The Cyber Professionals Who Ignore AI Will Slowly Become Irrelevant 

(AKA) Why Cybersecurity Is Quietly Becoming an AI Profession 

(AKA) Nobody Told Me AI Had Become Part of My Job

That headline sounds harsher than I normally like to write. 

It's also why I've left it as a working title for now. 

This article itself isn't really about people becoming irrelevant. 

It's about how our quirky cyber security profession changes, usually without asking  anyone's permission. 

I still remember when cloud security wasn't really a specialty. 

Or at least it didn't feel like one. 

Nobody announced that cybersecurity professionals would now need to understand cloud  computing. 

Nobody sent an email saying, 

"Congratulations. Cloud security officially starts on Monday." 

The work simply arrived. 

Customers started asking different questions. 

New risks appeared. 

New skills quietly became expected. 

Looking back, the same thing happened with virtualization. 

Identity. 

Ransomware. 

None of those felt like dramatic turning points at the time. 

The job title stayed the same. 

The job itself slowly changed underneath it.

I've started wondering whether AI is following exactly the same path. About two years ago AI wasn't really part of my day. 

Then one customer asked whether ChatGPT should be allowed inside their organization. Another wanted an AI policy. 

Someone else asked about AI risk. 

Then came AI governance. 

Vendor reviews. 

Model inventories. 

Risk assessments. 

Awareness training. 

At some point I stopped thinking, 

"That's an interesting AI question." 

And started thinking, 

"This has quietly become part of my job." 

Oddly enough, I don't remember making a conscious decision to move into AI governance. I simply kept following the questions customers were asking. 

That feels familiar. 

Cloud wasn't adopted because cybersecurity professionals suddenly became fascinated  by virtualization. 

It happened because organizations moved to the cloud. 

Cybersecurity followed. 

I'm beginning to wonder whether AI is doing the same thing. 

Not because cybersecurity has suddenly become an AI profession. 

Because organizations are becoming AI organizations. 

Cybersecurity simply follows where organizations choose to go. 

That's a subtle difference, but I think it matters.

When people ask whether AI will replace cybersecurity professionals, I'm never quite sure  how to answer. 

I don't know. 

What I do know is that the conversations I'm having today are very different from the  conversations I was having only a few years ago. 

Customers aren't just asking about firewalls and vulnerability management anymore. They're asking about AI governance. 

Responsible use. 

Model risk. 

Data provenance. 

Human oversight. 

Those weren't normal cybersecurity conversations five years ago. 

Today they're becoming surprisingly common. 

Looking back over my own career, that's usually how change happens. Not with a dramatic announcement. 

Not with a new job title. 

Just with a different question from the next customer. 

Then another. 

Then another. 

One day you look back and realize your profession has quietly expanded again. I'm not convinced cybersecurity is becoming an AI profession. 

I am beginning to think that tomorrow's cybersecurity professionals will increasingly be  expected to understand AI in much the same way they're already expected to understand  cloud, identity, and risk. 

Looking at the conversations I've been having over the past two years... I suspect that transition is already underway.

Hayden Pritchard
Hayden Pritchard

I've spent much of my career helping organizations make difficult decisions about cybersecurity, governance, and risk.

That work has taken me through hospitals, regulated industries, boardrooms, investigations, and more standards documents than I'd care to admit. Along the way I've become increasingly interested in something that doesn't appear in most governance frameworks: how people actually think.

Here, I write essays rather than reports. I explore the ideas that stay with me long after the meeting ends: why frameworks often ask the same questions in different languages, why some human limitations may actually be strengths, and how emerging technologies quietly change the assumptions that regulation depends upon.

Professionally, my work focuses on AI governance, cyber risk, healthcare, and safety-critical systems.

Personally, I'm just trying to understand them a little better than I did yesterday.

https://www.solvingcyber.com
Previous
Previous

AI-enabled glasses. The Laws Haven't Changed. The Assumptions Have

Next
Next

Why I studied AI Fundamentals after Sec+