Summary
The core message of the provided transcript is that Europe’s cybersecurity skills challenge is not simply a headcount problem: it is also a matching problem involving specific roles, shared language, education-to-work transitions, and national differences. Moderator Liesbeth Holterman framed the panel through Dutch and European human-capital initiatives, including the Dutch Cybersecurity Skills Programme, NCC-NL connections, the Cyberhub, and ENISA’s European Cybersecurity Skills Framework. The panel brought together perspectives from ENISA, Digital Europe, Security Delta, and Estonia’s NCC to examine whether the long-discussed skills gap is changing and how Europe can respond more precisely.
Mark argued first that the gap is “a bit of both”: Europe needs more cybersecurity specialists, but also better security skills in adjacent roles such as software development. His example was that if coders produced fewer security risks, fewer specialist resources would be needed to fix or defend legacy and vulnerable systems. Evangelos then explained that the skills gap has persisted because cybersecurity keeps expanding in importance, while earlier role claims such as CSO or penetration tester lacked a common assurance framework. ENISA’s European Cybersecurity Skills Framework was presented as a deliberately simple, high-level tool with 12 profiles, designed to create a shared vocabulary, help identify high-demand roles such as penetration tester and incident responder, and eventually support mobility across European countries.
The discussion then moved from frameworks to evidence. When the audience was asked who knew and used the framework, awareness existed but active use was more limited, leaving “room for development.” Tiina added that awareness of the gap has increased, but pointed to a sharper bottleneck: students and juniors are finding it increasingly difficult to secure internships and first cybersecurity jobs. This creates a contradiction, because organisations say they need more professionals while hesitating to hire the very juniors who could become future seniors.
Alexia described Cyberhub as an Erasmus-funded project connecting industry, academia, and public authorities across seven hubs, with an eighth being established in Italy. Its skills-needs analysis, based on the ECSF, examined more than 4,300 cybersecurity vacancies and found diverse demand: cybersecurity implementer appeared in more than 1,300 vacancies, architect in almost 1,000, and risk manager close to 700. She concluded that Europe should focus less on a generic shortage narrative and more on skills intelligence: matching the right skills to the right place at the right moment. The provided transcript ends while Tiina is explaining why university programmes give general knowledge, while workplaces often demand position-specific skills.
Key Topics
5 key topics from Liesbeth Holterman, Mark Ruijsendaal, Evangelos Ouzounis, Alexia Papadimitriou and Tiina Pau at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Use ECSF profiles to define roles and training needs clearly.
- Create junior pathways before expecting future senior cybersecurity talent.
- Match curricula to workplace-specific skills through industry-academia collaboration.
- Base workforce planning on vacancy data, not generic shortage narratives.
- Localize skills strategies because national ecosystems have different needs.
“do we have the right skills in the right place at the right moment?”
Up Next

Next in agenda
The pre-intrusion layer
Andriy Kusyy


Also on european policy
Catch up to keep up: how to connect cybersecurity, AI, and the economy to rebuild our basis?



Related
