Retraining IT administrators in cybersecurity is the quickest route to building in-house expertise for most Dutch employers, and it’s precisely the route that’s least often considered. The position is open, the recruitment agency sends profiles that aren’t a good fit, and three doors down sits someone who has known the environment for five years, knows which server must never be patched during business hours, and can pinpoint exactly who has been granted administrative privileges outside of standard procedures.
That knowledge cannot be transferred or purchased. It takes an external specialist months to acquire it, and you pay him in full for the time it takes him to build that expertise. That’s the same ramp-up period we factored into the cost of strategically hiring a cybersecurity professional. Retraining IT administrators skips those months. Anyone seriously considering retraining IT administrators is primarily buying back time. It’s by no means always cheaper.
Why the market itself is already dictating this path
For Security+, the certification considered the entry-level qualification in the field, CompTIA recommends approximately two years of work experience in a security or systems administration role. The industry itself thus indicates that systems administration is the logical stepping stone. For the Security+ exam, 28 percent of the test covers security operations, including topics such as hardening, logging, monitoring, and access control. This is work that an administrator already performs on a daily basis, albeit in a different form.
Anyone considering retraining IT administrators is therefore building on a foundation that the certifying body itself considers standard. The European agency ENISA reaches the same conclusion from a different perspective. The European Cybersecurity Skills Framework describes twelve occupational profiles with associated tasks and competencies, intended to help employers, professionals, and trainers speak the same language. ENISA uses this framework to support skills development within companies. When you compare an administrator role with those twelve profiles, the overlap is striking, especially in the operational roles.
The gap to an analyst role is smaller than most managers assume. That also explains why external candidates with impressive résumés sometimes fall short: they bring subject matter expertise but lack situational awareness, while your internal candidate has the opposite profile. Subject matter expertise can be learned through a structured program. Situational awareness takes years to develop and cannot be bought anywhere.
Which administrator profiles switch over the fastest
Not every administrator is a suitable candidate, and determining this in advance is what determines whether the retraining of IT administrators succeeds or fails. In practice, three profiles tend to fare the best.
The network administrator
Someone who works with segmentation, firewall rules, and routing on a daily basis already has a mental model of how traffic flows through the organization. That model forms the basis of detection work. This candidate learns relatively quickly to interpret the same traffic in terms of intent and is a good fit for a SOC role. In practice, this is the profile that, after completing a training program, is quickest to handle alerts independently, because with every alert, they immediately know which segment is affected and what is supposed to be running there.
The Identity and Account Administrator
Anyone who manages Active Directory knows which permissions have been granted and which ones no one can account for. These days, attackers are more likely to use valid accounts than malware, as we discussed in our post on identity-based attacks and the role of your IAM team. This administrator recognizes anomalies that an outsider wouldn’t notice: a service account that suddenly starts logging in interactively, an administrator group that didn’t exist last month, or an account that remained active after an employee left the company.
The Monitoring and Systems Administrator
Someone who has set up logging knows which sources are reliable, where the gaps are, and where the timestamps are incorrect. That’s more valuable than it seems, because an analyst who doesn’t know what’s missing will consistently draw the wrong conclusions. When you retrain IT administrators, you get this knowledge for free, whereas an outside hire takes months to figure out which log source you can’t trust.
What these three areas have in common is broad system knowledge. Candidates who manage only one application or primarily provide user support need more time to get up to speed, although the service desk remains a valuable resource, as we described in the context of Tier 1 versus Tier 2. For that group, the path is more likely to involve a broad entry-level program rather than a specialized analyst training program. That doesn’t make them unsuitable—it just takes longer to bring them up to speed.
The Six Skills That Are Missing
Retraining IT administrators only works if you clearly identify what’s still missing. The existing knowledge base is extensive, and that’s precisely why the gap is underestimated.
| Domain | What the administrator is already doing | What's included |
| Network | Segmentation, firewall rules, routing | Interpreting Traffic Patterns as Aggressive Behavior |
| Identity | Create accounts, groups, and permissions | Recognizing the misuse of legitimate accounts |
| Logging | Setting Up and Storing Logs | Correlate logs to build a narrative of the attack |
| Endpoints | Deployment, patching, managing images | Assessing Deviant Behavioral Patterns |
| Documentation | Record Changes | Support findings with evidence |
| Way of Thinking | Repairing What Is Broken | Assuming that something was deliberately broken |
The last rule is the hardest to follow and is rarely put into practice. Administrators are trained to keep systems running. A role in cybersecurity requires the opposite reflex: assuming that a malfunction could be intentional behavior, and not restoring the system until you’ve documented what was there. This shift comes through practice under time pressure, as we described in the section on hands-on incident response training. Simply reading a manual isn’t enough here.
