Training

Why we need continuous cyber training as AI gathers strength

Skill development and AI education concept, hands using mouse and keyboard with icons for brain gears, graduation cap, book and presentation chart, upskilling workforce

COMMENTARY: Cybersecurity has become ubiquitous throughout every part of the global economy.

Cloud, IoT, software supply chains, and AI have expanded both the promise and the risk of digital transformation. At the same time, AI has intensified the need for professionals who can keep pace with emerging threats and tools. It makes sense that the latest ISC2 Cybersecurity Workforce Study found that AI topped the list as the most pressing technical skills need (41%).

[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]

Yet AI creates a challenge that extends beyond technology itself: organizations must determine how to hire for needed skills, develop them through onboarding, and keep them current as technologies evolve.

Recent ISC2 workforce, hiring, and enterprise training research conveys a common narrative thread: building cybersecurity capacity and resilient teams requires more than just recruiting talent and closing the known workforce gap. Meeting security needs demands clearer skills pathways that help professionals enter the field, become productive more quickly from day one, and continuously develop new capabilities throughout their careers.

AI reshapes cybersecurity skills requirements

The workforce study highlights how rapidly cybersecurity skills needs are changing as AI adoption becomes table stakes. Respondents identified AI for threat detection and response (42%) and threat modeling and risk assessment (39%) as priority competencies needed on cyber teams, while 35% cited defending AI models from attack as a priority skills requirement.

These findings illustrate a broader shift. Organizations are not simply competing for cybersecurity talent. They are trying to build capabilities in areas that continue to evolve, requiring clearer ways to define, develop, and assess critical skills.

Onboarding makes the skills need challenge visible

The skills need challenge becomes especially visible when organizations bring new talent onto their cyber teams.

Recent SkillBit findings shed more light on this onboarding challenge: more than half of surveyed security executives said it can take six months before a new hire delivers meaningful value, and seven in 10 say they have few openings suited to candidates with fewer than two years of experience.

As recently reported in SC Media, those pressures can launch and reinforce a cycle in which employers hesitate to hire early-career talent, then struggle to develop the experienced professionals they need. Too often, organizations treat early-career cybersecurity professionals as if they require years on the job before they can contribute meaningfully.

ISC2 research suggests that lengthy onboarding timelines are not necessarily inevitable when employers define the necessary skills and responsibilities clearly and invest in structured training. In ISC2’s hiring research, nearly two-thirds (64%) of hiring managers said entry-level professionals could be trained to handle tasks independently in less than nine months, with 38% reporting less than six months. What’s more, 76% reported spending less than $5,000 to get an entry-level professional to that point.

Organizations can strengthen their talent pipelines when they distinguish between skills needed on day one and those that can be developed through onboarding, coaching, and practical experience.

AI makes continuous learning essential

The same principle applies to experienced professionals, particularly as AI reshapes skills requirements.

A combination of skills benchmarks and continuous learning matters. ISC2’s enterprise training research found that 47% of security leaders named AI as the most pressing skill their organization was addressing or planned to address through training, while 53% cited time and scheduling as barriers to effective training. Hiring managers should define role-specific AI skills, make time to practice them, and update training as tools and the threat landscape transforms.

This transformation makes objective validation of knowledge, skills and abilities more important, but employers also must create the time and structure needed for learning, including training on both using and securing AI systems.

Some organizations build skills by allowing time for professional development during work hours (28%), funding internal training (24%), and encouraging employee-led training and knowledge sharing (21%).

We need to view workforce development as a continuous process rather than a discrete hiring event. Entry-level professionals need ownership, structure and coaching, while we must encourage experienced professionals to share knowledge as technologies and threats evolve.

Certifications support skills pathways

Certifications are one important part of the broader learning and employment ecosystem, helping organizations define skills, validate competence, and support continuous development.

For hiring managers, a globally-recognized certification indicates an agreed-upon baseline of knowledge, skills, and capabilities required to practice competently. Unlike one-and-done credentials, professional certifications are time-limited, revocable, and require continuing education. Just as important, they reinforce an obligation to deploy those skills in a way that’s relevant, principled, and ethical.

The profession's future depends on getting this balance right. Cybersecurity needs skills standards that employers can trust, pathways that professionals can follow, and learning models that keep pace with change. Together, they can help organizations build a workforce capable of meeting the demands of AI-driven change.

Casey Marks, chief operating officer, ISC2

SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Each contribution has a goal of bringing a unique voice to important cybersecurity topics. Content strives to be of the highest quality, objective and non-commercial.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds