Cybersecurity Responsibilities Beyond IT: Evidence from 100 Current U.S. Vacancies
Author: MTF Institute Research Team
Institution: MTF Institute
Publication date: 15 September 2026
Technical report: MTF-CF-RR-2026-09-15-47
DOI: https://doi.org/10.5281/zenodo.22768680
Visible word count: 4,508 (Unicode word tokens after Markdown destination URLs are removed)
Research geography: United States
Vacancy retrieval date: 15 September 2026
Study design: Structured purposive sample
Accepted vacancies: 100 unique public postings
Partitions: 50 employee/individual-contributor postings and 50 manager, supervisor, director/head or executive postings
Course Factory run: f4f999d9-b64b-4fd2-b29f-73e08c6e2c45
Abstract
Cybersecurity work is often discussed as if it belongs only to specialists. This report examines a different question: what do employers explicitly ask ordinary business employees and non-technical leaders to do when their work touches accounts, business data, customers, staff, vendors or suspicious events? The evidence is a structured purposive sample of 100 unique current public U.S. vacancies retrieved on 15 September 2026. Fifty postings cover individual contributors across human resources, operations, customer service, healthcare administration, education and nonprofit work. Fifty cover managers, supervisors, directors/heads and executives across these and related business functions.
The most common theme was data handling and privacy, coded in 99 of 100 vacancies: 49 of 50 employee postings and all 50 management postings. Routine cyber hygiene appeared in 17 records, passwords and authentication in 14, incident reporting and escalation in 14, vendor and third-party risk in 8, and phishing or social engineering in 3. Codes overlap. The small number of postings that explicitly named phishing does not show that phishing is unimportant; it shows that vacancy language in this selected corpus more often expressed security through confidentiality, verification, records, access, compliance, vendor review and issue routing.
Employee postings supplied more explicit operational detail across authentication, reporting and routine hygiene. Management postings concentrated heavily on discretion and protection of sensitive information, with narrower clusters around access removal, vendor review, training and escalation-path design. Across both partitions, employers linked security to observable work: verifying identity, restricting disclosure, preserving accurate records, documenting decisions, flagging irregularities and handing issues to the correct function. The findings support a cross-functional view of cybersecurity capability, while remaining descriptive of this sample rather than estimating the wider U.S. labor market.
1. Why examine cybersecurity beyond technical roles?
Organizations create and use sensitive information through ordinary business processes. Payroll staff handle bank and compensation data. HR teams manage employee records and access changes. Patient-access staff verify identity and process protected health information. Registrars and student-service teams administer education records. Customer-service workers authenticate callers and document account decisions. Procurement leaders evaluate suppliers that may receive data or system access. Office managers and executives handle confidential operational material. In each case, the work is business work first, yet poor judgment can create a security, privacy or fraud pathway.
U.S. public guidance provides a stable reason to take these responsibilities seriously. The Cybersecurity and Infrastructure Security Agency asks organizations and individuals to recognize and report phishing, use strong passwords and password managers, enable multifactor authentication and install updates through its Secure Our World guidance. The Federal Trade Commission's Cybersecurity for Small Business connects staff training with phishing awareness, remote access, vendor security and incident planning. The National Institute of Standards and Technology provides a small-business quick-start guide that places protective actions within the broader functions of governing, identifying, protecting, detecting, responding and recovering.
Those guidance sources explain sound practice; they do not tell us how frequently employers mention a behavior in vacancies. Vacancy evidence answers a narrower question: what an employer chose to state publicly for a particular role at a particular time. This report keeps the two forms of evidence separate. Counts come only from the 100 accepted vacancy records. Public guidance is used to interpret why low-incidence but high-consequence behaviors still matter.
2. Research question and scope
The study asked:
What observable cybersecurity behaviors, work products, decision boundaries and escalation responsibilities do current U.S. employers assign to non-technical staff and leaders in relation to phishing and social engineering, passwords and authentication, business-data handling, third-party and vendor exposure, incident reporting and routine cyber hygiene?
The population of interest for sampling was cross-functional work performed by non-technical employees, supervisors, managers, executives and owners whose ordinary duties include digital communication, business data, accounts, vendors or incident escalation. Dedicated cybersecurity, information-security, IT, security-operations, governance-risk-compliance and security-engineering jobs were excluded. The study is not an occupational survey of a single profession, and it is not a count of all vacancies that could benefit from security awareness.
