ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Human-AI teams in cyber-security

Nikolaos Maroulis at Hack The Box argues that the future of cyber-security is human-led, AI-enabled 

 

The UK government’s Spring Statement reinforced its commitment to AI-driven defence, with10% of the 2.2 billion defence budget earmarked for novel technologies such as drones and Artificial Intelligence (AI). This forms a part of wider government efforts to incorporate AI to help drive cost savings and productivity.  

 

Businesses across industries are following suit, increasingly adopting AI in the hope of strengthening their security posture. Yet, while AI can detect threats, automate responses, and process vast amounts of data at speed, it shouldn’t be treated as a silver bullet solution.  

 

It is a tool, and like any tool, its effectiveness depends on the expertise guiding and monitoring it. An over-reliance on AI creates a false sense of security.  

 

AI can enhance threat detection and response, but it can lack context and cannot replicate human judgment or strategic thinking. Cyber resilience depends on the synergy between AI and human expertise, not on prioritising one over the other. 

 

AI-ready security teams 

AI-driven tools are transforming the way security teams operate, reducing alert fatigue and automating tasks for both red teams and blue teams. However, human oversight remains indispensable, meaning that workforce development must keep pace. 

 

Blue teams need to be upskilled to interpret AI-generated insights and act decisively when automation falters. AI can fail, so teams need to retain sufficient skills to step in and course correct. 

 

Without ongoing upskilling, security teams risk misinterpreting AI outputs or overlooking novel threats that automation was not designed to detect. 

 

Our Cyber Attack Readiness Report found that while 41.9% of security teams upskill weekly, a concerning 27.9% upskill quarterly or not at all. Irregular upskilling patterns run the risk of dangerous gaps in defensive security capabilities. 

 

While AI can enhance crisis preparedness, without structured workforce development plans and cybersecurity benchmarking techniques to monitor performance and identify skill gaps, security professionals may struggle to leverage AI effectively. 

 

Introducing AI-driven security tools also presents new challenges, particularly in terms of workforce retention. While AI can alleviate some pressure by automating routine tasks, it also creates new demands. 

 

As AI continues to play a larger role in security, professionals will need to develop expertise in areas like AI model validation, adversarial AI defence, and automation oversight.  

 

This shift presents an opportunity for organisations to equip their workforce with the skills and tools necessary to keep pace, and to ensure the opportunities created by AI generates are complementary to processes, rather than a burden. 

 

The dual role of AI in upskilling 

AI is transforming upskilling for both offensive and defensive security functions. 

 

For red teams, AI can simulate an almost infinite number of attack scenarios tailored to a company’s tech stack, and automate elements of an attack to improve efficiency. For blue teams, AI-driven upskilling platforms create dynamic environments that expose defenders to evolving attack techniques. 

 

Purple team exercises become more adaptive when informed by dynamic, AI-generated scenarios. AI-driven tabletop exercises, for example, enable organisations to test their defences against realistic threats. 

 

Real-time simulations help security teams refine their response strategies and improve decision-making under pressure. These platforms accelerate upskilling by presenting new challenges that mirror the rapidly shifting threat landscape. 

 

However, AI cannot replace expertise. Its value lies in augmenting human learning, improving response times, and enabling more informed decision-making when an attack occurs. 

 

Security teams must be prepared not only to follow AI guidance but also to question and adapt its outputs. 

 

AI lowers barriers for attackers 

AI is accelerating the pace and scale of sophisticated cyber threats. Tasks that once required advanced skills, such as crafting convincing phishing emails, writing exploit code, or modifying malware to evade detection, can now be automated with AI tools. 

 

Phishing campaigns powered by AI adjust in real time based on response patterns, while adaptive malware can modify itself to bypass conventional security controls. 

 

Large language models generate scripts for exploiting vulnerabilities, enabling attackers with limited technical expertise to launch effective assaults. 

 

As adversaries harness AI to refine and automate their methods, defenders must evolve in parallel. The strength of security operations now depends on teams that can critically assess AI-generated outputs and anticipate how attackers will use similar technologies. 

 

This reflects the importance of continuous benchmarking processes and regular assessments for maintaining robust defences. 

 

AI: a tool, not a silver bullet 

One significant risk facing security teams is treating AI as a substitute for human expertise rather than a complement. While AI will increasingly take on more tasks, this shift won’t happen overnight. 

 

For the foreseeable future, the relationship between humans and AI in security will remain symbiotic, AI enhancing and automating specific functions, while human judgment and context remain essential.

 

Over-reliance on AI can weaken an organisation’s security posture, leaving it vulnerable during system failures or outages. This is particularly concerning as the sophistication of attacks grows. Without human oversight, flawed AI outputs can lead to misconfigurations, false positives, and undetected threats, significantly impacting overall security posture. 

 

CISOs must focus on integrating AI in a way that strengthens human oversight. Security teams need a deep understanding of AI’s capabilities and limitations. Rather than isolating AI expertise within technical silos, organisations should embed it across all security functions and ensure constant monitoring of knowledge. 

 

Regular crisis simulations that test AI-driven defences against realistic attack scenarios help ensure that technology supports, rather than replaces, critical human decision-making. 

 

Dovetailing AI with human expertise 

For organisations to thrive in an AI-world, they must adopt a strategic approach that blends data-driven decision making with human expertise. 

 

Security teams will increasingly shift from direct intervention to a role focused on oversight and continuous improvement. Instead of merely reacting to threats, professionals will be responsible for monitoring, validating, and adjusting AI systems in real time.

 

This integrated approach requires ongoing investment in continuous skills development and assessment. Organisations that continuously benchmark their security performance against emerging AI-driven threats will be better positioned to adapt. 

 

By creating environments where AI complements human intuition, companies can cultivate a more resilient defence posture, ensuring that AI is used as a tool for empowerment rather than a single point of reliance.

 


 

Nikolaos Maroulis is VP of Artificial Intelligence at Hack The Box

 

Main image courtesy of iStockPhoto.com and KamiPhotos


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543