The Cybersecurity Skills Organizations Will Need by 2028
Share
The cybersecurity skills organizations will need by 2028 are already evolving as artificial intelligence becomes part of everyday business and security operations. The shift isn’t simply about teaching security professionals how to use AI tools. It requires organizations to rethink what their security teams need to know, how they work, and where human judgment fits as more tasks become automated.
This is one of the central issues explored in the IBM Institute for Business Value report, Cybersecurity 2028: Your workforce, built for the AI frontier. The research, conducted with Oxford Economics, surveyed 1,013 C-level executives across 17 countries and seven industry sectors. The respondents included CISOs, CIOs, CTOs, and business leaders.
The research identifies talent, skills, and cybersecurity as three of the leading challenges organizations expect to face over the next three years. For security leaders, that creates a workforce problem that goes beyond recruitment. Teams need to develop the capabilities required to work with AI while continuing to manage an increasingly complex threat environment.
Key points from the IBM research
- AI literacy will become a core cybersecurity skill: Security professionals will need to understand what AI can do, where it can fail, and how it should be used responsibly.
- Business and regulatory knowledge will matter more: Cybersecurity professionals will increasingly need to understand business priorities, regulations, and the changing threat environment.
- AI agents will change security operations: IBM found that 64% of executives expect every employee in their IT/IS organization to use AI agents within two years.
- Human expertise will shift toward judgment and supervision: AI will handle more routine work, while professionals will focus on complex decisions and oversight.
- Security awareness needs to extend beyond the security team: Employees and business teams will need a better understanding of AI-related security risks.
- The talent shortage remains a major challenge: Recruiting specialized AI security professionals takes an average of 99 days, while 21% of security team members leave annually.
AI literacy will become part of the security skill set
AI is becoming part of technology environments across organizations. For cybersecurity teams, that means understanding AI can no longer be treated as a specialist skill that belongs only to data scientists or AI engineers.

The IBM research found a significant difference between executive and frontline employee AI readiness. 82% of executives demonstrate fluency in AI capabilities, limitations, and responsible use practices, compared with 53% of frontline employees.
The difference also appears in professional development. While 52% of organizations have integrated AI skills into executive development programs, only 38% have done the same for the broader workforce.
For cybersecurity professionals, AI literacy needs to go beyond knowing how to use a generative AI application. Security teams need to understand how AI systems produce results, where those results can be unreliable, and what risks can arise when AI is connected to business systems and sensitive data.
A security analyst who understands both the underlying threat and the technology producing an AI-generated recommendation is better positioned to decide whether that recommendation should be acted upon.
Cybersecurity professionals will need business and regulatory skills
Technical security knowledge will remain essential. But organizations also need professionals who understand the business and regulatory environment in which security decisions are made.
The IBM research identifies three areas that executives find particularly difficult to source:
- navigating regulations,
- understanding the business, and
- dealing with the changing threat landscape.
Each was cited by 54% of respondents. This combination is becoming more important because AI isn’t being adopted only within IT or security departments. It’s moving into business processes, software development, customer service, and decision-making.
Security professionals therefore need to understand how AI is being used across the organization. They also need to explain security risks in terms that business leaders can act on.
A security professional who can identify a vulnerability is valuable. Someone who can explain the vulnerability, its potential business impact, and the regulatory implications is even more useful to an organization making technology decisions.
The cybersecurity talent shortage is meeting the AI skills gap
Organizations were already struggling to recruit cybersecurity professionals before AI became a major part of the technology agenda. The growth of AI adds another demand for specialized skills.
According to the executives surveyed by IBM, recruiting a specialized AI security professional takes an average of 99 days. At the same time, 21% of security team members leave each year.
That creates a difficult situation for security leaders. Hiring can take months, while existing teams are expected to adopt new technologies, manage new risks, and maintain day-to-day security operations.
This makes reskilling an important part of cybersecurity workforce planning. Organizations don’t necessarily need to build entirely new teams to acquire every AI-related capability. Existing security professionals can develop AI skills as part of their career development. Security analysts, engineers, and architects can expand their roles as AI becomes part of their working environment.
The IBM research also shows that organizations are increasing their investment in talent because of AI, with more of their talent budgets expected to go toward AI reskilling.
