Heading image for CyberPath can get the framework right and still get the system wrong

What the image represents

He wrote a thousand pages telling people what to do, then stood there baffled when their deadlines, budgets and bonuses told them to do something else.

I read the CyberPath Occupational Framework and Capability Framework because I wanted to understand how the Professionalisation Consortium is thinking about genuine cyber capability. The work is strong. It is thoughtful about occupations, roles, skills, experience and competence, and it is clearly trying to move beyond weak proxies such as qualifications, job titles and theoretical knowledge.

But there is a problem hiding underneath that strength.

CyberPath is very good at describing the objects in the workforce system. It is much less developed on the agents inside it: employers, candidates, universities, RTOs, recruiters, certification providers and government. More importantly, it does not yet go far enough in asking what each of those actors is trying to optimise for, and what happens when their local incentives collide with the outcome CyberPath is trying to create.

That matters because CyberPath’s biggest risk may not be that people reject it.

It may be that they embrace it.

Imagine CyberPath creates a technically perfect definition of a competent cyber practitioner

Once CyberPath starts to influence hiring, promotion, education, funding and professional recognition, it stops being just a framework for describing capability. It becomes an economic signal. Employers will start looking for it. Candidates will try to acquire it. Educators will teach toward it. Assessment providers will standardise what can be assessed efficiently. Recruiters will use it to screen people faster.

None of these people needs to cheat or behave badly. They can all make perfectly rational decisions, based on the incentives in front of them, and still produce a system that gradually rewards the appearance of capability more than capability itself.

CyberPath's biggest threat isn't bad standards. It's Goodhart's Law.

Anyone who has worked in cyber has seen a smaller version of this problem inside organisations. A security team writes the policies, procedures, standards and controls. They are technically correct. Then the business does something else because someone has a deadline, there is no funding, or a manager’s bonus depends on cost savings.

The person who wrote the standard looks around and wonders why nobody is following it.

The answer is simple: the standard is not the only thing shaping behaviour. The incentives around people are often stronger.

CyberPath faces the same problem at a national scale.

That is the argument in the Point of View I sent to ACS, AISA and Home Affairs. The risk is not that CyberPath defines capability badly. The risk is that it defines capability well, becomes trusted and valuable, and then people learn how to optimise for the signal. At that point, the credential can remain credible while becoming progressively less connected to the capability it was designed to represent.

That is the uncomfortable part.

CyberPath could look successful by many of the measures we normally use. It could achieve broad adoption. Employers could start requiring it. Candidates could seek it out. Educators could align to it. Government could point to participation and uptake.

And the system could still be failing.

In fact, widespread adoption without evidence of signal validity may be the worst outcome. It would create confidence in a measure that may no longer tell us what we think it tells us.

According to the National Cyber Security Strategy, page 50, Australia already has a problem with employers struggling to trust whether qualifications and experience reflect genuine, job-ready cyber capability. If CyberPath becomes another signal that people learn to optimise around, we risk recreating the same problem with a more sophisticated national framework sitting on top of it.

A $1.9 million public investment deserves a higher standard of proof than adoption.

The test should be whether CyberPath becomes a demonstrably better signal of genuine cyber capability than the proxies it is replacing.

To establish that, I think CyberPath needs to do two things.

First, it should explicitly model how the system is likely to behave. Agent-based modelling is well suited to this problem because the risk does not sit inside any single actor. It emerges from the interaction between many actors, each making sensible decisions according to their own objectives. The model should ask what each actor optimises for, what CyberPath changes economically for them, how they can legitimately game the signal, and what system-level behaviour emerges.

Second, CyberPath should develop empirical evidence that the signal actually works better. If someone recognised through CyberPath is supposed to represent genuine capability, then we should test whether that recognition is more strongly correlated with job-ready performance than qualifications, job titles, years of experience or the other signals employers already use.

Three levels of evidence for testing how CyberPath will behave in the real world

The sequence in the Point of View is deliberate: map the incentives, model the likely behaviour, then test the outcomes in the real world. Conceptual, modelled, empirical.

Because adoption is not evidence of validity.

The real test is whether, after everyone has had every reason to optimise around it, CyberPath still tells us who can actually do the work.