1. Introduction
Artificial intelligence is changing the cybersecurity environment. As AI becomes more capable and more widely integrated into business, technology and everyday life, it is creating new opportunities—but also new questions about how digital systems, information, identities and increasingly intelligent technologies should be protected.
The World Economic Forum’s Global Cybersecurity Outlook 2026 identifies AI as a major force reshaping both offensive and defensive cybersecurity capabilities. It reports that 94% of survey respondents anticipated AI would be the most significant driver of change in cybersecurity in the year ahead, while 87% identified AI-related vulnerabilities as the fastest-growing cyber risk over the course of 2025. The report also found that 77% of organizations had adopted AI for cybersecurity, including uses such as phishing detection, intrusion and anomaly response, and user-behaviour analytics.
World Economic Forum — Global Cybersecurity Outlook 2026
The relationship between AI and cybersecurity can be understood through three interconnected challenges:
1. AI as a Threat — AI can increase the speed, scale and sophistication of certain malicious activities and expand capabilities available to attackers.
2. AI as a Defense — AI can strengthen threat detection, monitoring, analysis, automation and incident response, helping cybersecurity professionals identify and respond to suspicious activity faster.
3. Securing AI Itself — As AI becomes integrated into applications and business operations, organizations must also protect the data, models, APIs, identities, cloud infrastructure and connected systems on which AI depends.
This creates an unusual security environment: AI can help create or amplify cybersecurity risks, help defend against them, and simultaneously become something that cybersecurity must protect.
This leads to the central question explored in this article:
As AI increases capabilities on both sides of cybersecurity, which side gains the greater advantage—and what skills will organizations and cybersecurity professionals need to keep pace?
2. AI Is Changing Both Sides of Cybersecurity
AI is not inherently a cybersecurity threat or a cybersecurity defense. Its impact depends on who is using it, how it is designed and deployed, and what objective it is being used to achieve.
This dual-use nature makes AI particularly important to cybersecurity. Many of the same characteristics that make AI valuable to legitimate organizations—speed, automation, pattern recognition, analysis of large volumes of information and the ability to generate content—can potentially be used for malicious purposes as well.
The result is an unusual technological race. AI can help attackers perform certain activities faster or at greater scale, while also helping defenders analyze larger volumes of security information and respond more efficiently.
For example:
| AI as a Threat Accelerator | AI as a Defensive Accelerator |
| More scalable social engineering and phishing | Faster phishing and suspicious-content detection |
| Faster analysis of potential targets and weaknesses | Faster analysis of logs, events and anomalies |
| Automation of parts of malicious workflows | Automation of repetitive security operations |
| More adaptive and convincing malicious content | Threat intelligence, hunting and prioritization support |
| New exposure created by AI systems and data flows | Continuous monitoring and AI-assisted response |
This does not necessarily mean that either attackers or defenders will permanently gain the advantage. Instead, it suggests that AI may accelerate both sides of an attack-and-defense cycle that has existed throughout the history of cybersecurity.
Attack → Detection → Prevention → Adaptation → New Attack → Improved Detection → Improved Prevention
What is changing is the potential speed and scale of that cycle.
Cybersecurity professionals are therefore not simply defending yesterday’s systems against yesterday’s threats. They increasingly operate in an environment where AI may assist the attacker, assist the defender, and exist within the technology environment being protected.
That raises a larger question:
If AI can make both attack and defense faster, does cybersecurity ever reach a finish line—or does each improvement on one side create pressure for further improvement on the other?
3. How AI Can Increase Cyberattacks
Artificial intelligence can change cyberattacks in an important way: it can give attackers greater speed, scale, automation and adaptability.
It is important, however, not to exaggerate AI’s role. Cybercrime existed long before generative AI. Phishing, malware, identity theft, software vulnerabilities, social engineering, unauthorized access and data theft are not new.
Cybercriminals do not necessarily need AI to invent completely new forms of attack. What AI can change is the speed, scale, accessibility and sophistication with which some existing malicious activities may be carried out.
AI did not create cybercrime. It can accelerate it.
If AI helps attackers perform certain activities faster, more convincingly, at greater scale or with less manual effort, the overall cybersecurity challenge can increase.
The following examples show how this acceleration can occur.
AI Can Make Social Engineering More Convincing
For many years, one of the easiest ways to attack a computer system has been to target the person using it.
An organization may invest heavily in firewalls, endpoint protection, cloud security, identity management and monitoring. But an attacker may instead attempt to persuade an employee to reveal information, approve a request, open something unsafe, or provide access that should not have been provided.
AI can potentially make these social-engineering attempts more convincing.
