Brands
Latest top stories

Hack The Box report signals how AI is reshaping cybersecurity skills — and widening the readiness gap

20 May 2026

 

Artificial intelligence is beginning to reshape the cybersecurity workforce in ways that extend far beyond automation tools and chatbots. A new report published on May 19 by Hack The Box suggests the industry is entering a broader structural transition in which AI-related cybersecurity skills, operational readiness and cross-functional expertise are becoming increasingly central to cyber defence strategies.

Originally known for its gamified hacking labs and global cybersecurity community, Hack The Box has increasingly repositioned itself around what it calls “AI cybersecurity readiness” — training both human teams and AI systems to operate in adversarial cyber environments. The company says its platform is used by large enterprises, government agencies and managed security providers to simulate real-world attack-and-defence scenarios.

The company’s Cybersecurity Workforce Intelligence Report analysed anonymised training and platform data from more than 702,000 cybersecurity professionals across 251 countries and territories. The findings point to rapidly growing demand for AI security capabilities, particularly around prompt injection, machine learning model exploitation and attacks targeting so-called agentic AI systems.

The report arrives at a time when organisations across industries are deploying generative AI tools faster than many security teams can fully assess the associated risks. Governments, regulators and cybersecurity agencies have increasingly warned that AI systems introduce new attack surfaces while simultaneously lowering barriers for cybercriminals to automate phishing, malware development and social engineering.

Against that backdrop, the Hack The Box data suggests cybersecurity workforce development is becoming as strategically important as cybersecurity technology itself.

“AI is creating a divide between teams that can operationalise it and those that can’t, and that divide directly translates into risk,” said Haris Pylarinos, Founder and CEO of Hack The Box.

“For CISOs, the challenge is ensuring their teams can operate effectively with AI, and without it when needed.”

 

AI cybersecurity skills move from experimental to operational

 

One of the clearest signals in the report is how rapidly AI-focused cybersecurity training has shifted from a niche specialism into an operational priority.

Hack The Box said prompt injection accounted for 29 percent of AI-related challenges solved on its platform during the analysed period, followed by machine learning model exploitation at 24 percent and agentic AI hijacking at 12 percent.

Prompt injection refers to techniques that manipulate the instructions given to AI systems in order to bypass safeguards or extract unintended information. Security researchers and companies including OpenAI, Anthropic and Google DeepMind have all identified prompt manipulation as one of the emerging security concerns surrounding large language models.

Machine learning model exploitation involves attempts to manipulate, poison or reverse-engineer AI systems. Agentic AI attacks refer to risks associated with autonomous AI systems capable of taking multi-step actions with limited human supervision.

The growing focus on these areas reflects how cybersecurity teams are increasingly being asked to secure not only traditional IT systems, but also AI-enabled applications and workflows embedded inside enterprise operations.

Hack The Box’s growing focus on AI security mirrors wider changes taking place across the cybersecurity industry itself. Over the past year, the company has expanded beyond traditional penetration-testing labs into AI-focused cyber ranges designed to benchmark both human teams and autonomous AI agents under simulated attack conditions.

The company has also launched AI Red Teamer certification programmes and increasingly positioned itself around validating how humans and AI systems operate together under operational pressure. Rather than focusing solely on theoretical coursework, Hack The Box’s platform centres on live-fire simulations and adversarial testing environments intended to replicate real-world attack scenarios.

Developments at Hack The Box underscore how the cybersecurity industry itself is adapting to broader changes in enterprise software infrastructure. AI systems are no longer confined to research environments or experimental pilots. Increasingly, they are being integrated into customer service platforms, productivity software, software development pipelines and internal business operations.

That creates new security responsibilities for organisations already struggling with long-standing cybersecurity workforce shortages.

According to the latest estimates from ISC2, the global cybersecurity workforce gap still measures in the millions despite years of hiring growth.

 

Traditional cybersecurity roles begin to blur

 

The Hack The Box report also points to traditional distinctions between offensive and defensive cybersecurity roles becoming less rigid.

Historically, cybersecurity teams often operated in separate domains. Offensive security specialists focused on penetration testing and identifying vulnerabilities, while defensive teams concentrated on monitoring systems, detecting attacks and responding to incidents.

Increasingly, however, organisations are moving towards so-called “purple team” models that combine offensive and defensive capabilities more closely.

Hack The Box said growing overlap between offensive and defensive training patterns suggests organisations increasingly value practitioners who understand both attack techniques and defensive response strategies.

That mirrors wider industry developments.

Cybersecurity companies and governments have increasingly emphasised adversarial testing of AI systems, partly because AI tools can produce unpredictable behaviours that traditional software testing methods may not fully capture.

The report suggests adaptability is becoming one of the defining characteristics of effective cybersecurity teams.

Rather than relying purely on narrowly specialised expertise, organisations increasingly appear to be prioritising professionals capable of operating across multiple domains and rapidly evolving technologies.

