AI & TechnologyCyber Security

AI is changing what it means to be cyber ready

By Christine Bartlett, Chief Marketing Officer at Hack The Box

Traditionally, cybersecurity leaders have measured readiness by their people’s technical skills, certifications and experience responding to incidents. AI is forcing us to rethink that definition. 

The question is no longer just whether security professionals have the skills to defend their organisations. Organisations also need to understand how effectively those professionals can work alongside AI systems. That is a very different measure of cyber readiness. 

From analysing source code and identifying vulnerabilities to assisting with reverse engineering and malware analysis, AI is becoming part of the everyday toolkit for security professionals. Much of the conversation has understandably focused on what AI can automate. But perhaps the more important discussion is around what happens to the role of the human. 

Cybersecurity capability has largely been measured by technical proficiency. Could a practitioner identify an exploit? Could they detect malicious behaviour? Could they respond to an incident quickly and effectively? Of course, knowing about these capabilities is essential. But AI is changing the skills that provide the greatest value. 

As AI is embedded across more security operations, many routine technical tasks will be faster and more accessible. The differentiator will be the ability to interpret AI’s outputs, recognise when they are incomplete or incorrect, and make informed decisions in nuanced or ambiguous situations. 

In other words, the cyber skills gap is becoming a cyber readiness gap. AI is very good at accelerating certain types of work, but cybersecurity isn’t a collection of isolated technical problems. 

AI performs well where reasoning is bounded, the available information is clear, and the route to a solution is relatively deterministic. They can accelerate code analysis, explain vulnerabilities, assist with exploit development and support secure coding remarkably effectively. But real-world attacks rarely follow these neat paths. 

Security professionals have to deal with incomplete information, changing environments and unexpected obstacles. Effective incident response needs practitioners who can reassess assumptions, pivot when an investigation reaches a dead end and balance technical evidence with operational context. These are the areas where judgement matters most and where AI still has limitations. 

Recent research from the UK AI Security Institute illustrates this challenge. Using a bespoke Hack The Box cyber range known as Cooling Tower, researchers evaluated how frontier AI models performed across complex, multi-step attack scenarios. 

While the models demonstrated impressive capabilities on individual tasks, they struggled to maintain progress across longer attack chains that required sustained reasoning, contextual awareness and repeated adaptation. The findings highlighted both how quickly AI capability is advancing and why human expertise continues to make the difference in complex environments. 

The lesson here was not that AI has failed, far from it. It is just that AI’s strengths and limitations are becoming clearer. Organisations that understand where AI accelerates work and where human expertise is still essential will ultimately gain the greatest advantage. 

This shift has significant implications for how organisations develop and assess cybersecurity talent. Technical certifications and classroom-based learning have provided valuable evidence of knowledge. They will continue to be useful measures, but knowledge alone is not enough to prepare someone for responding to a live cyber incident. 

Operational readiness is about how people perform under pressure, how effectively they collaborate, how quickly they recognise when an approach is failing and whether they can adapt when technology produces unexpected results. These capabilities become even more important when AI enters the workflow. All capabilities are even more important when AI enters the workflow. Rather than simply knowing whether an individual can solve a problem, organisations now also need to understand how effectively they solve problems with AI. 

Can they recognise hallucinations? Can they validate recommendations before acting on them? Can they determine when automation should be trusted and when human intervention becomes necessary? 

This is where hands-on cyber ranges and Capture The Flag (CTF) exercises are having renewed importance. 

CTFs have been viewed primarily as competitions that allow practitioners to test their technical skills against realistic security challenges. Well-designed cyber exercises enable organisations to observe how teams operate in realistic and uncertain environments. They expose decision-making, collaboration, communication and problem-solving under pressure, rather than simply measuring technical aptitude. 

They also create an opportunity to understand how AI is influencing team performance. Instead of focusing just on who completed a challenge first, organisations can begin looking at elements such as where AI accelerated the investigation, where AI produced misleading recommendations, the tasks that needed experienced human judgement, and how effectively participants validated AI-generated outputs. 

These insights help to provide a far more realistic picture of operational readiness.  

Hack The Box’s enterprise workforce research showed that between 2023 and 2025, enterprise CTF events grew by 3.5 times, participating organisations increased by 2.7 times, and the number of teams almost tripled. Team interaction rates also remained above 80% for three consecutive years. 

This demonstrates that organisations are not reducing investment in practical training because of AI. They are investing in helping people develop and test their skills in realistic scenarios. So, as AI becomes more capable, practical experience becomes more valuable, not less. 

Foundational cybersecurity knowledge is still essential because practitioners need sufficient understanding to recognise when AI is correct, when it is partially correct and when it is confidently wrong. The role of the security professional is evolving from executing every technical task manually to supervising intelligent systems. 

This requires people who understand both cybersecurity and AI enough to question recommendations and not to simply accept them. It also reinforces the convergence between offensive and defensive security skills, as practitioners increasingly need broader technical awareness to validate AI-driven outputs across different parts of the security lifecycle. 

With cyber readiness increasingly depending on how effectively individuals and teams combine human judgement with AI assistance, the organisations that adapt quickest are unlikely to be those with the most sophisticated AI tools alone. They will be the organisations that invest in helping people develop the judgement, resilience and decision-making skills needed to use those tools effectively. 

AI will continue to reshape cybersecurity. It will automate more workflows, accelerate investigations and lower the barrier to performing many technical tasks. But cyber defence has never just been about completing technical tasks. It is about making good decisions in uncertain situations where the consequences matter. 

That is why the future of cybersecurity readiness will not be defined by how much AI an organisation deploys, but by how effectively its people learn to work alongside it. 

The cyber skills gap has not disappeared. It has evolved into a cyber readiness gap. 

The organisations that recognise this shift will be better prepared for the next generation of cyber threats. AI means readiness will not just be defined by technical expertise or the sophistication of AI tools. It will be measured by how effectively humans and intelligent systems work together to make better decisions when it matters most. 

Related Articles

Back to top button