Generative AI can produce professional-looking messages, improve grammar, adapt tone, summarize publicly available information and generate communications that appear more natural than the poorly written phishing messages many people learned to recognize in the past.
This changes an important assumption.
Poor spelling and obvious mistakes can no longer be relied upon as signs that a message is fraudulent.
AI-generated text can be polished, professional and contextually convincing.
This makes human cybersecurity awareness even more important, not less important.
If someone inside the organization opens the door to an attacker by approving a fraudulent request or sharing sensitive information, many of the protections can become far less effective.
AI Can Increase Personalization
Traditional malicious campaigns often relied on sending the same or similar message to thousands of people and hoping that a small percentage responded.
AI can make personalization easier.
Attackers may be able to process publicly available information about organizations, industries, job roles or current events and use it to create communications that appear more relevant to a particular recipient.
The more relevant a message appears, the more likely a person may be to trust it.
This is particularly important as individuals and organizations make increasing amounts of information available through websites, professional profiles, social media, online directories and other digital sources.
AI can help process that information faster. Therefore, the problem is not simply:
More information is becoming public.
It is also:
Technology is becoming better at analyzing that information quickly.
AI Can Strengthen Impersonation and Deepfake Risks
Generative AI is not limited to text.
AI systems can generate or manipulate images, audio and video, creating additional opportunities for impersonation and deception.
This can make it more difficult to rely solely on familiar voices, images or apparently realistic digital communications as proof of identity.
For organizations, this can affect areas such as requests for payments, account changes, password resets, confidential information, approvals and communications appearing to come from executives, colleagues, customers or suppliers.
This reinforces a fundamental security principle:
Trust should increasingly be verified through processes and controls, not simply through how convincing digital communication appears.
AI Can Help Attackers Operate at Greater Scale
One of AI’s most important characteristics is its ability to automate and process information quickly. For legitimate organizations, this can increase productivity.
For attackers, the same capability can increase scale.
Activities that previously required substantial manual effort may increasingly be assisted by AI. This does not mean cyberattacks become fully autonomous, but even partial automation can allow malicious actors to attempt more activity within the same period.
For example, instead of manually researching a small number of potential targets, technology can assist in processing information across a much larger group.
The malicious objective may be unchanged. The scale is what changes.
This is one reason AI can significantly affect cybersecurity even when it does not create a completely new type of attack.
AI Can Accelerate Reconnaissance
Before attempting an attack, malicious actors may try to understand an organization’s technologies, people, services and potential weaknesses.
AI can help process and organize large amounts of available information more quickly, potentially making it easier to identify patterns and prioritize areas for further attention.
AI does not eliminate the need for attacker knowledge, but it can act as an accelerator.
AI May Accelerate Search for Software Weaknesses
Modern software environments can contain enormous amounts of code, libraries, dependencies, configurations and integrations.
AI-assisted development tools can help legitimate programmers understand and improve software. Similar analytical capabilities can also potentially be misused to help identify suspicious patterns, weaknesses or insecure configurations.
This creates another cybersecurity challenge.
As software development becomes faster through AI, secure software development must also become faster.
Organizations cannot assume that increasing development speed without increasing security capability will produce the same risk profile. The faster technology changes, the faster security teams may need to test, monitor, patch and adapt.
AI Can Increase the Speed of Attack Adaptation
Traditional security systems often depend partly on recognizing known patterns.
AI can potentially help malicious actors modify content, communication or other aspects of their activity more quickly. This matters because cybersecurity is not a static contest.
A defender may identify one attack pattern and create a rule or control to detect it. An attacker may then change the pattern. AI can potentially accelerate this cycle.
Attack → Detection → Adaptation → New Detection → Further Adaptation
As both sides automate more of this process, the time between these stages can become shorter.
This is another reason modern cybersecurity increasingly requires continuous monitoring and continuous learning, rather than relying only on controls installed once and left unchanged.
AI Can Lower Some Barriers to Cybercrime
Advanced cyberattacks still require significant knowledge and expertise. AI does not automatically turn an inexperienced person into a sophisticated attacker.
However, AI can make technical information easier to understand, help organize information and automate some routine activities. This may lower the barrier for certain forms of malicious activity.
The concern is therefore not only whether AI makes sophisticated attackers more capable. It is also whether it enables more people to attempt lower-level malicious activities at greater scale.
Organizations may consequently face a higher volume of attempted attacks even while advanced cyber operations continue to require substantial expertise.
AI Can Also Create New Targets
There is another side to the problem that is sometimes overlooked.
Organizations are rapidly introducing AI into:
Applications → Websites → Cloud Platforms → Customer Service → Analytics → Business Processes → Software Development → Connected Devices → Decision-Making Systems
Every new implementation can introduce additional data, identities, permissions, APIs, integrations and infrastructure.
