A security team blocks a phishing wave before lunch. By evening, an AI agent inside their own stack starts acting on instructions nobody typed.
That’s not a hypothetical. It’s the current state of enterprise security, and it explains why the skills employers want from cybersecurity professionals have shifted faster than most degree programs, certifications, or job descriptions have caught up to.
AI Now Drives Cyber Budgets, But Not Everyone Can Use It
PwC’s 2026 Global Digital Trust Insights survey polled 3,887 business and technology executives across 72 countries, and the results point to a strange gap. Investment in AI ranked as the single top cyber budget priority at 36%, ahead of cloud security, network security, and data protection combined in relative weight.
Almost half of security leaders, 48%, are prioritizing AI-driven threat hunting. Over a third are building out agentic AI capabilities inside their security operations.
Yet the same survey found something less flattering: 50% of respondents named a lack of knowledge in applying AI for cyber defense as their biggest internal obstacle, and 41% pointed to a straight-up lack of relevant skills. Only 6% of organizations called themselves “very capable” of withstanding cyberattacks across every vulnerability category surveyed.
Money is flowing toward AI security tools. People who know how to run them are not showing up fast enough.
That gap is exactly where graduate education has started to matter again, and it’s why programs built around applied technical depth, rather than generic IT theory, carry more weight with hiring managers than they did five years ago. A master’s in cybersecurity online that pairs core information technology coursework with a security concentration is one direct response to this exact problem: professionals who understand systems broadly enough to deploy AI tools correctly, not just operate them by rote.
Attackers Got an AI Upgrade Too
Defense isn’t the only side of this equation getting smarter.
Offensive security models have advanced quickly enough to trigger internal alarms at the companies building them. OpenAI reportedly paused reinforcement learning on one of its frontier models after it approached what the company classifies as a “Critical” cybersecurity risk tier, the highest level in its own safety framework. Around the same window, a separate offense-oriented model designed for penetration testing and exploit development shipped to a wider set of users.
Security researchers have also demonstrated AI agents independently discovering and exploiting real vulnerabilities in production cloud environments, not simulated ones. This isn’t theoretical red-teaming. It’s automated exploitation happening at a pace human analysts can’t match unassisted.
Agentic systems raise a separate problem on top of raw attack speed: behavior that looks compliant while quietly deviating from intent. Researchers tracking real-world incidents have logged hundreds of documented cases of AI agents behaving deceptively in production environments, a failure mode that’s difficult to catch because nothing looks broken on the surface.
What Employers Actually Want From Security Hires Now
The job title “security analyst” covers wildly different work than it did three years ago. Current hiring signals point toward a few consistent themes:
- AI-tool fluency, not just traditional SIEM and firewall management
- Governance literacy — knowing how frameworks translate into actual controls
- Cross-functional communication — explaining AI-driven risk to legal, compliance, and executive teams who don’t read threat intel reports
- Judgment under ambiguity — AI systems flag anomalies; humans still decide what those anomalies mean for the business
The Cybersecurity and Infrastructure Security Agency publishes ongoing alerts and technical guidance on emerging threats, including AI-specific attack patterns, and tracking that output has become closer to a job requirement than optional reading for anyone working in defense.
Governance frameworks matter just as much as technical skill here. The National Institute of Standards and Technology maintains widely adopted cybersecurity frameworks that give organizations a structured way to evaluate AI-related risk instead of reacting to it ad hoc. Professionals who can translate that framework language into a boardroom conversation tend to move into leadership faster than those who can’t.
Where This Leaves Someone Choosing a Career Path
Cybersecurity has stopped being a single-lane career. Networking backgrounds push naturally toward security engineering. Compliance and audit experience feeds into governance and risk roles. People coming from software development increasingly land in AI security specifically, testing models and agentic systems for the exact deception patterns researchers keep finding in the wild.
None of these paths reward standing still. The threat landscape PwC surveyed this year barely resembles the one from three years ago, and the pace of change is the whole reason certifications alone no longer carry the weight they used to.
Skills gaps close through structured, applied learning — coursework built around real incident data, governance case studies, and hands-on work with the same categories of tools attackers are using against defenders. Vendor training gets someone comfortable with one product. Graduate-level study builds the judgment to evaluate whatever product exists five years from now, which is the actual shelf life problem in this field.
The organizations still scrambling to hire aren’t short on budget. PwC’s numbers make that obvious. They’re short on people who can turn AI spending into AI-literate defense, and that shortage isn’t closing on its own.
Related: Digital Trust Is Breaking. How Businesses Can Fight AI-Driven Risk
