Ivanti CISO Takes on AI Security, Governance, Talent Gap

You might be familiar with the ongoing cybersecurity talent shortage — the struggle to find enough analysts, incident reporters, and threat hunters to defend networks. That challenge hasn’t disappeared, but the rapid adoption of artificial intelligence has created a new, distinct problem: an AI security skills gap. According to Ivanti research, 44% of professionals say their companies have invested in AI, yet employees lack the adequate skills and training to use it safely. This isn’t just a numbers game; it’s a fundamental mismatch between the expertise on hand and what’s now required.

With AI adoption, a new layer of risk has emerged, and the skills needed to manage it don’t map neatly onto existing roles. Traditional security teams may understand network threats, but they often aren’t equipped for AI risk management — things like model poisoning, data leakage through prompts, or the ethical governance of automated decisions. Closing this gap demands a deliberate workforce upskilling effort, one that goes beyond simply adding more people to the security team. The old shortage was about headcount; the new one is about capability.

What Is the New AI Security Skills Gap and How Does It Differ from the Old One?

For years, the cybersecurity workforce evolution was defined by a simple math problem: too many threats, not enough people to stop them. The traditional gap was a headcount issue. Organizations scrambled to hire more analysts to monitor logs, more incident responders to contain breaches, and more threat hunters to find hidden attackers. If you could find someone with a security certification and a willingness to work odd hours, you had a solution. That equation has flipped. The new AI security skills gap isn’t about missing bodies at a desk; it’s about missing competencies in the people you already have.

Ai security skills gap - real-life example
Bild: geralt / Pixabay

From Analyst Shortage to AI Skill Deficit

The old gap was filled by adding more warm bodies to the security team. The new gap is about what those bodies can do. Companies are investing heavily in artificial intelligence tools, expecting them to automate detection, streamline response, and predict threats. But the tool is only as good as the person tuning it. If your team can run a SIEM but doesn’t know how to validate an AI model’s output or interpret its false positives, you have an AI competency deficit. This is a fundamental shift in the traditional vs. modern skills gap. It’s no longer about having enough people; it’s about having people who understand the new technology.

Why 44% of Employees Are Left Behind

Ivanti research highlights a stark reality: 44% of professionals say their companies invested in AI, but employees lack adequate skills and training. That’s nearly half the workforce being handed powerful tools without the manual. Without upskilling, organizations risk falling behind AI, sacrificing regulation and control, and exposing vulnerabilities. The machine moves fast, but if your team can’t keep up with its logic or correct its drift, you lose visibility. The old gap left you understaffed; the new one leaves you blind.

What Specific AI Skills Are Most in Demand for Cybersecurity Roles?

That blindness is exactly where the AI security skills gap hits hardest. Closing it means knowing which concrete abilities matter most. AI is reshaping cybersecurity roles, and job postings now consistently require AI skills. It is no longer enough to understand traditional network defense; you need to work alongside intelligent systems that learn, adapt, and sometimes make mistakes.

Inspiration for Ai security skills gap
Bild: whitedaemon / Pixabay

AI for Threat Detection and Response

Attackers are using AI to breach systems faster than ever. To counter that, professionals must use AI for threat detection and response. This means learning how to deploy and tune AI threat detection platforms that analyze network behavior in real time. You need to understand how machine learning for security models flag anomalies and how to investigate their alerts. Skills like interpreting model outputs, reducing false positives, and automating incident response are becoming essential. Without them, your team cannot keep pace with AI-driven attacks. It is a practical shift: you move from reacting to alerts to training and validating the systems that generate them.

Understanding AI as Part of the Security Stack

AI is becoming part of the core security stack, requiring deeper understanding and upskilling. It is not a black box you plug in and forget. Working with AI-powered security tools means knowing their data inputs, training pipelines, and failure modes. You need to recognize when a model is drifting or being poisoned. This demands hands-on practice with security-specific models, from fine-tuning their parameters to auditing their decisions. Bridging the AI security skills gap starts with these concrete capabilities. They turn a blind team into one that sees the machine’s logic clearly and corrects its drift before it causes damage.

How Can Organizations Effectively Upskill Their Workforce to Close the AI Governance Gap?

Closing the AI governance gap doesn’t require hiring an entirely new team of specialists. The fastest path forward is often right under your nose: upskilling the security professionals you already have. Without a deliberate effort to build AI upskilling programs, your organization risks falling behind the technology, sacrificing regulation and control, and exposing vulnerabilities that could have been prevented.

Ideas around Ai security skills gap
Bild: geralt / Pixabay

Leveraging Automation for Strategic Focus

One of the most practical first steps is to use automation as a force multiplier. As routine tasks like log monitoring and alert triage become automated, your staff can shift their attention to higher-value work. This isn’t just about efficiency—it’s about freeing professionals to focus on decision-making, risk assessment, and proactive security strategy. Automation handles the noise, while your people handle the nuance. That’s where real AI governance begins.

Building AI Competency from Existing Security Knowledge

Remember that the true leverage of AI in security comes when it is used by those who already have baseline security knowledge and skills. Your current cybersecurity team understands threats, compliance, and risk management. What they need is targeted training on how AI models work, how to audit their outputs, and how to spot bias or drift. A practical cybersecurity training framework might include hands-on workshops with AI governance tools, case studies on model failures, and clear guidelines for evaluating AI decisions. This approach turns general security expertise into specialized AI oversight capability.

