How AI Is Reshaping Cybersecurity Skills
Hack The Box CEO Haris Pylarinos joins Mike Vizard to discuss how AI is changing the structure of cybersecurity teams, the path from entry-level work to senior expertise and the way defenders respond to machine-speed attacks. They examine why hands-on training becomes more important as AI agents automate routine tasks, increase alert volume and require professionals with broader cybersecurity knowledge. Pylarinos explains why organizations should augment teams with AI while keeping humans in the loop to validate agent decisions, manage risk and avoid becoming overly dependent on automation.
Transcript
Hey guys, thanks for the throw. We're here with Haris Pylarinos, who's the CEO of Hack The Box, and we're having a little chat about the impact AI is having on cybersecurity teams and skills. Haris, welcome to the show.
Thank you very much for inviting me. It's very nice to be here. I think we're starting to get a little bit of a handle on how AI is being used by cybersecurity teams.
It's still early yet, but there's a concern, I guess, about how this is going to impact the way we structure those teams, and I'm bringing that up because it seems like a lot more senior people are using AI to automate tasks that might've been done by mid-level or entry-level folks. But then where does the expertise come in the future when those folks retire? Because, well, eventually they will leave us, or they'll get a better job somewhere else, and we won't have anybody to fill their shoes.
So, from your perspective, how is all this going to play out, and what do savvy cybersecurity teams need to be thinking about? Well, I think one of the main paths on becoming a senior at your profession is by work experience, and if we see the lower rankings of cybersecurity professionals being replaced to some extent from AI agents, then a material problem arises. How do you become a senior?
You need to build the work experience, or you have to start working on a higher seniority from day one. So, training becomes 10 times more important. You need to be able to simulate the entry-level position tasks through platforms like Hack The Box in order to be able to become proficient and senior enough to take on a position, let's say, higher in the hierarchy of a SOC or a pen test team, et cetera.
To your point about that, do we need to change the way we train cybersecurity professionals, then? " Well, first of all, whether it's automated or not, they need to understand the mechanics of it. We have calculators now to do our math, but in school we are still taught how to do mathematics by pen and paper.
You need to understand how something operates, even if it's automated, because this will assist you in solving more complex problems. Now, in terms of how I see the cyber professionals evolving over the years, I think it will be less focused on specific verticals of cybersecurity. So instead of having pen testers, SOC analysts, security engineers, et cetera, I think we will need more professionals with more spherical knowledge of cyber that, with the help of agents and other automation tools, will be able to deliver on a much higher volume than they used to.
One of the issues too that I hear folks struggling with is, well, the attacks and the responses are all now happening at machine speed, and that's faster than most humans can comprehend. So how do I think about managing and responding to attacks these days when they're going to happen and things we'll measure in milliseconds? That's why AI is not an option, but a necessity.
Criminals augment their capabilities with AI, being able to perform faster attacks with a much greater volume, and on the defending side, you need to adopt the same technologies to be able to deflect such attacks or to handle the additional volume of those attacks. Because if we look 10, 15 years ago, a random example, let's say that you have 1,000 alerts per day, you can easily build a large enough team to go through each and every one and respond in time. Now, if we're talking about millions of alerts per hour in some occasions, it's impossible to staff up to resolve the problem.
You need to augment the cyber professionals with AI in order to be able to cope with the additional attacks. And that brings another point that is discussed heavily of if cyber departments will shrink in terms of hiring. Because given that now a cyber professional can deliver, let's say, four times the volume that they would, wouldn't we need four times less cyber professionals to staff our department?
But the answer to that is that the number of people you have depends on the volume of attacks that you are receiving. The volume of attacks is augmented with AI, so the same staff should remain, and it should be augmented with AI in order to be able to deflect the additional volume of attacks. That's my opinion.
Do we also need to think about retraining many of the cybersecurity folks we do have today, because as more tasks get automated, they might not be ready for the higher-level assignments that we need to give them. So is there a need to just re-look at the skillsets we have? We need to rethink how we operate on an AI-enabled environment.
That's not just for cybersecurity engineers, but I think globally, whoever fails to grasp the new reality will become obsolete. And we specifically started working years ago on preparing humans for the AI era, and we are currently in the process of introducing, apart from cybersecurity for AI and LLMs, we are also introducing training material on how to augment your capabilities as a cyber professional in the AI era. To your point about that, if I am today in cybersecurity, what should I be focused on?
I'm asking the question because lately it seems like a lot of the responsibility for security operations has been shifted over to the main IT team, and maybe the idea here is that the cybersecurity teams would then have more time to go focus on hunting threats. But if we look at AI, does that change that mix, or do we still need to train all the IT folks about security and it's still a team sport? In an ideal world, everyone should be trained on security.
