Technical Insight

GAR INSIGHT
Cybersecurity Skills Certification in the AI Era

Artificial intelligence is changing cybersecurity faster than organizations can redefine the skills required to defend their systems. Security professionals are no longer dealing only with networks, endpoints, applications and conventional cyber threats. They increasingly operate in environments where AI systems can be both a critical business asset and a powerful instrument in the hands of attackers.

This shift raises an important question for employers, certification bodies and cybersecurity professionals: how should cybersecurity competence be defined, assessed and certified when AI is changing both the threat landscape and the tools used to defend against it?

Traditional cybersecurity qualifications will remain important. But the AI era is creating a new layer of competence involving AI-enabled attacks, AI-assisted defence, model security, data integrity, automated decision-making, adversarial techniques and the governance of AI-enabled security tools.

The shift is significant: Cybersecurity certification increasingly needs to demonstrate not only what a professional knows, but whether that person can use, challenge and govern AI-enabled security technologies competently.

Cybersecurity Competence Is Entering a New Phase

Cybersecurity has always been a rapidly evolving profession. Cloud computing, mobile technologies, operational technology, connected products and increasingly complex supply chains have continuously expanded the skills expected from security professionals.

Artificial intelligence accelerates this evolution considerably.

Cybersecurity professionals increasingly need to understand not only how conventional information systems can be attacked, but also how AI systems introduce new vulnerabilities and how AI itself can change the economics and speed of cyber operations.

The result is a broader professional profile in which cybersecurity, AI technology, risk management and governance increasingly intersect.

AI Is Changing Both Sides of the Cybersecurity Equation

One of the defining characteristics of the emerging environment is that artificial intelligence can strengthen both attackers and defenders.

Security teams can use AI to analyze large volumes of events, identify anomalous behaviour, prioritize vulnerabilities, automate repetitive security activities and support incident investigation.

Attackers can use similar capabilities to accelerate reconnaissance, improve social engineering, generate malicious content, identify potential vulnerabilities and automate elements of attack campaigns.

AI FOR DEFENCE Faster Detection and Analysis

AI can help security teams process large volumes of information, identify anomalies and focus attention on potential threats.

AI FOR ATTACK Faster and More Scalable Threat Activity

Attackers can use AI to improve reconnaissance, phishing, automation and exploitation at greater speed and scale.

What should certification demonstrate?

A cybersecurity professional should be able to understand what AI-enabled security technology is doing, evaluate its limitations and evidence, and make defensible decisions rather than simply operate the tool.

The Security of AI Systems Is Becoming a Cybersecurity Discipline

Organizations are deploying AI systems into business processes, products, infrastructure and decision-making environments. Those systems themselves require protection.

AI security introduces technical questions that may not have formed part of traditional cybersecurity certification programmes.

AI Threat Modelling

Identify threats affecting AI models, applications, interfaces, datasets and connected systems.

Model & Application Security

Evaluate security controls associated with AI-enabled applications and deployment environments.

Adversarial Techniques

Understand attacks designed to manipulate AI behaviour, inputs or model performance.

Data Integrity

Evaluate risks such as data poisoning, manipulated training information and compromised datasets.

Prompt & Interface Security

Understand prompt injection, unauthorized manipulation and risks arising through AI application interfaces.

AI Incident Response

Investigate abnormal AI behaviour, security events and compromise involving AI-enabled systems.

AI Tools Do Not Eliminate the Need for Human Competence

AI can process enormous volumes of information and assist professionals in identifying patterns that might otherwise be difficult to detect.

But cybersecurity decisions frequently involve uncertainty, incomplete evidence and competing operational priorities.

A professional may need to determine whether an alert represents a genuine attack, whether a vulnerability creates a material business risk, whether an automated recommendation is appropriate or whether a security control introduces unacceptable operational consequences.

AI can support the decision. It cannot replace professional accountability. The stronger AI-enabled security tools become, the more important it becomes that cybersecurity professionals can verify, challenge and interpret their outputs.

What Should Cybersecurity Certification Actually Assess?

This creates an important challenge for personnel-certification bodies and scheme owners.

If AI can answer technical questions, generate scripts, explain vulnerabilities and assist with security analysis, examinations based predominantly on memorized knowledge may become less effective at distinguishing genuine professional competence.

