See travel advice due to Middle East conflict
Travel advice
Female cyber professional looking at screen

How do we train the next generation in cybersecurity?

Hidden risks of automation

Drawing on his personal experience, VMIA Chief Information Security Officer, Ian Pham, explores the challenges and risks of introducing AI into entry-level cybersecurity roles. He reflects on the importance of deliberate capability development, the hidden risks of automation, and practical steps leaders can take to ensure the next generation of cyber professionals are equipped with the skills and judgement needed to respond to real-world incidents.

A decade ago, early in my cyber career, I cut my teeth on security vulnerabilities, keeping the security lights on and managing access permissions for a large organisation. It was relentless entry level work – high volume, repetitive and unglamorous, but essential for keeping the business safe.

In my first week, with a single mis-click, I deleted every manager's access in the organisation.

One wrong selection, one bulk action, and suddenly, no manager anywhere in the business could action anything. A core system was down for more than 2 hours, grinding the entire organisation to a standstill. I found myself in major incident management, answering to senior leadership. I could easily have been sacked, but 2 things saved me.

The first was a manager who did not feed me to the wolves, who let me explain myself without it becoming a hearing, and carried the accountability upward where it belonged. The second was a team who spent the rest of the day recovering the system with me, then checked whether I was alright once everything was back on. Neither was luck. Both were deliberate choices people made.

Lessons learned

I learnt more in those 2 hours than in any course since. I also learnt the lesson I’ve carried furthest, that no one should have had the access to strip permissions across an organisation without a safeguard in place, particularly in their very first week at the organisation. The mistake was mine, but the absence of controls was not.

That was the sharpest lesson, but it was not the only one. Most of what I learnt over the following years were built slowly, through thousands of ordinary access requests, vulnerability reviews and small escalations, all without AI. If I had AI back then, I know I would have been faster and made fewer mistakes, but I would not have gained critical thinking.

AI efficiency case is strong but with future risk

Putting AI into basic support roles is not marketing, it’s logical. That choice now sits in front of every security function.

Security alerts arrive faster than anyone can triage them properly, so analysts skim and skimming is where things get missed. AI is well suited to such high-volume work. It can quickly gather background information, summarise complex histories, and automate routine responses, allowing analysts to focus on more important work. This means faster responses, fewer missed alerts, and consistency in handling at all hours, even in the early hours of the morning when cyber criminals are most active.

The risk sits downstream

Efficiency gains from AI in cyber support are immediate, but the real cost shows up years later when we need someone to handle a serious incident and realise no one has the necessary experience. Most security skills can’t be written down – they come from experience, instincts, and coaching.

If AI absorbs the volume of work, the job changes shape. Analysts may face their first major incident without the experience needed to recognise problems. Other fields, like aviation and medicine, have learnt this the hard way. Supervising automation leads to missed mistakes, not through carelessness but because people become used to agreeing with the operating model. This means escalations get weaker, the ability to challenge the model erodes, and the development pipeline into specialist and senior roles suffers, including my own role. None of this shows up on a security or risk dashboard. That’s why I’m worried.

The answer is deliberate design, not restraint

So, can an analyst who never did the repetitions ever lift on their own? Yes, but only if we put the weight back deliberately, because nothing in the operating model will do it for us. Here’s 5 things I would recommend for any security leader:

  • Make them answer first - The analyst records their own assessment before the AI's is revealed, then compares. Review the disagreements weekly. That’s your coaching agenda, and it takes only ten minutes.
  • Roster the unassisted work - One shift a fortnight, or a fixed share of routine alerts, worked without AI. Put it in the roster rather than the training plan, or it won’t happen.
  • Make the tool explain itself - Require the case note to answer why this is unusual here, not just what to do next. Used that way, a tool built for speed also teaches.
  • Test your worst-case scenarios - Look at what your newest person can do and work out together what happens if they get it wrong at the worst moment. If the answer looks anything like my first week, you’ve found a control gap, and closing it is what makes learning survivable.
  • Report capability as a risk - Alongside alerts closed, track how many escalations senior staff judge to be well framed and take that to the board with your other people risks. What’s not measured is quietly lost.

Definitely consider automating the triage. Just make sure the next analyst still gets to make their own mistakes in an environment we’ve designed for them to survive it, with a manager who stands in the room when it happens.

P.S. AI helped me write an early version of this and it read as inauthentic, so I scrapped it and put it back to being an editor rather than the author. There’s a lesson in that too."

Updated