These become things that must be protected.
Therefore, AI can increase cyber risk in two fundamentally different ways:
1. AI can strengthen the capabilities available to attackers.
2. AI adoption can create additional systems, data flows and connections that attackers may attempt to target.
This is why securing AI itself becomes the third major theme of this article.
AI Systems Depend on Data—and Data Is Valuable
AI systems often depend on large quantities of data from databases, cloud applications, sensors, business systems, customer interactions, websites, enterprise applications and connected devices.
As organizations become increasingly data-driven, protecting the confidentiality, integrity and availability of that data becomes increasingly important.
A simple principle follows:
Unreliable Data → Unreliable AI
Cybersecurity is therefore not only about preventing information from being stolen. It is also about protecting accuracy, trustworthiness, accessibility and appropriate use of information.
Organizations may need to ask:
· Can we trust the information entering the system?
· Has it been altered?
· Who is allowed to access it?
· Where did it come from?
· Could it be manipulated?
· Will it be available when required?
These questions become especially important when AI-supported decisions affect business operations, healthcare, industrial processes or connected physical systems.
These developments are also increasing the value of combining data knowledge with an understanding of the business or industry environment in which that data is used. In business, areas such as Business Administration with Data Analytics & Digital Marketing can help learners understand how organizations use data to support operations, analysis, decision-making, customer engagement and digital marketing. In healthcare administration, Digital Health Office Administration & Data Security reflects the growing importance of managing digital information while understanding privacy, appropriate access and data security.
As AI and data become more deeply integrated into different industries, understanding how information is collected, used, analyzed and protected can become valuable well beyond traditional IT and cybersecurity roles.
Edge AI Can Create More Distributed Security Challenges
AI processing is also moving closer to where data is generated.
Instead of sending everything to a centralized cloud environment, some analytics and AI processing can occur on edge devices or systems closer to sensors, equipment and users. This can improve speed, reduce latency and, in some cases, reduce the need to continuously transmit large amounts of data to the cloud.
For example, a manufacturing sensor may use nearby AI processing to identify abnormal equipment behaviour. A healthcare device may analyze certain information locally to support faster alerts. A camera may analyze images locally rather than continuously sending everything to a distant cloud system.
This is Edge AI: using AI closer to where data is generated and where faster analysis or action may be required.
But moving intelligence closer to the edge also changes the security environment. Devices, sensors, locally processed data, AI capabilities, communications and connections to other systems may all require protection.
There is another important issue: AI decisions can only be as reliable as the data and information on which they are based. If an edge device or sensor sends incorrect, incomplete, corrupted or manipulated data to a cloud or AI system, the resulting analysis, prediction or recommendation may also be inaccurate—even when the AI system itself is functioning as designed.
This means cybersecurity must protect not only the confidentiality of data, but also its integrity and trustworthiness from the point where it is created. In environments such as healthcare, manufacturing, transportation, agriculture and smart cities, unreliable input data could potentially lead to unreliable decisions or actions.
The security chain can therefore extend across:
Physical Environment → Sensor / Device → Edge → Network → Cloud → Data & Analytics → AI → Decision / Application → Edge / Device
This is where Edge AI Security becomes important.
In simple terms:
Edge AI brings intelligence closer to where data is created. Edge AI Security helps protect that intelligence—and the devices, data, access, communications and connected systems on which reliable AI decisions depend.
A useful principle is:
Trusted Input → Trusted Processing → More Reliable AI Output
Conversely:
Compromised or Incorrect Input → Unreliable Analysis → Potentially Incorrect Decision or Action
A simple way to visualize the security requirement is:
Edge AI Security = Protect the Device + Protect the Data + Protect the AI + Protect Access + Protect Communications + Protect Connections to Cloud and Other Systems
In some connected environments, the consequences can extend beyond the loss of information. A compromised device or unreliable AI decision could potentially influence equipment, operations or actions in the physical world.
These developments are also bringing previously separate areas of technology closer together. There is growing overlap between areas such as Cloud Data Analytics and Edge AI Security, particularly where data moves between edge devices, cloud platforms, analytics and AI systems. In sectors such as healthcare and engineering, AI & IoT for Healthcare and Engineering provides another example of how intelligent software, connected devices, data and physical systems are becoming part of the same technology environment.
The important point is not that everyone needs to specialize in every area. Rather, understanding how these technologies connect can make it easier to recognize where security risks arise and where protection needs to be applied.
As AI moves closer to the edge, cybersecurity must move with it.
