Career Overlap Transition record Edition 1 · ESCO v1.2.1
Table 1Transition record

digital forensics experttocyber incident responder

A digital forensics expert already meets 34% of what the cyber incident responder role asks for. The move turns on 11 required skills not yet in the profile.

From digital forensics expert
34%
Overlap1
To cyber incident responder
18 Skills carried over
11 Required, not held
73.7 Difficulty2
Career overlap Distant match

34%

Learning distance Substantial retraining

73.7/ 100

1 Share of the cyber incident responder role’s weighted skill requirement already met by the digital forensics expert profile. Required skills count in full, supplementary skills at 0.35. Directional: the figure for the reverse move differs. 2 Combines what is missing with how specialised it is, so a gap of general skills scores easier than the same number of narrow ones.

Why

Why this move works

A cyber incident responder role treats 12 of its required skills as things a digital forensics expert already does. These are the ones it depends on most.

  • GDPR
  • ICT network security risks
  • ICT security legislation
  • ICT security standards
  • attack vectors
  • collect cyber defence data

What stands in the way is 11 required skills the profile does not yet cover. Table 3 groups them; Table 4 says which to take first.

Table 2

Table 2 · What you already bring

Of the 18 skills that carry over, these are the ones fewest other occupations ask for. A cyber incident responder role needs them, and most people applying for one will not have them already. This is the part of a digital forensics expert background worth leading with.

Skill the target role also needs Area
  • already held collect cyber defence data information skills
  • already held GDPR business, administration and law
  • already held operating systems information and communication technologies (icts)
  • already held develop information security strategy assisting and caring
  • already held cyber attack counter-measures services
  • already held ICT encryption information and communication technologies (icts)

All 18 carried skills, including the 12 the cyber incident responder role treats as required.

Table 3

Table 3 · What you would need to learn

The 57 missing skills fall into 13 areas of the ESCO skill hierarchy, numbered below in the order worth working in: the areas carrying the most required skills come first, and inside each one the required skills sit above the supplementary ones.

Skill to acquire Tier
01 working with computers 2 required, 8 supplementary
  • required, not held ICT safety required
  • required, not held protect ICT devices required
  • optional, not held implement a firewall optional
  • optional, not held implement a virtual private network optional
  • optional, not held implement anti-virus software optional
  • optional, not held implement spam protection optional
  • optional, not held manage changes in ICT system optional
  • optional, not held manage keys for data protection optional
  • optional, not held optimise choice of ICT solution optional
  • optional, not held remove computer virus or malware from a computer optional
02 communication, collaboration and creativity 2 required, 4 supplementary
  • required, not held communicate with stakeholders required
  • required, not held engage with stakeholders required
  • optional, not held consult with business clients optional
  • optional, not held give live presentation optional
  • optional, not held provide user documentation optional
  • optional, not held troubleshoot optional
03 information and communication technologies (icts) 1 required, 8 supplementary
  • required, not held ethical hacking principles required
  • optional, not held C++ optional
  • optional, not held ICT process quality models optional
  • optional, not held Internet of Things optional
  • optional, not held Python (computer programming) optional
  • optional, not held cloud monitoring and reporting optional
  • optional, not held cloud security and compliance optional
  • optional, not held internet governance optional
  • optional, not held web application security threats optional
04 business, administration and law 1 required, 6 supplementary
  • required, not held risk management required
  • optional, not held ICT project management methodologies optional
  • optional, not held Process-based management optional
  • optional, not held lean project management optional
  • optional, not held project management optional
  • optional, not held business intelligence optional
  • optional, not held copyright legislation optional
05 information skills 1 required, 5 supplementary
  • required, not held create incident reports required
  • optional, not held implement ICT risk management optional
  • optional, not held ensure proper document management optional
  • optional, not held perform risk analysis optional
  • optional, not held perform scientific research optional
  • optional, not held track key performance indicators optional
06 assisting and caring 1 required, 3 supplementary
  • required, not held handle cybersecurity incidents required
  • optional, not held ensure information security optional
  • optional, not held protect personal data and privacy optional
  • optional, not held provide information optional

7 further areas in the appendix

Table 4

Table 4 · Where to start

The 3 entries a cyber incident responder role is least likely to hire without. The ordering is computed from the skill data, not from what pays.

Each entry opens a course search for that skill. Career Overlap earns nothing from these links.

