ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Plugging the skills gap with AI

Jamal Elmellas at Focus-on-Security asks whether AI can help reduce the cyber-security workforce gap

 

Acute workforce shortages in the cyber-security space are forcing businesses to look for new ways to address the problem.

 

There are currently 3.4m job vacancies in cyber-security worldwide, equivalent to 42% of the total workforce and its growing, with 14,100 vacancies arising every year in the UK alone but throwing the net wider won’t necessarily help when it comes to skilled roles.

 

What we can do is to reduce the workload to help those skilled professionals work more productively.  

 

Artificial intelligence (AI) and automation have been gaining ground in recent years but the introduction of Large Language Models (LLMs) has caused a fundamental shift. They can be used to produce text, audio, image and video in seconds and, as they use natural language processing (NLP), are user friendly. Closed sourced versions such as OpenAI’s ChatGPT and Google’s Bard can be accessed via APIs and used to develop company specific solutions to augment the workforce and they’ve been enthusiastically adopted. 

 

Generative AI has been hugely disruptive, accelerating automation according to The Economic Potential of Generative AI report by McKinsey. In fact, it’s brought forward the time when we can expect to see half of all workforce tasks automated by a full ten years to 2045.

 

So, given its potential to redefine working practices, does this mean AI could help to fill the skills gap? 

 

AI in action

A recent Forbes Advisor survey found just over half of businesses in the US are now using AI applications for cyber-security and fraud management and Generative AI can be applied to a range of tasks. It is already being used to generate reports and documentation for governance risk and compliance (GRC) purposes, where it can quickly provide the basis policies or summarise verbose reports. 

 

From a coding perspective, it can draw from libraries and rapidly write secure code which means it could be used to both create and debug code helping those in DevSecOps. And penetration testers, who are said to have some of the scarcest skillsets according to the Cyber-security skills in the UK labour market 2023 report, can use it to create phishing tests and social engineering exercises by grabbing OSINT from social media platforms and designing personalised tests, for example. 

 

Looking ahead, 75% of businesses intend to adopt AI and automation technologies over the next five years, with automation a primary workforce strategy that 80% of organisations intend to pursue, states the Future of Work 2023 study by the World Economic Forum. That’s despite the fact that these businesses have had to weather tough economic conditions, indicating that AI is clearly seen as essential for growth.

 

But while Generative AI is very intuitive, there are still hurdles to overcome. The introduction of AI will require safeguards to be put in place such as ethical use policies to govern use. Businesses will need to ensure its output is validated, particularly given that, at present, there’s no means to check attribution. And then there’s the issue of upskilling.

 

Working with AI will become as inherent to our daily lives as working alongside the internet is today but whereas that technology gradually evolved, and our skillsets with it, Generative AI has been a big bang moment. The report predicts that over the next five years specialised AI and big data roles will grow 30-35%. Currently, AI only ranks 15th on its list of core skills but it already comes way above computer programming, network and cyber-security skills. 

 

Upskilling

The ranking implies that those that equip themselves with AI skills will therefore futureproof their skillsets and be more employable. We can expect to see new specialist roles emerge as businesses look to AI-enable their systems but just about everybody who works in a professional capacity will benefit from getting to grips with AI prompting and analysis.

 

Human input will be vital in terms of turning a practiced and discerning eye to the AI’s output but so too will problem-solving and creativity. 

 

AI will reshape the labour market, which means we could well see a shortage, at least initially, in those with the right skillsets to implement and utilise it effectively. That presents the cyber-security professional with a real opportunity to get ahead of the curve and differentiate themselves by familiarising themselves with how these systems work and driving their adoption in the workplace. 

 

It’s worth noting, too, that AI is expected to accelerate the capabilities of threat actors. Vendors have already put forward numerous use cases, with the technology being used to create backdoors, craft malware and phishing and vishing (voice phishing) attacks. It ups the ante considerably meaning that in order to keep pace, AI-defence systems will be needed, again redefining the roles of the Security Operations Centre (SOC) team.

 

Nobody knows what this brave new world will look like in terms of roles and responsibilities. However, what’s likely is that cyber-security professionals will enjoy far more agency over their roles and will be freed from the problems of things like alert fatigue.

 

But while AI can expedite processes, it doesn’t yet have the ability to critically assess or devise solutions, so it is unlikely to replace advanced roles, such as forensic analysis, security architecture, interpreting malicious code or penetration testing. 

 

Which brings us back to our question – will AI solve the skills gap? Such technological shifts have previously led to a merging of roles which means we could see the number of vacancies diminish. But equally we should expect the demand for AI to spawn a whole range of new roles.

 

What we can expect is that it will significantly impact the way we work, augmenting the cyber-security professional’s role by taking on much of the mundane work, a development that will be welcomed and may even be enough to persuade the 25% of security leaders that Gartner says have talked of quitting the profession to stay. 

 


 

Jamal Elmellas is COO at Focus-on-Security

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543