If elite ethical hackers are worried about AI, most security teams should be too, warns Phil Chapman at Firebrand Training

Valentina Palmiotti, better known as Chompie, had a remarkable few days at this year’s Pwn2Own competition in Berlin. She won $70,000 across two days, pulling an all-nighter between rounds and walked away as one of the most decorated individual competitors at one of ethical hacking’s biggest annual events.
She also said she entered because she thought it might be her last chance. Her reasoning was straightforward: AI is getting good enough that even the best human hackers are going to struggle to keep up. Tools like Anthropic’s Mythos can already find vulnerabilities at a scale and speed that no individual can match. In Chompie’s view, the accessible end of competitive hacking is going to dry up, leaving only a handful of the very best with a genuine edge.
If someone at the top of the profession is questioning her own future in it, the rest of the industry probably deserves a moment of reflection too.
Chompie and her peers are outliers. They have spent years sharpening highly specialised skills and they are already finding ways to work alongside AI rather than against it.
But most security professionals are not in that position. Day-to-day security work means managing real threats inside real organisations, often with tight budgets, understaffed teams and not nearly enough hours in the week. According to the government’s Cyber Security Breaches Survey, only 19% of UK businesses ran any staff cyber-security training in the past twelve months. That number has barely shifted in years.
So, while the top hackers are already adjusting their approach, a large chunk of the UK security workforce has not yet had the chance to start.
I have a long-standing background in looking at threat intelligence in all forms, and one thing that was drilled into me early on is that the technology employed is almost never the issue. What matters is whether the person using it knows what they are looking at. Raw intelligence is only useful if you can read it, contextualise it and act on it quickly. That takes experience and training, and there is no workaround.
AI lowers the barrier to entry for attackers. Attacks that used to require real skill can now be largely automated. Vulnerabilities that might have taken an experienced defender several days to find can now be flagged in a fraction of the time. The volume of what defenders are up against is growing, and so is the sophistication.
Microsoft UK National Security Officer Jo Miller’s briefing at Infosec Europe 2026 highlighted the statistic that a cyber-attack can break out and compromise entire corporate networks in as little as 27 seconds. She emphasised that cyber-defence is no longer optional and urged boards to treat cyber-risk as a fundamental governance issue.
However, AI also improves what defenders can do. Research from Firebrand found that only 27% of UK organisations are fully prepared for AI-powered attacks. But among those that have invested in ongoing certified training, 86% report a measurable reduction in cyber-risk. Better tools exist for defenders too. The question is whether people have the skills to use them properly.
The organisations managing this well tend to treat training as something ongoing rather than a one-time event. AI moves quickly and teams that start building that capability now will have something to build on as things develop.
Nearly half of UK organisations in Firebrand’s research have experienced at least one attack in the past twelve months. The cost, factoring in recovery, downtime, fines and reputational damage, typically landed between £100,000 and £199,999. For most organisations, that is more than a decent training programme would cost.
Orange Tsai, another contestant at Pwn2Own, described AI as a brilliant assistant that frees him up to pursue more ideas and go further with the ones worth pursuing. AI is not pushing human judgment out of cyber-security but making that judgment count more. The teams that invest in their people will be able to use AI tools effectively, understand what those tools are actually telling them, and respond with the speed and clarity the current environment demands.
Chompie’s concern is not about AI being unbeatable. It’s about pace. The organisations that act now will be in a stronger position than those that wait until they have no choice.
Phil Chapman is Cybersecurity Subject Matter Expert at Firebrand Training
Main image courtesy of iStockPhoto.com and ATHVisions
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543