How AI and Cloud Adoption Are Changing Cybersecurity Skills and Staffing Needs

Two cybersecurity professionals work at computer monitors in a blue-lit operations center, with digital dashboards and a world map displayed behind them. The scene reflects the growing technical and staffing demands associated with AI, cloud adoption, and cybersecurity.

AI and cloud adoption are changing cybersecurity requirements by expanding the identities, data, applications, models, and access points organizations must protect. As a result, cybersecurity skills are becoming more specialized, with greater emphasis on identity and access management, cloud security, AI security, fraud detection, risk management, and incident response.

As a result, organizations need to determine which cybersecurity capabilities are critical, which skills they already have, and whether gaps should be addressed through hiring, upskilling, contingent specialists, or managed services.

ISC2’s 2026 analysis of its cybersecurity workforce research points to AI, cloud computing security, risk assessment, application security, and governance, risk, and compliance (GRC) among the areas where organizations need additional skills.

Why Is Identity Security Becoming Central to Cybersecurity?

As employees, contractors, applications, machines, and AI systems interact across cloud environments, identity increasingly determines who, or what, can reach critical systems and data. Identity security is therefore becoming a foundational component of modern information security rather than simply an administrative IT function.

The identity perimeter now includes people and machines

Traditional employee accounts are only part of the identity landscape. Organizations may also need to manage third-party users, service accounts, APIs, cloud workloads, automated processes, and AI agents.

That changes the underlying security question. Instead of focusing primarily on protecting network infrastructure and a defined perimeter, organizations must continually determine who or what should have access to a resource, how much access should be granted, and under what conditions.

Effective identity and access management (IAM) can include authentication, authorization, privileged access management, identity governance, and policies based on Zero Trust Architecture principles.

Identity security requires specialized capabilities

Modern access management requires more than provisioning and removing employee accounts.

Cybersecurity specialists may need to understand cloud architectures, authentication protocols, privileged identities, application permissions, network security, and the business processes those controls protect.

As a result, organizations may need professionals who can bridge traditional cyber security disciplines with cloud, application, and business knowledge rather than treating identity as an isolated administrative responsibility.

What New Security Capabilities Does Enterprise AI Require?

New security capabilities that enterprise AI will require include secure AI applications and data, AI security that crosses organizational boundaries, new combinations of cybersecurity and AI skills.

Secure AI applications and data

Enterprise AI systems can interact with sensitive data, external models, APIs, plugins, cloud infrastructure, and other business applications. Security teams therefore need to consider permissions, data exposure, application interfaces, third-party dependencies, and secure development practices.

Existing disciplines remain relevant. Vulnerability assessment, penetration testing, ethical hacking, network security, and application security can continue to play important roles, but practitioners may need to understand how those disciplines apply to AI-enabled systems.

The objective is not necessarily to create an entirely separate security function for AI. It is to extend established information security principles into a technology environment with new architectures, interactions, and potential failure modes.

AI security that crosses organizational boundaries

AI security can involve cybersecurity, engineering, data, privacy, legal, risk, and governance teams. Technical controls alone cannot answer every question about how an AI system should access information or how an organization should respond when its use creates business risk.

That increases the value of cybersecurity professionals who can translate technical issues into operational decisions. Communication, collaboration, critical thinking, and other soft skills can be important alongside technical expertise, particularly when security decisions affect multiple business functions.

New combinations of cybersecurity and AI skills

The emergence of AI security does not make established cybersecurity skills obsolete. Instead, organizations may need professionals who can combine knowledge of AI systems with experience in areas such as cloud computing, identity, secure development, security architecture, and risk.

Microsoft’s 2026 Responsible AI Transparency Report, for example, discusses security challenges associated with increasingly interconnected and agentic AI systems, including the importance of access, permissions, memory, and how systems are used over time.

For example, a Security Engineer with cloud and application expertise may develop AI security capabilities, while an information security analyst may increasingly encounter AI-related risk in assessments and governance activities.

How Are Deepfakes and AI-Enabled Fraud Changing Security Operations?

Generative AI can produce increasingly convincing synthetic text, voice, images, and video. For security teams, that increases the importance of verifying identities and sensitive transactions rather than assuming a communication is legitimate because it looks or sounds authentic.

Social engineering is harder to evaluate by appearance alone

Social-engineering attacks have long relied on convincing people that a fraudulent request comes from someone they trust. Synthetic content adds another tool for impersonation.

A fraudulent request might involve credentials, financial transactions, sensitive data, or access to internal systems. In those situations, established verification procedures can provide an important defense regardless of how convincing the message, voice, or video appears.

Microsoft’s 2026 Responsible AI Transparency Report identifies fraud, impersonation, deepfakes, and social engineering among the malicious applications of increasingly accessible AI capabilities.

Detection technology is only part of the response

Deepfake detection and other security tools can contribute to an organization’s defenses, but detection technology does not eliminate the need for strong processes.

Identity verification, transaction validation, secondary approvals, anomaly detection, access controls, and escalation procedures can all help reduce reliance on a single communication channel as proof of identity.

The broader principle is verification over appearance. A convincing email, phone call, or video should not independently establish trust when the request involves sensitive access, information, or transactions.

Human judgment remains part of the control environment

AI-enabled deception is not exclusively a problem for the security operations center. A SOC analyst, fraud analyst, finance employee, executive, help desk professional, or identity specialist could encounter a suspicious request.

Organizations therefore need a combination of technology, procedures, training, and human judgment. Threat intelligence can help teams understand emerging attack techniques, while Security Information and Event Management (SIEM) platforms and other monitoring systems can provide technical signals. Digital forensics, malware analysis, and incident response capabilities become important when suspicious activity requires deeper investigation.

