Why I studied AI Fundamentals after Sec+
By Brian Randall
Billy Joel was right. We didn’t start the fire. But for better or worse, those of us in Cybersecurity have to deal with it.
Our fires started from insider threats in the 70’s, which gave us intro-to-GRC. Then we get landmark events like the Morris Worm in '88, which helped create our baseline for endpoint security.
Skip forward to more modern examples and we get fires like STUXNET (2010), proving that code is a real, physical, tangible threat. Then Wannacry (2017) proved that security should never be an afterthought.
So as I studied my basics, I would constantly ask, “Why are salaries so high for a profession that supposedly takes 6-12 months of hard work to break into?” Then I’d notice another fire in the periphery. 6-12 is the number of months it takes to break in if you work strategically and/or move from an adjacent field. But it doesn’t stop at 6-12 months. You do your time, get your education, then every day of the job from then on is another day of education.
Every “fire” I’ve mentioned is really an added domain that security professionals must understand and practice working with. Just like an outdated system, a security practitioner who’s outdated is a liability. So yes, I’m studying physical/network/cloud security in detail as I write this, but as soon as I got the top-down on cyber, I started studying AI foundations.
I’m sure you’ve heard plenty about AI, so I’ll make it brief. This is my quick proof on why AI is so darn important for you.
In the same year as Wannacry, we get a paper from Google Brain, “Attention is All You Need,” followed by the emergence of transformers used in generative AI training, and finally, 2023’s GenAI explosion. And if you’ve been alive the past few years, you’ve witnessed the professional uncertainty that ensued– but Wannacry proved that security is prevalent, so why would we worry for our jobs in security? This is a tale as old as time:
New tech comes along →
The industry changes →
People are displaced →
The people learn new skills and adapt (although it is quite painful).
If I’m a shoemaker during the second industrial revolution that gets replaced by an assembly line, will my experience help me? Most definitely.
The person who understands the shoe is going to work smarter on the line. Better yet, that person could manage, supervise, or build the line themselves. So yes, we need to understand our domain, information security, but even the nature of information is changing.
There’s a quote by Microsoft CEO Satya Nadella I really like in his blog post from July 12, 2026: “In the cloud era, enterprises accumulated data. In the AI era, they accumulate learning. The trust boundary must evolve accordingly, from protecting information to protecting the mechanisms through which organizations learn, adapt, and compound intelligence.” Now, he’s talking about enterprise trust and business acumen– but where do security operations occur?
Inside.
Everything.
So if I’m a cloud security architect amidst the “Fourth Industrial Revolution”, my cloud know-how is a great baseline– but if I don’t know how to factor in AI, I become a liability. As Satya said, AI is about learning, this is a revolution in how property and data are classified, which is literally what we protect.
Security+ is like the shoemaker from earlier learning their craft. That used to be most of the battle. Sure, ML was integrated into SIEM/SOAR, AV, webmail security, but it couldn’t actively investigate alerts. So you could have a Sec+, understand phishing investigations, learn a bit of the hands-on, and do alright. How about now?
AI can conduct behavioral analysis of code and humans. Perhaps not at the same level as an experienced analyst, but quite a bit faster, and it can run playbooks autonomously. This means point and click analysts might not do so hot in the future.
Currently, Sec+ won’t land you a gig. You need to prove your worth, something like a practical certificate or lab projects. Soon, AI literacy is likely going to be on that docket as well.
Already, certificates like CySA+ (v4) include heavy AI considerations, and some of the top paying gigs in Cybersecurity are– you guessed it– AI-based. Almost exclusively reserved for folks with extensive AI and security backgrounds (look up AI Red Team Lead).
But that’s what we’re here for, right? At the cost of learning continuously, we get to be part of a profession that deals with major current issues from the inside– Billy Joel was right, but it just so happens that some of us don’t mind the fire, in fact, we’d like to be at the forefront. And how could I mitigate today’s fire without understanding yesterday’s? That’s why I started learning AI Fundamentals directly after Sec+.