Appendix

Appendix · The rest of the record

All 18 skills that carry over
Skill Type
  • already held GDPR knowledge
  • already held ICT network security risks knowledge
  • already held ICT security legislation knowledge
  • already held ICT security standards knowledge
  • already held attack vectors knowledge
  • already held collect cyber defence data skill
  • already held cyber attack counter-measures knowledge
  • already held cyber security knowledge
  • already held operating systems knowledge
  • already held provide ICT consulting advice skill
  • already held security engineering knowledge
  • already held security threats knowledge
  • already held ICT encryption knowledge
  • already held cloud technologies knowledge
  • already held develop information security strategy skill
  • already held implement ICT security policies skill
  • already held information security strategy knowledge
  • already held manage IT security compliances skill
The 7 learning areas not shown above
Skill to acquire Tier
07 engineering, manufacturing and construction 1 required, 2 supplementary
  • required, not held building systems monitoring technology required
  • optional, not held embedded systems optional
  • optional, not held safety engineering optional
08 services 1 required, 1 supplementary
  • required, not held incidents and accidents recording required
  • optional, not held defence standard procedures optional
09 health and welfare 1 required
  • required, not held operational tactics for emergency responses required
10 management skills 6 supplementary
  • optional, not held lead disaster recovery exercises optional
  • optional, not held manage ICT change request process optional
  • optional, not held create project specifications optional
  • optional, not held define quality standards optional
  • optional, not held manage a team optional
  • optional, not held perform project management optional
11 constructing 1 supplementary
  • optional, not held monitor system performance optional
12 core skills and competences 1 supplementary
  • optional, not held manage digital identity optional
13 generic programmes and qualifications 1 supplementary
  • optional, not held leadership principles optional
46 supplementary skills, helpful but not required
Skill to acquire Tier
  • optional, not held C++ optional
  • optional, not held ICT process quality models optional
  • optional, not held ICT project management methodologies optional
  • optional, not held Internet of Things optional
  • optional, not held Process-based management optional
  • optional, not held Python (computer programming) optional
  • optional, not held cloud monitoring and reporting optional
  • optional, not held cloud security and compliance optional
  • optional, not held consult with business clients optional
  • optional, not held defence standard procedures optional
  • optional, not held embedded systems optional
  • optional, not held implement ICT risk management optional
  • optional, not held implement a firewall optional
  • optional, not held implement a virtual private network optional
  • optional, not held implement anti-virus software optional
  • optional, not held implement spam protection optional
  • optional, not held internet governance optional
  • optional, not held lead disaster recovery exercises optional
  • optional, not held lean project management optional
  • optional, not held manage ICT change request process optional
  • optional, not held manage changes in ICT system optional
  • optional, not held manage keys for data protection optional
  • optional, not held monitor system performance optional
  • optional, not held optimise choice of ICT solution optional
  • optional, not held project management optional
  • optional, not held web application security threats optional
  • optional, not held business intelligence optional
  • optional, not held copyright legislation optional
  • optional, not held create project specifications optional
  • optional, not held define quality standards optional
  • optional, not held ensure information security optional
  • optional, not held ensure proper document management optional
  • optional, not held give live presentation optional
  • optional, not held leadership principles optional
  • optional, not held manage a team optional
  • optional, not held manage digital identity optional
  • optional, not held perform project management optional
  • optional, not held perform risk analysis optional
  • optional, not held perform scientific research optional
  • optional, not held protect personal data and privacy optional

6 further entries not listed here

59 held skills the cyber incident responder role does not ask for
Skill Type
  • not needed by the target role Aircrack (penetration testing tool) knowledge
  • not needed by the target role Backbox (penetration testing tool) knowledge
  • not needed by the target role BlackArch knowledge
  • not needed by the target role Cain and Abel (penetration testing tool) knowledge
  • not needed by the target role ICT infrastructure knowledge
  • not needed by the target role John The Ripper (penetration testing tool) knowledge
  • not needed by the target role Kali Linux knowledge
  • not needed by the target role LDAP knowledge
  • not needed by the target role LINQ knowledge
  • not needed by the target role MDX knowledge
  • not needed by the target role Maltego knowledge
  • not needed by the target role Metasploit knowledge
  • not needed by the target role N1QL knowledge
  • not needed by the target role Nessus knowledge
  • not needed by the target role Nexpose knowledge
  • not needed by the target role OWASP ZAP knowledge
  • not needed by the target role Parrot Security OS knowledge
  • not needed by the target role SPARQL knowledge
  • not needed by the target role Samurai Web Testing Framework knowledge
  • not needed by the target role THC Hydra knowledge
  • not needed by the target role WhiteHat Sentinel knowledge
  • not needed by the target role Wireshark knowledge
  • not needed by the target role XQuery knowledge
  • not needed by the target role analyse network configuration and performance skill
  • not needed by the target role apply reverse engineering skill
  • not needed by the target role audit techniques knowledge
  • not needed by the target role check methods knowledge
  • not needed by the target role computer forensics knowledge
  • not needed by the target role data storage knowledge
  • not needed by the target role design computer network skill
  • not needed by the target role digital data processing skill
  • not needed by the target role educate on data confidentiality skill
  • not needed by the target role establish an ICT security prevention plan skill
  • not needed by the target role forensic intelligence knowledge
  • not needed by the target role gather data for forensic purposes skill
  • not needed by the target role hardware architectures knowledge
  • not needed by the target role hardware platforms knowledge
  • not needed by the target role identify ICT security risks skill
  • not needed by the target role identify ICT system weaknesses skill
  • not needed by the target role implement ICT network diagnostic tools skill

19 further entries not listed here

23 gaps that are knowledge rather than practice

Knowledge gaps usually close through study. Practical skill gaps usually need something you can point at.

Skill to acquire Tier
  • required, not held building systems monitoring technology required
  • required, not held ethical hacking principles required
  • required, not held incidents and accidents recording required
  • required, not held operational tactics for emergency responses required
  • required, not held risk management required
  • optional, not held C++ optional
  • optional, not held ICT process quality models optional
  • optional, not held ICT project management methodologies optional
  • optional, not held Internet of Things optional
  • optional, not held Process-based management optional
  • optional, not held Python (computer programming) optional
  • optional, not held cloud monitoring and reporting optional
  • optional, not held cloud security and compliance optional
  • optional, not held defence standard procedures optional
  • optional, not held embedded systems optional
  • optional, not held internet governance optional
  • optional, not held lean project management optional
  • optional, not held project management optional
  • optional, not held web application security threats optional
  • optional, not held business intelligence optional
  • optional, not held copyright legislation optional
  • optional, not held leadership principles optional
  • optional, not held safety engineering optional
Index
Note

How this record was compiled

Both occupations are taken from ESCO, which lists the skills and knowledge each occupation is expected to have and marks every one required or optional. Nothing here is a prediction about hiring, and nothing here knows that a particular employer wants a particular certificate. Treat Table 3 as a starting point for your own research rather than a syllabus. The full method states what these figures can and cannot tell you.