LOADING

Type to search

What the GovTech Case Study Says About Building an AI-Ready Workforce

Cybersecurity

What the GovTech Case Study Says About Building an AI-Ready Workforce

Share
GovTech AI Case Study: Building an AI-Ready Cybersecurity Workforce

The discussion around artificial intelligence and cybersecurity often focuses on models, tools, vulnerabilities, and the growing threat posed by AI-enabled attacks. The GovTech case study in IBM’s Cybersecurity 2028: Your workforce, built for the AI frontier takes the discussion in a more practical direction. It looks at what happens when an organization moves beyond AI experimentation and begins building the infrastructure, skills, and processes needed to use AI across a large public-sector environment.

Singapore’s Government Technology Agency, or GovTech, was faced with a challenge that will be familiar to many large organizations. Government agencies had growing interest in generative AI and machine learning, but developing separate AI capabilities for individual agencies would have created duplication, increased costs, and made it harder to establish consistent practices. GovTech responded by developing MAESTRO, a platform designed to make AI capabilities available across government organizations while giving teams a common environment in which to develop and deploy applications.

The case study is particularly relevant because it demonstrates that AI adoption at scale is not simply a question of selecting a foundation model. The organization has to consider infrastructure, cost, accessibility, workforce capability, and the governance required to operate AI across different business functions. These issues are closely connected to cybersecurity because every expansion in AI use creates questions around data access, identity, permissions, monitoring, and accountability.

Moving from AI experiments to an organizational capability

One of the strongest points in the GovTech example is the decision to approach AI as a shared capability rather than as a collection of independent projects. MAESTRO provided government agencies with access to a common platform and reduced some of the technical barriers that can prevent organizations from moving promising AI projects into production.

That distinction matters. Many organizations have successfully demonstrated what generative AI can do in a controlled pilot, but scaling those experiments across an enterprise is considerably more difficult. Different teams may select different models, use different data sources, create their own workflows, and develop separate approaches to security and governance. Over time, this can create an increasingly fragmented AI environment that is difficult for technology and security leaders to understand.

GovTech’s platform approach provided a way to address some of these challenges while making AI available to a wider group of users. According to the case study, MAESTRO was adopted by 20 public-sector organizations within nine months, involving more than 45 project teams and over 300 data scientists and machine learning engineers.

The significance of those figures isn’t simply the scale of adoption. It shows how a shared platform can help an organization move AI beyond a small specialist group and into multiple operational settings. That is an important consideration for organizations planning their own AI workforce strategy. If AI remains dependent on a handful of specialists, adoption will be constrained by the availability of those people. If the organization can provide appropriate tools and guardrails to a broader workforce, the number of potential use cases increases considerably.

Managing the economics of AI

The case study also addresses a problem that is sometimes overlooked in discussions about enterprise AI: cost.

Running sophisticated AI models at scale can require significant computing resources. Organizations that select the largest available model for every application may quickly find that the economics don’t work once usage increases.

GovTech approached this problem by matching models to workloads and using techniques such as model quantization. It also used services including Amazon Bedrock and SageMaker JumpStart to support model selection and deployment. According to the case study, this approach improved the cost performance of generative AI workloads by 75%.

For technology leaders, this is an important observation because it changes the way AI investments need to be evaluated. The question isn’t simply whether a model performs well in isolation. Organizations also need to consider the cost of running it, the volume of data being processed, the frequency of use, and the operational requirements associated with deployment.

That has a cybersecurity dimension as well. As AI becomes part of enterprise infrastructure, security teams will increasingly need to understand the architecture behind AI applications rather than treating them as standalone software. Knowing which models are being used, where they are hosted, what information they process, and which systems they can access will become part of understanding the organization’s overall attack surface.

Turning AI into measurable business outcomes

The GovTech case study is also useful because it provides concrete examples of what the organization achieved with its AI capabilities.

Singapore’s Ministry of Manpower used MAESTRO to develop an AI-powered sensemaking tool that processed more than one million documents over a three-month period. The system increased insight extraction by 60% and reduced sensemaking time by 50%, resulting in more than 2,000 hours of work saved.

The ministry also used the platform for job classification. The system processed 10 million job postings in three months and achieved 92% accuracy.

These examples demonstrate an important principle in enterprise AI adoption. The value of AI is not measured by the sophistication of the underlying model. It is measured by whether the technology improves a process or enables employees to handle work that would otherwise consume substantial amounts of time.

This distinction is particularly important for security leaders. AI is often introduced into cybersecurity with expectations of faster detection, automated investigation, and improved incident response. Those applications need to be evaluated in the same way. A security organization should be able to demonstrate what has improved, whether that is investigation time, analyst workload, detection quality, response speed, or another measurable outcome.

