I write a lot about the need for a comprehensive and ongoing information security and privacy education program within organizations. Many people do. More is needed. However, something that I don’t see written about much is the need for information security and privacy practitioners and leaders to also receive ongoing training covering the issues for which they are responsible. We see a lot of seminars and conferences offered, but it is often hard to get the budget approved to attend these, let alone be able to take 2, 3, 4 or even 5 days away from the office.