Artificial intelligence is changing cybersecurity faster than organizations can redefine the skills required to defend their systems. Security professionals are no longer dealing only with networks, endpoints, applications and conventional cyber threats. They increasingly operate in environments where AI systems can be both a critical business asset and a powerful instrument in the hands of attackers.
This shift raises an important question for employers, certification bodies and cybersecurity professionals: how should cybersecurity competence be defined, assessed and certified when AI is changing both the threat landscape and the tools used to defend against it?
Traditional cybersecurity qualifications will remain important. But the AI era is creating a new layer of competence involving AI-enabled attacks, AI-assisted defence, model security, data integrity, automated decision-making, adversarial techniques and the governance of AI-enabled security tools.
Cybersecurity Competence Is Entering a New Phase
Cybersecurity has always been a rapidly evolving profession. Cloud computing, mobile technologies, operational technology, connected products and increasingly complex supply chains have continuously expanded the skills expected from security professionals.
Artificial intelligence accelerates this evolution considerably.
Cybersecurity professionals increasingly need to understand not only how conventional information systems can be attacked, but also how AI systems introduce new vulnerabilities and how AI itself can change the economics and speed of cyber operations.
The result is a broader professional profile in which cybersecurity, AI technology, risk management and governance increasingly intersect.
AI Is Changing Both Sides of the Cybersecurity Equation
One of the defining characteristics of the emerging environment is that artificial intelligence can strengthen both attackers and defenders.
Security teams can use AI to analyze large volumes of events, identify anomalous behaviour, prioritize vulnerabilities, automate repetitive security activities and support incident investigation.
Attackers can use similar capabilities to accelerate reconnaissance, improve social engineering, generate malicious content, identify potential vulnerabilities and automate elements of attack campaigns.
AI can help security teams process large volumes of information, identify anomalies and focus attention on potential threats.
Attackers can use AI to improve reconnaissance, phishing, automation and exploitation at greater speed and scale.
A cybersecurity professional should be able to understand what AI-enabled security technology is doing, evaluate its limitations and evidence, and make defensible decisions rather than simply operate the tool.
The Security of AI Systems Is Becoming a Cybersecurity Discipline
Organizations are deploying AI systems into business processes, products, infrastructure and decision-making environments. Those systems themselves require protection.
AI security introduces technical questions that may not have formed part of traditional cybersecurity certification programmes.
Identify threats affecting AI models, applications, interfaces, datasets and connected systems.
Evaluate security controls associated with AI-enabled applications and deployment environments.
Understand attacks designed to manipulate AI behaviour, inputs or model performance.
Evaluate risks such as data poisoning, manipulated training information and compromised datasets.
Understand prompt injection, unauthorized manipulation and risks arising through AI application interfaces.
Investigate abnormal AI behaviour, security events and compromise involving AI-enabled systems.
AI Tools Do Not Eliminate the Need for Human Competence
AI can process enormous volumes of information and assist professionals in identifying patterns that might otherwise be difficult to detect.
But cybersecurity decisions frequently involve uncertainty, incomplete evidence and competing operational priorities.
A professional may need to determine whether an alert represents a genuine attack, whether a vulnerability creates a material business risk, whether an automated recommendation is appropriate or whether a security control introduces unacceptable operational consequences.
What Should Cybersecurity Certification Actually Assess?
This creates an important challenge for personnel-certification bodies and scheme owners.
If AI can answer technical questions, generate scripts, explain vulnerabilities and assist with security analysis, examinations based predominantly on memorized knowledge may become less effective at distinguishing genuine professional competence.
Future certification schemes may therefore need to place greater emphasis on demonstrated capability.
Evaluate how candidates respond to realistic security problems rather than isolated technical questions.
Assess investigation, containment, prioritization and decision-making under realistic conditions.
Determine whether candidates can interpret threat information and identify credible attack paths.
Assess the ability to identify weaknesses, dependencies and appropriate controls.
Determine whether candidates can identify inaccurate, incomplete or unsafe AI-generated security conclusions.
Evaluate whether the candidate can explain and defend decisions in complex or ambiguous situations.
Cybersecurity certification in the AI era should demonstrate that a professional can evaluate AI-assisted evidence and make competent security decisions — not merely operate an AI-enabled tool.
ISO/IEC 17024 Becomes Increasingly Relevant
ISO/IEC 17024 provides an internationally recognized framework for bodies operating certification of persons.
Its principles are particularly relevant as new cybersecurity and AI-related professional certifications emerge.
A credible personnel-certification programme should establish a clearly defined certification scheme identifying the competence requirements, assessment methods, certification criteria and continuing requirements applicable to the professional role.