The research geography was fixed as the United States before integration. Accepted records had a U.S. work location, U.S.-remote scope or explicit U.S.-inclusive eligibility. One manager record stated “United States or Canada”; it was retained because U.S. applicants were explicitly included, while the original location was preserved. One employee record stated “Remote”; the frozen employee methodology records that every accepted employee posting had reliable U.S. scope. Neither case supports a Canadian or global claim.
3. Method
3.1 Sampling design
The study used a structured purposive design. Search and acceptance sought explicit evidence across specified role families and the six target areas. This design is appropriate for discovering and comparing stated responsibilities across diverse business work, but it does not provide a probability sample. Results therefore use formulations such as “14 of 100 accepted vacancies” rather than “14% of U.S. jobs.”
Two independent collection partitions supplied 50 records each. The employee partition focused on frontline and individual-contributor work in human resources, administration, sales and customer service, healthcare administration, education and nonprofit settings. The management partition covered supervisors, managers, senior managers, executives, procurement owners and public-service leaders. A vacancy was accepted only when the public employer or applicant-tracking-system page preserved a traceable employer, title, posting identity and U.S. scope; showed a live application action, future closing date or continuous/open-until-filled status on the retrieval date; and contained at least one explicit target responsibility in the job body.
Pages were excluded when they were closed, duplicated, non-U.S. without U.S. eligibility, dedicated technical/security roles, talent pools, anonymous-employer pages, or pages whose only security language came from an applicant notice or generic footer. Generic “follow policy” language did not qualify without a specific security, privacy, data, access, vendor or incident behavior.
3.2 Coding
Every accepted record preserved employer, title, location, canonical source URL, retrieval date, current-status evidence and a concise paraphrase of the relevant requirement. It was coded, where stated, for six overlapping topics: phishing/social engineering; passwords/authentication; data handling/privacy; vendor/third-party risk; incident reporting/escalation; and routine cyber hygiene. The records also retained role family, seniority, behavior, output, cadence and interface or escalation text.
The two source schemas used different names and manager codes. Integration renamed equivalent fields, mapped manager topic codes one-to-one to the frozen coding dictionary, and rolled finer manager role labels into the shared role-family taxonomy. Original manager role and seniority labels remain in the normalized records, so the mapping is reversible. No missing workplace mode, cadence, escalation route, qualification or authority was inferred.
Cross-partition deduplication produced 100 unique record IDs, 100 unique normalized canonical URLs and 100 unique normalized employer-title-location keys. The source hashes were independently checked before analysis. Every normalized record passed identity, date, URL, topic, role, seniority, requirement-paraphrase and source-ledger matching checks.
3.3 Counting and interpretation
Topic counts overlap. A record with authentication, privacy and reporting evidence contributes once to each relevant topic. Co-occurrence counts identify records containing both codes; they do not imply that the duties occur at the same moment. The combined denominator is 100, while each partition denominator is 50.
Behavior, output and interface summaries use transparent secondary pattern rules over the explicit normalized text. For example, the output category “records, files or documentation” counts preserved output text containing one of those concepts. These categories are also overlapping and narrower than the topic codes. They help show the form of work products without adding facts that were not present in the sources.
3.4 Rights and reproducibility
The evidence bundle stores links, dates, current-status observations, derived facts and paraphrases. It does not store full job descriptions, screenshots, applicant data, credentials, paywalled content, proprietary training material or copied tables. Primary employer or employer-controlled ATS pages are the vacancy sources. The public report links to selected records near illustrative claims; the frozen source ledger contains all 100 URLs.
4. Composition of the accepted sample
The integrated corpus spans eight normalized role families. Human resources and people operations contribute 26 vacancies; healthcare administration 19; education and nonprofit work 19; operations and administration 16; sales, marketing and customer service 10; finance and accounting 7; procurement and vendor management 2; and non-security legal/compliance work 1.
The split by partition reflects the collection design. All 50 employee records are individual-contributor vacancies. The management partition contains 39 managers, 6 supervisors/team leads, 3 executives/owners and 2 directors/heads. Finance, procurement and most operations leadership appear only in the manager partition, while customer-service roles are concentrated in the employee partition. Comparisons must therefore be read as descriptions of these two designed partitions, not as controlled tests of seniority.