Modern enterprise environments often combine cloud infrastructure, legacy systems, remote work environments, software supply chains and AI-enabled applications simultaneously. As infrastructure becomes more interconnected, separating offensive and defensive disciplines becomes operationally harder.

 

Why hands-on cybersecurity training is becoming more important

 

One of the more notable findings in the report concerns the role of structured, organisation-led cybersecurity training.

Hack The Box said AI-focused training programmes achieved completion rates of 64 percent, suggesting relatively strong engagement compared with many traditional corporate learning initiatives.

The company argues that hands-on, scenario-based training is becoming increasingly important as cybersecurity environments grow more dynamic.

That reflects broader concerns within the industry that traditional compliance-based cybersecurity training often fails to prepare teams for real-world operational environments.

Cybersecurity agencies including the European Union Agency for Cybersecurity (ENISA) and the US Cybersecurity and Infrastructure Security Agency (CISA) have repeatedly stressed the importance of continuous exercises, simulations and practical testing.

The rise of AI may further accelerate that shift.

Unlike conventional software systems, generative AI systems can behave unpredictably depending on how users interact with them. That makes static security policies harder to enforce and increases the importance of practical experimentation and adversarial testing.

The findings suggest operational resilience may increasingly depend on whether teams understand how AI systems can fail, be manipulated or behave unexpectedly.

 

AI cybersecurity changes the economics of defence

 

Part of the tension surrounding AI in cybersecurity is that the technology simultaneously creates opportunities and risks.

AI systems can help automate threat detection, analyse large volumes of security data and accelerate certain defensive tasks. At the same time, attackers are increasingly experimenting with AI-assisted phishing campaigns, automated vulnerability discovery and synthetic social engineering.

The broader cybersecurity industry is currently experiencing a rapid influx of AI experimentation, much of it driven by concerns that AI systems may lower barriers for attackers while simultaneously increasing pressure on already overstretched security teams.

Earlier this month, researchers warned that AI-assisted offensive techniques are beginning to accelerate vulnerability discovery and exploitation workflows, potentially shifting the economic balance between attackers and defenders.

At the same time, security leaders continue to warn that overreliance on AI-generated outputs may introduce new operational risks if organisations fail to maintain sufficient human oversight and validation processes.

Hack The Box itself appears aware of that tension. Much of the company’s recent positioning focuses less on replacing security professionals and more on testing how humans and AI systems perform together in realistic operational environments.

That may explain why the report repeatedly emphasises adaptability and operational readiness rather than automation alone.

“The findings suggest that effective teams will increasingly be defined by adaptability, judgment and cross-functional expertise,” the report states.

For years, much of the cybersecurity industry focused heavily on software tooling, endpoint protection and automated detection platforms. Increasingly, however, organisations are recognising that security outcomes also depend heavily on workforce capability, operational processes and institutional resilience.

The rise of AI appears to be accelerating that transition.

 

Why CISOs may need to rethink workforce strategy

 

For chief information security officers — commonly known as CISOs — the report ultimately presents a workforce challenge as much as a technology challenge.

Hack The Box argues that organisations need to prioritise AI-related security skills, invest in integrated offensive-and-defensive training models, expand access to global talent pipelines and commit to continuous hands-on upskilling.

Those recommendations align with wider industry concerns that traditional cybersecurity workforce models may struggle to keep pace with the operational realities introduced by AI-enabled infrastructure.

The report also suggests cybersecurity workforce readiness is becoming economically strategic in its own right.

If AI lowers the cost and speed of offensive cyber activity faster than organisations can train defensive teams, operational capability may increasingly become one of the defining competitive advantages in cybersecurity resilience.

That positioning also helps distinguish Hack The Box from more traditional cybersecurity awareness and certification providers. Rather than focusing primarily on compliance training or theoretical certification tracks, the company has built much of its reputation around hands-on cyber ranges, gamified labs and adversarial simulations designed to mirror operational conditions as closely as possible.

At the same time, the report stops short of portraying AI as a complete transformation of cybersecurity itself.

Many of the underlying pressures highlighted in the findings — workforce shortages, fragmented skill development, operational complexity and evolving attack surfaces — existed long before generative AI systems entered the mainstream.

What appears to be changing is the speed at which those pressures are intensifying.

The report ultimately suggests that the cybersecurity industry’s next bottleneck may not be tooling, but operational capability.

As organisations integrate AI into software development, infrastructure and business operations, the ability of security teams to understand, test and challenge those systems may increasingly determine whether AI becomes a resilience advantage — or an additional source of systemic risk.

 

Further reading on MoveTheNeedle.news:

Yubico targets the next phase of AI security through OpenAI partnership

Language Is the New Attack Surface: Why AI Security Needs a Fundamental Rethink

DuckDuckGoose CEO warns AI-generated identities are already testing digital banking security