Cyber Security

You Might Be Looking for the Most Valuable Cybersecurity People in the Wrong Place

By Brooke Johnson, Chief Legal Counsel, SVP of HR & Security at Ivanti

Your security operations likely now run on tools that act before anyone sees what they did: blocking a transaction, quarantining a device, and reseting credentials. By the time a human looks at the alert, the action is already three steps in the past. 

This is mostly a good thing. Adoption tracks accordingly: the 2026 State of Cybersecurity Report from Ivanti finds 87% of security teams treating agentic AI adoption as a priority, and 77% of cybersecurity professionals say they are comfortable with these systems acting without human review. Practitioners want this work automated and have wanted it automated for years.

The technology is finally catching up.

Somebody needs to be able to figure things out 

What follows from automation, though, has caught a lot of teams off guard. When something goes wrong (e.g., a customer locked out of their account, a flagged transaction that turns out to be legitimate, a quarantine that takes down half a department), somebody has to be able to walk through what happened and why. It needs to be explained in the kind of plain English that satisfies a board member, a customer, a regulator or a journalist. That capability turns out to be much, much harder to staff for than the automation itself was to deploy.

Compliance is where this tends to crop up most obviously. Historically, compliance has been treated as paperwork, like a sign-off function bolted onto the end of a process somebody else owns. That arrangement was justifiable when the “things being signed off” were policies and procedures (written by humans!) and executed slowly enough that documentation could keep up.  

It really does not work for autonomous systems. Documentation written after deployment cannot govern decisions being made before deployment. By the time the report is filed, the model has been making calls for weeks.  

The role is changing 

It’s now becoming common for companies to place compliance professionals alongside the engineers building the systems, often before deployment and sometimes before procurement. The titles vary. It might be an AI governance lead, AI risk officer, head of responsible AI, chief AI ethics officer, or occasionally something improvised inside an existing security org chart. The function is, presumably, consistent.  

These professionals review system behavior in production, set the boundaries within which the system is allowed to act, and own the explanation when something goes off the rails. They are responsible for the answer to “why did the AI do that,” and they need to have that answer ready before the question is asked. 

This work requires a particular blend of skills that almost nobody needed five years ago. Specifically: Enough technical depth to understand why a model produced a given output. Enough legal and regulatory literacy to know which outputs create exposure. Enough communication ability to explain both to non-specialists.  

That’s a lot. 

Ivanti’s research finds that 59% of security professionals expect demand for hybrid skills to climb over the next three to five years. The World Economic Forum’s Future of Jobs Report 2025 puts AI and big data at the top of its global fastest-growing skills ranking, with networks and cybersecurity directly behind. Two adjacent skill sets, climbing fast, increasingly required of one person. 

That hybrid person is hard to hire 

The World Economic Forum also reports that only 14% of organisations have the skilled talent they need to meet their cybersecurity objectives. Before you write that off as a failure of recruitment, know that recruitment is really not the key problem here.  

There is no large external pool of professionals who already combine deep security expertise with model risk understanding and regulatory fluency. And you can’t wait for one of these specialists to pop up on the market and knock on your door. If you do expect that, you can also expect to keep waiting. 

Internal development is slower and less satisfying than hiring, but it’s the realistic option for most companies. Case in point: Security analysts with appetite for governance work can be moved toward AI risk roles with deliberate training and rotation. Compliance professionals with technical curiosity can be embedded within engineering teams to absorb how models behave in production.  

Start internal 

This isn’t the flashy move, but it produces people who can do the work that is needed, which is more than can be said for most external hires at this stage. Plus, they’ll already know your operations. 

There is a tendency in coverage of AI and cybersecurity to treat automation as all about jobs disappearing. That POV misses what is happening in real life. Routine investigation is being absorbed by software, yes. But there are other things: work that depends on judgment, accountability and the ability to defend a decision in plain language.  

Those things are becoming more important, more central to how security functions are run, and considerably more valuable. Not less. And definitely not disappearing. 

Find that talent within your ranks. Develop that talent now. Don’t wait around for it to show up.  

Related Articles

Back to top button