When Chaitanya, a third-year Bachelor of Computer Applications (BCA) student in Pune, began studying cybersecurity, he thought an advanced certification would help him enter the industry.
He became interested in penetration testing after Class 12 and cleared the Offensive Security Certified Professional (OSCP) examination in his second year.
OSCP is a hands-on certification focused on finding and exploiting vulnerabilities in computer systems. (Sign up for THEdge, The Hindu’s weekly education newsletter.) But the job search brought a different experience.
“I sent around 200–300 applications for VAPT, SOC Analyst, Cybersecurity Analyst internships and entry-level roles, but I didn’t get a single interview or opportunity,” he said.
VAPT, or vulnerability assessment and penetration testing, involves finding weaknesses in websites, applications or networks and testing whether they can be exploited.
A Security Operations Centre (SOC) analyst monitors systems for signs of cyberattacks and investigates suspicious activity.
Cybersecurity is attracting students as organisations become increasingly dependent on digital systems and face new kinds of cyber threats.
The DSCI’s Cyber Security Outlook 2026 report says organisations are dealing with both a shortage of skilled professionals and the rapid adoption of artificial intelligence in security operations.
AI tools are increasingly being used for alert triage, threat hunting and incident investigation.
The threat landscape is also changing.
Attackers are increasingly targeting cloud systems, digital identities and APIs.
In 2025, cloud-targeted attacks rose 37% year-on-year, while AI-enabled cyberattacks increased 89%, according to the report.
Join THEdge LinkedIn group The growing demand for cybersecurity skills is also prompting IITs and public universities to expand specialised programmes, with IIT Kanpur and IIT Madras launching undergraduate cybersecurity degrees this year.
Professor Prakriti Singh, who teaches cybersecurity at Dayananda Sagar University, says the changing nature of the field is one reason it attracts young people.
“Cybersecurity particularly appeals to Gen Z, a generation that thrives on continuous challenges and dynamic problem-solving,” she said.
“The work can involve responding to new vulnerabilities and attacks rather than following a fixed set of tasks.
A zero-day vulnerability, for instance, is a security flaw that is not yet known to the people responsible for fixing it.” But students also enter the field with some misconceptions.
“A common misconception is that cybersecurity is strictly confined to coding and purely technical tasks,” Professor Singh says.
The field also covers areas such as cyber law, policy and understanding the psychology behind cyberattacks.
Gap in industry For students looking for technical roles, the bigger challenge comes after the course: getting the first opportunity.
“I have no idea where to start or what skills to learn,” says A.
Vetri Selvam, a second-year cybersecurity student in Tamil Nadu.
He is unsure whether he should focus on coding and problem-solving like computer science students, learn full-stack development or concentrate on cybersecurity skills.
A new security architecture in West Asia?
Veera K, a Bengaluru student preparing for an SOC role, has spent months learning networking and tools such as Wireshark, Splunk and Sysmon .“I’ve been told that there is no entry-level job for a fresher and that IT experience is needed,” he said.
He is now considering a helpdesk role as a possible route into IT before moving into cybersecurity.
The difficulty is not simply a lack of demand for cybersecurity professionals.
Industry data points to a gap between the skills employers need and what some candidates can demonstrate.
The DSCI-SANS Indian Cyber Security Skilling Landscape 2025-26 report found that 73% of enterprises and 68% of cybersecurity service providers reported limited availability of skilled candidates.
At the same time, 63% of enterprises and 59% of providers said candidates lacked sufficient hands-on practical skills.
The report also found that 84% of organisations took between one and six months to fill cybersecurity positions.
So, while companies report difficulty finding skilled candidates, fresh graduates can still find it difficult to enter the industry.
What employers look for Aabhishhek Mitra, CEO of Indian Cyber Security Solutions, says the difference often comes down to what a candidate can actually do.
“Practical capability” is the first thing he looks for, followed by problem-solving, real-world exposure, research and projects, communication, certifications and degrees, he says.
A degree, he says, provides an academic foundation.
A certification can demonstrate knowledge in a particular area.
But neither necessarily proves that a candidate can investigate an incident, analyse a problem or document a security finding.
Cybersecurity jobs can involve analysing alerts, investigating suspicious activity, following incident-response procedures and handling sensitive information.
That is one reason some employers ask for previous experience even in jobs described as entry-level.
Mr.
Mitra said companies should also distinguish between formal employment experience and demonstrated practical experience.
For students, that experience can come through internships, realistic projects, research, capture-the-flag competitions, bug bounty work, open-source contributions and hands-on labs.
That distinction is reflected in the experience of Aditya Vakkalanka, a 2026 graduate from a tier-3 college who secured a junior cybersecurity analyst job.
His college placements did not have a cybersecurity opening, so he applied off-campus.
He says he contacted around 150 companies through cold emails and calls.
He did not have a cybersecurity certification when he was hired.
Instead, he had spent about one-and-a-half years building practical skills through cybersecurity projects, capture-the-flag competitions, TryHackMe and PortSwigger labs.
He had also worked on a research paper.
His recruitment process included an assessment in which he had to hack a machine and submit a detailed report.
“Fundamentals matter,” he said.
“Certifications help, but they don’t help if you don’t have deep basics.” From classrooms to real-world skills For universities, the challenge is to prepare students for a field that is changing quickly while giving them a strong foundation.
“Conventional degree programmes rarely offer a comprehensive, dedicated cybersecurity pathway at the undergraduate level,” Professor Singh said.
Specialised programmes can help students build that foundation while exposing them to industry requirements, she said.
External certifications and online courses can strengthen a student’s profile, but Professor Singh describes them as a supplement to structured education rather than a replacement for it.
The industry is also placing greater emphasis on practical skills.
The Cyber Security Outlook 2026 report identifies continuous reskilling, AI-assisted investigation and cross-functional cybersecurity skills as increasingly important as organisations combine human expertise with automation.
For students entering the field, the route is therefore not always a straight line from a cybersecurity degree to a cybersecurity job.
Chaitanya says he is now focusing on getting internships and roles in IT, SOC or security-support, over certifications.
Mitra says students can begin building the experience employers seek even before they enter a full-time role.
“Students can bridge the gap through internships, realistic projects, research, CTFs, bug bounties, open-source and hands-on labs,” he said.