Close Menu
NCIJ Network NCIJ Network
    What's Hot

    No signs Chagos deal can be adapted to suit Trump, say UK officials | Chagos Islands

    September 23, 2026

    The Guardian view on Russian disinformation: a foreign threat that relies on UK complicity | Editorial

    September 23, 2026

    Zoox grounds Atlanta test fleet after workers report toxic gas exposure symptoms

    September 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • No signs Chagos deal can be adapted to suit Trump, say UK officials | Chagos Islands
    • The Guardian view on Russian disinformation: a foreign threat that relies on UK complicity | Editorial
    • Zoox grounds Atlanta test fleet after workers report toxic gas exposure symptoms
    • Adobe Patches Critical Flaws in Connect, AEM Forms
    • Stablecoins hold nearly $200 billion in US debt, but money funds bought the surge
    • NASA’s Hubble Seeks Lensed Supernova, Marks 200,000 Orbits
    • Millions of heads of lettuce ruined by aphid outbreak
    • WATCH: Dutch methanol-ready subsea rock installation vessel launched
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 23
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Technology

    What do cybersecurity leaders want in staff? These 3 skills beat certifications and experience

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 9, 2026 Technology No Comments7 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    gorodenkoff/iStock/Getty Images Plus

    Follow ZDNET: Add us as a preferred source on Google.


    ZDNET’s key takeaways

    • AI brings new challenges for hard-working cyber staff.
    • Talented professionals will question almost everything.
    • Work with agents to make decisions that reduce risks.

    Working in cybersecurity is a tough gig. While security teams work hard to prevent damage to their organizations, ZDNET reported earlier this year that many cyber professionals aren’t receiving the recognition they deserve

    Emerging technology brings new challenges. AI-assisted vulnerability discovery is accelerating the pace of bug reports, with a growing mismatch between what machines can surface and what humans can realistically triage.

    Also: AI failed to patch software flaws 74% of the time, 1Password’s study warns

    In such a fast-changing and challenging working environment, it’s easy to understand why almost half of cybersecurity pros want to quit.

    However, staff should pause before sending their resignation letters: in an age of AI, where threats come from multiple angles, your business needs you now more than ever.

    As Fabrizio Pilotti, CIO at Aston Martin Aramco Formula One, said to ZDNET recently, digital leaders must think carefully about the balance between AI and human capabilities, and maintaining this equilibrium effectively creates new opportunities for security professionals.

    “In IT, lots of rules are changing. We’re thinking a lot about team structure, even job descriptions between the agentic part and non-agentic part,” he said.

    “I would say cyber, together with software development, is at the top of our priority list because of growing complexity and changing environments, where you have to react so fast.”

    Also: Assume AI cybersecurity attacks are the future: 43% of companies have already experienced it

    The good news, therefore, is that talented cyber staff could finally receive the recognition their skills fully deserve.

    But as agentic AI hoovers up elements of the traditional IT security role, how can cyber professionals prove their worth and build a successful career?

    The experts suggest successful candidates will focus on three key areas: curiosity-led critical thinking, instinctive qualities that sit above the automation line, and an ability to turn ambiguous signals into confident, risk-based decisions.

    Blend curiosity with critical thinking

    Eric Schmitt, global chief information security officer at risk and claims administration specialist Sedgwick, said many people mistakenly believe that a great cybersecurity professional is someone with certifications or years of experience.

    While those credentials can indicate someone’s likely capabilities, they are no guarantee of success, particularly in a world where AI and other emerging technologies transform the nature of attacks and the methods of response.

    Also: How Google used AI agents to find and fix 1,072 Chrome security bugs – in 60 days

    To this end, Schmitt told ZDNET that a great cybersecurity professional excels in one key area: curiosity.

    “I would rather hire someone a year into their career who constantly asks, ‘Why does this work this way?’ over someone 20 years in who doesn’t,” he said.

    Schmitt said that while experience teaches you what has worked in the past, curiosity teaches you what might break next and where the solution may be, a distinction that has never mattered more than it does in today’s rapidly changing threat landscape.

    “Credentials tell me where someone’s been, while questions like ‘Why does this agent call that service?’ or ‘Why do we follow this process?’ or trying to figure out which data a certain model is reading, who can modify it, and what an agent is allowed to do on its own, can tell me how they think a lot better.”

    Also: AI is both a cyber weapon and a massive target, CrowdStrike warns

    However, curiosity alone is not enough. Schmitt suggested curious cybersecurity professionals also need strong critical thinking skills.

    “Curiosity generates the most impactful questions, and critical thinking decides which answers hold up,” he said.

    “AI has made this type of thinking an urgent component, because these tools produce confident, plausible output at volume, but someone still has to ask whether it’s right and be able to tell.”

    Schmitt said curiosity without critical rigor leads to noise, and rigor without curiosity leads to stagnation, suggesting professionals with the right blend of capabilities will appeal to businesses that develop a proactive approach to cyber risks.

