ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

AI is creating a new cyber-skills gap 

Haris Pylarinos at Hack The Box explains why AI means cyber-security leaders must rethink workforce development, treating continuous, hands-on upskilling as a core component of operational readiness

Linked InXFacebook

For years, cyber-security leaders have viewed the skills gap as a headcount problem. Not enough people, not enough capacity, not enough time. But as organisations accelerate their use of AI, a more critical and less visible capability gap is emerging. 

 

The issue is no longer just about a shortage of cyber-security professionals. It is a shortage of professionals with the right skills to secure AI systems and manage the risks they introduce. 

 

Workforce intelligence from Hack The Box (HTB), based on more than 700,000 cyber-security professionals across 251 countries, shows just how quickly this shift is happening. AI penetration testing now ranks among the top global training interests at number four. That level of interest suggests security professionals recognise that AI security skills are becoming essential, even if many organisations are still in the early stages of building those capabilities. 

 

AI expands the attack surface 

As organisations deploy generative AI tools, integrate large language models into applications and experiment with autonomous agents, they are introducing entirely new attack surfaces. 

 

These systems behave very differently from traditional software. They can be influenced by language, manipulated through inputs and disrupted in ways that do not rely on conventional security vulnerabilities. This means that the skills needed to secure them are fundamentally different. 

 

HTB data highlight strong current interest in training across three emerging areas: prompt injection, model exploitation and agentic AI attacks. These are the same areas that are becoming major attack vectors. 

 

Prompt injection is now a primary concern. Unlike traditional attacks, it targets how AI systems interpret instructions rather than exploiting code vulnerabilities. Attackers can manipulate prompts to extract sensitive information, override safeguards or alter system behaviour. Its relative ease of execution, combined with defensive complexity, makes it especially challenging for organisations to manage. 

 

Model exploitation is also attracting increasing attention. This includes risks such as model backdooring, weight extraction and supply chain compromise. As organisations rely more heavily on third-party and pre-trained models, this is particularly relevant.  

 

In addition, the rise of agentic AI introduces an entirely new class of threats. AI agents capable of interacting with systems, data sources and business processes open up opportunities for attackers to manipulate workflows, abuse function-calling capabilities and compromise retrieval-augmented generation (RAG) pipelines. Although they are e still maturing, these attack vectors are evolving rapidly and require new defensive thinking. 

 

Traditional skills are not enough 

While many of the core cyber-security principles still apply in AI environments, they are not enough on their own. 

 

Security teams need to understand how models behave, how training data can be influenced and how AI systems may respond under adversarial conditions. This requires a blend of traditional cyber-security expertise, AI literacy and hands-on experience with real-world attack scenarios. 

 

The challenge is compounded by the speed of AI adoption. Businesses will often be deploying AI tools faster than security teams can properly assess them. New capabilities can appear in production environments within days, leaving security teams expected to secure systems they have not had time to fully understand. 

 

And it is here that the skills gap becomes most visible. The issue is not simply that organisations lack people. Existing teams are not equipped with the specific, practical skills required to identify and mitigate AI-driven risks. 

 

Crucially, securing AI systems is not a problem that AI can solve on its own. While organisations are increasingly using AI to enhance detection, automate analysis and accelerate response, human expertise remains central to effective security. AI systems can support but require skilled practitioners to validate outputs, recognise subtle manipulation and make informed decisions in complex scenarios. In practice, this means keeping the human firmly “in the loop,” not as a fallback but as a core part of having resilient AI-enabled security operations. 

 

The rise of the hybrid security professional 

The nature of cyber-security roles is also changing. HTB data shows a clear convergence between offensive and defensive skill development. Practitioners are increasingly building capabilities across both domains, reflecting a shift away from rigid specialisation towards more integrated “purple team” models. 

 

Defensive professionals are expanding their knowledge of attack techniques, while offensive practitioners are developing a stronger understanding of detection and response. This crossover is a direct response to the complexity of modern threats. 

 

AI-related risks do not fit neatly into traditional organisational silos. Securing AI systems has to include combined expertise across penetration testing, threat modelling, detection engineering, incident response and governance. Organisations that maintain strict functional boundaries will struggle to keep pace. 

 

Security effectiveness depends on broader, more versatile skill sets. The security professional now needs to understand how systems can be attacked, how attacks can be detected and how risks evolve over time. 

 

Rethinking workforce development 

Historically, training has been treated as a periodic activity, as something delivered to meet compliance requirements or support individual career progression. In the context of AI, that model is no longer viable. 

 

The pace of change means many skills become outdated quickly, while new attack techniques emerge faster than traditional training cycles can accommodate. As a result, organisations must treat continuous learning as part of operational readiness, not an optional extra. 

 

HTB’s findings reinforce this shift. Structured, hands-on training programmes, including gamified labs and Capture the Flag (CTF) exercises, consistently drive higher levels of engagement and capability development compared to self-directed approaches. 

 

This matters because AI security cannot be learned through theory alone. It requires practical experience, including testing models, exploiting weaknesses and understanding how systems behave under pressure. 

 

Equally important is the need to distribute AI security knowledge more widely. Organisations cannot rely on a small group of specialists. As AI becomes embedded across business operations, a broader section of the cyber-security workforce needs at least a working understanding of AI-related risks. 

 

The goal is not just to train people to use AI tools. It is to develop practitioners who can critically assess AI systems, identify emerging threats and adapt as technologies evolve. 

 

The capability challenge 

With AI, the cyber-security skills gap is not disappearing, but it is changing. 

 

What was once primarily a hiring challenge is becoming a capability challenge. In the future, success will not be defined by the size of a security team but by its ability to adapt, learn and respond to new forms of risk. 

 

AI is reshaping attack techniques, expanding the threat landscape and forcing organisations to rethink how they build and maintain security expertise. And for security leaders, the message is clear - workforce development must be a strategic priority. 

 

The organisations that invest in building AI-ready teams with the skills to secure AI systems, understand emerging attack vectors, and continuously evolve will be best positioned to manage the threats of tomorrow. 

 


 

Haris Pylarinos is Founder and CEO of Hack The Box 

 

Main image courtesy of iStockPhoto.com and Patamaporn Umnahanant

Linked InXFacebook
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543