Future certification schemes may therefore need to place greater emphasis on demonstrated capability.

Practical Cybersecurity Scenarios

Evaluate how candidates respond to realistic security problems rather than isolated technical questions.

Incident-Response Simulation

Assess investigation, containment, prioritization and decision-making under realistic conditions.

Threat Analysis

Determine whether candidates can interpret threat information and identify credible attack paths.

Security Architecture Review

Assess the ability to identify weaknesses, dependencies and appropriate controls.

AI-Generated Evidence Review

Determine whether candidates can identify inaccurate, incomplete or unsafe AI-generated security conclusions.

Professional Judgement

Evaluate whether the candidate can explain and defend decisions in complex or ambiguous situations.

Cybersecurity certification in the AI era should demonstrate that a professional can evaluate AI-assisted evidence and make competent security decisions — not merely operate an AI-enabled tool.

ISO/IEC 17024 Becomes Increasingly Relevant

ISO/IEC 17024 provides an internationally recognized framework for bodies operating certification of persons.

Its principles are particularly relevant as new cybersecurity and AI-related professional certifications emerge.

A credible personnel-certification programme should establish a clearly defined certification scheme identifying the competence requirements, assessment methods, certification criteria and continuing requirements applicable to the professional role.

A credible cybersecurity certification scheme should define:
  • the professional role being certified;
  • the tasks the certified person is expected to perform;
  • the knowledge, skills and abilities required;
  • the level of professional judgement expected;
  • how competence will be independently assessed;
  • how examination integrity will be protected;
  • how continuing competence will be demonstrated; and
  • when recertification is required.

AI Creates a New Examination Integrity Problem

Artificial intelligence affects not only what cybersecurity professionals need to know. It also affects how certification examinations can be administered.

Generative AI systems can answer technical questions, explain security concepts and produce sophisticated responses within seconds.

Remote examinations and unsupervised assessments may therefore face increasing difficulty in determining whether an answer represents the candidate’s own competence.

Should Candidates Be Allowed to Use AI?

There may not be one universal answer.

If a certification aims to demonstrate independent technical capability, AI access may need to be restricted.

If competent use of AI is part of the actual professional role, however, a controlled AI-assisted assessment may sometimes provide a more realistic evaluation.

INDEPENDENT ASSESSMENT Demonstrate Core Human Capability

Candidates perform defined tasks without AI assistance where independent knowledge and technical capability are essential.

AI-ASSISTED ASSESSMENT Demonstrate Responsible Technology Use

Candidates use authorized AI tools while being assessed on verification, critical thinking and final professional judgement.

New Cybersecurity Certification Roles Are Likely to Emerge

The convergence of cybersecurity and artificial intelligence is also likely to create increasingly specialized professional roles.

Not every emerging job title needs a new certificate. The certification industry should identify where a distinct, measurable and professionally meaningful body of competence genuinely exists before creating new credentials.

Certification Must Follow Competence — Not Market Fashion

The rapid growth of artificial intelligence creates significant commercial opportunities for training and certification providers.

It also creates a risk that new credentials appear faster than meaningful competence frameworks can be developed.

A credible certification should therefore begin with the professional activity being certified, not with the certificate title.

WEAK CERTIFICATION MODEL Credential First

Create a marketable AI-cybersecurity title and build a short examination around terminology.

COMPETENCE-BASED MODEL Professional Role First

Define the work, responsibilities, competence and assessment methodology before creating the credential.

Continuing Competence May Matter More Than Ever

Cybersecurity knowledge has always had a limited shelf life. Artificial intelligence may shorten it further.

A professional certified today may encounter substantially different AI technologies, security tools, attack techniques and regulatory expectations several years from now.

Recertification and continuing professional development therefore become central components of credible cybersecurity personnel certification.

Professional Development

Require continuing education relevant to changing cybersecurity and AI technologies.

Professional Experience

Maintain evidence that the certified individual remains active in relevant professional practice.

Emerging Threat Awareness

Ensure competence remains aligned with new attack techniques and security risks.

AI Security Knowledge

Maintain awareness of evolving AI architectures, controls and attack methods.

Practical Competence

Where appropriate, reassess the professional’s continuing ability to perform relevant security activities.

