Dr. Ervin Frenzel: Bridging the Cyber Workforce Gap with a Vision and Systems Leadership

The global cybersecurity enterprise faces a pressing paradox. While corporate security budgets continue to expand alongside rising data breaches, higher education institutions and training programs annually output thousands of certified graduates into a market that remains short of qualified talent.

Industry analysts frequently frame this deficit as a simple shortage of technical workers. However, Dr. Ervin Frenzel, CEO, Founder, and Lead Trainer at Blue Sage Cyber, sees a far deeper structural failure. To Dr. Frenzel, the cybersecurity crisis is not a quantitative supply issue. It is an architectural misalignment built on an unexamined academic approach.

As a former Non-Commissioned Officer (NCO) in the United States Army, an industry practitioner with over three decades of security experience, an academic developer who built seven Texas college degree programs, and a researcher holding multiple master’s degrees alongside advanced doctoral work, Dr. Frenzel brings a distinct cross-disciplinary perspective. He operates at the intersection of technical security, organizational leadership, and systems engineering.

Through Blue Sage Cyber, Dr. Frenzel is challenging the fundamental assumptions that govern how workforce talents are trained, how risk is managed, and how higher education prepares students for modern enterprise defense.

The Genesis of a Paradigm Shift

Dr. Frenzel’s move to challenge higher education was born from frontline operational reality.

After retiring from military life, where his leaders focused on practice and mentoring, he gradually worked up to leading sophisticated security groups. However, as a leader, he faced a common problem that new corporate recruits were constantly deficient in some skills.

“Every time I moved through the ranks of leadership, I found out that when we hired new people, they did not have certain skills, which is not uncommon to any workforce leaders,” Dr. Frenzel says. “So, again I became a trainer and educator, using my time and leadership experience that I got when I was an NCO in the Army. It was the same cycle again: starting as an entry level specialist, gaining new skills, applying them, and then teaching them to others.”

This effort grew quickly because other nearby departments were also struggling with their training needs. Recognizing that corporate entities would not be able to solve this challenge on their own, Dr. Frenzel went back into academia to address the issue from its roots.

Working with educational institutions in Texas, he developed four Associate and three Baccalaureate programs for cybersecurity and technology. Yet within academia, he found the key reason behind the disconnect; namely, there is a significant disconnect between career academic researchers and the real world.

Exposing the Ivory Tower Disconnect

During his experiences in devising curriculum for colleges, Dr. Frenzel found that most academic researchers involved in making cybersecurity program design had little experience in enterprise.

“Many of these researchers I came across showed a lot of resistance. They seemed to misrepresent their workforce experience. If asked directly, they would claim that they had been working in companies such as company X, although not X per se, but similar kinds of content. Since nobody ever verified these credentials, they spoke without any fear of reprisal. And they normally did. It disgusted me because these ‘professionals’ were steering our students towards jobs that they themselves had not done nor had talked to people doing those jobs,” says Dr. Frenzel.

Comparing this phenomenon to the blind men and the elephant story, he found researchers specializing in certain narrow technical pieces without understanding the overall ecosystem. To make matters worse, researchers would defend themselves against queries regarding skill deficiencies of their graduates by stating that job placement was not their concern.

What alarmed Dr. Frenzel was the way families had placed their trust in the academic professionals who had only been guessing regarding the careers of the students. In a move to address the systemic issue at hand, he decided to go ahead and break down the career fields to look at the ecosystems surrounding them in order to synthesize them into holistic subjects of study.

When he compared his framework with the basic career field documents, he found out that the skills that were needed matched accurately, indicating that the academics were actually neglecting some of the most important skills while conducting research. The change of attitude was witnessed by him after he saw over forty students standing in line outside his office seeking advice on their resumes and how to convert what they learn to career skills.

Technical Security versus Cybersecurity: A Critical Distinction

Central to Dr. Frenzel’s framework is a distinction most executives and academics overlook: the operational boundary between Technical Security and Cybersecurity. In corporate jargon, “cybersecurity” is often misused as a catch-all for firewalls, policies, and compliance alike. Dr. Frenzel warns that this vagueness fuels enterprise vulnerabilities and confuses job seekers.

“Technology security centers around preventing loss of control of your organizational technical security,” Dr. Frenzel explains. “Cybersecurity centers around enabling the end-user and the environment in which they engage the organizational technology.”

In dismissing this disconnect, Dr. Frenzel referred to seminal DoD literature, which included the Willis Ware reports from 1967 and 1978 that indicated that early pioneers recognized that technical control is merely part of an overall human-oriented system. In confusing the two, education programs place technical requirements on students without consideration of how those tools integrate with human behavior and actions.