The source mix is also uneven: Workday supplies 47 records, Ashby 29, GovernmentJobs 15 and Lever 9. The employee partition is 47 Workday, 2 Lever and 1 Ashby. The manager partition is 28 Ashby, 15 GovernmentJobs and 7 Lever. Differences in platform indexing, employer style and the types of organizations using each ATS may affect what was visible and how requirements were worded.
Employer concentration is limited but not absent. The 100 vacancies come from 92 employers. Louisiana State University contributes 4; First National Bank of Omaha 3; and M&T Bank, Broward College and Conduit Health 2 each. The remaining 87 employers contribute one record apiece. No employer supplies more than 4% of the corpus, satisfying the planned cap of five records per employer.
5. Findings across the six focus areas
5.1 Data handling and privacy: 99 of 100
Data handling and privacy was coded in 99 vacancies: 49 employee postings and all 50 manager postings. This is the defining pattern of the sample. Employers usually expressed cybersecurity responsibility through the information attached to ordinary work rather than through technical security terminology.
The information classes were varied. Human-resources roles protected workforce, payroll, performance and recruiting data. Capital One's HR data-management role connected retention, masking, privacy controls and destruction activities to workforce-data processes (VE-001). Entrust linked HR-system configuration and troubleshooting with privacy and access controls (VE-006). In the manager partition, NetBox Labs connected confidential employee information with documented lifecycle changes and removal of systems access during exits (VM-066).
Healthcare roles emphasized patient information, authorization and records integrity. Sentara Health required validation of medical-record documents, confidentiality and reporting of suspected privacy or security problems (VE-007). A South Shore Health release-of-information role tied disclosure to authorization and HIPAA checks (VE-030). Novir's management vacancy joined HIPAA compliance, access oversight, documentation integrity and staff education (VM-090).
Education and public-service roles referred to student, case, legal, payroll, criminal or investigative information. Broward College's evaluator role called for accurate student-record handling without weakening privacy or integrity (VE-040). The City of Poulsbo required confidential handling of police-department information in an office-management role (VM-078).
These examples show that “data protection” in non-technical work is operational. It appears as authorized disclosure, accurate data entry, protected records, retention, careful communication, controlled system access and documented handling. The count does not show that each role has the same risk or control set. It shows that nearly every selected posting gave information stewardship an explicit place in the role.
5.2 Routine cyber hygiene: 17 of 100
Routine cyber hygiene appeared in 17 vacancies: 13 employee and 4 manager records. The accepted code includes approved systems and software, device or remote-work care, awareness/training, updates and related protective routines where the posting stated them.
Penn State's administrative role combined information handling, access control, records management and cybersecurity procedures, with support requests going through the service desk (VE-016). First National Bank of Omaha customer-care roles required identity checks and a private home workspace before or during account service (VE-025). Anyscale linked confidential people operations with execution of compliance training (VM-067).
Vacancy incidence is lower than the breadth of stable public guidance. CISA's Secure Our World brings phishing reporting, strong unique passwords, password managers, MFA and software updates together as basic protective behaviors. The gap is analytically important: employers may rely on organization-wide policies and onboarding for universal hygiene while using vacancies to emphasize role-specific records or confidentiality duties. The present data cannot test that explanation, so it remains a plausible interpretation rather than a finding.
5.3 Passwords and authentication: 14 of 100
Passwords and authentication appeared in 14 vacancies: 11 employee and 3 manager records. The evidence was wider than password creation. It included caller authentication, account access, credential resets, secure HR-system configuration, access restrictions and removal of access during exits.
Two M&T Bank fraud-support postings required detailed questioning and account review before access or exceptions, and produced decisions such as account restrictions, credential resets and investigator handoffs (VE-023, VE-024). FNBO's customer-care roles similarly connected authentication with account actions and interaction records (VE-026). On the management side, NetBox Labs explicitly connected employee exits with removal of systems access (VM-066).
The practical theme is authorization before action. Non-technical workers are not configuring enterprise identity architecture in these examples; they are confirming that the person, request and requested action fit approved access. The distinction matters because it sets a safe boundary between performing a business transaction and administering technical controls.
5.4 Vendor and third-party risk: 8 of 100
Vendor and third-party risk appeared in 8 vacancies: 5 employee and 3 manager records. Employee evidence often involved coordinating vendors while protecting information or supporting contract records. Bristol Myers Squibb tied sensitive-information handling to vendor intake and governance records (VE-004). Broward College's paralegal role connected legal, student and contractual information with contract-support work (VE-044).