Ethics & Professional Conduct

Maintain continuing compliance with applicable professional and ethical expectations.

What Organizations Should Look for in Cybersecurity Certifications

Employers should also become more selective when evaluating cybersecurity credentials.

The existence of a certificate does not automatically demonstrate that the holder possesses the competence required for a particular cybersecurity role.

Organizations should consider:
  • whether the certification has a clearly defined professional scope;
  • whether competence requirements reflect current cybersecurity practice;
  • whether AI-related competencies are relevant to the certified role;
  • how candidates are assessed;
  • whether practical competence and professional judgement are evaluated;
  • how impartiality and examination integrity are protected;
  • whether continuing competence is required; and
  • whether certification is independently accredited where appropriate.

The Future Cybersecurity Professional

Artificial intelligence will automate parts of cybersecurity work, but this does not mean professional competence becomes less important.

Instead, the nature of competence changes.

Cybersecurity professionals will increasingly work alongside intelligent tools while remaining responsible for interpreting evidence, understanding risk, challenging automated conclusions and making decisions that can affect organizations, infrastructure, customers and society.

TRADITIONAL EMPHASIS Technical Knowledge

Certification focuses heavily on security concepts, technologies, procedures and technical recall.

AI-ERA EMPHASIS Competence + Judgement + AI Literacy

Certification increasingly evaluates whether professionals can apply technical knowledge, challenge AI outputs and make accountable decisions.

Preparing for the Next Generation of Cybersecurity Certification

Certification bodies, scheme owners, employers and professional organizations should begin reviewing existing cybersecurity competence frameworks against the realities of AI-enabled work.

This does not necessarily require replacing established cybersecurity certifications.

In many cases, existing schemes can evolve by introducing appropriate AI-security competencies, revised assessment methods and stronger continuing-competence requirements.

Where genuinely new professional activities emerge, however, new certification schemes may be justified.

Cybersecurity certification in the AI era must prove more than technical knowledge. It must demonstrate that a professional can use, verify and challenge intelligent security systems while remaining accountable for the final decision.

What Are We Really Certifying?

The central issue is ultimately one of trust.

Organizations need confidence that certified cybersecurity professionals can perform clearly defined roles competently in an environment where access to automated intelligence is becoming almost instantaneous.

The strongest certification schemes will therefore distinguish between information retrieval, tool operation and genuine professional competence.

The future cybersecurity professional will not be defined by the ability to compete with artificial intelligence. The professional will be defined by the ability to use it intelligently, challenge it when necessary and remain accountable when security decisions matter.
Certification context: The convergence of artificial intelligence and cybersecurity is creating new competence requirements across security operations, AI-system protection, risk management and professional assurance. ISO/IEC 17024 provides a framework for bodies operating certification of persons and supports competence-based certification schemes. Organizations developing or selecting cybersecurity personnel certifications should distinguish independent competence certification from training completion and should ensure that certification scope, assessment methods, examination integrity, continuing competence and any applicable accreditation arrangements are appropriate to the professional role being certified.
GLOBAL ALLIANCE REGISTER

How Global Alliance Register Can Support You

Global Alliance Register supports organizations and project stakeholders with independent technical-assurance services relevant to personnel certification within the digital and AI context. Based on the article's emphasis on certification and personnel competence assessment, GAR can coordinate competent specialists, laboratories, inspectors, auditors and accredited conformity-assessment resources as appropriate to the actual technical need. Within the context of this article, Global Alliance Register can support you in the following areas:

01

Coordinate competent and appropriately accredited certification resources for personnel certification and support readiness, findings resolution, surveillance and periodic reassessment as applicable.

02

Review the occupational role, competence model and certification scope for personnel certification so that knowledge, skills and demonstrated capabilities are clearly defined and independently assessable.

03

Support scheme governance for personnel certification, including impartiality, assessor and examiner competence, certification decisions and appropriate separation between training and independent certification.

04

Structure the assurance approach for personnel certification so consultancy, testing, inspection, audit and certification roles maintain the appropriate independence and decision-making boundaries.

05

Define or review examinations, practical assessments and other assessment methods for personnel certification so competence is evaluated consistently, objectively and against measurable criteria.

Scroll to Top