Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some cybersecurity professionals do study outside work, but available evidence does not show how many or how many hours they spend. The better-supported conclusion is that ongoing skill development is normal in cybersecurity, while the time, budget and employer support available for it vary considerably. Workforce surveys measure employer-supported learning and time constraints; they do not measure the share of professionals who study specifically on their own time.

What the workforce evidence actually shows

The most useful data describes how organizations support development, not unpaid after-hours study. ISC2’s 2025 Cybersecurity Workforce Study surveyed 16,029 people responsible for cybersecurity at workplaces across North America, Latin America, Asia-Pacific, Europe, the Middle East and Africa. Respondents reported several separate organizational approaches:

Reported approach Share of respondents
Professional-development time during working hours 28%
Encouragement to use free vendor training and educational content 25%
Budget allocated for internal training 24%
Encouragement of internal training sessions and knowledge sharing 21%

These percentages represent different answers, not portions of one workforce that can be added together. They also do not establish that the remaining respondents study after work; a person may learn through a manager-approved course, workplace practice, peer coaching or no formal activity at all.

ISC2’s 2024 workforce study found that more than half of respondents said they did not have enough time to learn new skills. That is a survey finding about those respondents, not a measurement of every cybersecurity worker. Taken together, the two ISC2 studies describe a field in which learning is valued, time is scarce and organizational support is uneven.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why the question is difficult to answer

The informal question “Outside of Work, How Many Hours per Week Do You Study?” appears in community discussions, but replies to that question are not a representative workforce sample. They can illustrate individual routines without showing what is typical.

Professional development also includes activities that are easy to miss when people use “study” to mean reading at home:

  • Training completed during paid working hours.
  • Internal demonstrations, tabletop exercises and knowledge-sharing sessions.
  • Free vendor courses and product documentation.
  • Hands-on work that develops a new capability while performing the job.
  • Self-paced reading, practice labs, flash cards, apps or exam preparation outside work.

Because the reviewed workforce studies do not ask how much time is spent on personal study, no defensible weekly average or percentage of after-hours learners can be given.

What employers say they value

ISACA’s 2025 survey summary, based on responses from more than 3,800 cybersecurity professionals, lists adaptability as a qualification factor for 61% of respondents, hands-on experience for 60% and soft skills for 59%. These are separate response categories and should not be summed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The pattern favors demonstrable capability over a particular number of study hours. A professional who applies a new detection technique, communicates risk clearly or adapts to a changing control requirement may be developing valuable skills without following a formal evening study schedule.

“In a world of AI-based attacks, disinformation campaigns, and constantly shifting mandates, adaptability is the new baseline for survival,” said Jeff Wade, global CISO and cybersecurity strategist.

Practical ways to keep skills current

Start with a role-specific gap

Choose a capability connected to current responsibilities or a clearly identified gap: for example, cloud logging, identity controls, incident response, threat modeling or security communication. A narrow objective makes limited study time more useful than a general attempt to “learn cybersecurity.”

Match the format to the objective

ISC2 identifies textbooks, study guides, flash cards, apps, self-paced resources and credential-specific preparation as legitimate self-study formats. NIST’s NICE online learning catalog lists free and low-cost cybersecurity courses and practical learning options. Use a format that fits the skill:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Concept review: a textbook, guide or short course.
  • Recall and terminology: flash cards or an app.
  • Operational ability: a lab, exercise or supervised workplace task.
  • Exam preparation: material mapped to the chosen credential’s current objectives.

Prefer application over an arbitrary hour target

Set an outcome—such as building a small detection rule, completing a lab and documenting the result, or explaining a control to a nontechnical stakeholder—instead of treating a fixed number of evening hours as a universal requirement. Keep notes on what you can perform, not only what you have read.

Use employer time and resources first

Ask whether learning can be scheduled during working hours, supported through an internal session, funded from a training budget or covered by approved vendor education. This makes development part of the job rather than assuming that unpaid personal time is the only route.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to choose a learning option

Decision factor Questions to ask
Role and skill objective Does this address a real responsibility or documented gap?
Credential alignment For an exam, does the material match the current objectives and edition?
Practical application Does it include hands-on work, or is it concept review only?
Cost and access Is there a free or low-cost alternative, and will an employer budget cover paid material?
Time and schedule Is it self-paced, scheduled, or available during paid work hours?

When a study guide or practice book makes sense

A credential-specific study guide or practice-test book is most defensible when you are preparing for a named certification and the material is mapped to that exam. Check the publication edition, the exam objectives and the provider’s update policy before buying. A book is one option among the formats ISC2 lists; it is not a requirement for cybersecurity work, and buying one does not replace hands-on practice.

A realistic development plan for constrained schedules

  1. Define one outcome. Write the skill you need and how you will demonstrate it.
  2. Check workplace support. Ask for development time, internal training, a peer session or approved vendor resources.
  3. Select the lightest effective format. Use a short course, guide, lab or reference rather than collecting unrelated material.
  4. Apply the skill. Complete a safe exercise or work task and record the result.
  5. Review evidence of progress. Keep a brief portfolio, runbook improvement, lab report or manager feedback note.
  6. Adjust the cadence. Increase, reduce or pause personal study according to workload, recovery needs and the next skill gap.

What this means for managers

Do not treat after-hours study as an implicit job requirement. The survey evidence points to a more equitable approach: provide learning time where possible, make internal knowledge sharing routine, offer free or funded resources and evaluate applied capability. This also reduces the risk that people with caregiving duties, health constraints or limited disposable time are disadvantaged by an unofficial expectation of unpaid study.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Bottom line

Cybersecurity requires continuing learning, and many professionals choose to learn in personal time. However, current workforce studies do not establish what proportion does so or how many hours they spend. The evidence supports a more precise statement: skill development takes place through a mixture of paid work time, employer programs, practical experience and optional self-study, with access differing by organization and individual.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.