Cybersecurity Talent Report on AI Empowerment Released as Models Enter Core Business
At the First China Cyberspace Security Conference on Sept. 18, a report on cybersecurity talent in the AI era found that dedicated AI security teams and practical training lag behind adoption, with gaps across model security, AI application security and AI-enabled security.
The report places its findings against the rapid expansion of AI capabilities. It cites METR, an AI evaluation organization, as showing that the complex tasks frontier AI models can complete are lengthening quickly: measured by the time a human expert needs for a task, the task duration models can handle at a 50 percent success rate has been doubling about every seven months. As AI works independently for longer periods and gains access to more data and system permissions, ensuring that it cannot be manipulated by malicious instructions or break permission boundaries has become a question that must be answered, the report says.
It divides the practical tasks facing cybersecurity talent in the AI era into three categories. Model security focuses on protecting models, underlying data and algorithms. AI application security focuses on new risks after models and agents enter business systems. AI-enabled cybersecurity focuses on using AI to improve vulnerability discovery, security operations, attack-defense confrontation and threat detection. The categories mean cybersecurity workers face a dual task: identifying and handling new risks brought by AI while using AI to improve security work.
The report describes a talent pool that is young, geographically and sectorally concentrated, and short of dedicated security forces. In model security, 65 percent of practitioners have fewer than five years of work experience. Guangdong, Beijing, Zhejiang, Shanghai and Jiangsu account for 46 percent of AI application security talent. In critical information infrastructure organizations, 75 percent of relevant talent is concentrated in the power, finance and communications sectors.
Dedicated teams have not kept pace with AI deployment. According to the report, 64 percent of organizations working with large models still rely on traditional security teams or R&D teams for model security, and only 23 percent have set up dedicated AI security research teams. Among organizations deploying AI applications, 81 percent have not established dedicated AI security teams.
The skills gap extends beyond model knowledge. In AI application security, the share of personnel not yet proficient in prompt security, content compliance, interface security and business logic security was 54 percent, 64 percent, 60 percent and 65 percent, respectively. The report says AI security talent needs to understand not only model mechanisms but also data security, interface security, permission control and business risk analysis. People who combine algorithm knowledge, attack-defense skills and business understanding are becoming important to AI application security.
AI is also changing traditional cybersecurity work. Large models and agents are being introduced in vulnerability discovery, security operations, threat analysis and response handling to improve information processing and task execution. But the report says AI efficiency does not replace professional judgment. Practitioners with more than 10 years of experience reported a 58.3 percent satisfaction rate with AI-assisted vulnerability discovery efficiency, the lowest among groups by years of experience. The result reflects that in complex, specialized and demanding security tasks, senior personnel pay more attention to whether AI output is accurate, stable and verifiable. AI can assist analysis and task execution, but judgments about vulnerability causes, attack paths, business impact and remediation plans still need security personnel, according to the report.
Universities are moving AI into cybersecurity training. The report says 68 percent of universities have made AI-related courses independent required or elective courses. Moving from course offerings to practical capability still faces constraints in computing power, faculty, cases and training environments. Only 10 percent of surveyed teachers believed their university had established a relatively complete AI security practical training system; 26 percent of universities had sufficient computing conditions to support model training and adversarial attack experiments; and about 21 percent of teachers had experience in both cybersecurity attack-defense and AI algorithms. Among the most scarce teaching resources, 80 percent of demand is concentrated in hands-on cases, real attack cases and experimental guidance.
The report also addresses evaluation. It says AI security scenarios are expanding and traditional evaluation based on degrees, certificates, seniority and knowledge mastery cannot fully judge whether a security worker can find and handle risks in complex environments. Based on the ASK-P practical capability evaluation system, the report explores classified and layered evaluation methods for model security, AI application security and AI-enabled cybersecurity. Compared with traditional methods, the approach focuses more on whether personnel can use knowledge and skills in real or simulated environments to complete security tasks, handle actual risks and produce verifiable practical results. It is intended to help universities set training goals, companies identify competency and practitioners plan growth paths.
The report recommends that future cybersecurity talent development be closer to real business and practical needs, defining ability by actual tasks, organizing training around real scenarios and evaluating talent by task completion, with universities, research institutes, cybersecurity companies and key industries participating together in training, evaluation and use. Yongxin Zhicheng, one of the report’s lead editors, said it will continue to work with universities, research institutes and industry partners on practical capability research around real business, real risks and real attack-defense scenarios.