A Systematic Map Review of European Cybersecurity Skills Frameworks using Hierarchical Knowledge Graphs
This paper presents a systematic map review of European cybersecurity skills frameworks, utilizing hierarchical knowledge graphs to synthesize evidence from 94 sources into structured limitation and enhancement pillars, thereby addressing the current fragmentation and providing a unified evidence base for ecosystem harmonization.
Original paper licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
In the modern world, the safety of our banks, hospitals, and power grids depends on a workforce capable of defending digital systems against constant attack. To build this workforce, governments and organizations create "frameworks." Think of these frameworks as detailed maps or blueprints that list exactly what a cybersecurity expert needs to know and be able to do. They define the skills required for different jobs, from spotting a virus to managing a network, ensuring that a person hired in one country has the same core abilities as someone hired in another. For these maps to work, everyone must agree on the names of the skills and how they fit together. However, when too many different groups draw their own maps using different languages and scales, the result is confusion. A student might learn a skill called "threat analysis" in one program, only to find a different definition in another, making it hard to move between jobs or countries. This confusion creates gaps where essential skills are missing, leaving the digital world more vulnerable than it needs to be.
A team of researchers from the University of Naples Federico II set out to untangle this mess across Europe. They did not just look at one or two of these skill maps; they gathered a massive collection of ninety-four different documents. This collection included academic studies, official reports from major organizations, and deliverables from large European projects dedicated to fixing the cybersecurity workforce. Their goal was to step back and look at the entire ecosystem at once, rather than getting lost in the details of a single project. They wanted to understand why these frameworks were so fragmented and to find the best strategies proposed to fix the problem. To do this, they used a method that allowed them to organize thousands of ideas into a structured, navigable system, linking every problem they found with the specific solutions suggested to solve it.
The researchers discovered that the biggest problem is not a lack of ideas, but a lack of unity. They found that the landscape of cybersecurity skills is highly fragmented. There are many different frameworks, but they do not speak the same language. This inconsistency makes it difficult for schools, companies, and governments to agree on what training is needed or how to measure success. The study identified six main pillars of problems holding the system back. The most frequent issue was this fragmented and inconsistent landscape of frameworks. Other major hurdles included uneven inclusion, where small businesses, women, and specific sectors were often left out of the planning; gaps in covering new technologies like artificial intelligence; and weak governance structures that failed to coordinate efforts across different countries. The researchers also noted that funding was often unstable, making it hard to maintain long-term training programs.
To address these deep-rooted issues, the researchers organized the proposed solutions into eleven distinct categories. The most common strategy suggested by the literature was to improve interoperability, which means making the different frameworks work together seamlessly rather than trying to replace them all with one new map. The experts proposed aligning existing systems with a central European standard, much like ensuring all electrical plugs fit into the same socket. This would allow a skill learned in one context to be recognized in another. Other key strategies involved updating school curricula to include emerging technologies, creating better certification systems that are consistent across borders, and establishing stronger governance to ensure that funding and coordination do not fall apart when a specific project ends. The study highlighted that while the problems are systemic, the solutions are becoming clearer: the path forward lies in connecting the existing pieces rather than building new ones from scratch.
The team did not just list these problems and solutions; they built a complex digital map, or a knowledge graph, to show exactly how they connect. This map linked the ninety-four source documents to the specific problems they discussed and the solutions they proposed. By tracing these connections, the researchers could see which strategies were most frequently suggested to fix which specific gaps. They found that the literature consistently points toward harmonization as the primary answer to fragmentation. The data showed that while the problems are widespread, the proposed solutions are becoming more focused on creating a unified, adaptable system. The study suggests that the European cybersecurity ecosystem is not missing a single missing piece, but rather struggling to align the many pieces it already has. The researchers concluded that by using these structured maps to navigate the landscape, policymakers and educators can finally move from disjointed efforts to a coordinated strategy that builds a stronger, more inclusive, and better-prepared workforce for the future.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.