Close Menu
NCIJ Network NCIJ Network
    What's Hot

    BIP-110 Begins Mandatory Signaling on Bitcoin

    August 9, 2026

    Russian forces kill several in Ukraine, launch ‘brutal’ attack in Odesa | Russia-Ukraine war News

    August 9, 2026

    A Democratic Socialist Spreads the Word, Even in Hostile Territory

    August 9, 2026
    Facebook X (Twitter) Instagram
    Trending
    • BIP-110 Begins Mandatory Signaling on Bitcoin
    • Russian forces kill several in Ukraine, launch ‘brutal’ attack in Odesa | Russia-Ukraine war News
    • A Democratic Socialist Spreads the Word, Even in Hostile Territory
    • Britain is paying the price for failing to invest in its young people | Richard Partington
    • What do cybersecurity leaders want in staff? These 3 skills beat certifications and experience
    • Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
    • BIP-110 Chain Falls Behind as Hashpower Support Lags
    • Inside the War on Hezbollah’s Finances
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Sunday, August 9
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Technology

    What do cybersecurity leaders want in staff? These 3 skills beat certifications and experience

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 9, 2026 Technology No Comments7 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    gorodenkoff/iStock/Getty Images Plus

    Follow ZDNET: Add us as a preferred source on Google.


    ZDNET’s key takeaways

    • AI brings new challenges for hard-working cyber staff.
    • Talented professionals will question almost everything.
    • Work with agents to make decisions that reduce risks.

    Working in cybersecurity is a tough gig. While security teams work hard to prevent damage to their organizations, ZDNET reported earlier this year that many cyber professionals aren’t receiving the recognition they deserve

    Emerging technology brings new challenges. AI-assisted vulnerability discovery is accelerating the pace of bug reports, with a growing mismatch between what machines can surface and what humans can realistically triage.

    Also: AI failed to patch software flaws 74% of the time, 1Password’s study warns

    In such a fast-changing and challenging working environment, it’s easy to understand why almost half of cybersecurity pros want to quit.

    However, staff should pause before sending their resignation letters: in an age of AI, where threats come from multiple angles, your business needs you now more than ever.

    As Fabrizio Pilotti, CIO at Aston Martin Aramco Formula One, said to ZDNET recently, digital leaders must think carefully about the balance between AI and human capabilities, and maintaining this equilibrium effectively creates new opportunities for security professionals.

    “In IT, lots of rules are changing. We’re thinking a lot about team structure, even job descriptions between the agentic part and non-agentic part,” he said.

    “I would say cyber, together with software development, is at the top of our priority list because of growing complexity and changing environments, where you have to react so fast.”

    Also: Assume AI cybersecurity attacks are the future: 43% of companies have already experienced it

    The good news, therefore, is that talented cyber staff could finally receive the recognition their skills fully deserve.

    But as agentic AI hoovers up elements of the traditional IT security role, how can cyber professionals prove their worth and build a successful career?

    The experts suggest successful candidates will focus on three key areas: curiosity-led critical thinking, instinctive qualities that sit above the automation line, and an ability to turn ambiguous signals into confident, risk-based decisions.

    Blend curiosity with critical thinking

    Eric Schmitt, global chief information security officer at risk and claims administration specialist Sedgwick, said many people mistakenly believe that a great cybersecurity professional is someone with certifications or years of experience.

    While those credentials can indicate someone’s likely capabilities, they are no guarantee of success, particularly in a world where AI and other emerging technologies transform the nature of attacks and the methods of response.

    Also: How Google used AI agents to find and fix 1,072 Chrome security bugs – in 60 days

    To this end, Schmitt told ZDNET that a great cybersecurity professional excels in one key area: curiosity.

    “I would rather hire someone a year into their career who constantly asks, ‘Why does this work this way?’ over someone 20 years in who doesn’t,” he said.

    Schmitt said that while experience teaches you what has worked in the past, curiosity teaches you what might break next and where the solution may be, a distinction that has never mattered more than it does in today’s rapidly changing threat landscape.

    “Credentials tell me where someone’s been, while questions like ‘Why does this agent call that service?’ or ‘Why do we follow this process?’ or trying to figure out which data a certain model is reading, who can modify it, and what an agent is allowed to do on its own, can tell me how they think a lot better.”

    Also: AI is both a cyber weapon and a massive target, CrowdStrike warns

    However, curiosity alone is not enough. Schmitt suggested curious cybersecurity professionals also need strong critical thinking skills.

    “Curiosity generates the most impactful questions, and critical thinking decides which answers hold up,” he said.

    “AI has made this type of thinking an urgent component, because these tools produce confident, plausible output at volume, but someone still has to ask whether it’s right and be able to tell.”

    Schmitt said curiosity without critical rigor leads to noise, and rigor without curiosity leads to stagnation, suggesting professionals with the right blend of capabilities will appeal to businesses that develop a proactive approach to cyber risks.

    “Together, these skills allow a security professional to keep pace with a threat landscape that no longer rewards static expertise,” he said. “Managers should hire for curiosity and cultivate critical thinking, because everything else can be taught.”

