CyberDefenseMagazine

Cybersecurity Professionals Who Ignore AI Are Arming Their Enemies


I build workforce development solutions. My whole job is recognizing where skill gaps may be opening up before they become crises, and I’m seeing a gap forming in cybersecurity that should be keeping CISOs up at night.

Cyber criminals are already using AI. Not experimenting with it, but properly and legitimately making use of it. Attacks by AI-enabled adversaries rose 89% in 2025 alone, and the average time for a criminal to move laterally through a compromised network has dropped to just 29 minutes, which is a 65% increase in speed from 2024.

Simply put: security teams still running manual processes are not operating in the same threat environment as the people attacking them.

AI lowers the barrier to entry for attackers far more dramatically than it raises it for defenders. A threat actor doesn’t need a security clearance, a compliance framework, or an approved tech stack. They can spin up an AI-assisted attack campaign overnight with minimal overhead. Over 82% of phishing emails now use AI in some form —a 53.5% increase in a single year— and 92% of polymorphic attacks utilize AI to “achieve unprecedented scale.”

Let’s get specific, then, because “start using AI” is the kind of advice that sounds useful until you have to act on it.

The global cybersecurity workforce gap stands at around 4.8 million unfilled positions. That’s 4.8 million roles’ worth of human judgment that simply doesn’t exist, and when new threat actors —new techniques, new vectors, new tools— are emerging faster than any team can manually track, the only realistic way to stay current is to use AI to do what humans physically cannot: process threat intelligence at scale, in real time, without burning out.

The highest-value application is alert triage. Cybersecurity professionals face a barrage of security alerts every single day, but AI can categorise that crushing volume, sort it by priority, and surface the alerts that actually warrant attention, ensuring the most pressing threats don’t get buried under noise. It can automate alert triage and alert pattern clustering, but also accelerate processes like evidence collection and correlation, all the while enriching alerts with value-added context.

Newly discovered vulnerabilities are now being exploited at an average of just 4.76 days after disclosure. AI can compress the intelligence-gathering process dramatically by ingesting feeds, summarizing relevant developments, and flagging what matters to a specific organization’s risk profile.

Instead of “replacing the analyst”, AI can free them up to focus on more advanced investigations. AI handles the volume, the pattern recognition, the noise reduction. The analyst handles judgment, context, and the decisions that actually require a human being.

With an important caveat: knowing that AI tools exist is not the same as knowing how to use them effectively, and that’s still different from knowing how to evaluate their outputs critically. The latter is and must remain a non-negotiable skill.

The cybersecurity workforce already has a well-documented shortage problem, but what’s less discussed is the AI fluency gap sitting inside that shortage. AI hallucinates. It can produce confident, plausible-sounding information that is factually wrong. Verification has to be built into the workflow as standard practice: in a security context where decisions have real consequences for real infrastructure, acting on unverified AI output is a huge liability.

Besides AI risk literacy, other technical and trainable skills CISOs should be developing across their teams include prompt engineering (knowing how to extract useful output from AI tools) and output validation (knowing how to check that output against authoritative sources). By 2028, 50% of threat detection, investigation, and response platforms will incorporate agentic AI capabilities, up from less than 10% today: the teams building that fluency now will be the ones ready to deploy those tools effectively when they arrive.

Organizational culture around AI in security teams is set from the top. If leadership treats AI as an IT novelty rather than a force multiplier, teams won’t prioritize it. If leadership doesn’t create clear guidelines on how AI tools should and shouldn’t be used —including ethical guardrails and data handling policies— teams will either avoid it entirely or use it inconsistently.

Leadership needs to address legitimate concerns like privacy, governance, and the risk of over-reliance on tools that can be wrong through safety guardrails, data handling rules, and clear boundaries on how AI outputs get used. It won’t get anywhere by pretending the tools don’t exist.

The practical implication for CISOs: before building out AI capability, audit what AI is already running; map sanctioned and unsanctioned usage; establish what data is flowing where. The organizations that skip this step and go straight to capability-building are leaving an unmonitored attack surface wide open.

About the Author

Emil Barr, an American serial entrepreneur, currently serves as CEO of Flashpass. Co-Founded by Emil, Flashpass is a venture-backed workforce development platform that contracts with state and federal agencies to reskill workers for the AI economy. Alongside running Flashpass, he regularly writes for the Wall Street Journal, Financial Times, Entrepreneur and Forbes.

Emil can be reached online via LinkedIn and X.



Source link