Artificial intelligence is reshaping and found that AI penetration testing now ranks among the top global cybersecurity training priorities, while , founder and CEO of Hack The Box, in a challenges on its platform, followed by machine learning model exploitation at 24%, and agentic AI hijacking at 12%. According to Hack The Box, those attack categories reflect growing concern over threats targeting AI models and autonomous systems directly.
“Training data signals a clear shift toward AI-driven attack vectors, highlighting where the next generation of cybersecurity risks is emerging,” the report states.
The Hack The Box report also found that AI penetration testing ranked No. 4 globally among cybersecurity training interests and that enterprise-led AI security training completion rates reached 64% in late 2025. “Cybersecurity skill development is shifting toward a continuous, integrated model where offensive insights and defensive capabilities evolve together,” the report states. “Cybersecurity training participation reflects an increasingly global workforce.”
The ISC2 workforce study, which is based on responses from 16,029 in cybersecurity: 35%
When asked about the technologies that will have the most negative impact, AI topped the list again with 52% of respondents.
“As AI moves from experimentation into operational reality, its impact is becoming more tangible,” the ISC2 report stated. “Unlike other technologies whose influence appears to be stabilizing, AI continues to intensify conversations around risk, responsibility, and readiness.”
The studies also suggest AI is driving changes in how cybersecurity teams are structured. Hack The Box found an overlap between offensive and defensive security skill development. Defensive practitioners increasingly participate in offensive training exercises, while offensive security professionals are also building defensive expertise, according to the research.
ISC2’s research also highlighted mounting concern about workforce preparedness as AI-driven attacks become more sophisticated. AI-powered social engineering attacks ranked as the top cybersecurity challenge professionals faced over the past 12 months, cited by 51% of respondents. That number rises to 57% when respondents look ahead to the next two years.
The reports suggest security leaders view AI-enabled phishing, impersonation, and deception campaigns as more immediate threats than traditional workforce shortages or compliance burdens, which have historically dominated cybersecurity workforce surveys. For CISOs, the research points toward several emerging priorities: investing in AI security skills, adopting continuous hands-on training programs, and expanding global talent pipelines to address persistent workforce shortages.
“For many teams, the challenge is no longer whether AI will shape security outcomes, but how quickly they can adapt alongside it,” the ISC2 report stated.
SOCIAL SHARE CARD GENERATOR