AI Can Increase Third-Party and Supply-Chain Risk
Modern organizations rarely build every technology they use themselves. They depend on software vendors, cloud providers, APIs, AI services, open-source components, technology partners and other suppliers.
AI can add more dependencies to this ecosystem.
An organization may therefore secure its own internal systems carefully while still depending on external technologies and data flows.
This creates an important principle:
Your cybersecurity can be affected by technologies and organizations outside your direct control.
As AI becomes integrated into more products and services, organizations need to understand not only their own security controls but also how third-party technologies connect to their environment.
AI-Generated Code Creates Both Opportunity and Responsibility
AI-assisted development and analysis tools can help developers work faster and examine large amounts of software and configuration information more efficiently.
But faster software development does not automatically mean more secure software. AI-generated or AI-assisted code still requires appropriate review, testing, security validation and human oversight.
If organizations use AI to accelerate development without strengthening secure-development practices, vulnerabilities or configuration problems may also be introduced more quickly.
The objective should therefore not simply be:
Use AI to write software faster.
It should be:
Use AI to develop software faster while maintaining or improving security.
Speed without adequate security can simply move risk faster.
The Cybersecurity Time Window May Become Shorter
All these developments lead to a larger concern.
Organizations already face pressure to move quickly between discovering a vulnerability, understanding the risk and implementing appropriate protection.
As AI accelerates analysis and automation on both sides, that window may become even shorter.
· Attackers may discover opportunities faster.
· Defenders may detect them faster.
· Software developers may release changes faster.
· Cloud infrastructure may be deployed faster.
· Security teams may need to respond faster.
This means speed itself becomes part of cybersecurity capability.
But speed alone is not enough. Fast automated decisions without appropriate knowledge, controls and human oversight can create new problems.
The objective is therefore:
Speed + Accuracy + Security + Human Judgment
In an AI-accelerated environment, organizations may increasingly need all four. Responding quickly is valuable only when the response is sufficiently accurate, secure and appropriately governed.
AI Can Increase Both the Quantity and Quality of Cyber Threats
The overall impact can be summarized in two dimensions.
Quantity: AI can help automate and scale malicious activity, potentially increasing the number of attempts organizations must detect and manage.
Quality: AI can potentially make some attacks more convincing, targeted, adaptive and difficult to distinguish from legitimate activity.
AI can therefore increase both the quantity and quality of cyber threats. Organizations may have to identify more threats while some of those threats become more difficult to recognize.
This creates an important consequence: if AI can help malicious activity move faster, cybersecurity must also become capable of detecting, analyzing and responding faster.
That brings us to the defensive side of AI.
4. If AI Gives Attackers Speed, Defenders Need Speed Too
If artificial intelligence can help attackers operate faster and at greater scale, cybersecurity professionals cannot depend entirely on slower, manual methods of detection and response.
Modern digital environments can generate enormous volumes of information. As organizations become more digital, the amount of security information that must be monitored can continue to grow.
No security team can manually investigate every event with equal attention.
This is one of the areas where AI can become a powerful defensive tool.
AI can help security teams process large volumes of information, identify patterns, detect anomalies, prioritize suspicious activity, automate repetitive tasks and accelerate investigation and response.
The objective is not necessarily to remove people from cybersecurity. It is to help cybersecurity professionals find what matters faster.
AI Can Help Detect Suspicious Activity Faster
Traditional security tools can use predefined rules, signatures and known indicators to identify suspicious activity. These remain important, but attackers do not always behave in the same way.
AI and machine-learning techniques can complement traditional controls by examining patterns across large amounts of security data and helping identify activity that differs from expected behaviour.
Security teams may need to examine patterns involving:
· Unusual login behaviour
· Unexpected access to information
· Abnormal network activity
· Unusual system or application behaviour
· Changes in user or device activity
· Combinations of events that become suspicious when considered together
The value of AI is not that every unusual event is automatically an attack. It is that AI can help surface patterns requiring human attention.
Unusual behaviour can have many legitimate explanations. Cybersecurity professionals still need to investigate the context and determine what the activity means.
Organizations may also have an important defensive advantage: they can often understand their own systems, users, normal operating patterns and business priorities better than an outside attacker. When that organizational knowledge is combined with AI, automation and skilled cybersecurity professionals, suspicious deviations may be identified and investigated more effectively.
AI Can Help Security Teams Manage Alert Overload
A major cybersecurity challenge is not always too few alerts, but too many. Security technologies can generate large volumes of notifications, ranging from serious threats to routine or low-risk events.
AI can help correlate events, reduce repetitive analysis and prioritize alerts that deserve closer investigation, allowing professionals to focus their limited time on higher-priority problems.
The important question becomes: Which alerts require my attention first, and why?
