翻訳待ち:What do cybersecurity leaders want in staff? These 3 skills beat certifications and experience
AI サービスが一時的に利用できないため、復旧後に翻訳を補完します。ソース概要:Certifications and years of experience can only take you so far in cyber now. Automation means new skills are coming to the fore.
AI サービスが一時的に利用できないため、復旧後に翻訳を補完します。
Follow ZDNET: Add us as a preferred source on Google.ZDNET's key takeawaysAI brings new challenges for hard-working cyber staff.Talented professionals will question almost everything.Work with agents to make decisions that reduce risks.Working in cybersecurity is a tough gig. While security teams work hard to prevent damage to their organizations, ZDNET reported earlier this year that many cyber professionals aren't receiving the recognition they deserveEmerging technology brings new challenges. AI-assisted vulnerability discovery is accelerating the pace of bug reports, with a growing mismatch between what machines can surface and what humans can realistically triage.Also: AI failed to patch software flaws 74% of the time, 1Password's study warnsIn such a fast-changing and challenging working environment, it's easy to understand why almost half of cybersecurity pros want to quit.However, staff should pause before sending their resignation letters: in an age of AI, where threats come from multiple angles, your business needs you now more than ever.As Fabrizio Pilotti, CIO at Aston Martin Aramco Formula One, said to ZDNET recently, digital leaders must think carefully about the balance between AI and human capabilities, and maintaining this equilibrium effectively creates new opportunities for security professionals."In IT, lots of rules are changing. We're thinking a lot about team structure, even job descriptions between the agentic part and non-agentic part," he said."I would say cyber, together with software development, is at the top of our priority list because of growing complexity and changing environments, where you have to react so fast."Also: Assume AI cybersecurity attacks are the future: 43% of companies have already experienced itThe good news, therefore, is that talented cyber staff could finally receive the recognition their skills fully deserve.But as agentic AI hoovers up elements of the traditional IT security role, how can cyber professionals prove their worth and build a successful career?The experts suggest successful candidates will focus on three key areas: curiosity-led critical thinking, instinctive qualities that sit above the automation line, and an ability to turn ambiguous signals into confident, risk-based decisions.Blend curiosity with critical thinkingEric Schmitt, global chief information security officer at risk and claims administration specialist Sedgwick, said many people mistakenly believe that a great cybersecurity professional is someone with certifications or years of experience.While those credentials can indicate someone's likely capabilities, they are no guarantee of success, particularly in a world where AI and other emerging technologies transform the nature of attacks and the methods of response.Also: How Google used AI agents to find and fix 1,072 Chrome security bugs - in 60 daysTo this end, Schmitt told ZDNET that a great cybersecurity professional excels in one key area: curiosity."I would rather hire someone a year into their career who constantly asks, 'Why does this work this way?' over someone 20 years in who doesn't," he said.Schmitt said that while experience teaches you what has worked in the past, curiosity teaches you what might break next and where the solution may be, a distinction that has never mattered more than it does in today's rapidly changing threat landscape."Credentials tell me where someone's been, while questions like 'Why does this agent call that service?' or 'Why do we follow this process?' or trying to figure out which data a certain model is reading, who can modify it, and what an agent is allowed to do on its own, can tell me how they think a lot better."Also: AI is both a cyber weapon and a massive target, CrowdStrike warnsHowever, curiosity alone is not enough. Schmitt suggested curious cybersecurity professionals also need strong critical thinking skills."Curiosity generates the most impactful questions, and critical thinking decides which answers hold up," he said."AI has made this type of thinking an urgent component, because these tools produce confident, plausible output at volume, but someone still has to ask whether it's right and be able to tell."Schmitt said curiosity without critical rigor leads to noise, and rigor without curiosity leads to stagnation, suggesting professionals with the right blend of capabilities will appeal to businesses that develop a proactive approach to cyber risks."Together, these skills allow a security professional to keep pace with a threat landscape that no longer rewards static expertise," he said. "Managers should hire for curiosity and cultivate critical thinking, because everything else can be taught."Sit above the automation lineThis focus on critical thinking skills also appeals to Ankur Anand, CIO at recruiter Harvey Nash, who suggested industry research points to a significant problem -- over-reliance on AI tools could leave enterprises exposed to attacks.He referred to SecRespond's recently released benchmark that tested 23 leading AI models against real forensic data from compromised systems. Every model failed on the same category of attack: intrusions that never triggered an alert in the first place."That's the detail that should worry people more than any skills-gap statistic," he told ZDNET, suggesting that most security tools, including those that use AI, work by investigating something that's already flagged as unusual."If nothing trips the alarm, an AI built to investigate alarms has nothing to chew on."Also: How to keep your AI conversations as private as possibleAnand said the best cybersecurity professionals possess the judgment to know when something's awry."They'll have the instinct to get suspicious about a system that looks completely fine, and to ask why it's quiet when everyone else is only watching for what's loud."So, how can IT security staff hone these instincts? Anand suggested the skills worth investing in sit above the automation line.He pointed first to threat-hunting capabilities: "Going looking for trouble with no alert telling you where to look."Also: Open weights vs. closed: An AI civil war's afoot, and the stakes are existentialSecond, AI oversight will be a crucial skill, plus the ability to describe potential risks to non-IT employees."That's about knowing when a model's output is wrong and having the confidence to say so aloud in a meeting," he said."Plain communication matters more than it used to, because someone still has to turn 'the model flagged this' into a decision the business can actually act on."Finally, Anand said good old-fashioned technological expertise will play an important role in helping cybersecurity professionals turn judgments into actions."Basic Python is worth learning too, so you can query and interrogate the tools doing the triage instead of just accepting their verdicts," he said.Focus on prioritizing riskThe key takeaway for cybersecurity professionals, suggested Errol Weiss, chief security officer at member-driven organization Health-ISAC, is the need to shift their focus to adaptive thinking and operational judgment in the age of AI."That transition requires clear thinking under pressure, curiosity, and the ability to turn ambiguous signals into a confident, risk-based decision," he told ZDNET.Also: OpenAI's attack agent did exactly what it was told - just more relentlessly than expectedWeiss said adaptability is crucial because AI is accelerating both attack and defense cycles, meaning security teams are dealing with faster-moving threats, more noise, and often have less time to respond."We need individuals who combine technical skills with an understanding of how systems operate in the real world, especially in sectors like healthcare, where patching or mitigation isn't straightforward," he said."Communication is a core skill. Security professionals need to explain risk in a way that drives action across clinical, operational, and executive teams."Weiss said the people who stand out will be those who can quickly interpret and prioritize risk.Also: AI is getting scary good at finding hidden software bugs - even in decades-old codeWhen AI tools can do much of the heavy lifting, it is the human in the loop -- in this case, the talented cybersecurity professional -- who will help organizations manage risks."AI tools can surface potential security issues, but they don't understand business context, safety implications, or operational constraints," he said."That's where human expertise remains critical. AI will continue to augment cybersecurity, but it won't replace the need for experienced professionals who can make decisions during uncertainty. The most effective practitioners will be those who can work alongside AI, question its outputs, and translate insights into practical, timely action."