Can AI Help Reduce The Cybersecurity Workforce Gap?

Much has been made of whether Artificial Intelligence (AI) will steal our jobs but what if it could do the opposite and help us to resolve the current skills crisis? According to (ISC)2 there are 3.4m job vacancies in cybersecurity worldwide, equivalent to 42% of the total workforce and its growing, with 14,100 vacancies arising every year in the UK alone. 

These skills shortages have already forced businesses to look at where they can automate processes, with 17% of organisations using AI/ML and automation in cybersecurity operations, according to (ISC)2. But such figures predate the emergence of generative AI.

Now, according to the Future of Work 2023 study by the World Economic Forum (WEF), 75% of businesses intend to adopt AI and automation technologies over the next five years. Moreover, automation is now regarded as a primary workforce strategy that 80% of organisations intend to pursue. 

AI As An Aid

There’s now much more belief in the ability of the technology to aid us in tasks. AI is already being used in a cybersecurity context to generate reports and documentation in GRC. It’s able to draw from libraries and rapidly write secure code which means it could be used to both create and debug code jeopardising those in DevSecOps. Penetration testers and red teamers are also likely to use its capabilities to create phishing tests and social engineering exercises as it can grab OSINT from social media platforms etc. 

These and other use cases illustrate the ability of the technology to lighten the load of security teams and that’s vitally important because stress is directly contributing to the workforce gap. A recent survey found that over half of UK IT industry decision makers think they will lose cybersecurity staff this year due to burnout.

Alleviating the pressure on security personnel also frees up resource, so that instead of having to start from scratch when generating code or a report, the cybersecurity professional simply needs to check, verify and extend the results produced by the AI. This is likely to see job remits change overtime, and AI skills become prized.  

Changing Roles

The same WEF survey found that AI and big data roles are predicted to grow 30-35% over the next five years. Furthermore, while AI only ranks 15th on its list of core skills today, that is still well above the ranking of computer programming, network and cybersecurity skills, suggesting AI will soon be regarded as an essential core skillset. 

We’re also now seeing vendors offer the technology alongside their solutions. This enables their customers to use AI to summarise SOC incident reports and SOAR playbook outputs, for instance, improving the speed of response. And these advances are driving investment.

A recent Blackberry survey revealed that 48% of IT decision makers plan to buy AI-driven cybersecurity solutions during the course of this year and 82% over the next two years.

Taking all these factors into consideration, it appears that AI is in many ways a logical extension of the automation we’ve already seen in the industry, such as automated threat hunting, incident response, and even red teaming. It’s by no means perfect and as with any tool the results will need to be verified with quality checks in place. But it does move us on from the point of cybersecurity being a purely technical career.

The Human Factor

As we’ve seen in recent reports such as the (ISC)2 Cybersecurity Hiring Managers Guide, soft skills are becoming far more sought after and valued. They’re a core part of any cybersecurity job interview, with the top non-technical skills being the ability to work in a team and independently, with project or customer facing experience, and good presentation skills.

Top soft skills include problem solving, creativity, analytical thinking, the desire to learn and critical thinking. This is because it is now widely acknowledged that while technical skills can be taught, these other skillsets are innate.

Of course, many cybersecurity jobs do require technical competency but there are now such a diversity of roles and skillsets that the UK Cyber Security Council has been tasked with mapping these into a Cyber Career Framework using 16 Cyber Pathways. In a similar fashion, the EU launched its European Cybersecurity Skills Framework (ECSF) in September to enable employers, recruiters and candidates to more accurately advertise job positions and plan their workforce. 

My guess would be that those roles will again morph over time as AI begins to permeate the workplace and we’ll see prompting, for example, become core skillset.

We can expect some roles to merge, others to expand and new ones to evolve – but the constant will be the human in the machine. AI has great potential and will almost certainly help alleviate the cyber skills shortage. But it is no substitute for human intellect, intuition, reasoning and analysis.

Jamal Elmellas is COO at Focus-on-Security                      Image:  Adi Goldstein on Unsplash

You Might Also Read: 

The Skills Gap Is Increasing Risk & Exposure To Attack:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« Malvertising Proliferates As Half Of Online Ads Are Now AI Generated 
Zero Trust: A Paradigm Shift in Cybersecurity »

ManageEngine
CyberSecurity Jobsite
Check Point

Directory of Suppliers

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

IntaForensics

IntaForensics

IntaForensics offer a full range of digital investigation services and are able to adapt to the individual needs of solicitors, private clients, Law Enforcement Agencies and commercial businesses.

Howden Broking Group

Howden Broking Group

Howden provides a range of specialist insurance solutions to clients around the world including Cyber Liability insurance.

Netteam

Netteam

Netteam designs, implements and services networking solutions for companies of all sizes.

Sysmosoft

Sysmosoft

Sysmosoft specializes in providing highly secured telecommunication solutions for mobile devices for companies requiring protected access to sensitive data remotely.

Resilia

Resilia

RESILIA is a comprehensive portfolio of tools and training to help your organization achieve global best practice in cyber security.

DynaRisk

DynaRisk

DynaRisk helps companies protect their staff, clients and supply chain from cyber threats by enabling people to take action for themselves.

Data Destruction London

Data Destruction London

Data Destruction London offers fast, confidential and compliant expert data destruction services to businesses and organisations in London.

Stratus Cyber

Stratus Cyber

Stratus Cyber is a premier Cyber Security company specializing in Managed Security Services. Our services include Blockchain Security, Pentesting, and Compliance Assessments.

BlackCloak

BlackCloak

BlackCloak provides Concierge Cyber Security for high-net-worth individuals and corporate executives to protect them from cybercrime, reputational risks, hacking and identity theft.

Axxum Technologies

Axxum Technologies

Axxum Technologies is a premier provider of Network Communications and Information Technology Security Solutions.

Paradyn

Paradyn

Paradyn-managed security services can provide a holistic view of your business environment, no matter how simple or complex it is.

Shorebreak Security

Shorebreak Security

Shorebreak Securioty specialize in conducting highly accurate, safe, and reliable Information Security tests to determine the risks posed to your business.

FastNetMon

FastNetMon

FastNetMon is a very high performance DDoS detection and mitigation tool which could detect malicious traffic in your network and immediately block it.

Secjur

Secjur

Secjur is a provider of AI-based compliance tools that aim to put compliance, data protection, information security and whistleblowing on autopilot.

Raven

Raven

Raven are on a mission to help companies protect their cloud native applications by focusing on runtime.

SafetyDetectives

SafetyDetectives

SafetyDetectives' mission is to give our readers accurate and valuable information so they can make informed decisions about staying safe, secure and protected on the internet.