AI Can Strengthen Phishing and Fraud Detection
Just as AI can help attackers create more convincing phishing and social-engineering communications, it can also help defenders detect them.
AI-assisted security systems can analyze messages, links, sender behaviour, communication patterns and other signals to identify potentially suspicious activity.
As AI-generated content becomes more convincing, automated detection must be supported by human awareness, verification procedures, identity controls and organizational policies.
AI Can Support Threat Intelligence
Cybersecurity professionals need to understand not only what is happening inside their environment, but also what threats are emerging outside it.
AI can help organize, summarize, correlate and prioritize information about vulnerabilities, attack patterns and malicious activity, helping professionals identify which threats are most relevant and require attention.
This can turn large volumes of threat information into actionable intelligence more quickly.
AI Can Assist Threat Hunting
Unlike threat detection, which often begins with an alert, threat hunting proactively searches for suspicious activity that may already exist within an environment.
AI can help analysts examine large datasets, identify unusual patterns and connect related events. However, professionals still need knowledge of systems, networks, identities, applications, cloud environments and organizational context to determine what those patterns mean.
AI can accelerate investigation, but knowledge determines what the results mean.
AI Can Help Correlate Activity Across Multiple Security Layers
A cyberattack may involve several small events across different systems rather than one obvious warning. An unusual login, access request or change in application behaviour may appear harmless individually but become suspicious when examined together.
AI can help correlate events across security sources and identify relationships that may be difficult to recognize manually at scale.
In interconnected environments, understanding relationships between events can be more valuable than examining each event in isolation.
AI Can Help Prioritize Vulnerabilities and Risk
Organizations may have many vulnerabilities, but not all represent the same level of risk.
AI-assisted security tools can combine vulnerability information with technical and organizational context to help identify which weaknesses should be addressed first.
Human judgment remains important because technical severity is only one part of organizational risk.
AI Can Accelerate Incident Investigation
When suspicious activity is detected, security teams need to quickly determine what happened, what was affected and whether the threat is continuing.
AI can help analyze information across logs, systems and cloud services, enabling professionals to understand incidents and make informed decisions faster.
AI Can Support Faster Incident Response
Detection without response provides limited protection. Once a credible threat is identified, organizations may need to act quickly.
Depending on the environment and established policies, automated security systems can support actions such as restricting suspicious access, isolating affected resources, increasing monitoring or initiating predefined response workflows.
Detection → Analysis → Decision → Response
Automated responses can also disrupt legitimate users or business operations if they are incorrect.
The objective is to automate appropriate actions while maintaining control, validation, accountability and human oversight where required.
AI Can Strengthen Identity and Access Monitoring
Organizations increasingly need to understand who or what is requesting access, what they are accessing and whether the behaviour is expected.
AI-assisted analysis can help identify unusual authentication and access patterns, particularly across complex cloud environments.
As digital environments become more complex, protecting identity and access becomes as important as protecting the perimeter.
AI Can Help Defend Cloud and Multi-Cloud Environments
As cloud technologies converge, Security and Automation of Multi-Cloud Containerized Workloads becomes an important area of knowledge. Containers package applications and their required components so they can run consistently across different environments, while containerized workloads are the applications and services running within them, often managed through technologies such as Kubernetes.
Because these workloads can be rapidly created, scaled and updated across multiple clouds, AI-assisted security can help monitor activity and identify risks. However, professionals still need to understand cloud architecture, identity, networking, containers, automation, data and configuration.
Modern cybersecurity increasingly requires knowledge of the technology being protected.
AI Can Support Security at the Edge
Edge AI can create security challenges, but it can also contribute to the defense.
By analyzing data closer to where it is generated, AI-assisted security can help identify suspicious behaviour or abnormal conditions more quickly, particularly where rapid response is important.
However, effective detection still depends on securing devices, data, communications, networks and cloud connections.
Edge AI can bring detection closer to where activity occurs—but Edge AI Security is needed to protect the environment in which that detection takes place.
AI Can Make Cybersecurity More Proactive
Traditional cybersecurity can sometimes become reactive:
Attack → Alert → Investigation → Response
AI and automation can help move parts of security toward a more proactive model:
Continuous Monitoring → Pattern Recognition → Early Warning → Investigation → Preventive or Rapid Response
This does not mean every attack can be predicted or prevented. But earlier identification can provide defenders with something extremely valuable: time. In an environment where AI may be shortening the cybersecurity time window, even a small amount of additional response time can matter.
AI Does Not Replace Cybersecurity Knowledge and Human Judgment
Sophisticated AI tools cannot compensate for weak cybersecurity fundamentals. Organizations still need secure identities and systems, network and application security, cloud and data protection, vulnerability management, monitoring, incident response, governance and security-aware people.
