Training

Don’t think of readiness as just an onboarding problem

Futuristic Hand Reaching for AI Technology Interface Representing Artificial Intelligence and Data Management in a Digital World. Glyphic.

COMMENTARY: Most security leaders would readily admit that training a new hire requires a significant time investment.

In my observation, for them to operate independently and efficiently, it can take as much as six months. New research released last week from SkillBit agrees: 57% of cybersecurity leaders say full productivity takes half-a-year.

[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]

But there’s a number that should actually worry the industry more: 39% of leaders also cite skills decay as a concern, a sign that what people learn will go stale almost as quickly as they learn it. In a threat landscape being reshaped by intelligent automation, we can’t have readiness stay static, something that organizations only need to build once. Rather, recurring hands-on training and continuous learning must become the standard.

AI has become the great equalizer for small business owners, who now have access to capabilities that were once exclusive to Fortune 500 companies. However, there's a catch: democratized AI means democratized risk. Our own research recently found that while 90% of small and midsized businesses are using or experimenting with AI, only 23% have a documented AI use policy in place. Every organization that gains enterprise-level intelligence also inherits enterprise-level security challenges.

Today's economy drives tighter assessments of ROI on cybersecurity spending. Companies that can point to real customers achieving measurable results will win existing budget from vendors that are not capturing the performance improvements from AI. Unfortunately, organizations face significant challenges across the talent lifecycle, from onboarding new hires to keeping experienced professionals up-to-date as technologies and attack methods evolve.

Security skills are expiring faster

SkillBit’s research suggests organizations are falling short in onboarding talent, developing skills, and sustaining readiness in a rapidly-changing security environment. The most important finding in this survey is not that it takes six months for a new hire to become productive: it’s that the half-life of cybersecurity knowledge has shrunk faster than most organizations can train people. AI has accelerated the pace of change in security operations, threat detection, software development, and adversary behavior.

There's a wide gap between expectations versus reality: 64% of leaders rate three months as an acceptable time-to-value for a new hire. Yet, many wait twice that long, and with 70% of organizations reporting few or no roles for candidates with less than two years' experience, there's little room to grow talent from the ground up.

Leaders see the fix in how people learn: 71% would rather invest in weekly 20-minute learning sessions than 30-to-40 hours of training once or twice a year, and more than two-thirds value problem-solving, critical thinking, and adaptability over expertise in a specific technology stack.

Security leaders can no longer think about readiness as an onboarding problem. They need to think about it as a continuous learning problem. For SMBs, that creates a significant opportunity to leverage trusted technology partners that can bring technology expertise, managed services, and AI security capabilities that are otherwise difficult to build internally.

We're entering a period where the demand for cybersecurity expertise will exceed the industry's ability to hire and train talent. That's why managed service providers (MSPs) and intelligence providers are increasingly important. Partners can aggregate expertise across customers, spread the cost of advanced AI security tools, and offer access to skills that many businesses cannot hire on their own.

AI readiness does not consist of the mere deploying new technology. It's about creating an operating model where people, processes, AI systems, and external expertise work together. The organizations that move fastest will combine internal talent with trusted partners that bring specialized security knowledge, continuous monitoring capabilities, and real-world experience helping organizations navigate rapid change.

Security teams should focus on three strategies to close this readiness gap:

  • Build a continuous learning culture: Annual training cycles cannot keep pace with AI. Security teams need short, recurring, hands-on training that reinforces skills throughout the year, not just during compliance deadlines. The survey points toward growing interest in shorter, ongoing learning approaches that align with how practitioners retain knowledge.
  • Leverage partners as force multipliers: Organizations should not assume every emerging AI skill must get developed in-house. Cybersecurity partners such as MSPs can deliver specialized expertise, accelerate adoption, and help organizations maintain readiness while internal teams focus on strategic priorities.
  • Measure readiness, not certifications: The question isn't whether someone completed training: it's whether they can detect, investigate, and respond to real-world threats. Organizations should regularly evaluate operational readiness through simulations, exercises, and practical assessments rather than relying solely on course completion metrics.

AI has created more security work, not less. As threats become more sophisticated, organizations will need a combination of skilled employees, AI tools, and trusted partners to stay ahead. The winners won't necessarily have the largest teams. They'll have the ability to continuously learn, adapt, and tap into expertise wherever it exists.

Nick Heddy, president, chief commerce officer, Pax8

SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Each contribution has a goal of bringing a unique voice to important cybersecurity topics. Content strives to be of the highest quality, objective and non-commercial.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds