Can AI Help Reduce The Cybersecurity Workforce Gap?

Much has been made of whether Artificial Intelligence (AI) will steal our jobs but what if it could do the opposite and help us to resolve the current skills crisis? According to (ISC)2 there are 3.4m job vacancies in cybersecurity worldwide, equivalent to 42% of the total workforce and its growing, with 14,100 vacancies arising every year in the UK alone. 

These skills shortages have already forced businesses to look at where they can automate processes, with 17% of organisations using AI/ML and automation in cybersecurity operations, according to (ISC)2. But such figures predate the emergence of generative AI.

Now, according to the Future of Work 2023 study by the World Economic Forum (WEF), 75% of businesses intend to adopt AI and automation technologies over the next five years. Moreover, automation is now regarded as a primary workforce strategy that 80% of organisations intend to pursue. 

AI As An Aid

There’s now much more belief in the ability of the technology to aid us in tasks. AI is already being used in a cybersecurity context to generate reports and documentation in GRC. It’s able to draw from libraries and rapidly write secure code which means it could be used to both create and debug code jeopardising those in DevSecOps. Penetration testers and red teamers are also likely to use its capabilities to create phishing tests and social engineering exercises as it can grab OSINT from social media platforms etc. 

These and other use cases illustrate the ability of the technology to lighten the load of security teams and that’s vitally important because stress is directly contributing to the workforce gap. A recent survey found that over half of UK IT industry decision makers think they will lose cybersecurity staff this year due to burnout.

Alleviating the pressure on security personnel also frees up resource, so that instead of having to start from scratch when generating code or a report, the cybersecurity professional simply needs to check, verify and extend the results produced by the AI. This is likely to see job remits change overtime, and AI skills become prized.  

Changing Roles

The same WEF survey found that AI and big data roles are predicted to grow 30-35% over the next five years. Furthermore, while AI only ranks 15th on its list of core skills today, that is still well above the ranking of computer programming, network and cybersecurity skills, suggesting AI will soon be regarded as an essential core skillset. 

We’re also now seeing vendors offer the technology alongside their solutions. This enables their customers to use AI to summarise SOC incident reports and SOAR playbook outputs, for instance, improving the speed of response. And these advances are driving investment.

A recent Blackberry survey revealed that 48% of IT decision makers plan to buy AI-driven cybersecurity solutions during the course of this year and 82% over the next two years.

Taking all these factors into consideration, it appears that AI is in many ways a logical extension of the automation we’ve already seen in the industry, such as automated threat hunting, incident response, and even red teaming. It’s by no means perfect and as with any tool the results will need to be verified with quality checks in place. But it does move us on from the point of cybersecurity being a purely technical career.

The Human Factor

As we’ve seen in recent reports such as the (ISC)2 Cybersecurity Hiring Managers Guide, soft skills are becoming far more sought after and valued. They’re a core part of any cybersecurity job interview, with the top non-technical skills being the ability to work in a team and independently, with project or customer facing experience, and good presentation skills.

Top soft skills include problem solving, creativity, analytical thinking, the desire to learn and critical thinking. This is because it is now widely acknowledged that while technical skills can be taught, these other skillsets are innate.

Of course, many cybersecurity jobs do require technical competency but there are now such a diversity of roles and skillsets that the UK Cyber Security Council has been tasked with mapping these into a Cyber Career Framework using 16 Cyber Pathways. In a similar fashion, the EU launched its European Cybersecurity Skills Framework (ECSF) in September to enable employers, recruiters and candidates to more accurately advertise job positions and plan their workforce. 

My guess would be that those roles will again morph over time as AI begins to permeate the workplace and we’ll see prompting, for example, become core skillset.

We can expect some roles to merge, others to expand and new ones to evolve – but the constant will be the human in the machine. AI has great potential and will almost certainly help alleviate the cyber skills shortage. But it is no substitute for human intellect, intuition, reasoning and analysis.

Jamal Elmellas is COO at Focus-on-Security                      Image:  Adi Goldstein on Unsplash

You Might Also Read: 

The Skills Gap Is Increasing Risk & Exposure To Attack:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« Malvertising Proliferates As Half Of Online Ads Are Now AI Generated 
Zero Trust: A Paradigm Shift in Cybersecurity »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Certification Europe

Certification Europe

Certification Europe (now Amtivo Ireland) is an accredited certification body which provides ISO management system certification, including ISO 27001.

Advanced Resource Managers (ARM)

Advanced Resource Managers (ARM)

ARM provide specialist recruitment services for technology and engineering including cyber security.

Security Audit Systems

Security Audit Systems

Security Audit Systems is a website security specialist providing website security audits and managed web security services.

Momentum Cyber

Momentum Cyber

Momentum Cyber provides world-class M&A and strategic advice combined with unparalleled senior-level access to the Cybersecurity ecosystem.

InstaSafe Technologies

InstaSafe Technologies

InstaSafe®, a Software Defined Perimeter based (SDP) one-stop Secure Access Solution for On-Premise and Cloud Applications.

DataProtect

DataProtect

DataProtect is a specialized information security company providing consultancy, information management, integration and training services.

Assystem

Assystem

Assystem delivers a comprehensive security approach for the industrial and service sectors that integrates physical security systems, industrial cyber-security, functional safety and dependability.

Scanmeter

Scanmeter

Scanmeter helps identifying vulnerabilities in software and systems before they can be exploited by an attacker.

Intrinium

Intrinium

Intrinium is an Information Technology and Security Solutions company, providing comprehensive consulting and managed services to businesses of all sizes.

Pelion IoT

Pelion IoT

Pelion Connected Device Services are the easiest way to securely connect and manage your devices, allowing you to focus on forging your future.

Cyber Skyline

Cyber Skyline

Cyber Skyline is a revolutionary cloud platform to practice, develop, and measure your team's technical cybersecurity skills.

AgileBlue (Agile1)

AgileBlue (Agile1)

AgileBlue (formerly Agile1) is a managed breach detection company with an Autonomous SOC-as-a-Service for 24×7 monitoring, detection and guided response.

InfoSec Brigade

InfoSec Brigade

InfoSec Brigade offers a suite of specialized solutions that help businesses to mitigate risk by integrating cyber and IT security protocols with business goals.

EmberOT

EmberOT

EmberOT is at the forefront of operational technology (OT) security, offering cutting-edge solutions designed to protect critical infrastructure within energy, utilities, and manufacturing sectors.

Vortacity Cyber

Vortacity Cyber

Vortacity is a boutique cybersecurity provider specializing in associations, nonprofits, and mission-based organizations.

Cyberverse Foundation

Cyberverse Foundation

Cyberverse Foundation is an organization dedicated to building a robust cybersecurity ecosystem in India.