AI should strengthen cybersecurity fundamentals—not replace them.
AI can identify patterns, prioritize alerts and recommend actions, but professionals must still determine what is genuinely malicious, how serious the risk is and what response is appropriate.
AI may reduce repetitive information-processing work, allowing cybersecurity professionals to focus more on investigation, judgment, architecture and decision-making. This requires an understanding of the systems, networks, applications, cloud platforms, data and connected devices that AI is helping them protect.
AI Versus AI: Who Has the Advantage?
This brings us back to the central question.
Attackers can use AI to process information, automate activity, personalize attacks and adapt more quickly. Defenders can use AI to monitor enormous environments, correlate events, identify anomalies, prioritize threats and accelerate response.
Both sides gain speed. Both sides gain automation. Both sides gain greater ability to process information.
So, who wins?
There may be no permanent answer. The advantage may shift continuously as technologies, attack techniques and defensive capabilities evolve.
Organizations can improve their position through a combination of:
Better Technology + Better Data + Strong Cybersecurity Fundamentals + Automation + Skilled Professionals + Human Judgment + Governance
AI does not make cybersecurity less important. It can make effective cybersecurity more important.
The Growing Importance of Cybersecurity & AI-Driven Threat Detection
As cyber threats become faster and increasingly AI-assisted, Cybersecurity & AI-Driven Threat Detection can help professionals understand, identify, investigate and respond to evolving threats.
This requires combining knowledge of networks, systems, applications, cloud platforms and identities with AI-assisted monitoring, threat intelligence, threat hunting, detection, investigation and incident response.
The objective is not simply to operate an AI security tool, but to understand what it is monitoring, what may represent a risk and how to respond appropriately.
5. Cybersecurity Does Not Stop at Threat Detection
Detecting a threat is only one part of cybersecurity. As discussed earlier, modern digital environments are highly interconnected, and a weakness in one area can potentially affect systems, information, users and operations elsewhere in the organization.
Protecting such an environment therefore requires more than threat detection. Organizations also need appropriate identity and access controls, monitoring, security policies, risk management, compliance and governance.
As organizations become larger and their technology environments more complex, managing these requirements manually can become increasingly difficult. This is where knowledge of Enterprise Cybersecurity and Governance Automation becomes valuable. It can help professionals understand how cybersecurity controls, governance requirements, risk management, compliance and automation can work together across an enterprise rather than being managed as isolated activities.
Security follows technology. Governance helps ensure that security is applied consistently. Automation helps organizations do this at scale.
6. Security at Different Technology Layers
AI vs. AI will not determine cybersecurity by itself.
The outcome will also depend on the people who design systems, secure infrastructure, interpret information, govern AI use, respond to incidents and make decisions when automated systems cannot.
This has an important implication for cybersecurity education. If modern cybersecurity professionals need to understand the technologies they are protecting, education must increasingly connect security knowledge with knowledge of the underlying technology environment.
No single program needs to make every student an expert in every layer. Different areas of study can instead develop greater depth in particular parts of the environment while helping students understand how those areas connect.
These areas should therefore not be viewed in isolation. Together, they illustrate how modern cybersecurity spans different but interconnected layers of technology.
Threat Detection, Investigation & Response
Cybersecurity & AI-Driven Threat Detection
This area connects traditional cybersecurity knowledge with emerging AI-assisted defensive capabilities. Learning can include monitoring, threat intelligence, threat hunting, detection, investigation, incident response, digital forensics and the use of AI-assisted tools to help professionals identify and evaluate suspicious activity.
The objective is not simply to learn how to operate security tools, but to understand what is being monitored, what may represent a threat and how to respond appropriately.
AI-Assisted Cybersecurity
Cyber Security with Artificial Intelligence
Artificial intelligence and machine learning are increasingly being integrated into cybersecurity. Knowledge in this area can help learners understand how AI, security analytics and data-driven approaches can support the identification of patterns, anomalies and potential risks.
It also reinforces an important principle discussed throughout this article: AI can support cybersecurity, but professionals still need the underlying cybersecurity knowledge required to understand and evaluate what AI discovers.
Cloud, Data & Edge Security
Cloud Data Analytics & Edge AI Security
As data moves among cloud platforms, analytics systems, AI applications and edge environments, professionals can benefit from understanding both how that data is processed and how the surrounding environment is protected.
This area brings together knowledge of cloud technologies, data analytics and Edge AI Security, helping learners understand security requirements across increasingly distributed and data-driven environments.