Human judgment will remain central to cybersecurity
AI can automate a growing number of security tasks, but cybersecurity isn’t simply a collection of repetitive processes. IBM estimates that 67% of cybersecurity workloads currently rely on human expertise. The report expects that reliance to fall by 34% over the next three years as AI and automation take on more work.
That doesn’t mean human expertise becomes less important. It means the nature of that expertise changes. Security professionals may spend less time working through routine alerts and more time investigating unusual incidents, reviewing AI-generated findings, assessing unfamiliar threats, and deciding how automated systems should respond.
This creates demand for professionals who can supervise AI-enabled security operations. They need to understand enough about the technology to recognize errors and enough about cybersecurity to determine when an automated response is appropriate.
Human judgment becomes particularly important when the situation doesn’t match known patterns. AI can process large amounts of information quickly, but security professionals still need to make decisions when the available information is incomplete or ambiguous.
AI agents will change what security teams manage.
AI agents are another reason cybersecurity roles are likely to change. The IBM research found that 76% of executives believe AI agents will significantly improve the way their organizations operate, while 72% believe they will unlock innovation. Another 67% expect agents to improve the return on existing AI investments.
More importantly for security teams, 64% expect every employee in their IT/IS organization to use AI agents within two years. AI agents introduce different security considerations because they can take actions rather than simply provide information.
Security teams will need to understand what an agent can access, which systems it can interact with, what permissions it has, and how its actions are monitored. This puts machine identities, access controls, and activity monitoring higher on the security agenda. The question is no longer only whether an AI system produces an accurate answer. Security teams also need to consider what happens when that system is permitted to act on the answer.
As organizations increase their use of AI agents, professionals with AI agent security skills will become increasingly important.
Security awareness can’t remain inside the security team
AI security isn’t something that can be managed entirely by the cybersecurity department. IBM identifies security awareness, behaviors, and culture, or the security ABCs, as an important foundation for organizations moving toward an AI-centric operating model.
The research shows significant gaps in how organizations address AI-related risks. Only 46% report wide-scale or comprehensive capability in addressing specific AI risks such as prompt manipulation and manipulated content.
The figures are lower for other areas. Only 40% report comparable capability around AI-related privacy and intellectual property risks, while 37% report it for ethical issues such as fairness and bias. Only 33% report wide-scale or comprehensive capability around AI regulations and guidelines. These gaps require a broader approach to security awareness.
Employees need to understand how using AI can expose sensitive information. Developers need to understand secure AI development practices. Business leaders need to understand the risks associated with AI-enabled decision-making. Cybersecurity teams will have an important role in helping these groups understand and manage those risks.
Cybersecurity operations will become more autonomous.
AI is also changing the way security operations themselves are structured. The IBM research identifies IT/IS observability and resilience, AIOps, and autonomous cybersecurity as areas where AI can significantly change operations.
These capabilities can move security teams beyond traditional monitoring and scripted automation. AI can analyze large volumes of logs, metrics, and traces, identify anomalies, and help predict problems.
More advanced autonomous cybersecurity systems can identify vulnerabilities, analyze threats, and take action with limited human intervention. IBM describes the more mature stage of this development as security operations that become increasingly self-correcting, self-healing, and self-directing.
That creates a different type of responsibility for security professionals. Instead of manually responding to every alert, they may spend more time supervising automated systems, investigating exceptions and improving the processes that support those systems. The ability to work effectively with autonomous cybersecurity tools will therefore become an important part of the future security skill set.
New roles may combine security, AI and business expertise
The changing nature of security work may also lead to new combinations of existing skills. IBM recommends developing business-minded security specialists and refers to emerging roles such as cyber curators and AI forensics strategists.
The job titles themselves may not become standard across the industry. What matters is the combination of capabilities behind them. A professional working in this area may need to understand cybersecurity, AI systems, business requirements, and the context in which automated decisions are made.
They may also need to evaluate AI-generated evidence, investigate AI-related incidents, and help determine how AI systems should be governed. For organizations facing a cybersecurity skills shortage, developing these capabilities within existing teams may be more practical than creating a new job title for every emerging technology.
The workforce needs to move with the technology.
IBM places organizations into three broad categories based on their progress toward an AI-centric operating model: crawl, walk, and run.