    Sit above the automation line

    This focus on critical thinking skills also appeals to Ankur Anand, CIO at recruiter Harvey Nash, who suggested industry research points to a significant problem — over-reliance on AI tools could leave enterprises exposed to attacks.

    He referred to SecRespond’s recently released benchmark that tested 23 leading AI models against real forensic data from compromised systems. Every model failed on the same category of attack: intrusions that never triggered an alert in the first place.

    “That’s the detail that should worry people more than any skills-gap statistic,” he told ZDNET, suggesting that most security tools, including those that use AI, work by investigating something that’s already flagged as unusual.

    “If nothing trips the alarm, an AI built to investigate alarms has nothing to chew on.”

    Also: How to keep your AI conversations as private as possible

    Anand said the best cybersecurity professionals possess the judgment to know when something’s awry.

    “They’ll have the instinct to get suspicious about a system that looks completely fine, and to ask why it’s quiet when everyone else is only watching for what’s loud.”

    So, how can IT security staff hone these instincts? Anand suggested the skills worth investing in sit above the automation line.

    He pointed first to threat-hunting capabilities: “Going looking for trouble with no alert telling you where to look.”

    Also: Open weights vs. closed: An AI civil war’s afoot, and the stakes are existential

    Second, AI oversight will be a crucial skill, plus the ability to describe potential risks to non-IT employees.

    “That’s about knowing when a model’s output is wrong and having the confidence to say so aloud in a meeting,” he said.

    “Plain communication matters more than it used to, because someone still has to turn ‘the model flagged this’ into a decision the business can actually act on.”

    Finally, Anand said good old-fashioned technological expertise will play an important role in helping cybersecurity professionals turn judgments into actions.

    “Basic Python is worth learning too, so you can query and interrogate the tools doing the triage instead of just accepting their verdicts,” he said.

    Focus on prioritizing risk

    The key takeaway for cybersecurity professionals, suggested Errol Weiss, chief security officer at member-driven organization Health-ISAC, is the need to shift their focus to adaptive thinking and operational judgment in the age of AI.

    “That transition requires clear thinking under pressure, curiosity, and the ability to turn ambiguous signals into a confident, risk-based decision,” he told ZDNET.

    Also: OpenAI’s attack agent did exactly what it was told – just more relentlessly than expected

    Weiss said adaptability is crucial because AI is accelerating both attack and defense cycles, meaning security teams are dealing with faster-moving threats, more noise, and often have less time to respond.

    “We need individuals who combine technical skills with an understanding of how systems operate in the real world, especially in sectors like healthcare, where patching or mitigation isn’t straightforward,” he said.

    “Communication is a core skill. Security professionals need to explain risk in a way that drives action across clinical, operational, and executive teams.”

    Weiss said the people who stand out will be those who can quickly interpret and prioritize risk.

    Also: AI is getting scary good at finding hidden software bugs – even in decades-old code

    When AI tools can do much of the heavy lifting, it is the human in the loop — in this case, the talented cybersecurity professional — who will help organizations manage risks.

    “AI tools can surface potential security issues, but they don’t understand business context, safety implications, or operational constraints,” he said.

    “That’s where human expertise remains critical. AI will continue to augment cybersecurity, but it won’t replace the need for experienced professionals who can make decisions during uncertainty. The most effective practitioners will be those who can work alongside AI, question its outputs, and translate insights into practical, timely action.”

    beat certifications cybersecurity experience leaders Skills staff
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    OpenAI’s new AI smart speaker will reportedly sell for between $300 and $400

    New Mexico court orders Meta to pay additional $567M in child safety case

    SpaceX’s Terafab will rely on natural gas power plants, not Tesla solar panels

    Xteink X4 Pro Pocket E-Reader Review (2026): Fun but Limited

    Airbnb says AI is helping it ship features faster as it tests a new search function

    I’m a diehard OnePlus user: Here’s my plan now that the company is leaving North America

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    BIP-110 Begins Mandatory Signaling on Bitcoin

    August 9, 2026

    Russian forces kill several in Ukraine, launch ‘brutal’ attack in Odesa | Russia-Ukraine war News

    August 9, 2026

    A Democratic Socialist Spreads the Word, Even in Hostile Territory

    August 9, 2026

    Britain is paying the price for failing to invest in its young people | Richard Partington

    August 9, 2026
    Latest Posts

    With Hopes High for New H.I.V. Prevention Pill, Merck Takes Steps to Ensure Access

    July 24, 2026

    Trump to speak at rescheduled White House Correspondents’ Dinner following failed April shooting

    July 24, 2026

    When is an apology not an apology? When it comes from an AI boss with an out-of-control chatbot | Marina Hyde

    July 24, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    BIP-110 Begins Mandatory Signaling on Bitcoin

    August 9, 2026

    Russian forces kill several in Ukraine, launch ‘brutal’ attack in Odesa | Russia-Ukraine war News

    August 9, 2026

    A Democratic Socialist Spreads the Word, Even in Hostile Territory

    August 9, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.