Management evidence was more explicit about review structure. Talkiatry's Head of Procurement vacancy called for a vendor-risk framework covering security, privacy, HIPAA, business-associate agreements and related procurement decisions (VM-092). Sardine's procurement manager role coordinated security, privacy, legal, finance and IT review across deals, contracts and renewals (VM-093). Conduit Health connected vendor management with partner controls, issue routing and escalation paths (VM-098).
The 8-record count is modest, yet the work products are concrete: assessments, agreements, review records, contracts, renewal tracking, partner controls and procurement recommendations. FTC guidance separately advises businesses to address security in vendor relationships and remote access arrangements (Cybersecurity for Small Business). Vacancy evidence shows where some employers place that work; public guidance explains why the risk extends beyond the procurement team.
5.5 Incident reporting and escalation: 14 of 100
Incident reporting and escalation appeared in 14 vacancies: 11 employee and 3 manager records. Incidents were not limited to confirmed cyberattacks. They included suspected privacy breaches, fraud, access or configuration problems, compliance concerns and operational issues with security implications.
Sentara's health-record role directed suspected breaches or security problems to the appropriate compliance or privacy officer (VE-007). First PREMIER Bank expected customer and fraud concerns to be documented and escalated through established channels (VE-022). Endeavor Health linked compliance concerns to management and unresolved financial issues to specialist teams (VE-035).
Manager examples included appropriate escalation without a named destination, investigation and resolution under sector rules, and construction of escalation paths. Tabz required an HR/office manager to escalate issues appropriately while leaving the destination unstated (VM-068). North Slope Borough connected incident investigation and resolution with protected client information (VM-094). Conduit Health required issue routing across support, fulfillment, clinical and product functions (VM-098).
Stable FTC data-breach response guidance distinguishes prompt internal mobilization, evidence preservation, service-provider review and documentation from decisions about authorized external notification. That distinction is compatible with the vacancy evidence: non-technical staff can recognize, record and route without taking actions outside their authority.
5.6 Phishing and social engineering: 3 of 100
Only 3 vacancies explicitly carried the phishing/social-engineering code, all in the employee partition. Two M&T Bank fraud-support postings involved questioning, account review, access decisions and investigator handoff where impersonation or fraud was relevant (VE-023, VE-024). Anagram Security's marketing role required translation of security-awareness issues into public and customer-facing material (VE-029). No manager vacancy in the accepted partition used enough explicit evidence for this code.
The correct conclusion is narrow: phishing language was rare in this selected vacancy corpus. It would be incorrect to conclude that phishing is rare in practice or irrelevant to managers. CISA and FTC guidance explicitly treat recognition, reporting and current awareness as everyday protective actions (CISA, FTC). The contrast illustrates why vacancy frequencies and stable guidance must not be merged into a single prevalence claim.
6. Co-occurrence: how responsibilities cluster
Fifty-eight vacancies carried one target code, 31 carried two, 9 carried three and 2 carried four. The most common pair was data handling with routine cyber hygiene, found in 16 records: 12 employee and 4 manager vacancies. Data handling co-occurred with authentication in 14 records, incident reporting in 14, and vendor risk in 8. These totals largely mirror the topic counts because data handling appeared in all but one record.
Authentication and cyber hygiene co-occurred in 5 records. Authentication and incident reporting co-occurred in 3. Phishing co-occurred with data handling, authentication and incident reporting in 2 records each, and with hygiene in 1. Incident reporting and cyber hygiene co-occurred in 2; incident reporting and vendor risk in 1. All non-zero pairs are preserved in the frequency artifact.
The clustering supports a process view of non-technical cybersecurity. An identity-verification decision often produces an account record and may require escalation. A vendor review touches data handling, contracts and named interfaces. A suspicious request links recognition with verification, documentation and handoff. However, a co-occurrence code does not prove sequence or causation. It simply shows that the same posting stated both areas.
7. Employees and managers: descriptive contrasts
Data handling was nearly universal in both partitions: 49 employee vacancies and 50 manager vacancies. Beyond that shared base, employee postings carried more of the other target codes: hygiene 13 versus 4; authentication 11 versus 3; incident reporting 11 versus 3; vendor risk 5 versus 3; and phishing 3 versus 0.
