Professionalism is critical in the age of AI

In 2026, almost every technology vendor claims to be “powered by AI”. The promise is familiar: lower costs, greater efficiency and stronger security. Yet for many cyber practitioners, the headlines tell a more unsettled story. As organisations announce AI-driven restructures, and automation accelerates across technical teams, people are asking what kind of work will remain, what skills will matter, and how they can prove they are ready for it. 

That is why Australia’s pilot cyber professionalisation program, CyberPath, matters now. At first glance, professional standards built around capability frameworks, assessment, development and accreditation can seem like yesterday’s problem. 

In reality, standards are becoming more important than ever.

ACS Digital Pulse 2026 argues that Australia's technology workforce is "no longer built through a single, linear pipeline.” Talent is increasingly being recognised through skills, not just job titles. This shift creates new entry points into the profession and opens practical pathways to narrow the skills gap. Alongside this, Dr Susan McGinty notes that greater gender diversity and inclusion in cyber security are not just matters of fairness; they unlock capability, innovation and the sector’s full potential (from Advancing the Cyber Sector). Together, these shifts point to three opportunities for employers:

  1. Access more workers who meet current and future skills needs
  2. Draw on broader skill sets to understand and respond to adversaries
  3. Leverage diverse perspectives to adapt and innovate

A diverse and inclusive workforce that reflects the communities we protect is critical. Yet accessibility remains difficult when employers lack a shared view of what good looks like in a role, or consistent ways to assess capability. At the same time, aspiring practitioners and career changers struggle to translate their strengths, experience and life journeys into future cyber roles. AI hasn't reduced these challenges; it’s amplified them amid uncertainty.

 

The paradox AI has created

Skills shortages are acute, but there is a lack of clarity around how AI is reshaping the fabric of our workforce. Currently, 74% of cyber teams are changing their size, role structures, and transforming the way tasks are performed. Agentic and generative AI is impacting all domains of cyber, with traditional entry-level roles being hit hardest and disrupting the future talent pipeline. Whilst automation has its place, many organisations are struggling to understand where to redeploy and how to develop their talent to lift their cyber risk posture. Jay Bhalodia, Federal Managing Director at Microsoft, put it starkly (from SAN’s 2026 Cybersecurity Workforce Research Report):

“The risk isn't AI itself but using AI to automate these growth pathways instead of focusing on accelerating them."

The consequence is a widening gap between headcount, capability, and accountability. The same research found organisations now rank a skills gap (60%) well above a staffing gap (40%): a spread that has grown five-fold in a single year, while career progression concerns have more than tripled. 

In a June 2026 Five Eyes cybersecurity agencies joint statement, there was a stark warning around how frontier AI is compressing the "window between vulnerability discovery and exploitation" to a matter of months, not years, and called cyber resilience "a core business risk and leadership responsibility" rather than a technical afterthought. How organisations approach defence in depth hasn’t materially changed, but the accessibility, speed, scale, and consequently the capability of adversaries has shifted. 

Adversaries have a low barrier of entry to advanced capabilities, whilst at the same time, defenders lack learning pathways backed by practical exposure. The roles that used to teach people the profession are shrinking, the threat environment is accelerating, and the bar for demonstrated capability keeps rising. Professionalism is the footing that closes the gap. Technical Program Lead for CyberPath, Jakub Zvěřina, argues that:

“Cyber security is a strategic capability for Australia, which if neglected, threatens to undermine our economy, democratic values, and the safety of our people, systems, and data. AI is driving a revolution, and it’s critical that we clearly articulate what good looks like, improve accessibility with clear pathways, and push skills left to build a resilient culture around cyber.”

 

Technology changes fast. The need for security doesn't.

CyberPath starts from a simple idea: technology will keep changing, but the need for capable, accountable people will not.

Cyber security work is becoming more complex. Practitioners are expected to protect legacy and emerging technologies, work across cloud environments, understand the convergence of IT and OT, and prepare for risks such as the Q-Day threat. They are also operating in a regulatory environment that continues to shift under the 2023–2030 Australian Cyber Security Strategy.

That complexity makes professionalisation harder, but also more important. A useful framework cannot simply list technical skills and assume every practitioner follows the same pathway. It needs to reflect how cyber work is actually done, how people build capability, and how organisations assess whether someone is ready to do the work.

That is what makes CyberPath distinctive globally. It looks beyond technical knowledge to consider the context in which cyber roles operate, including industry sector, organisation size, operating environment and neuro-inclusive dimensions of work. It recognises that people learn and progress in different ways, and that practical application matters as much as capability written on paper. It also acknowledges that cyber careers do not move upwards solely. Practitioners may deepen technical expertise, move into leadership, or shift sideways and diagonally into adjacent roles as the profession evolves.

AI makes this even more urgent. Fortinet's 2026 Cybersecurity Skills Gap Report found that 84% of organisations say AI has already made their security teams more effective, yet 60% report growing difficulty finding candidates with genuine AI-security experience. That is the gap between adoption and readiness. 

CyberPath responds by mapping how AI is reshaping competence across cyber domains without making a broad claim that “AI changes everything”. In security operations, analysts shift from manual triage to supervising automation and catching AI's false positives and negatives. In governance and compliance, AI can support evidence collection and risk scoring, pushing practitioners toward oversight, layering risk context, and assurance. In secure software development, it’s less about writing code and more about recognising insecure patterns an AI assistant may introduce. 

This is where human capabilities matter most. Adaptability, resilience, critical thinking and judgement are becoming more important, not less, as AI becomes more embedded in cyber work. The question for organisations is how they build those capabilities safely and consistently.

CyberPath helps answer that question. It reinforces a simple but important point: AI can augment capability, but it does not replace accountability.

 

Why professionalisation matters now

CyberPath builds on work completed in the Australian Cyber Workforce Playbook, a free resource developed through a government and industry partnership in 2025. The Playbook provides organisations with practical tools, case studies and guidance to build cyber capability and design more inclusive workforce pathways.

The action case is clear: capability has real value. ACS Digital Pulse 2026 shows that recognised skills lift has an earning potential for workers and productivity gain for businesses. It also shows that digital skills gaps are already increasing cybersecurity risk for many organisations.

That risk is especially acute for small and medium businesses. They make up 97.2% of Australian organisations, yet many may not detect or report cyber incidents. So while the Australian Signals Directorate received 84,700 cybercrime reports in 2025, the true scale of the problem is likely larger.

This is why workforce capability cannot be treated as abstract or optional. AI will keep changing what cyber security work looks like day to day, but it will not replace the need for people who can make sound judgement calls and be accountable for them.

CyberPath gives industry a credible way to show that those people are equipped to do the work.

 

Proving it, credibly

CyberPath is ambitious. It sets out to make cyber roles clearer, capability easier to assess, and professional standards more useful in practice. But the real test is not the design on a page. It is whether employers adopt it, practitioners use it, and the profession can see its value.

CyberPath will evaluate whether the pilot can:

  • Improve clarity of roles, skills and pathways

  • Improve accessibility by reducing unnecessary barriers

  • Strengthen employer assurance and public trust through clear, consistent assessment standards

  • Make adoption easier and demonstrate clear value for employers 

 

Your opportunity

CyberPath invites employers, practitioners and partners to help shape the future of Australia’s cyber workforce. To learn more or register as an early adopter, visit the CyberPath website.

Download the ACS Digital Pulse 2026 and discover the evidence and insights shaping Australia's digital future.