    “Together, these skills allow a security professional to keep pace with a threat landscape that no longer rewards static expertise,” he said. “Managers should hire for curiosity and cultivate critical thinking, because everything else can be taught.”

    Sit above the automation line

    This focus on critical thinking skills also appeals to Ankur Anand, CIO at recruiter Harvey Nash, who suggested industry research points to a significant problem — over-reliance on AI tools could leave enterprises exposed to attacks.

    He referred to SecRespond’s recently released benchmark that tested 23 leading AI models against real forensic data from compromised systems. Every model failed on the same category of attack: intrusions that never triggered an alert in the first place.

    “That’s the detail that should worry people more than any skills-gap statistic,” he told ZDNET, suggesting that most security tools, including those that use AI, work by investigating something that’s already flagged as unusual.

    “If nothing trips the alarm, an AI built to investigate alarms has nothing to chew on.”

    Also: How to keep your AI conversations as private as possible

    Anand said the best cybersecurity professionals possess the judgment to know when something’s awry.

    “They’ll have the instinct to get suspicious about a system that looks completely fine, and to ask why it’s quiet when everyone else is only watching for what’s loud.”

    So, how can IT security staff hone these instincts? Anand suggested the skills worth investing in sit above the automation line.

    He pointed first to threat-hunting capabilities: “Going looking for trouble with no alert telling you where to look.”

    Also: Open weights vs. closed: An AI civil war’s afoot, and the stakes are existential

    Second, AI oversight will be a crucial skill, plus the ability to describe potential risks to non-IT employees.

    “That’s about knowing when a model’s output is wrong and having the confidence to say so aloud in a meeting,” he said.

    “Plain communication matters more than it used to, because someone still has to turn ‘the model flagged this’ into a decision the business can actually act on.”

    Finally, Anand said good old-fashioned technological expertise will play an important role in helping cybersecurity professionals turn judgments into actions.

    “Basic Python is worth learning too, so you can query and interrogate the tools doing the triage instead of just accepting their verdicts,” he said.

    Focus on prioritizing risk

    The key takeaway for cybersecurity professionals, suggested Errol Weiss, chief security officer at member-driven organization Health-ISAC, is the need to shift their focus to adaptive thinking and operational judgment in the age of AI.

    “That transition requires clear thinking under pressure, curiosity, and the ability to turn ambiguous signals into a confident, risk-based decision,” he told ZDNET.

    Also: OpenAI’s attack agent did exactly what it was told – just more relentlessly than expected

    Weiss said adaptability is crucial because AI is accelerating both attack and defense cycles, meaning security teams are dealing with faster-moving threats, more noise, and often have less time to respond.

    “We need individuals who combine technical skills with an understanding of how systems operate in the real world, especially in sectors like healthcare, where patching or mitigation isn’t straightforward,” he said.

    “Communication is a core skill. Security professionals need to explain risk in a way that drives action across clinical, operational, and executive teams.”

    Weiss said the people who stand out will be those who can quickly interpret and prioritize risk.

    Also: AI is getting scary good at finding hidden software bugs – even in decades-old code

    When AI tools can do much of the heavy lifting, it is the human in the loop — in this case, the talented cybersecurity professional — who will help organizations manage risks.

    “AI tools can surface potential security issues, but they don’t understand business context, safety implications, or operational constraints,” he said.

    “That’s where human expertise remains critical. AI will continue to augment cybersecurity, but it won’t replace the need for experienced professionals who can make decisions during uncertainty. The most effective practitioners will be those who can work alongside AI, question its outputs, and translate insights into practical, timely action.”

    beat certifications cybersecurity experience leaders Skills staff
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Zoox grounds Atlanta test fleet after workers report toxic gas exposure symptoms

    Pornhub age checks investigated by Ofcom

    Could we be about to see the end of northern English dialects? My experience – and the science – says aye | Zahaan Bharmal

    YouTube’s Custom Feeds Give You More Control Over the Algorithm

    Nearly 70% of workers use AI regularly now – but many get no time to upskill

    PitPro’s first tire-changing robot goes live in Canada

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    No signs Chagos deal can be adapted to suit Trump, say UK officials | Chagos Islands

    September 23, 2026

    The Guardian view on Russian disinformation: a foreign threat that relies on UK complicity | Editorial

    September 23, 2026

    Zoox grounds Atlanta test fleet after workers report toxic gas exposure symptoms

    September 23, 2026

    Adobe Patches Critical Flaws in Connect, AEM Forms

    September 23, 2026
    Latest Posts

    Ransom Cartel ransomware creator sentenced to 16 years in prison

    August 5, 2026

    Uber CEO brushes off reports of a Waymo break-up

    August 5, 2026

    Fauci Faces Contempt Vote. Here Are the Legal Issues Involved.

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    No signs Chagos deal can be adapted to suit Trump, say UK officials | Chagos Islands

    September 23, 2026

    The Guardian view on Russian disinformation: a foreign threat that relies on UK complicity | Editorial

    September 23, 2026

    Zoox grounds Atlanta test fleet after workers report toxic gas exposure symptoms

    September 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.