I know that's a bit biased because that's pretty much our business. But, I think IT folks should have a certain level of understanding, which is way above just awareness. And specialized cybersecurity folks should have, as I said, spherical knowledge around the entire field and specialize in what they see that they're most capable at, whether that's threat hunting or incident response or whatever.
I think there's also a lot of concern of late that cybersecurity teams will be overwhelmed by the number of vulnerabilities that are about to be discovered by tools such as Mythos from Anthropic, but I'm sure there'll be others. And the theory is, hopefully, that maybe we're using AI to develop and deploy the patches faster. But, are we entering some sort of new era here that cybersecurity professionals maybe are not quite as prepared for as they should be?
The truth is that criminals are faster in adopting because they don't have anything to lose usually. But I'm pretty confident that because I've met with thousands of cyber professionals globally, and I see a lot of talent out there. I see people that are ready to adapt to any situation, people hungry for knowledge and new ways of doing things.
So I believe AI adoption will be smooth, and it will assist them in patching, detecting attacks, all of their tasks, in good time overall. I don't see a huge gap between criminal capability, and ethical hacker and defender capabilities. Do you think the bad guys are training their people to use AI?
I'm sure the other side has, shall we say, the opposite- Bad guys are already- ... that's the plan ... using AI, and they train themselves.
I don't believe it's something structured like they have their dark web training certifications and things like that. It's much more unstructured, obviously. But bad guys are adopting new technologies to their interest, and we've seen the basic LLM chatting is used to scam more organization employees simultaneously.
In the past, when a criminal wanted to start phishing an organization, they tried to form a very nice email, probably addressed from the CEO of the company, asking to do something urgent, download something, depending on the case. Now we see utilizing LLMs to create customized messages for each individual based on their social profiles. LLMs are capable of chatting to each individual at the same time, again, trying to fool them into taking an action that they shouldn't.
That is something AI-enabled, and that greatly increases the success rate of a potential attack. I think you touched on this, but I want to clarify the point. But we're focused so much on training humans for cybersecurity, but are we also going to need to train and retrain AI agents?
And each environment is slightly different, so I need to specialize, and each of those AI agents may have a core set of capabilities, but eventually, I also have to train them about my environment. So are we going to be in some sort of continuous training loop for the AI agents? We are at a continuous training loop for AI agents.
We actually have a specific product as we are a training company, and we train humans. We also train agents, and we have what we call the AI Range, where it's a customized environment that can enable agents to do reinforcement learning and become better and better on what they do. So as humans train, agents should train as well, and both of them together is the ultimate solution to defend ourselves from criminals.
So what do you see organizations doing today that just makes you shake your head a little bit and go, "Folks, we need to be a little bit smarter about how we're approaching all this"? Given that AI solves so much issues, it's an impressive technology. I see first over-adoption sometimes, meaning let's do AI everything.
And the second is over-relying and over-trusting AI systems, meaning that AIs make mistake. But given the fact that they have so much information to share, and they seem quite convincing when they provide the solution to your problem, the main problem is that they are equally convincing where they are talking something that is completely irrelevant. So we, as humans, have to always ensure that we think before we act.
If we are to act for information based from an AI system, we need to think and cross-check what we are receiving. And in general, there is no agent right now that can completely take over your work and do it for you. Agents are there to augment your capabilities, and we need to remember that.
They're not here to replace us, so we should not act as if they are smarter than us, or the future that does not involve the human in the loop. To your point about that, am I also going to need AI agents to validate the output of another AI agent? And theoretically, that other AI agent shouldn't be using the same LLM.
So ultimately, is this becoming an orchestration challenge as we go forward because I just can't trust one AI agent? Definitely not, and I think it will come to that. I see armies of agents doing certain tasks, agents checking other agents about their performance and how accurate they are.
And ultimately, I see humans on top playing with those agents, orchestrating, and devoting their time to higher and more strategic problems than trivial tasks. So if that's the case, is the training therefore going to be more about how to master and manage the AI agents per se? Or at least is that the next level of training that we need to get to?
Because I may still know what the AI agent is doing, but the challenge is figuring out how to manage them all. I think there will be plenty of tools to assist in managing agents, but in order to successfully manage and understand an agent's capability, you need to understand what you would do if there was no agent. I think it's fundamental, and that's why I don't believe training will greatly be changed.
You need to learn everything, plus how to operate in a modern environment with AI in place. You need to understand every action that an AI system would do, because when it comes to cross-checking if it's a valid action or not, you need to be able to drill down, understand what it did, why it did it, and judge if it was the right or the wrong call. All right.
Well, folks, I think you heard it here. The only thing worse than not having any AI at all is becoming overly dependent upon it, because if we don't know how it works, we can't roll it back, we can't understand what happened, and, well, the enemy will just have more fun with us than we possibly could have thought because they'll know how the AI works better than we do. Haris, thanks for being on the show.
Thank you very much. All right. And back to you guys in the studio.