
The UKโs cybersecurity sector is booming. According to UK Cyber Security Sectoral Analysis 2025, the sector generated ยฃ13.2 billion in revenue and created 6,600 new jobs in the past year. Itโs an industry success story, but one born out of a response to the growing volume and complexity of cyber threats, many of which are powered by malicious use of AI.ย ย
While companies are investing heavily in advanced security technology, their effectiveness often hinges on something less glamorous, but equally critical โ the โhuman firewallโ.ย ย
Safeguarding issuesย ย
Employees are a vital line of defence in an organisationโs security. They are also the most targeted, and this has increased in recent years as AI-powered social engineering tactics become more persuasive and successful.ย ย
Rather than placing blame on or getting rid of people, employers need to invest in their human firewall through continuous training. Recent attacks on retailers such as the Co-op, Harrods, and M&S (which is expected to cost the UK business ยฃ300 million) serve as a reminder that safeguarding systems begins with valuing and strengthening people.ย ย
AI-powered tools enhance threat detection and speed up responses to incidents, but theyโre not a silver bullet. Their effectiveness still relies on the insight and judgement of those who use and manage them. Itโs essential to equip and educate teams to use these advanced tools responsibly and effectively.ย
But how can organisations close a widening skills gap when AI is reshaping the way we work?ย
The rise of AI-powered attacksย
Cybercriminals are using AI to launch faster, more convincing and adaptive attacks โ from deepfakes to credential stuffing. These highly targeted and evolving threats can bypass traditional defences, making them harder to identify.ย
This new wave of AI attacks is forcing organisations to rethink their security strategies, some of which involve fighting AI with AI. But leaning too heavily on automation can bring some unwanted consequences.ย ย ย
The automation trapย
AI is fantastic for streamlining repetitive tasks and scaling operations, but it canโt completely replace human expertise, a common misconception that organisations have when it comes to adopting AI solutions. Automation improves response times, but it can fall short when it comes to interpreting complex scenarios or making judgment calls in real time.ย
The balance lies in understanding that AI can improve an organisationโs capacity to work and defend, but human oversight remains the cornerstone of an effective cybersecurity strategy. This is why upskilling employees, especially those outside of core security teams, is essential.ย
Upskilling the โhuman firewallโย
Cybercriminals frequently exploit human behaviour with social engineering tactics that manipulate peopleโs trust, curiosity, fear, and lack of awareness about current cyberattack methods in order to gain valuable information.ย ย
These vulnerabilities arenโt due to peopleโs negligence; itโs the ingenuity of cybercriminals and the limitations of technical safeguards that are creating a problem. Strengthening the โhuman firewallโ then means moving beyond one-off training sessions and improving an organisationโs entire security posture.ย
The โmindset-skillset-toolsetโ triad modelย
Businesses can enhance their cybersecurity defences by adopting a comprehensive โmindset-skillset-toolsetโ triad model, which ensures thorough training across all levels.ย ย
- Mindset: highlight the individualโs responsibility. When employees believe their actions directly impact security outcomes, theyโre more likely to engage with best practices.ย ย
- Skillset: effective training has to go beyond theory. Simulated phishing attacks, real-world scenarios that are analysed, and next-gen AI-powered personalised learning help employees develop the critical skills needed to recognise and respond to threats in real-time. Building muscle memory through repetition is key.ย
- Toolset: introduce processes and tools that strengthen employeesโ security stance. One example is to introduce password managers to discourage the use of the same log-ins across multiple accounts, which is often done out of convenience.ย
A resilient security culture doesnโt happen by chance. Itโs created by building the right attitudes, providing hands-on skills, and a good toolkit. With this approach, organisations reduce their risks and turn their people into proactive defenders against AI threats, in turn strengthening their firewall.ย
The secret value of โleast privilegeโ accessย ย
Another strategy when it comes to proactive cybersecurity defences is to enforce the principle of โleast privilegeโ access. This tactic grants users access ONLY to the data thatโs needed for their role. Limiting excessive access is important for preventing the potential for widespread data exposure and damage in the event of an account compromise. At the same time, itโs also important to avoid overly restrictive access, which can hinder productivity and lead to shadow IT issues.ย ย
Striking this delicate balance when it comes to privileged access is where sophisticated permission managers are invaluable tools to work with. They streamline this process and take away the guessing game of who has been granted access to what.ย ย
Human controlย
AIโs influence on cybersecurity will continue to evolve, but the crucial role of human expertise remains paramount. People are indispensable for tasks that AI cannot handle alone, such as managing AI systems and navigating complex, nuanced scenarios. AI serves as a powerful assistant. Organisations must prioritise upskilling their workforce to effectively wield these tools and maintain a strong human defence against ever-evolving cyber threats.ย