- the professional role being certified;
- the tasks the certified person is expected to perform;
- the knowledge, skills and abilities required;
- the level of professional judgement expected;
- how competence will be independently assessed;
- how examination integrity will be protected;
- how continuing competence will be demonstrated; and
- when recertification is required.
AI Creates a New Examination Integrity Problem
Artificial intelligence affects not only what cybersecurity professionals need to know. It also affects how certification examinations can be administered.
Generative AI systems can answer technical questions, explain security concepts and produce sophisticated responses within seconds.
Remote examinations and unsupervised assessments may therefore face increasing difficulty in determining whether an answer represents the candidate’s own competence.
Should Candidates Be Allowed to Use AI?
There may not be one universal answer.
If a certification aims to demonstrate independent technical capability, AI access may need to be restricted.
If competent use of AI is part of the actual professional role, however, a controlled AI-assisted assessment may sometimes provide a more realistic evaluation.
Candidates perform defined tasks without AI assistance where independent knowledge and technical capability are essential.
Candidates use authorized AI tools while being assessed on verification, critical thinking and final professional judgement.
New Cybersecurity Certification Roles Are Likely to Emerge
The convergence of cybersecurity and artificial intelligence is also likely to create increasingly specialized professional roles.
Certification Must Follow Competence — Not Market Fashion
The rapid growth of artificial intelligence creates significant commercial opportunities for training and certification providers.
It also creates a risk that new credentials appear faster than meaningful competence frameworks can be developed.
A credible certification should therefore begin with the professional activity being certified, not with the certificate title.
Create a marketable AI-cybersecurity title and build a short examination around terminology.
Define the work, responsibilities, competence and assessment methodology before creating the credential.
Continuing Competence May Matter More Than Ever
Cybersecurity knowledge has always had a limited shelf life. Artificial intelligence may shorten it further.
A professional certified today may encounter substantially different AI technologies, security tools, attack techniques and regulatory expectations several years from now.
Recertification and continuing professional development therefore become central components of credible cybersecurity personnel certification.
Require continuing education relevant to changing cybersecurity and AI technologies.
Maintain evidence that the certified individual remains active in relevant professional practice.
Ensure competence remains aligned with new attack techniques and security risks.
Maintain awareness of evolving AI architectures, controls and attack methods.
Where appropriate, reassess the professional’s continuing ability to perform relevant security activities.
Maintain continuing compliance with applicable professional and ethical expectations.
What Organizations Should Look for in Cybersecurity Certifications
Employers should also become more selective when evaluating cybersecurity credentials.
The existence of a certificate does not automatically demonstrate that the holder possesses the competence required for a particular cybersecurity role.
- whether the certification has a clearly defined professional scope;
- whether competence requirements reflect current cybersecurity practice;
- whether AI-related competencies are relevant to the certified role;
- how candidates are assessed;
- whether practical competence and professional judgement are evaluated;
- how impartiality and examination integrity are protected;
- whether continuing competence is required; and
- whether certification is independently accredited where appropriate.
The Future Cybersecurity Professional
Artificial intelligence will automate parts of cybersecurity work, but this does not mean professional competence becomes less important.
Instead, the nature of competence changes.
Cybersecurity professionals will increasingly work alongside intelligent tools while remaining responsible for interpreting evidence, understanding risk, challenging automated conclusions and making decisions that can affect organizations, infrastructure, customers and society.
Certification focuses heavily on security concepts, technologies, procedures and technical recall.
Certification increasingly evaluates whether professionals can apply technical knowledge, challenge AI outputs and make accountable decisions.
Preparing for the Next Generation of Cybersecurity Certification
Certification bodies, scheme owners, employers and professional organizations should begin reviewing existing cybersecurity competence frameworks against the realities of AI-enabled work.
This does not necessarily require replacing established cybersecurity certifications.
In many cases, existing schemes can evolve by introducing appropriate AI-security competencies, revised assessment methods and stronger continuing-competence requirements.
Where genuinely new professional activities emerge, however, new certification schemes may be justified.
What Are We Really Certifying?
The central issue is ultimately one of trust.
Organizations need confidence that certified cybersecurity professionals can perform clearly defined roles competently in an environment where access to automated intelligence is becoming almost instantaneous.
The strongest certification schemes will therefore distinguish between information retrieval, tool operation and genuine professional competence.
The future cybersecurity professional will not be defined by the ability to compete with artificial intelligence. The professional will be defined by the ability to use it intelligently, challenge it when necessary and remain accountable when security decisions matter.