Multi-Cloud, Container & Automation Security
Security and Automation of Multi-Cloud Containerized Workloads
Modern applications may operate across multiple cloud platforms and containerized environments supported by Kubernetes, automation and cloud-native technologies.
Knowledge in this area can help professionals understand how these environments are built, deployed, managed, automated and secured. As infrastructure becomes more dynamic and automated, security increasingly needs to operate at the same speed as the technology it protects.
Operating System & Application Security
Enterprise Linux & Application Security Engineering
Operating systems and applications remain important foundations of the modern technology environment. Understanding enterprise Linux, application environments, permissions, configurations and security controls can help professionals recognize where vulnerabilities may arise and how systems and applications can be better protected.
This illustrates why cybersecurity knowledge becomes more valuable when combined with an understanding of how the underlying technology works.
Cloud Infrastructure & Cybersecurity
Cloud and Cybersecurity Technologies
Cloud adoption has changed how organizations build and operate technology environments. Infrastructure, applications, identities and data may now extend across cloud-based systems rather than remaining within a traditional organizational network.
Combining cloud knowledge with cybersecurity knowledge can therefore help professionals understand both how cloud environments operate and how they should be protected.
IT Infrastructure, Support & Cybersecurity Foundations
Cloud-Based IT Support & Cybersecurity
Cybersecurity does not begin only with advanced threat-detection systems. Endpoints, user accounts, operating systems, networks, cloud services and everyday configuration and support activities can all influence an organization’s security.
Knowledge across IT support, networking, systems, cloud technologies and cybersecurity can therefore provide an important foundation for understanding where security problems originate and how technology should be configured and maintained securely.
Enterprise Security, Governance & Automation
Enterprise Cybersecurity & Governance Automation
As discussed in the previous section, detecting and responding to threats is only part of enterprise cybersecurity. Larger organizations also need to consider risk, compliance, governance, accountability, security controls and automation across complex technology environments.
Knowledge in this area can help professionals understand how cybersecurity can move beyond individual technologies and security tools toward the consistent management and governance of security across the enterprise.
Automation becomes particularly important as organizations attempt to monitor environments, apply controls, identify exceptions and maintain governance across technology that can change continuously.
Bringing the Layers Together
These areas illustrate why modern cybersecurity cannot always be understood as a single isolated technical specialty.
Different professionals may develop greater expertise in different areas, but the technologies they protect are increasingly interconnected. Cloud systems depend on networks and identities. Applications depend on operating systems, data and infrastructure. AI depends on data, applications and computing environments. Edge systems may connect digital decisions with devices and physical operations. Enterprise governance must consider risks that can arise across all of them.
The educational objective should therefore not be to make every learner an expert in everything. It should be to help learners develop strong knowledge in their chosen area while understanding how that area connects with the broader cybersecurity environment.
Technology Layers + Security Knowledge + AI & Automation + Human Judgment + Governance = A More Complete Understanding of Modern Cybersecurity
7. When Digital Security Can Affect the Physical World
Edge AI and IoT can connect digital systems with physical environments. Information from sensors and devices may be analyzed by AI and used to support decisions involving equipment, operations or other real-world activities.
Physical Environment → Digital Data → AI Analysis / Decision → Digital Command → Physical Environment
This means cybersecurity may need to protect not only information and systems, but also the integrity of data, connected devices, communications and AI-supported decisions that can influence physical outcomes. As these technologies become more connected, the boundaries between cybersecurity, AI security, IoT security and physical-system security increasingly overlap.
8. Cloud-Native AI Requires Cloud-Native Security
Modern AI applications may operate across cloud platforms, containers, Kubernetes and automated infrastructure. Securing these environments requires more than using security tools; professionals also need to understand how the underlying infrastructure is built, deployed, connected and automated.
You cannot fully understand how to secure a modern cloud-native environment without understanding how that environment works.
This makes knowledge of multi-cloud platforms, containers, orchestration, identity, infrastructure automation and security automation increasingly valuable as AI and cloud-native technologies continue to converge.
9. AI Security Is Also About Protecting AI
As AI becomes integrated into business and technology, AI itself becomes something cybersecurity must protect. This includes protecting data, models, applications, APIs, identities, permissions and infrastructure, supported by appropriate monitoring and governance.
AI security is increasingly becoming part of cybersecurity architecture and governance—not simply AI development.
10. The Human Still Matters
AI can strengthen cybersecurity, but people still make important decisions involving access, data, communications and AI-generated content.
Cybersecurity and AI awareness therefore matter beyond IT. Everyone who uses technology has a role in protecting information, using systems securely and using AI responsibly.
11. What Skills Will People Need in the AI Era?
The skills required will depend on a person’s role and level of responsibility.
