Logo
Cybersecurity

AI Is Raising the Bar for Cybersecurity Talent

AI can process alerts faster than people ever could. The harder part is knowing when its answer is wrong.

ITSEC AsiaITSEC Asia
|
Sep 02, 2026
AI Is Raising the Bar for Cybersecurity Talent

For cybersecurity teams, AI is quickly moving from something experimental to something people actually use.

The World Economic Forum’s Global Cybersecurity Outlook 2026 found that 77% of surveyed organizations had adopted AI for cybersecurity. It is already being used for tasks such as phishing detection, intrusion response and user-behaviour analysis.

That sounds like good news for teams struggling with workload. And mostly, it is.

But AI doesn’t remove the need for skilled cybersecurity professionals. It changes what those professionals need to be good at.

Automation Can Do More. So Humans Have to Do More Too.

The same WEF research found that 54% of organizations considered insufficient knowledge or skills a barrier to using AI effectively in cybersecurity. Another 41% pointed to the need for human oversight.

That second number matters.

AI can analyse enormous amounts of information quickly. What it still struggles with is context: whether an unusual event is genuinely dangerous, how a technical issue affects the business and what action makes sense when the available information is incomplete.

Cybersecurity professionals increasingly need to:

  • Validate AI-generated findings rather than accept them automatically
  • Recognise when an automated recommendation doesn’t fit the situation
  • Investigate activity across cloud, endpoint, identity and network environments
  • Connect technical findings with actual business risk
  • Make decisions when there isn’t a neat textbook answer

In other words, knowing how to use AI is becoming useful. Knowing when not to trust it may be even more useful.

Indonesia Is Facing the Same Shift

Komdigi has been making a similar point.

In August 2026, Vice Minister of Communication and Digital Affairs Nezar Patria said AI was changing both cyber defence and cybercrime. He warned that agentic AI could allow attacks to operate more autonomously while AI-assisted social engineering and deepfakes were becoming harder to recognise.

His response was not simply “use more technology.”

Komdigi has called for stronger AI-based cybersecurity talent, closer collaboration between universities and industry and a move toward security by design, where security becomes part of how systems are built rather than something added after problems appear.

That requires people who understand both the tools and the consequences of using them.

Training Has to Catch Up With the Job

The World Economic Forum ranks networks and cybersecurity among the three fastest-growing skills expected through 2030. It also argues that as AI takes over more repetitive security tasks, professionals will spend more time on oversight, governance and higher-level decision-making.

That changes what good cybersecurity training should look like.

Learning concepts still matters. Certifications still have a role. But professionals also need opportunities to investigate, test assumptions and make decisions in conditions that resemble actual operations.

That is the direction behind ITSEC Cyber & AI Academy, which combines cybersecurity learning with hands-on exercises and scenarios informed by ITSEC Asia’s operational experience.

The goal isn’t to train people to compete with AI at processing information faster.

Machines already have a fairly comfortable lead there.

The goal is to develop professionals who know what the information means and what to do next.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

Share this post

You may also like

Your Cybersecurity Skills Gap Might Be a Job Design Problem
Cybersecurity

Your Cybersecurity Skills Gap Might Be a Job Design Problem

Cybersecurity job descriptions can become ambitious documents. An organization needs someone who understands cloud security, investigates incidents, tests applications, manages risk, explains regulations, tunes security tools and perhaps briefs senior management when something goes wrong. Five years of experience preferred. The candidate sounds excellent. Finding this person may take a while. ENISA’s European Cybersecurity Skills Framework offers a useful reminder that cybersecurity isn’t one profession wearing several different badges. The framework separates the field into 12 professional profiles, including Cyber Incident Responder, Cybersecurity Architect, Penetration Tester, Cybersecurity Risk Manager, Digital Forensics Investigator and Cyber Threat Intelligence Specialist. Each profile has different tasks, knowledge and competencies. They also depend on one another. That changes how organizations should think about a “skills shortage.” CHECK THE JOB BEFORE BLAMING THE TALENT POOL Some roles will naturally overlap, particularly in smaller teams. ENISA’s own user manual treats the framework as flexible and shows how organizations can combine responsibilities according to their circumstances. The problem starts when overlap becomes accumulation. A useful workforce review can ask: * Which tasks genuinely

ITSEC AsiaITSEC Asia
|
Sep 22, 2026 — 3 minutes read
This is How Information Security Analysis Protects What Prevention Can't
Cybersecurity

This is How Information Security Analysis Protects What Prevention Can't

INTRODUCTION Organizations worldwide are investing more in cybersecurity than at any point in history, yet breaches are growing more frequent, more expensive, and more damaging. The global average cost of a data breach reached USD 4.88 million in 2024, the highest figure ever recorded. Even more alarming, the average time to identify a breach stood at 194 days, nearly half a year of undetected attacker activity inside a network before anyone realized something was wrong. These numbers raise an urgent question every business leader must answer honestly: if an attacker entered your network today, how long would it take your organization to find out? And once discovered, could you identify exactly what was accessed, how the attacker moved, and what vulnerabilities made it possible in the first place? For most organizations, the honest answer is: not fast enough, and not with enough certainty. That gap is precisely what Information Security Analysis (ISA) is designed to close. Prevention, including firewalls, antivirus, and multi-factor authentication, is necessary but not sufficient. When attackers

|
Mei 11, 2026 — 7 minutes read
Why Annual Penetration Testing Is No Longer Enough in Today's Threat Landscape
Cybersecurity

Why Annual Penetration Testing Is No Longer Enough in Today's Threat Landscape

If you only went to the doctor once a year, you probably would not assume you were perfectly healthy for the other 364 days. Health changes over time. New conditions can develop, existing issues can worsen, and unexpected problems may arise between checkups. That is why people increasingly rely on regular monitoring and preventive care rather than waiting for an annual appointment to discover something has gone wrong. Cybersecurity works in much the same way. For many years, annual penetration testing has been considered a cybersecurity best practice. Organizations schedule an assessment, receive a report, address the findings, and repeat the process the following year. In relatively static environments, this approach provided a reasonable level of assurance. Modern organizations, however, no longer operate in static environments. Cloud adoption has accelerated. APIs have become essential to digital services. Development teams deploy updates continuously, and third-party integrations have become increasingly common. As organizations move faster, their attack surfaces evolve just as quickly. A system that was secure six months ago may look very

ITSEC AsiaITSEC Asia
|
Jan 09, 2026 — 7 minutes read

Receive weekly
updates on new posts

Subscribe