Several design factors caution against reading these differences as seniority effects. Employee roles were concentrated in HR, healthcare, education and customer service, where vacancies often describe transactions, identity checks, records and first-line routing. Manager roles included many people-operations and office-management postings whose security evidence was a concise confidentiality expectation. Source platforms also differed sharply by partition. The analysis does not control for role family, sector, employer or ATS style.
Even so, the text reveals a useful division of work. Employee examples frequently describe the moment of action: authenticate a caller, validate a disclosure, update a record, restrict an account, report a concern or submit a service-desk request. Manager examples more often emphasize discretion, oversight, process documentation, training, lifecycle access, vendor decisions, reporting and early surfacing of irregularities. These are complementary layers, not a hierarchy of importance.
The narrow lexical behavior summary reinforces this picture. Explicit “protect or limit sensitive information” wording appeared in 77 records: 34 employee and 43 manager postings. Accuracy, integrity, documentation, record, audit or evidence wording appeared in 20: 16 employee and 4 manager. Explicit report/route/escalate/surface language appeared in 12: 7 employee and 5 manager. Identity/access/authorization wording appeared in 8: 7 employee and 1 manager. These lexical patterns are reproducible summaries of the behavior field, not substitutes for the manually assigned topic codes.
8. Outputs, cadence and interfaces
8.1 Work products
The most common explicit output pattern was records, files or documentation, present in 67 vacancies: 43 employee and 24 manager records. Reports, metrics, audits or reviews appeared in 36: 20 employee and 16 manager. Systems, access, accounts or transactions appeared in 25: 16 employee and 9 manager. Procedures, guidance, training or playbooks appeared in 16: 9 employee and 7 manager. Issues, incidents, resolutions or corrective actions appeared in 11: 8 employee and 3 manager. Vendor, contract or procurement products appeared in 7: 3 employee and 4 manager.
These products make security work reviewable. “Be careful” is difficult to observe; an authorized account action, an access-removal record, a documented handoff, a vendor assessment or a corrective-action plan can be checked. The outputs also connect protective behavior to normal operational quality. Accurate records help both service delivery and incident reconstruction. Clear issue documentation supports both customer resolution and escalation. A vendor review supports both procurement and risk ownership.
8.2 Cadence
All 50 employee records and 24 manager records contain some cadence text. After applying overlapping normalized cadence codes, daily work appeared in 52 vacancies: 45 employee and 7 manager. Lifecycle work appeared in 22: 17 and 5. Event-driven work appeared in 8: 6 and 2. Monthly and annual work each appeared in 7. Weekly and quarterly work each appeared in 4. Thirty-two manager records had no usable fixed frequency; no employee record was coded unstated because every employee source retained some cadence wording.
Daily activity includes records, calls, registrations, payroll or office operations. Lifecycle activity includes onboarding, role change, exit, academic or award cycles, vendor selection, contracting and renewal. Event-driven activity includes fraud, suspected breaches, access issues, complaints and other anomalies. Periodic rhythms include reporting, reviews, training and reconciliation. Because cadence codes overlap, the sum exceeds 100.
8.3 Interfaces and escalation routes
Exactly 50 records preserve explicit interface-or-escalation text: 35 employee and 15 manager vacancies. Twenty-six explicitly report, route, escalate, surface, flag, advise, feed or hand work to another party. Twenty-six name cross-functional or external coordination. Twenty-four name a leader or supervisor relationship. Three explicitly say that the escalation destination or route is unstated. These pattern sets overlap.
Named interfaces include HR and HRIS, IT, privacy, compliance, legal, security, finance, product, engineering, clinical operations, registrars, faculty, managers, executives, vendors, investigators and service desks. This variety argues against a single universal escalation chart. The recurring capability is to know the local route, preserve concise facts, share only what the receiver needs, and ask for a decision or support when the issue exceeds the worker's access or authority.
9. What the evidence supports for cross-functional practice
The evidence supports a workplace capability model rather than one occupational profile. Across role families, a non-technical professional may need to recognize sensitive information, verify identity or authorization, use approved channels and repositories, keep accurate records, protect credentials, question unusual requests, document issues and route them promptly. Leaders may additionally need to define expectations, oversee lifecycle access, coordinate vendor review, ensure staff training, review outputs and establish escalation paths.
