Cyber SecurityAI & Technology

AI cyber risk has arrived faster than the skills to contain it

By Phil Chapman, Cybersecurity Subject Matter Expert at Firebrand Training

The most significant cyber risk facing UK organisations right now is not a new piece of malware or an unfamiliar attack vector. It’s a workforce that has not been prepared for the speed at which AI has changed the threat. Attackers can automate reconnaissance, generate targeted deception at scale and adapt intrusion attempts in real time. New data from Firebrand Training makes clear just how wide that gap has become. 

What the data actually says 

A UK-wide survey of senior leaders across energy, financial services, retail and telecoms illustrates the scale of the shift. 77% believe AI is increasing cyber risk, yet only 27% consider themselves fully prepared for AI-powered attacks. That readiness gap is the country’s soft spot.  

Leaders are clear about where AI bites, with data loss prevention being their top worry (59%). Automated tools can discover, extract and disguise sensitive data far faster than legacy monitoring systems can detect it. Adversarial techniques follow (52%) with attackers iterating at machine speed to find weak points. Then there is social engineering, which 41% of respondents see as a heightened threat.  

Deepfake calls, synthetic identities and hyper-personalised phishing have made the human attack surface more vulnerable than ever. Nearly half of the organisations surveyed had experienced at least one attack in the past twelve months, and the financial cost, once recovery, downtime, regulatory fines and reputational damage are factored in, most landed between £100,000 and £199,999.   

Capability, not just tooling 

Yet the most striking finding from the survey is not about threat vectors at all, it is about people. Nearly seven in ten organisations admit their teams are only partially trained, or not trained at all, for AI-driven threats. Technology investment can fill some gaps, but when the threat evolves faster than the workforce, capability becomes the deciding factor.  

The UK’s problem is not a lack of intent. 73% of organisations are already increasing training efforts in response to AI-related risk. But the survey suggests these efforts remain uneven, often incrementaland rarely connected to a clearly defined capability model. Too many teams still rely on generic cyber training, which does little to prepare them for AI-specific attack patterns or the governance challenges that accompany them.  

This is where the broader debate must shift. As AI becomes embedded across business operations, the country needs a workforce prepared at multiple layers, from everyday users who must recognisemanipulated content, to technologists designing secure architectures, to leaders shaping safe adoption strategies. A one-size-fits-all approach to training cannot meet that need.  

The right training for the right people 

What the research highlights is the importance of role-specific capability development. Non-technical professionals need structured literacy to use AI safely and responsibly. Technical teams need deep practitioners-level expertise to build and secure AI systems in real environments. Leadership needs clarity on governance, ethics, risk and organisational design. These are not adjacent skills, they are independent and failing at any weakens the entire system.  

Another insight from current capability frameworks is the growing emphasis on governance and responsible AI. Organisations are now expected to integrate privacy, data stewardship, ethical evaluationand safe tool usage into their day-to-day operations – not as a separate compliance workstream, but as part of how AI is used at every level. This reflects a meaningful shift in how organisations are being asked to think about adoption.  

Deploying AI tools without the governance literacy to use them safely creates its own category of risk, one that sits alongside the external threat but is entirely self-inflicted. The question is no longer about what AI can do for an organisation, but whether the people using it understand the risks they are taking on when they do.  

The final, perhaps most encouraging, finding in the survey is that training works. Among organisations with ongoing certification-based development, 86% report a measurable reduction in cyber risk. That is not a marginal gain, it’s substantial and points directly to where the investment needs to go. 

If there is a path forward, it lies in treating AI capability as infrastructure, not as a secondary concern. That means structured learning pathways, ongoing validation, workforce-wide literacy frameworksand advanced specialist development, all aligned to the real attack patterns organisations now face.  

Author

Related Articles

Back to top button