Cybersecurity & AI Awareness
People working outside IT increasingly benefit from understanding privacy, data protection, secure use of digital systems, appropriate access and responsible AI use. They do not need to become cybersecurity specialists, but they are part of the organization’s security environment.
Technical Cybersecurity Skills
IT and cybersecurity professionals need deeper knowledge of the technologies they protect, together with skills in areas such as threat detection, security monitoring, incident response, automation and AI-assisted security.
Enterprise Cybersecurity & Governance Skills
More advanced responsibilities can require knowledge of security architecture, governance, risk, compliance, automation, resilience and leadership, enabling professionals to move from operating individual security controls toward helping design and govern security across an organization.
Awareness → Technical Knowledge → Enterprise Security & Governance
12. What Should a Modern AI-Era Cybersecurity Diploma Teach?
A modern cybersecurity diploma should not teach AI instead of cybersecurity fundamentals. It should help students understand how AI fits into a broader and evolving security environment.
A strong program should combine:
- Cybersecurity foundations — security principles, networking, operating systems, identity, applications and data
- Modern infrastructure security — cloud, multi-cloud, containers, IoT and edge environments
- Threat detection and response — ethical hacking, vulnerability awareness, threat intelligence, threat hunting, SIEM, incident response and digital forensics
- AI and automation — AI/ML concepts relevant to cybersecurity, AI-assisted detection, scripting and security automation
- Enterprise security — governance, risk, compliance, resilience and responsible use of AI
- Practical learning — labs, projects and realistic security scenarios
The objective is not to make every graduate an expert in every technology. It is to provide sufficient breadth to understand the environment being protected, appropriate depth for the chosen career direction, and the practical foundation to continue learning as AI, cybersecurity and the underlying technologies evolve.
A strong cybersecurity education should ultimately help students understand not only individual security technologies, but how they connect and where weaknesses can create risk across the wider environment.
13. AI: Threat or Defense? The Answer Is Both
AI can strengthen both cyber threats and cyber defense. The advantage may increasingly depend on better technology, better data, stronger cybersecurity knowledge, effective processes, governance and skilled people.
There may never be a permanent winner. As AI capabilities evolve, threats and defenses will continue to evolve with them.
If AI accelerates technology, cybersecurity must accelerate with it.
About the Author
Donatus Doss, President of Canadian College for Higher Studies (CCHS), has more than four decades of experience in education and extensive experience in information technology and professional training.
His technology background spans software development, Novell NetWare, AS/400, Unix, Linux, Windows Server, networking, Cisco technologies, SAP, systems administration, cybersecurity, cloud computing and AI. Having worked with and taught technologies across several generations of computing, he brings a practical perspective on how IT infrastructure, cybersecurity and the skills required to protect modern systems have evolved.
Frequently Asked Questions (FAQ)
AI can increase the speed, scale and sophistication of some malicious activities and make deception more convincing. At the same time, AI can also strengthen cybersecurity detection, analysis and response.
No. AI can assist with monitoring, detection, analysis and response, but effective cybersecurity still requires appropriate controls, skilled professionals, governance and human judgment.
AI is more likely to change cybersecurity work than eliminate it. Professionals will still be needed to investigate threats, make decisions, design security controls, manage risk and oversee AI-assisted security.
Finding a threat is only the beginning. Organizations must also protect systems and information, control access, respond to incidents, recover operations, manage risk and maintain governance and compliance.
Modern applications increasingly operate across cloud, multi-cloud and containerized environments. Understanding how these environments are built, deployed and automated helps professionals understand how they should be secured.
Edge AI brings data processing and intelligence closer to devices, sensors and physical environments. Security must therefore protect the devices, data, communications, access and AI-supported processes involved.
AI may identify a threat, but governance helps determine who can act, how risk is managed, what controls apply and how security decisions remain accountable and consistent.
Yes, at an appropriate level. People across business, healthcare, accounting, marketing, supply chain and other fields increasingly handle digital information and AI-enabled technologies, making security, privacy and responsible AI awareness valuable professional skills.
Look for a program that combines strong cybersecurity fundamentals, practical learning and knowledge of the technologies being protected, while incorporating relevant AI, automation and modern security practices.
There may be no permanent advantage. AI can strengthen both sides, and the outcome can depend on technology, data, cybersecurity knowledge, governance, human expertise and how quickly each side adapts.
Latest Post
- AI and Cybersecurity: What Everyone Needs to Know in 2026
- How Government, Funding Organizations, Colleges and Students Can Work Together
- AI Is Already Becoming Part of Everyday Work
- Why Cybersecurity and AI Are Becoming One Career Path in Canada
- What Jobs Can You Get With Cloud and Cybersecurity Skills in Canada?