The current skills gap in cybersecurity is a legitimate concern. But it’s nothing new, in fact, it’s the next iteration of a problem that organizations have faced with every major digital shift. Every evolution of how data is stored, sent, and received leaves security as one of the first casualties of structural change.
Take cloud adoption. When enterprises raced to the cloud starting around 2010, security teams were left scrambling to rebuild their approach from the ground up, with corporate data moving faster than teams could be trained in cloud architecture and data sovereignty. By 2015, employer demand for security talent had outpaced supply.
The same pattern is repeating with AI, but with one important distinction. Previous waves of technological change exposed skills gaps. AI has the potential to conceal them by creating the illusion of competence. As AI becomes embedded across security workflows, teams can move faster and accomplish more, even as fewer practitioners develop the expertise needed to investigate novel threats, triage complex incidents, and think like an adversary.
If cybersecurity leaders fail to examine how AI is being adopted, and the skills gap it buries, they risk more than weaker defenses. They will potentially mistake AI-assisted productivity for capability, weakening the pipeline of future security experts that our industry has worked hard to build.
What’s Driving the Skills Gap
We recently conducted <a href="https://tryhackme.com/business/resources/reports/shadow-AI-report” rel=”nofollow noopener” target=”_blank”>research to explore the factors behind AI’s skills gap expansion. We discovered four compounding problems:
1. Businesses are, knowingly or not, trading skill for speed. AI-assisted workers may get more done, but it doesn’t come without a cost. 82% of cybersecurity workers say AI makes them feel more productive, but not more skilled. AI has been consistently recognized for its ability to deliver outputs that appear convincing on a surface level, but can rapidly fall apart upon closer scrutiny. When teams are pressured to maximize velocity, they’re incentivized to lean heavily on initial outputs and minimize time spent questioning them. The results are not only lower quality outputs slipping into critical workflows, but more concerningly, a degrading industry-wide fluency that’s needed to hold AI accountable long term.
2. Workers are losing trust in their own skills. Only 38% of cybersecurity professionals are confident their current skills will still be valuable in the near future, and 18% expect to take on tasks or responsibilities they haven’t learned how to handle. This confidence curb impacts not only daily job performance and satisfaction, but also retention. Employers who provide real guidance and reassurance to workers about the unique and irreplaceable value they continue to bring to the table will gain an upperhand when it comes to talent.
3. Job pressure is fueling AI dependency. Over three-quarters (76%) of professionals regularly lean on AI to complete tasks they don’t fully understand, and 66% say they’d struggle to do their job without AI tools at all. Under pressure to hit deadlines, 98% admit to using AI tools their organization hasn’t approved. While this paints an alarming picture about the scale of the growing threat unsanctioned AI use poses to security, having awareness of the root of the cause of the misuse is the first step to create meaningful change.
4. Training hasn’t kept pace with the job. Almost one in five professionals (18%) say training resources exist, but feel disconnected from what they actually do day-to-day. As AI reshapes the skills the job demands, static courseware isn’t enough. Training needs to mirror the real, AI-augmented environment teams actually work in. Otherwise, they’re not genuinely prepared to face security challenges in real contexts.
These challenges bring a larger issue into focus. The people tasked with governing AI risk are becoming dependent on the tools they’re supposed to be scrutinizing. Cybersecurity professionals must become the rock solid front line when it comes to secure and appropriate AI use, or we risk a long-term backslide in security expertise that could have significant socioeconomic impacts long term.
Prioritizing Capability Has To Come First
Since AI’s rollout to the everyday worker, there hasn’t been strict adherence to approved tools and use cases. Organizational AI policies today often act as a laundry list of what is approved and what isn’t, but governance alone won’t solve the problem.
Balancing capability with productivity through AI-assisted work demands a cultural shift in how we think about performance at work in the first place. We need to measure achievements by more than the speed they took to complete.
In practice, this might look like leaders asking analysts to walk through AI-assisted decisions without first referencing the tool’s recommendations and putting value on the critical thinking process itself. Seeing what analysts can explain from their own understanding, like the reasoning behind a decision, the trade-offs considered, and the signals they prioritize, are all better measures of meaningful capability than the final outcome alone.
Organizations should also create opportunities to compare AI-assisted and AI-independent performance. Not as a test of whether teams can work without AI, but as a way to identify where AI is accelerating expertise versus where it is masking a gap. The strongest teams will use AI as a force-multiplier rather than a substitute.
Many upskilling programs will need to evolve as well. Training shouldn’t focus exclusively on the adoption of new tools. In particular, it needs to reinforce the skills those tools can’t and shouldn’t replace.
For security teams, that’s developing the ability to investigate unfamiliar threats, understand attacker behavior, question assumptions, and make decisions when the available information is incomplete. Building those capabilities requires practice against realistic challenges in the context of real tools and real threats. Every AI-assisted task is an opportunity to strengthen human expertise, ensuring teams become more capable with AI while remaining effective without it and equipped to catch the tool’s mistakes.
Critically, none of this means slowing AI adoption or asking teams to work without the tools that make them more effective. It means being intentional about what AI should accelerate, and what humans still need to own.
Your AI Is Only as Good as Your Team
Every digital shift has forced the same test: will the people responsible for security build real understanding, or will the pressure to move fast paper over the gap instead? Cloud adoption made the industry answer that question the hard way through years of scrambling and hard-won expertise. Now, AI is creating a dangerous temptation to skip the test entirely.
For leaders grappling with the incredible task of adapting their workforce to this global shift in how work gets done, remember that where leadership places value is where employees will place value. Motivate and incentivize teams by rewarding good process, not maximum output. Continually reinforce the unflinching worth of inquiry, critical thinking and independent decision making. Publicly praise and acknowledge instances and individuals who go out of their way to make sure work is getting done right, even when AI offers a shortcut.
Day in and day out, we have to keep deciding collectively, will we make the easy decision or the right one? In a threat landscape where the risk is only growing, taking shortcuts too often can dismantle a talent pipeline that has the adeptness to execute the everyday and navigate the unknowns of their role.
Tinus Green is a Senior Content Engineer at TryHackMe, where he designs lab environments, network configurations and assessment content used by enterprise security teams, including red team engagement labs and SOC training scenarios. He is also Head of Consultancy at MWR CyberSec, where he leads the firm’s consulting practice and supports executive teams during active security incidents as one of MWR’s Crisis Directors.