In its roadmap for exposure management, the NCSC demonstrates just how closely these worlds are intertwined. The guidance explicitly targets system administrators in addition to ISOs and CISOs, and the first step is to take inventory of systems and determine which ones are accessible from the internet. System administrators usually already have this inventory. The cybersecurity expertise lies in the assessment that follows: Is this exposure necessary, and what level of risk are we willing to accept?
The calculation that determines the decision
Compare the costs of recruitment and retraining IT administrators over an 18-month period. When it comes to recruitment, you need to factor in the time it takes to fill the position, the agency fee, the training period before someone can work independently, and the market premium on the salary. We fully accounted for these costs in the hidden costs of a vacant position. Also factor in the risk that the new hire will leave within two years, because in a tight market, that’s the rule rather than the exception.
When retraining IT administrators, you have to factor in training costs, the loss of productivity during the retraining process, finding a replacement for the administrative work that falls behind, and a subsequent salary adjustment. Employers consistently overlook this last item, and it’s precisely where things go wrong: anyone who pays for retraining and then continues to pay the old salary is essentially training an employee for a competitor. Therefore, include that adjustment in the agreement from the outset, so that the discussion about it doesn’t take place only after someone already has another offer in hand.
The difference rarely lies in the total cost. It lies in when you have the capacity. In the best-case scenario, a recruitment process yields someone after nine to twelve months who still needs to get to know the environment. Retraining IT administrators yields someone who already knows the environment after an intensive program. For most organizations, that’s the deciding factor, and it’s the same trade-off as in our comparison between outsourcing and building an in-house team.
What Goes Wrong When You Do It Halfway
The most common mistake when retraining IT administrators is leaving their old tasks as they are. The administrator completes a training program, returns to work, and finds that they’re still fully responsible for patch management and user support. Cybersecurity work then becomes whatever’s left over after everything else is done—which is never. Within a year, this employee will leave, with your training listed on their resume. Therefore, before the program begins, agree on what percentage of the workweek will be dedicated to cybersecurity tasks and who will take over the administrative duties that are freed up. Without that agreement in writing, the new capacity will evaporate within a quarter.
The second mistake is training just one person. A single retrained administrator is a single point of failure: in the event of illness, vacation, or resignation, operations come to a standstill. Training two people at the same time costs less than twice as much, because they can ask each other questions and work together to apply what they’ve learned to their own environment. Employers who retrain IT administrators in pairs find, more often than average, that the knowledge actually sticks within the organization.
The third mistake is failing to define roles before the process begins. Without a clear end goal, no one knows when the retraining has been successful, and disputes arise regarding evaluation and compensation. Determine in advance which tasks will be transferred, to whom employees will report, and what level of performance is expected upon completion. When putting together an SOC team, we worked out those role-related questions in greater detail.
Which Program Fits Which Profile?
When it comes to retraining IT administrators, the choice of program depends on the candidate’s background and career goals. For a generalist administrator looking to transition into a full-fledged role in cybersecurity, the Cyber Security Specialist program is the logical path: fifteen weeks, from the basics to a job-ready profile, with the certification foundations that employers recognize.
If the candidate is specifically interested in detection and triage, the SOC T1 + T2 Analyst training program is a more direct fit, as it focuses entirely on alert assessment and investigation. For those who plan to advance to the highest analyst level later on, the SOC T3 Analyst training program is a natural progression, and the full range of training programs is organized by level.
A mixed team is also possible: one administrator can take the broad-based program, while the other specializes directly in the SOC. This way, you cover two levels without paying twice for the same thing. If you’re unsure about the entry level, look at what the candidate can solve independently rather than at their resume. Certificates prove knowledge, not judgment—a distinction we discussed when comparing certification to experience. When retraining IT administrators, a proven ability to work independently carries more weight than a list of certificates. We described which practical backgrounds are best suited for a career change in our section on lateral entry into cybersecurity.
Here's how to get started within a month
Retraining IT administrators starts with an assessment: go through the IT administration team and identify who has broad-based system knowledge. Have a brief conversation with those individuals about their interest, because forced retraining doesn’t work and will cost you a good administrator. Select two of them, document which tasks they will be relinquishing and to whom those tasks will be transferred, and agree in advance on the salary adjustment that will take effect upon completion.
Next, schedule the training program during a period when the administrative workload is low, and arrange for coverage of the work that will be left undone. Anyone who retrains IT administrators without planning for that coverage will see the process stall halfway through due to operational pressure. The page for employers lists the in-company options, and the calendar shows the upcoming start dates. Our 90-day onboarding roadmap explains how to structure the first few months after a return to work. Retraining IT administrators doesn’t require a search in an oversaturated job market. The people you’re looking for are already familiar with your environment. It simply requires a decision regarding budget and time. If you’d like to discuss which candidates on your team are eligible, please schedule an introductory meeting.



