Beyond Automation: Why Human Expertise Still Matters
STORY INLINE POST
There is a version of the AI-in-cybersecurity story that gets regularly retold. Artificial Intelligence will automate threat detection, close the workforce gap, and make complex analysis accessible to smaller, cheaper teams. It’s a reassuring narrative and it isn’t entirely untrue. But it does obscure a harder question that most organizations are not yet asking. If AI is handling more of the heavy lifting, what exactly do we need from the humans working alongside it?
The answer is more demanding than many expect. AI adoption in security operations is accelerating fast. According to recent Kaspersky data, almost every company either has or plans to have their own internal AI tool (97%), 11% already have a working tool, while the rest (86%) plan to introduce it later. This is a structural shift that raises the floor for human professionals.
Ironically, these AI ambitions face a serious hurdle in the shape of a shortfall of human resources. The global cybersecurity workforce gap reached an estimated 4.8 million in late 2024, which represents a 19% year-on-year increase. Demand is outrunning supply at exactly the moment when the nature of the work is changing most rapidly.
To understand what skills matter now, it helps to be precise about what AI actually contributes and where it stops. Organizations that extensively leverage AI in security reduce average breach costs by up to US$1.9 million and shorten breach life cycles by approximately 80 days. Those are more than marginal gains.
But AI has hard limits, and those limits define the human contribution. AI operates within the distributions it was trained on. It struggles with genuinely novel attack vectors like the kind that haven’t been seen before, the kind that a creative adversary deliberately engineers to evade detection.
AI can’t make judgment calls that require accountability, like deciding whether to disclose a breach, weighing business risk against security risk, or communicating findings to a board that needs to act on them. It cannot interrogate its own outputs with adversarial skepticism and it cannot build the trust with stakeholders that effective security leadership requires.
There is also a more uncomfortable dimension. AI is reshaping both attack and defense simultaneously. Kaspersky’s Market Pulse B2B research found 13% of companies experienced AI vulnerabilities exploitation and 11% faced deepfake attacks. While these numbers might seem low, there is every chance they will rise over time.
Threat actors are using the same tools defenders are to generate malware, automate social engineering at scale, and probe for vulnerabilities faster than patch cycles can respond. The ceiling for AI-powered offence is the floor for human-powered defense. Professionals need to understand how AI attacks are constructed in order to counter them.
When trying to identify professionals with the most sought-after credentials, Kaspersky research offers a useful starting point. Hiring managers were asked what most determines candidate qualification. The top response, cited by 70%, was hands-on training. Previous experience and work portfolios came in at 69%, ahead of certifications (68%) and university degrees (64%).
The market is already signaling that applied, practical capability commands a premium. In the AI era, this premium is only going to increase. Harder-to-teach skills may matter more than the technical ones. According to Kaspersky, 63% of InfoSec specialists say hard and soft skills are equally critical.
There is also a training gap that organizations are only beginning to confront. According to the recent study, 58% of recent graduates believe they need a deep understanding of AI to succeed at work, yet only 28% said AI was meaningfully integrated into their degree.
One reason the skills conversation in cybersecurity often stalls is that it treats the field as a single discipline. It isn't. The skill mix required of a malware analyst is fundamentally different from what a security operations professional needs, which is different again from the work of a threat intelligence analyst or a network security specialist.
“Upskilling your team in AI” is not a coherent plan. Different roles require different skill equations, and development investment needs to reflect that specificity. The Cyber Pathways tool is built around exactly this logic, helping individuals identify their specialization and understand what the path from current capability to genuine expertise actually looks like, rather than defaulting to a generic list of certifications.
For organizations, the temptation to treat AI as a substitute for headcount or deep expertise would be a dangerous mistake. AI’s value in cybersecurity lies in augmenting human expertise and strengthening resilience, and its impact depends on strong governance and human oversight from the outset.
Kaspersky research makes clear that hands-on training outranks credentials in what hiring managers actually value. And AI literacy needs to be embedded in role-specific contexts, not delivered as a standalone module disconnected from how people actually work.
Organizations are faced with a landscape where new competency areas are emerging faster than traditional training cycles can respond. Organizations need development infrastructure that can move at that pace.











