Cyber SecurityAI & Technology

Which AI Skills Are Now Essential for Cybersecurity Professionals

By Casey Marks, Ph.D., Chief Operating Officer, ISC2

Artificial intelligence (AI) is fundamentally redefining the cybersecurity workplace. The use of AI within enterprises affects every aspect of the practice, going beyond a cybersecurity professional’s traditional toolkit while amplifying the tools their adversaries have at their seemingly endless disposal.  

In addition to facing new threats that require better defense tools, cybersecurity teams must be able to account for AI models and integrations as they permeate all aspects of the cybersecurity profession: from threat detection and response to identity access management to governance and risk management and more. It is therefore the responsibility of everyone holding professional cybersecurity certifications to ensure they proactively seek opportunities to build new skills and keep up with the latest technologies and practices. AI is demanding that they accelerate this rate of learning.  

In fact, among those who said their organization’s security team has at least one skills need, AI represented the most pressing skills need, cited by 41% of participants in the 2025 ISC2 Cybersecurity Workforce Study. Yet acquiring, validating and demonstrating AI skills should never be a discrete, stand-alone or after-the-fact effort simply borne from the fear of being behind the AI curve. Instead, adopting an AI-centric professional mindset, bolstered by AI security skills and capabilities baked into fundamental cybersecurity practices, must be inextricable from an organization’s cybersecurity and risk management strategies.  

But are cybersecurity teams ready to embrace this mindset shift?  

Which AI Skills in Cybersecurity are Necessary for Better Defense? 

As the need for AI security expertise becomes integral to maintaining effective cybersecurity capabilities, the cybersecurity workforce appears to recognize both the promise and the risk of AI. A deep diveinto the cybersecurity workforce study reveals that 28% of respondents globally already have integrated AI security tools into their operations, including AI-enabled security solutions, generative AI and agentic AI capable of automated action. Another 41% say they are currently either evaluating or testing AI security tools, signaling strong interest paired with due diligence.  

This reserved momentum reflects a growing awareness that AI is not simply a panacea or plug-and-play solution. Instead, it demands operational readiness across people, processes and technology.Cybersecurity professionals are increasingly expected to apply their expertise in the context of AI-driven technologies, requiring continuous development of new skills alongside established practices. The following snapshot indicates where cybersecurity professionals can evolve their skills and capabilities along with AI advancements: 

  • Security and risk management: Understanding how AI assets shift the organizational risk posture. 
  • Asset security: Maintaining data integrity throughout the AI lifecycle, ensuring that the information used to “teach” these systems has not been tampered with or poisoned by malicious actors. 
  • Security architecture and engineering: Designing secure enclaves for high-performance AI compute and the implementation of robust input-validation mechanisms to defend against prompt injection and adversarial attacks 
  • Identify and access management (IAM): Incorporating the use of AI to enhance IAM through behavioral biometrics and adaptive authentication. 
  • Security operations: Integrating AI and ML into Security Orchestration, Automation and Response (SOAR) platforms and managing alert fatigue by using AI to correlate disparate events and provide high-fidelity context to security analysts, allowing for faster incident response. 
  • Software development security: Using AI-assisted coding tools, focusing on the risks of “hallucinated” vulnerabilities or the accidental inclusion of insecure code snippets generated by LLMs.  

Strengthening Organizational Commitment to AI Security Readiness  

Clearly, developing AI-related skills should not be treated as a niche specialization or siloed capability or, worse, as an afterthought. Instead, AI security must be woven into every layer of a cybersecurity strategy and risk framework, informing how teams think about risk, defense and response across all roles, from security operations analysts to CISOs. The most prepared organizations will be those that deliberately build teams that can tackle real-world cyber defense in an AI-driven environment.  

Organizations can invest in the most advanced AI-enabled platforms available, but without cybersecurity professionals who understand how these tools and tactics work, and where their limitations lie, risk remains. What’s more, as the integration of AI across enterprise environments reshapes cybersecurity responsibilities and evolving skill sets, adopting an AI governance strategy must happen ahead of any AI deployments. Clear governance will guide cybersecurity professionals who are now expected to use heightened critical thinking skills (amidst little context), logical reasoning and judgement, all of which are amplified precisely because of AI’s widespread impact on cybersecurity practices. 

So, just as AI skills must infuse all cybersecurity roles, AI projects should follow the same governance principles as other technology projects, including risk tiering and evaluation gates. Given that AI adoption specifically for cybersecurity is rolling out at a careful pace, it seems that organizations recognize the need to be intentional and cautious about weighing the risks and opportunities of AI security tools before deploying them. The transformative success of AI adoption depends on how well people are prepared to use AI security tools and to defend against malicious uses of AI for cyber attacks.  

Investing in AI Security Skills Attainment as a Foundation for Trust 

As AI becomes embedded across enterprise systems, cybersecurity professionals are being asked to secure not only infrastructure and data but also models, decision logic and automated actions that operate at machine speed. That shift fundamentally changes what effective cybersecurity practice looks like and raises the bar not only for professional competence but also for operational preparednessat large. Therefore, the onus of skilling does not fall solely on the cybersecurity professional; instead, employers must invest in their teams.  

According to the 2025 ISC2 Cybersecurity Workforce Study, respondents see AI as a catalyst for career development opportunities rather than a threat. Two-thirds (66%) of respondents said that AI will generate a need for broader skillsets across the field. Fortunately, most (94%) participants reported that their organizations are doing things to mitigate the effects of security teams skills needs, beyond just potentially hiring new workers. 

Many of the efforts that study participants value focus on upskilling. The most common avenues include allowing time for professional development during work hours (28%), allocating budget for internal training (24%) and allocating budget for external training (19%). It is crucial to channel professional development to upskilling efforts related to AI skills. Structured skills attainment and continuing professional development (e.g., courses, workshops, certificates and peer-to-peer sharing) assure that cybersecurity professionals demonstrate real-world and relevant skills. 

It is only by infusing AI skills throughout core cybersecurity domains, since nearly every core cybersecurity domain is touched by AI in some way, that the cybersecurity workforce can collectively combat nefarious uses of AI to wreak cyber havoc. Organizations that invest in the people, processes and technology to ensure that AI infuses their core cybersecurity domains will build the trust necessary to innovate responsibly within the parameters of advanced AI security guardrails, guidance and governance. 

Author

Related Articles

Back to top button