Decision boundaries are central. The evidence does not support asking ordinary staff to conduct forensic investigation, administer enterprise security systems, contact regulators or customers independently, or make legal determinations. It supports first-line protective action within assigned procedures and prompt handoff to authorized IT, security, privacy, compliance, legal or management functions. The most useful handoff states what was observed, when it occurred, which account, data, vendor or process is involved, what authorized action has already been taken, what evidence is preserved and what decision is needed.
The findings also show why lower-frequency topics should not disappear from organizational capability planning. Vendor risk appears in only 8 postings and phishing in 3, yet each can carry high consequence. Stable public guidance fills a different role by identifying enduring protective practices. NIST's small-business quick-start guide, CISA's Secure Our World and FTC small-business guidance establish a broader baseline without changing the vacancy counts.
10. Limitations
First, this is a structured purposive sample, not a probability sample. Searches deliberately sought vacancies with explicit target evidence across selected functions. Data-handling language was a major inclusion pathway. The finding that 99 records contain that code is exact for the corpus but cannot be generalized to 99% of U.S. vacancies, workers or employers.
Second, the research is point-in-time. A live application control, future closing date or open-until-filled statement was observed on 15 September 2026. ATS pages can be edited, withdrawn or reissued. Current-status evidence proves the observation date, not continuing availability.
Third, vacancies are selective employer communications. They omit practices that an employer treats as universal, obvious, handled through policy, or introduced after hiring. An unstated behavior is unknown, not absent in the workplace. This is especially important for phishing, MFA, updates and incident procedures.
Fourth, the two partitions differ in role and source composition. The employee partition is dominated by Workday and contains only individual contributors. The manager partition is dominated by Ashby and GovernmentJobs and spans four normalized seniority levels. Descriptive comparisons cannot isolate the effect of seniority.
Fifth, topic breadth varies. “Data handling and privacy” includes confidential employee, student, patient, financial, legal, case and business information. Some postings name sector rules or specific access processes; others state confidentiality in a role duty. The inclusion review required connection to the job body, but the operational depth is not uniform.
Sixth, the source schemas do not retain structured education, experience or required-versus-preferred fields. They also do not consistently preserve workplace mode, formal authority or an escalation destination. This report does not infer those dimensions from titles. A complete quantitative analysis of qualifications would require a new accepted evidence pass over primary sources.
Seventh, lexical behavior and output counts depend on disclosed text patterns. They are useful for reproducibility, but synonyms outside the pattern may be missed. The manually assigned topic codes remain the primary analytic classification.
Finally, this report distinguishes vacancy evidence from stable public guidance. Guidance sources explain recommended protective practice and organizational context; they do not validate vacancy prevalence. Conversely, a low vacancy count does not invalidate a public protective recommendation.
11. Conclusion
Across 100 selected current U.S. vacancies, cybersecurity responsibility beyond IT was expressed primarily as stewardship of information and disciplined business action. Data handling and privacy appeared in 99 records. Smaller but material clusters covered routine cyber hygiene (17), passwords and authentication (14), incident reporting and escalation (14), vendor and third-party risk (8), and phishing or social engineering (3). Employee postings more often described operational verification, transaction, record and handoff work; manager postings more often emphasized discretion, oversight, lifecycle processes, training, vendor review and escalation-path design.
The strongest common thread is not technical tooling. It is observable judgment at the point where work, data and authority meet: verify before acting, restrict disclosure, use approved access, preserve accurate records, identify anomalies, and route decisions beyond local authority to the correct function. Organizations can use that finding to clarify cross-functional expectations while recognizing the study's limits. The evidence describes a diverse, structured purposive sample observed on one date. It does not forecast hiring, estimate national prevalence or replace an employer's own policy, incident plan, legal advice or security leadership.
Data and methods note
The companion integrated artifacts contain the normalized 100-record dataset, complete source ledger, frequency tables, co-occurrence results, role-requirements matrix, methods/data dictionary, geography-coherence matrix, cross-functional workplace capability brief, record-level QA and corpus-acceptance decision. They preserve only paraphrased evidence and derived counts; no full job descriptions are reproduced.
Continue learning
Apply the evidence from this report through MTF Institute's Professional Certificate in Cybersecurity Essentials for Non-Technical Professionals. The programme turns the identified capabilities into structured theory, guided AI practice and reusable workplace artifacts.