ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

The AI boom’s bottleneck is capability and CISOs need to build it across their teams 

There is plenty of discussion around how to secure AI systems, defend against AI-enabled attacks, when to ensure human oversight and how to manage the risks that autonomous technologies create. CISOs are rightly particularly concerned about prompt injection, data poisoning, model manipulation and AI-generated attacks. But whether organisations have the capability to use AI effectively and securely is just as important. 

 

AI is becoming part of mainstream business operations for many organisations. But although they have access to AI, do they have the organisational capability to use it well?  For security teams, that means having people who can implement AI securely, test it properly, challenge its outputs, understand its limitations and make good decisions about where human oversight is required. 

 

When the impact of AI on the workforce is discussed, the focus is often on whether AI will replace jobs. Far less attention is given to how organisations can equip their existing security and IT teams to work effectively in an AI-enabled environment. 

 

For CISOs, it’s a workforce capability issue. Not that every security professional needs to become an AI engineer but security teams collectively need the knowledge, practical skills and judgement to work alongside AI. CISOs can’t assume that a security professional who was highly effective before the adoption of generative and agentic AI will still be effective simply by adding an AI tool to their existing workflow. 

 

Building AI capability across the security team 

There is a tendency to think of AI literacy as knowing how to write a good prompt or use a generative AI assistant. Those are useful skills but, for a security team, are only the starting point. The depth of knowledge will vary by role but the capability has to extend across the security function. 

 

A penetration tester needs to understand how to assess AI-enabled applications and agents. A threat hunter needs to understand how AI changes attacker behaviour. A SOC analyst needs to know when AI-generated analysis is useful and when it needs independent validation. Security architects need to understand how AI changes data flows, permissions and trust boundaries. 

 

An application that retrieves information and generates a response presents one set of security considerations; an autonomous agent that can access sensitive information, make decisions and take actions across multiple systems presents another. Security teams also need enough understanding to recognise these differences, assess the risks and determine where human intervention is required. 

 

Security skills need to evolve alongside AI threats 

AI capability also means understanding how AI itself can be attacked. Prompt injection, data poisoning, model manipulation, model extraction and attacks against AI agents need security professionals to think differently. And with AI being embedded in applications, development environments and security operations, these can’t be seen as niche, specialist skills. 

 

The latest Hack The Box Workforce Intelligence Report, based on more than 700,000 cyber-security professionals worldwide, shows that AI security is moving up the training agenda to become a mainstream priority. AI penetration testing, prompt injection, model exploitation and agentic AI security are all now prominent areas of professional development. 

 

For CISOs, AI security capability has to be built into the whole team’s development. Practitioners need opportunities to work with AI systems in realistic environments, understand how they behave under pressure and learn how attackers might exploit them. In the same way that traditional cyber-security skills are developed through practical exercises, AI security capabilities need to be tested and practised. The objective is not just to give people more knowledge but to help them develop, practise and demonstrate the experience and judgement needed. 

 

Knowing when not to trust AI 

Perhaps the most important AI capability CISOs need in their teams is judgement. AI may produce convincing outputs that are incomplete, inaccurate, or inappropriate for a specific business context. Security teams need to know how and when to challenge. 

 

That means asking for evidence, understanding what assumptions the system has made, knowing what information it had access to and considering what it may have missed. It means knowing when an answer can be accepted, when it needs independent verification and when a human decision-maker needs to intervene. 

 

These capabilities only develop through experience and practice. Hands-on learning gives people realistic opportunities to test AI, see where it fails and develop the confidence to challenge its recommendations. 

 

As organisations move towards agentic AI, realistic, practical learning will be even more important. An AI system that can execute actions, access sensitive information or interact with other systems needs closer human oversight. As autonomy increases, so will the consequences of poor judgement. And the value of security professionals who understand AI’s capabilities and its limitations will also increase. 

 

CISOs need to avoid automating away expertise 

AI is effective at accelerating routine and medium-complexity tasks but these are traditionally how cyber-security professionals developed skills and judgement. If AI takes over this work, without a development strategy in place, organisations could weaken their future talent pipeline. 

 

CISOs need to think about AI adoption and capability development together. Teams should have opportunities to use AI to accelerate their work, while also understanding the underlying reasoning, investigating independently and learning from failure. And this means creating new opportunities for people to practise, experiment, make decisions and develop judgement as AI takes on more of the work. 

 

Building an AI-ready security function 

For CISOs, AI capability has to be an ongoing workforce development priority. This means understanding what their teams can do today, where capability gaps are emerging and how those gaps can be addressed through practical, relevant development. 

 

AI readiness also needs CISOs to create an environment where human capabilities continue to develop as the technology changes. AI will continue to evolve. New models will appear; agents will become more autonomous and the boundary between human and machine activity will blur even more. 

 

The organisations that get the most from AI will be those that have built the capability to use it well. For CISOs, that means building security teams that work alongside AI, challenge it, test it, govern it and have the judgement to intervene when necessary. 

 


 

Haris Pylarinos is Founder and CEO at Hack The Box 

 

Main image courtesy of iStockPhoto.com and Hiraman


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543