Further evidence of the accuracy of Dr. Frenzel’s perception came from his membership in the Colloquium for Information Systems Security Education (CISSE.info), a professional society which is planning its 30th Colloquium event at present. Through CISSE, Dr. Frenzel was able to connect with information security thought leaders. However, it was because of his neurodiversity and autism that he had the boldness to take issue with the prevailing cybersecurity consensus. Many might have kept quiet, but Dr. Frenzel found it necessary to contact Dr. W. Victor Maconachy, the founder of CISSE, who was also the IEEE Chair for Information Assurance and co-creator of the MSR Information Assurance model.  Information Assurance was later renamed cybersecurity, the MSR model is still used today as a corner stone of understanding cybersecurity, although it is commonly referred to as the IA cube.

It is safe to say that Dr. Maconachy’s endorsement of Dr. Frenzel’s interpretation of the classics served as an affirmation of the user-centric systems approach and broke the technocentric deception of the industry. It was an epiphany, akin to taking off a mask. While Dr. Frenzel had matured in the industry and was a highly competent person technically speaking, his central concern has always been to serve the needs of the end-user. He understood that although technical systems are essential, they exist within an infinitely bigger environment of human interaction. Technology becomes obsolete over time, and over time it is replaced by newer technology, but the end-user who will need information from the technology will adapt to a newer technology over time. Where true leadership demands authentic human connection, an adherence to technocentric declaratives can put leaders into a corner.

“In describing today’s cybersecurity, if I were going to make up a name for it, I would probably call it enterprise level risk and security because it encompasses the entire organization, the people, the processes, the technology, and the technology security,” notes Dr. Frenzel. “The leadership of an organization needs to understand that you cannot just re-label a duck as a goose and assume all will work out well.”

The Birth of Blue Sage Cyber: Systems Thinking in Action

Founded with the intention to fill this gap, Blue Sage Cyber runs on a model that blends the insights provided by higher education with the rigors of workforce validation. As the founder, CEO, and Lead Trainer of the company, Dr. Frenzel regards these roles as two interrelated aspects of the same system. The business structure developed by Dr. Frenzel relies on systems engineering and systems thinking – methods of analyzing complex organizational problems from the perspective of dynamic, networked systems rather than separate parts.

“Neither my teams, my learners, myself, nor our end-users work in isolation,” says Dr. Frenzel. “I call my leadership style ‘interactive’. Cybersecurity is very similar to the puzzle game. Big picture thinking enables you to look at the macro environment. You should then look at the individual to understand how he/she fits into this big picture. In essence, focusing on one part enables you to focus on the whole: decompose and synthesize again in a better way.”

Student development at Blue Sage Cyber starts with an initial assessment of previous knowledge, operational gaps, and cognitive advantages. Instead of placing all students into rigid learning tracks that prepare them for multiple-choice exams, Dr. Frenzel mentors students in analyzing their gaps, assessing their risk landscape, and understanding the inner workings of enterprise systems.

Systems approach continues right into the corporate consulting services provided by Blue Sage Cyber. In assessing an organization’s risk posture, Dr. Frenzel does not present prepackaged answers. He collaborates with the organization’s leaders to assess the unique risk posture, organizational worldviews, and operational culture of that company.

According to Dr. Frenzel, advisors must first be invited to provide assistance before real change can happen, whether advising individuals or whole workforces. Change occurs starts from the inside, whether the inside is of a person or an organization. Since organizational leaders make up an organization’s risk appetite, risk avoidance, and risk engagement strategy, they ultimately determine how much assistance they will receive. Dr. Frenzel is there to help them define their vision and implement empirical analysis and changes.

Confronting the Technocentric Myth in Higher Education

Another issue that has been repeatedly addressed in publications and presentations of Dr. Frenzel is what he calls “the technocentric myth”. That is the fallacious belief that complex socio-organizational risks related to humans can be resolved with the application of more technology software and hardware solutions.

Such a bias is detrimental to academic developments and the resilience of corporations. As far as academic development is concerned, universities treating cybersecurity only as a technical field hidden within computer science departments fail to address the very factors that result in actual breaches – cognitive biases, socio-organizational culture, social engineering, policy inconsistencies.

To counter such an approach, Dr. Frenzel holds leadership and research positions, as well as cooperates within the frameworks of several large international systems organizations, among which there are INCOSE (International Council on Systems Engineering), SCiO (Systems Practice in Organisations), STA (Systems Thinking Alliance), EC-Council, ISC2.

“Everyone seems to think ecosystem sciences exist in silos, but they do not,” Dr. Frenzel emphasizes. “One ecosystem science by default works with another, and another, and the list grows. Diversity is not about looking or acting differently; it is thinking about and approaching problems differently. What unique perspectives can you bring to the conversation, rather than forcing someone to see things your way?”

An Unwavering Commitment to Authenticity and Lifelong Mastery

What sets Dr. Frenzel apart in an industry that frequently revolves around artificial credentials is his dedication to real and ongoing education.

