Ivanti CISO Takes on AI Security, Governance and Talent Gap
The advantages of AI are visible across the spectrum but few industries have felt the impact of this disruptive tech as much as cybersecurity.
Aiding with the highly repetitive tasks as vulnerabilities and patches pile up, AI has been a critical asset to the industry.
But is there a skills gap? Are employees ready to pick up the tech? And how protected are we really in this new threat landscape powered by AI?
Jack Nelson, Chief Information Security Officer and Deputy General Counsel at Ivanti, joins Cyber Magazine to answer these questions and more.
What is AI's impact on cybersecurity roles?
As with most industries, AI is reshaping roles and cybersecurity is no different. As companies rush to deploy AI and keep pace with competitors, itâs no surprise that the cybersecurity job landscape is changing.
Today, an increasing number of cybersecurity job postings require AI as a skill. As attackers increasingly use AI to breach systems, professionals must be able to use AI for threat detection and response. AI is no longer just a tool, itâs becoming part of the core security stack, demanding deeper understanding, accountability and upskilling.
However, this doesnât mean diminishing roles. Rather, a possibility to redefine them. As routine tasks become automated, organisations are seeing a growing need for professionals who can oversee AI systems, manage risk and guide decision-making.
AI is like a wizard’s wand in Harry Potter, you still need to know the spells before it can do any worthwhile magic
This shift places greater emphasis on strategic thinking, governance and cross-functional collaboration. The true leverage in AI use, particularly in the security setting, is when it is leveraged as a tool by those who have the baseline security knowledge and skillset to truly put it good use.
Could the real cybersecurity skills gap now involve managing and governing AI systems?
Absolutely. Prior to rapid AI adoption, the traditional âskills gapâ in cybersecurity has been framed around shortages of analysts, incident reporters and threat hunters.
But as organisations deploy AI, this definition needs updating. A new layer of risk has emerged with AI and the skills needed donât map in accordance with existing roles.
To keep pace with threats, agentic AI adoption has accelerated across organisations. However, our research shows that 44% of professionals say their companies have invested in AI across the organisation but employees still lack adequate skills and training to use these tools effectively.
Without upskilling professionals quickly, organisations risk falling behind AI, sacrificing regulation and control and exposing themselves to vulnerabilities.
The effectiveness of AI agents depends on the quality of human-generated data they are trained on and guided by. This creates a growing need to upskill cybersecurity professionals so that they can collaborate with AI â shifting from purely operational roles into oversight and training.
Just as an employee needs to be monitored and managed, AI needs to be too. In practice, this means defining what each AI tool is allowed to do, where it can and cannot be used and who is accountable for its outcomes.
AI agents need fully dedicated managers, who are responsible for their agent’s actions. Moreover, the employees who are ultimately accountable need to have the core skills to set the right guardrails and guidance for agents.
As automation takes over routine tasks, are cyber professionals being pushed into higher-value roles?
Yes, with automation helping with more routine tasks, this provides the opportunity for cyber professionals to re-shift their focus to higher-value, more strategic work.
Tasks like basic monitoring, triage and routine maintenance can increasingly be handled by AI, freeing professionals to focus on decision-making and risk assessment. Ideally, it will also provide more time to address the new risks AI systems pose, both from new attack surface and augmented threat actor activity.
By moving beyond day-to-day threat response, cybersecurity professionals can work toward shaping proactive security strategy, influencing policy and aligning cyber risk with broader business objectives.
- Ivanti research shows that 44% of professionals say their companies have invested in AI across the organisation but employees still lack adequate skills and training to use these tools effectively
- Ivanti found that among people who use generative AI tools at work, nearly a third (32%) keep their AI use completely hidden from management
- The World Economic Forum highlighted AI and cybersecurity as two of the fastest-growing global skills areas
This shift not only elevates their impact but also positions them to contribute meaningfully to board-level conversations, where understanding the intersection of technology, risk and regulation is essential.