For workforce development to succeed, make learning a continuous process rather than a one-off course. Pair junior staff with senior analysts who are already exploring AI, and create internal communities where people can share what they learn. The goal is to build a culture where every security professional feels equipped to question and guide the AI systems they work alongside. When you invest in your people’s growth, you close the governance gap from the inside out.

What Are the Concrete Risks and Vulnerabilities from the AI Governance Skills Gap?

Investing in your team’s expertise is a strong first step, but the real-world consequences of the AI security skills gap become visible when you look at the threats already in play. Without a workforce that understands how to govern AI, organizations leave themselves exposed to three specific, costly dangers: AI-driven cyberattacks, loss of operational control, and mounting regulatory exposure. Each one feeds on the others, and all of them can escalate quickly if you don’t have the right people in place to manage AI systems.

Ai security skills gap: ivanti ciso
Bild: Pexels / Pixabay

AI-Powered Threats from Attackers

Attackers are actively using AI to breach systems more effectively. They automate reconnaissance, craft highly convincing phishing messages, and evade traditional defenses. To counter this, your security professionals must use AI for threat detection and response. But if your team lacks the skills to deploy and tune these defensive AI tools, they’re effectively fighting modern weapons with outdated tactics. The AI governance risk here isn’t just about missing a threat — it’s about being outmaneuvered at machine speed. Without upskilling, your organization falls behind, and attackers gain a persistent advantage.

Loss of Control and Regulatory Exposure

When you lack governance expertise, regulation and control are among the first casualties. Unmanaged AI systems can produce biased decisions, leak sensitive data, or operate in ways that violate compliance rules. This directly impacts regulatory compliance AI requirements — frameworks like GDPR, CCPA, or sector-specific guidelines demand oversight that a skills gap simply cannot deliver. The result is a growing list of vulnerabilities: AI models drift, unexpected behaviors emerge, and without a governance layer, no one notices until after an incident. Concrete steps here include establishing a cross-functional AI review board, mandating regular model audits, and investing in role-specific training that covers both technical and ethical aspects of AI. Closing the skills gap is the only way to turn these risks into manageable, everyday practices.

Are Cybersecurity Roles Being Eliminated or Just Transformed by AI?

It’s easy to worry that automation might replace security jobs entirely. But the reality is more nuanced and far more promising. AI is not eliminating cybersecurity roles; it is reshaping them. As routine tasks become automated, organisations need professionals to oversee AI systems, manage risk, and guide decision-making. This shift creates new opportunities for those willing to adapt.

Automation frees professionals to focus on decision-making, risk assessment, and proactive security strategy. Instead of spending hours sifting through logs or triaging low-level alerts, you can concentrate on high-value work that requires human judgment. This is not about job loss—it’s about AI job transformation that elevates the role of the security professional.

From Routine Tasks to Strategic Oversight

Many of the repetitive, time-consuming tasks in cybersecurity are ideal candidates for automation. AI can handle alert correlation, initial threat detection, and even some incident response steps. This doesn’t mean the human is out of the loop. Rather, your role evolves into one of oversight: you validate the AI’s findings, investigate complex anomalies, and make strategic calls. This cybersecurity role evolution places you at the center of decision-making rather than on the front line of manual labor.

New Roles in AI Governance and Risk

As AI becomes more embedded in security operations, entirely new positions are emerging. Organisations now need specialists in AI governance, model risk management, and ethical oversight. These roles involve setting policies for how AI is used, auditing models for bias or failure, and ensuring compliance with regulations. If you are worried about the AI security skills gap, consider this: the gap is not in traditional skills alone, but in the ability to manage automation in security responsibly. By developing expertise in AI oversight and risk, you position yourself at the forefront of this transformation.

The key is to view AI as a collaborator, not a competitor. It handles the drudgery so you can focus on the strategy. The roles that survive—and thrive—will be those that combine technical knowledge with critical thinking and ethical judgment. That is a career path worth pursuing.

Frequently Asked Questions

How can you start closing the AI security skills gap in your team?

Begin by identifying specific AI-related tasks your cybersecurity team handles, such as threat detection or incident response. Then, provide hands-on training with AI tools in a sandboxed environment, focusing on how to interpret AI outputs and validate them. Pair this with a clear roadmap for upskilling, and encourage your team to earn practical certifications in AI security fundamentals.

How does the AI security skills gap differ from the traditional cybersecurity skills shortage?

The traditional gap focused on general cybersecurity knowledge, like network defense or compliance. The AI security skills gap adds a layer of specialized expertise, requiring professionals to understand machine learning models, data governance, and AI-specific vulnerabilities. It is not just about knowing security but also how AI systems operate and can be attacked.

Will AI replace cybersecurity roles, or just transform them?

AI is transforming cybersecurity roles rather than eliminating them. You will see automation handling repetitive tasks like log analysis, freeing you to focus on complex threat hunting and strategic governance. The key is to adapt by learning how to manage and secure AI systems, making your role more analytical and less manual.


Add Comment