Key takeaways

  • Working in cybersecurity is a tough gig.
  • However, staff should pause before sending their resignation letters: in an age of AI, where threats come from multiple angles, your…
  • "In IT, lots of rules are changing.

What happened

Working in cybersecurity is a tough gig. While security teams work hard to prevent damage to their organizations, ZDNET reported earlier this year that many cyber professionals aren't receiving the recognition they deserve In such a fast-changing and challenging working environment, it's easy to understand why almost half of cybersecurity pros want to quit.

"Curiosity generates the most impactful questions, and critical thinking decides which answers hold up," he said. " Schmitt said curiosity without critical rigor leads to noise, and rigor without curiosity leads to stagnation, suggesting professionals with the right blend of capabilities will appeal to businesses that develop a proactive approach to cyber risks.

"Together, these skills allow a security professional to keep pace with a threat landscape that no longer rewards static expertise," he said. " This focus on critical thinking skills also appeals to Ankur Anand, CIO at recruiter Harvey Nash, who suggested industry research points to a significant problem -- over-reliance on AI tools could leave enterprises exposed to attacks.

He referred to SecRespond's recently released benchmark that tested 23 leading AI models against real forensic data from compromised systems. Every model failed on the same category of attack: intrusions that never triggered an alert in the first place.

Why it matters

However, staff should pause before sending their resignation letters: in an age of AI, where threats come from multiple angles, your business needs you now more than ever. As Fabrizio Pilotti, CIO at Aston Martin Aramco Formula One, said to ZDNET recently, digital leaders must think carefully about the balance between AI and human capabilities, and maintaining this equilibrium effectively creates new opportunities for security professionals.

"In IT, lots of rules are changing. We're thinking a lot about team structure, even job descriptions between the agentic part and non-agentic part," he said. " The good news, therefore, is that talented cyber staff could finally receive the recognition their skills fully deserve. But as agentic AI hoovers up elements of the traditional IT security role, how can cyber professionals prove their worth and build a successful career?

The experts suggest successful candidates will focus on three key areas: curiosity-led critical thinking, instinctive qualities that sit above the automation line, and an ability to turn ambiguous signals into confident, risk-based decisions. Eric Schmitt, global chief information security officer at risk and claims administration specialist Sedgwick, said many people mistakenly believe that a great cybersecurity professional is someone with certifications or years of experience.

While those credentials can indicate someone's likely capabilities, they are no guarantee of success, particularly in a world where AI and other emerging technologies transform the nature of attacks and the methods of response. To this end, Schmitt told ZDNET that a great cybersecurity professional excels in one key area: curiosity. ' over someone 20 years in who doesn't," he said.

Schmitt said that while experience teaches you what has worked in the past, curiosity teaches you what might break next and where the solution may be, a distinction that has never mattered more than it does in today's rapidly changing threat landscape. " However, curiosity alone is not enough. Schmitt suggested curious cybersecurity professionals also need strong critical thinking skills.

What to watch

"That's the detail that should worry people more than any skills-gap statistic," he told ZDNET, suggesting that most security tools, including those that use AI, work by investigating something that's already flagged as unusual. " Anand said the best cybersecurity professionals possess the judgment to know when something's awry. " So, how can IT security staff hone these instincts?

Anand suggested the skills worth investing in sit above the automation line. " Second, AI oversight will be a crucial skill, plus the ability to describe potential risks to non-IT employees. "That's about knowing when a model's output is wrong and having the confidence to say so aloud in a meeting," he said.