Even with multiple master’s degrees in psychology, business management, technology, and information assurance, not to mention a doctorate in Cybersecurity, Dr. Frenzel is a current doctoral student working towards new analytical lenses for his understanding of complicated systems. To date, he has catalogued more than 150 cybersecurity academic programs in the U.S. and Europe, examining their results in light of market performance.

Nevertheless, even with these credentials, Dr. Frenzel maintains an attitude of extreme modesty and advises rising professionals not to fall into the trap of fake expertise.

“I’m still in school today to acquire new perspectives,” Dr. Frenzel states. “I have multiple master’s degrees, I’m working on another PhD, and I have over 35 years of security experience – but I’m not going to tell you I know anything. I’m still studying and learning. Be wary of anyone who claims to know everything.”

His dedication to rigorous research was brought out in one instance when he was being interviewed for the position of faculty at a college. During his interview, he gave a talk on workforce integration within systems. Although his talk was highly appreciated, Dr. Frenzel did receive a rejection letter.

However, the panel member of the interview later talked to Dr. Frenzel off campus and told him that the administration had worries about the standards of his presentation making the others raise the bar to match his standards.

“It scared them,” Dr. Frenzel chuckles. “Sometimes you have to recognize that it really is them, not you. Your strength might be terrifying to those who lack the same strength. It’s just like doing laundry. When pairing socks, you need to find the right sock to make a pair. Never assume you have to have all the answers; just have a good research capability and know where to start.”

Anchored by Faith, Family, and Personal Peace

For Dr. Frenzel, the ability to maintain top-notch performance in corporate consulting, academic research and teaching comes down to having an extremely solid individual base. In an environment where the rate of burn-outs is incredibly high, he attributes his ability to cope to the values that he got from his father and grandfather – faith, dedication to family and honest acceptance of one’s true self.

Away from corporate obligations, Dr. Frenzel makes it a priority to spend time with his wife and kids and travel around the country.
“My well-being depends on my faith greatly,” Dr. Frenzel said. “I love being with my wife, and I love learning new things. It is something that was taught to me by my father and grandfather when I was a kid. Me and my wife have known each other for many years, and I trust her to keep me in check.”

In the business world which constantly promotes performative personalities, Dr. Frenzel sees self-awareness as a key ingredient of career success and happiness.

“Fighting against who you are will always cause grief,” Dr. Frenzel reflects. “Accepting who you really are is key to a happy life. Others cannot make you happy; it is something you have to have inside of you. If you do not know that you have it, find out what the ‘it’ is. What brings you peace? Answer that, and life becomes awesome.”

Blueprint for the Next Generation: Advice to Emerging Leaders

The advice Dr. Frenzel gives to aspiring cybersecurity professionals and educators differs dramatically from mainstream trends in career guidance.

“Don’t get caught up in industry fads, or only pursue certifications,” advises Dr. Frenzel. “Pursue deep literacy in systems engineering, INCOSE Systems Engineering Handbook, Cybersecurity Body of Knowledge (CyBOK), NSA Inforation Assurance Technical Framework 3.1, and wicked system problem literature.” Moreover, Dr. Frenzel warns that it is important for rising experts to carefully choose their mentors.

Dr. Frenzel advises aspiring professionals to seek mentors actively working in their specific area of interest and on the exact countermeasures they wish to master. He stresses the importance of studying foundational documents, cautioning that if a field claims sole authorship of all primary sources, true original materials are being ignored. Learners must cultivate a passion for deep research to evaluate sources independently. Without thorough domain knowledge, he warns, many mentors merely offer wishful thinking rather than grounded guidance.

The Legacy of Blue Sage Cyber: Architecting the Future of Enterprise Defense

In light of this, the research conducted by Dr. Ervin Frenzel and Blue Sage Cyber provides a timely solution for a sector which currently finds itself at a crossroads.

Through questioning the relevance of academic syllabi and separating the security of individual components from that of the organization as a whole, as well as approaching leadership as an interaction and human-centered responsibility, Dr. Frenzel lays down the foundation for the future of the digital era.

Specifically, through addressing agency problems head-on in case managers work against the interests of their principals, while understanding that organizational alignment takes precedence over any technical fixes, and seeing the development of cybersecurity as a logical move from broader sectors into specialized sub-domains. His main aim is neither gaining recognition nor market share but making an impact through open and collaborative networks of people who together safeguard the human potential.

The main contribution made by Dr. Frenzel in his conclusion is recognizing differences. This comes from the fact that when boundaries are created in organizations, the organization creates both an inner and outer environment, both needing to be protected in fundamentally different ways. In his opinion, the real task of a leader is to recognize the framework behind all this and help people excel in their craft.

RELATED ARTICLES
- Advertisement -

Most Popular