What areas of cybersecurity are underexplored or under-taught?
I’ve been researching what actually helps people become effective cybersecurity professionals.
A lot of the discussion focuses on technical skills: pentesting, tools, certs, CTFs, SIEMs, etc.
But I keep seeing gaps around things like:
communicating with non-technical people
understanding business risk
executive escalation
audits & governance
knowing when NOT to act
risk acceptance
networking with people
understanding how security fits into the wider organisation
strong IT fundamentals
What areas of cybersecurity do you think are seriously underexplored or under-taught?
Especially areas that matter in real jobs but don’t get much attention in education.