While the technology can assist the decision, skilled people still need to interpret the evidence and determine the appropriate response.

What Cybersecurity Skills Should Organizations Build, Hire, or Outsource?

Organizations should prioritize cybersecurity skills according to their technology environment, risk profile, and frequency of need. They can then determine whether those capabilities should be developed internally, added through permanent hiring, accessed through contingent specialists, or delivered through managed services.

ISC2’s cybersecurity workforce research makes an important distinction here: difficulty accessing needed cybersecurity skills is not necessarily the same problem as simply having too few people.

That distinction can lead to a more targeted workforce strategy.

Identify the capabilities that matter to the organization

There is no universal list of cybersecurity skills every organization needs at the same depth.

Depending on the environment, priority capabilities could include:

  • Cloud security architecture and engineering
  • Identity and access management and privileged access
  • AI security and governance
  • Application security and secure development
  • Network security
  • Penetration testing and ethical hacking
  • Vulnerability assessment and management
  • Threat intelligence
  • Security Information and Event Management
  • Incident response
  • Digital forensics and malware analysis
  • Cybersecurity risk management
  • Operational technology security
  • Privacy, compliance, and data governance

The required expertise also varies by role. A SOC analyst monitoring SIEM platforms needs a different skill mix from a penetration tester assessing applications, a Security Engineer designing controls, or an information security analyst evaluating organizational risk.

Match the workforce model to the capability

Once organizations identify the capabilities they require, they can consider how each should be sourced.

Frequency matters. Capabilities that require continuous institutional knowledge or close integration with business operations may be stronger candidates for internal development. Highly specialized or episodic requirements may lend themselves to contractors or external providers.

Organizations can also combine approaches. An internal Security Engineer, for example, could work with an MSSP for monitoring and an external penetration tester for independent assessments.

Build a cybersecurity workforce around capabilities, not job titles

Starting with job titles can lead employers to search for candidates who satisfy long lists of technical requirements without first determining which capabilities the organization actually lacks.

A capability-based approach reverses that process.

Organizations can assess their technology environment and risks, identify the security capabilities required to support them, map those requirements against existing employees, and then determine where the gaps remain. Some may be addressed through training and upskilling. Others may justify permanent hiring, contingent talent, or managed services.

This approach also recognizes that technical expertise is only part of an effective cybersecurity workforce. Cybersecurity specialists increasingly work across IT, engineering, finance, legal, risk, operations, and executive leadership. The ability to communicate technical risk, collaborate across functions, and make decisions under uncertainty can be as important to the organization as familiarity with a particular security tool.

Cybersecurity Workforce Strategy Has to Evolve With the Technology Environment

AI and cloud adoption are not simply adding more technologies for security teams to protect. They are changing the mix of identity, AI, fraud, cloud, governance, network, and response capabilities organizations may need.

The workforce implication is equally important. The cybersecurity challenge should not automatically be framed as a need for more headcount.

Organizations can instead ask three questions: Which security capabilities are becoming critical to our environment? Which capabilities do we already have? And where should we build, hire, contract, or outsource expertise to close the remaining gaps?

Answering those questions can help employers build a cybersecurity workforce around the security capabilities the business actually needs—while retaining the flexibility to adapt as AI, cloud computing, and the threat environment continue to evolve.

Frequently Asked Questions

What cybersecurity skills are most important for AI adoption?

AI adoption can require a combination of application security, cloud security, identity and access management, data governance, risk management, and secure development skills. Organizations may also need professionals who understand how AI systems interact with enterprise data, applications, permissions, and third-party services.

Why is identity security important in cloud environments?

Cloud environments distribute applications, data, workloads, and users beyond a traditional network perimeter. Identity security helps organizations determine which human and machine identities can access those resources and what level of access each should receive.

What is AI security?

AI security is the practice of protecting AI systems, applications, data, and integrations while managing security risks created by their use. It can draw on existing disciplines including application security, cloud security, access management, data security, and cybersecurity risk management.

How are deepfakes changing cybersecurity?

Deepfakes can make impersonation more convincing by creating synthetic voice, video, images, and other content. Organizations can respond with layered controls including identity verification, transaction validation, access controls, detection technologies, employee training, and escalation procedures.

Should small businesses outsource cybersecurity?

Outsourcing can help small businesses access specialized cybersecurity capabilities they cannot efficiently maintain internally. The appropriate model depends on the organization’s risks, existing workforce, resources, and requirements; external providers do not eliminate the need for internal ownership and accountability.

Which cybersecurity functions can be outsourced?

Organizations can use external providers for functions such as managed monitoring, penetration testing, vulnerability assessment, incident response, digital forensics, specialized security assessments, and fractional security leadership. Core decisions about business risk, priorities, access, and accountability generally still require internal ownership.

Looking to hire top-tier Tech, Digital Marketing, or Creative Talent? We can help.

Every year, Mondo helps to fill thousands of open positions nationwide.

More articles about top industry salaries and trends:

Related Posts

Never Miss an Insight

Subscribe to Our Blog

This field is for validation purposes and should be left unchanged.

A Unique Approach to Staffing that Works

Redefining the way clients find talent and candidates find work. 

We are technologists with the nuanced expertise to do tech, digital marketing, & creative staffing differently. We ignite our passion through our focus on our people and process. Which is the foundation of our collaborative approach that drives meaningful impact in the shortest amount of time.

Staffing tomorrow’s talent today.