However, this shift does come with a risk. As organisations increasingly lean on AI to handle tasks once assigned to junior employees, the traditional entry points into the profession begin to erode.
To help combat this, organisations must re-think how early-career talent is developed. Rather than replacing junior roles, AI should augment them.
By enabling junior professionals to work alongside AI, organisations can accelerate learning and help these junior roles develop the baseline knowledge to fully leverage AI capabilities. In turn, this will build the critical skills needed for strategic roles, ensuring both immediate efficiency and long-term proficiency.
Are regulatory pressures accelerating the need for dedicated AI governance and compliance expertise?
With AI adoption comes the need for proper regulation or businesses risk exposing vulnerabilities. Responsible AI use is critical for organisations and should be foundational before widespread adoption.
However, the speed at which organisations are deploying AI is causing problems. Companies are losing sight of regulation and employee training, while security measures are being overlooked.
Organisations are adopting AI without understanding its risks. At the same time, government frameworks are fragmented and failing to keep pace. This creates a gap between innovation and oversight, where AI systems are used without accountability.
Lack of regulation leads to a lack of AI transparency. Ivanti found that among people who use generative AI tools at work, nearly a third (32%) keep their AI use completely hidden from management. Employees could be sharing company data, without malicious intent but with real consequences.
Therefore, organisations must encourage transparency by building a culture of trust. Rather than prohibiting AI use, leaders should assess which platforms meet security standards and provide trusted sanctioned options. Reduced friction for initial testing, while maintaining a secure environment, can help reduce shadow AI use.
At Ivanti, we are trying to do just that. We have established an AI Governance Council â a cross-functional group designed to define acceptable and prohibited use cases.
Weâve also implemented different tiers of oversight based on the use case, giving employees a path to submit AI tools for review, alongside practical guidelines. The goal isnât to slow innovation, but to enable it responsibly.
Is the future of cybersecurity talent defined by a blend of technical expertise and AI fluency?
Ultimately, being able to understand and utilise AI effectively will become a core requirement for all cybersecurity talent alongside technical expertise. Businesses must take responsibility in ensuring employees are trained to develop these hybrid skills.
As AI is embedded across security operations, cybersecurity professionals will be expected to work confidently alongside these systems rather than treat them as optional tools.
But that isnât to say that core security skills will become redundant. Employees must still be able to understand networks, systems and identify vulnerabilities.
At the same time, professionals need to understand how AI systems work, where they fail and how they can be manipulated. This is especially important as these systems become embedded in detection, response and vulnerability management.
AI fluency is more than being able to use it as a tool. It includes interpreting AI inputs and outputs critically, recognising bias or blind spots and governing how AI is deployed securely and ethically.
Those who can combine traditional security expertise with a clear understanding of AI will be best positioned to navigate an increasingly automated and complex threat landscape. AI is like a wizardâs wand in Harry Potter, you still need to know the spells before it can do any worthwhile magic.
How prepared are organisations to upskill teams for an AI-driven cybersecurity landscape?
The World Economic Forum highlighted AI and cybersecurity as two of the fastest-growing global skills areas. Therefore, there is a clear rise in demand for talent which can work alongside AI and take responsibility for its security.
Organisations need professionals who can combine cybersecurity expertise with AI literacy, risk management and regulatory awareness.
Enterprise AI adoption is moving out of its hype phase and into a moment of reckoning. As organisations rush to deploy AI, speed is often outpacing strategy, governance and workforce readiness.
Organisations are realising that AI alone doesnât create advantage; value comes from how effectively and securely it is implemented. This requires a workforce with both technical depth and AI understanding.
Through apprenticeships, mentorship programmes and hands-on learning pathways, employees can build real experience with AI.
Creating opportunities for role exploration and internal mobility â especially into emerging areas like cybersecurity â demonstrates a long-term commitment to closing skills gaps and developing resilient, future-ready teams.
There is a whole workforce of wizards in the making, we just need to make sure we teach them the spells along the way.