Extending AI into citizen-facing operations

Another example in the case study comes from Singapore’s Central Provident Fund Board, which handles approximately 600,000 citizen calls each year. AI was used to summarize call transcripts, allowing employees to process information from those conversations more efficiently.

This example illustrates another role AI can play in large organizations. It doesn’t necessarily have to replace the person performing the task. Instead, it can reduce the amount of time employees spend processing information and allow them to concentrate on decisions, follow-up, and interactions that require human judgment.

For cybersecurity professionals, this distinction is increasingly important. The same principle applies to security operations. AI can assist with alert triage, log analysis, threat intelligence processing, and incident investigation, but organizations still need experienced professionals to determine what the information means and what action should be taken.

As AI takes over more of the initial processing, human judgment becomes more important rather than less.

The workforce implications

The GovTech case study makes one point particularly clear: AI adoption at scale requires more than a small team of AI specialists. Once AI becomes part of everyday operations, more employees need to understand how to work with it, while specialist teams need to develop deeper expertise in areas such as model development, data, security, and governance.

This has direct implications for cybersecurity teams. Security professionals will need to understand how AI applications work, what data they access, how models are deployed, and where new risks can emerge. As organizations introduce AI agents and automated workflows, identity and access management will also become more complicated because software systems can have their own permissions and interact with business applications.

At the same time, the case study doesn’t suggest that every employee needs to become an AI engineer. GovTech’s approach shows the value of giving employees accessible tools while keeping specialist expertise available for more complex requirements. For security leaders, the challenge is to create a workforce that is comfortable using AI without assuming that technology can replace human judgment.

This is where cybersecurity training also needs to change. Employees need practical guidance on handling sensitive information, evaluating AI-generated outputs, recognizing potential risks, and using approved AI tools. Security professionals, meanwhile, need to build their understanding of AI security, data protection, identity, automation, and AI governance.

The workforce that organizations need by 2028, therefore, won’t be defined by AI skills alone. It will be a combination of technical expertise, security knowledge, business understanding, and the ability to make sound decisions when AI is involved. The GovTech case study shows what is possible when organizations make AI accessible to a broader workforce, but it also highlights why that accessibility needs to be supported by the right skills and controls.

What the GovTech case study means for Cybersecurity Professionals

  • Build cybersecurity skills for AI adoption: Security teams need to understand AI models, applications, agents, data flows, and the risks that come with deploying them across the organization.
  • Bring security into AI projects early: Security reviews should be part of AI development and deployment from the beginning, rather than being added after a system is already in production.
  • Strengthen identity and access controls for AI systems: As AI applications and agents gain access to business systems and sensitive data, security leaders need clear controls over who, or what, can access specific resources.
  • Improve visibility into enterprise AI use: Organizations need to know which AI models and applications are being used, what data they process, where that data goes, and how their activity is monitored.
  • Develop an AI-ready cybersecurity workforce: Security professionals need a combination of cybersecurity expertise, AI literacy, data security knowledge, automation skills, and strong judgment to work effectively in AI-enabled environments.
  • Balance AI accessibility with cybersecurity controls: GovTech shows that making AI available to a wider workforce can accelerate adoption, but security leaders must ensure that easier access doesn’t lead to uncontrolled data use, excessive permissions, or unmanaged AI applications.

What the GovTech Case Study Says About Building an AI-Ready Workforce

The GovTech case study is ultimately about scaling AI responsibly. It shows what can happen when an organization creates a common foundation instead of leaving individual teams to build disconnected AI capabilities.

For cybersecurity professionals, that distinction is becoming increasingly important. As AI moves into more business processes, the security team will have to understand not only how to defend against AI-enabled attacks but also how to secure the organization’s own use of AI.

That means understanding the systems behind the models, the identities that interact with them, the data they process, and the permissions they receive. It also means helping the wider workforce understand the risks associated with AI.

The GovTech example suggests that organizations don’t have to choose between making AI widely accessible and maintaining control over it. With the right architecture, skills, and governance, the two can develop together.

That is perhaps the most useful lesson from the case study for organizations preparing for the next stage of AI adoption. The competitive advantage will not come simply from having access to AI. It will come from having the people, infrastructure, and security practices needed to use it effectively and responsibly at scale.

Author

  • New Project 18

    Maya Pillai is a technology writer with over 20 years of experience. She specializes in cybersecurity, focusing on ransomware, endpoint protection, and online threats, making complex issues easy to understand for businesses and individuals.

    View all posts
Tags:
Maya Pillai

Maya Pillai is a technology writer with over 20 years of experience. She specializes in cybersecurity, focusing on ransomware, endpoint protection, and online threats, making complex issues easy to understand for businesses and individuals.

  • 1

You Might also Like