, not held computer programming optional
Index
Note

How this record was compiled

Both occupations are taken from ESCO, which lists the skills and knowledge each occupation is expected to have and marks every one required or optional. Nothing here is a prediction about hiring, and nothing here knows that a particular employer wants a particular certificate. Treat Table 3 as a starting point for your own research rather than a syllabus. The full method states what these figures can and cannot tell you.