About 18% of organizations are in the crawl stage, where AI transformation remains limited. 52% are in the walk stage, while 30% are in the run stage, with stronger AI-first foundations and more autonomous cybersecurity capabilities.
These categories aren’t a fixed sequence that every organization must follow. They provide a snapshot of how far organizations have progressed in their AI transformation. For security leaders, the important point is that workforce development needs to match the organization’s level of AI adoption.
A team in the early stages may need basic AI awareness and stronger security training. A team moving toward autonomous operations may need professionals who can manage AI agents, oversee automated decisions, and investigate complex AI-related incidents. The skills strategy needs to develop alongside the technology strategy.
What cybersecurity leaders should prioritize
Preparing for 2028 doesn’t require organizations to predict exactly what every cybersecurity job will look like. The pace of AI development makes that difficult. A better approach is to identify the capabilities that will remain important as AI takes on more operational work. These include AI literacy, threat analysis, business understanding, regulatory knowledge, AI governance, agent security, and human oversight.
Organizations also need professionals who can communicate across security, technology, and business functions. Training shouldn’t be limited to senior executives. The IBM research shows that organizations have made more progress in developing AI skills at the leadership level than among frontline employees.
Closing that gap will be important if AI is to become part of everyday security operations rather than remain concentrated among a small group of specialists. The same applies to security awareness. Employees who use AI need to understand its risks, while security professionals need to understand how those systems work and how they can be protected.
Conclusion
The cybersecurity skills organizations will need by 2028 won’t be defined by AI expertise alone. The stronger requirement will be the ability to combine cybersecurity knowledge with AI literacy, business understanding, regulatory awareness, and sound judgment.
IBM’s research shows why this shift matters. Organizations are increasing investment in AI skills while security teams continue to face talent shortages and growing demands. At the same time, AI agents and autonomous cybersecurity capabilities are becoming part of the conversation around future security operations.
For CISOs and other security leaders, workforce planning needs to start with the work itself. Some tasks will increasingly be handled by AI. Others will continue to depend on human expertise, particularly where investigation, context, and judgment are involved.
The organizations that prepare well for 2028 won’t necessarily be the ones that hire the largest number of AI specialists. They’ll be the ones that understand how cybersecurity work is changing and build the skills needed to work effectively with increasingly capable AI systems.
The future cybersecurity professional isn’t simply someone who knows how to use AI. It’s someone who knows when to use it, how to assess its output, how to secure it, and when human judgment needs to take over.
FAQs
1. What cybersecurity skills will organizations need by 2028?
Organizations will need professionals with a combination of cybersecurity expertise, AI literacy, business understanding, regulatory knowledge, and the ability to supervise AI-enabled security operations. Skills related to AI agents, AI governance, and human oversight are also likely to become more important.
2. Will AI replace cybersecurity professionals by 2028?
AI is expected to automate more cybersecurity workloads, but that doesn’t mean cybersecurity professionals will disappear. Human expertise will continue to be important for complex incidents, investigations, decision-making, and oversight of automated systems.
3. Why is AI literacy important for cybersecurity professionals?
AI literacy helps security professionals understand what AI systems can and can’t do. It allows them to assess AI-generated findings, recognize potential errors, and understand the risks associated with AI systems.
4. What skills will cybersecurity teams need to secure AI agents?
Security teams will need to understand agent permissions, machine identities, access controls, data exposure, monitoring, and automated actions. They will also need to assess what an AI agent is allowed to do and how those actions can affect the organization’s systems.
5. How can organizations prepare their cybersecurity workforce for AI?
Organizations can assess which security tasks are likely to be automated, identify current skills gaps, and incorporate AI capabilities into professional development. Training should cover both AI use and AI security, and it should reach employees beyond the executive level.
Sources
Primary source:
IBM Institute for Business Value, Cybersecurity 2028: Your workforce, built for the AI frontier, in collaboration with Oxford Economics.
Research basis:
The report is based on a Q1 and Q2 2025 survey of 1,013 C-level executives across security, technology, operations, and business functions in 17 countries and seven industry sectors. Respondents included 250 CISOs, 300 CTOs and CIOs, and more than 450 CEOs, CFOs, COOs, and CHROs.
Report publication:
IBM Institute for Business Value, June 2025.
