Editor’s note: ISACA recently released its State of Cybersecurity 2026 report. Below, Harshad Kadam, CISM, Senior Security Engineer Member, Founding Chapter Lead, AI Security Engineers Austin; Ekaterina Zuckermann, Information Security Governance & Regulatory Transformation Advisor, Advisense; Saurabh Misra, Senior Manager – Technology Risk, Governance, Audit & Cybersecurity, ManpowerGroup; Catherine Bwire, CISM, CISA, ISO 27001 Lead Auditor, ISO 27001 Lead Implementer, ISO 27701 Lead Implementer, ISO 22301 Lead Implementer, Chief Information Security Officer (CISO) & Digital Trust Leader; and Krutik Poojara, Application and Cloud Security Lead, Center Point Energy, and Founder of Nandee.ai, all cybersecurity professionals and members of ISACA’s Emerging Trends Working Group, share their views on some of the key findings. See more State of Cybersecurity resources at www.isaca.org/state-of-cybersecurity.
ISACA Now: According to the State of Cybersecurity findings, a slight majority of cybersecurity staff started in a different field and transitioned to cybersecurity. What type of background or skills lend themselves to a successful transition to cybersecurity?
Ekaterina Zuckermann: Some of the strongest backgrounds are quality management, operations, procurement and risk management. Cybersecurity can become too technically narrow, while real security problems rarely respect organizational boundaries. People who know how to think systemically and understand how failures propagate across processes, suppliers, people and technology can bring exactly the perspective cybersecurity needs.
Catherine Bwire: I came into cybersecurity through a broader technology and risk journey rather than following the traditional cybersecurity path. That experience shaped my view that there is no single route into the profession. People coming from IT, risk, audit, data, law or business can bring valuable perspectives, specifically when combined with curiosity and a willingness to continuously learn. The ability to understand the business context of a risk is just as important as understanding the technology behind it.
Krutik Poojara: I started my career as a developer and founder. As a founder, I had to wear many hats and understand different parts of the technology lifecycle, from development and architecture to deployment and working directly with customers. My transition into cybersecurity started when I had a banking client who asked us to assess a deployment for security issues. That experience led me into application security and cloud security. I believe backgrounds in software development, cloud engineering, infrastructure, IT and operations can provide a strong foundation for a transition into cybersecurity. More importantly, problem-solving, curiosity, understanding how systems work, and having the ability and willingness to continuously learn are skills that can help someone become successful in cybersecurity.
ISACA Now: State of Cyber respondents listed data security as the most important security skill needed and critical thinking as the top soft skill needed. What other skills would you say are especially important for cybersecurity professionals to have, and why?
Harshad Kadam: The skill I’d name is domain-crossing. Security with AI doesn't sit in one domain anymore – an agent problem is simultaneously a network problem, an identity problem and a data problem, and the failure usually lives in the seam between them. Data security and critical thinking are both real, but they’re skills you apply inside a domain. What makes crossing possible is first-principles thinking: outside your home domain the playbook doesn't transfer, so you have to reason from how the thing actually works rather than from the pattern you’re used to. That’s what is scarce right now: people with genuine depth in two or three areas who can see how a weakness in one becomes an exposure in another.
Ekaterina Zuckermann: The ability to see moving parts and trace consequences across an organization is critical. Cybersecurity professionals need to look at the same problem from multiple perspectives – technical, operational, legal, business and human – and most importantly, ask where and how things can fail. They also need enough understanding of legal and regulatory reality to recognize that implementing law is rarely a black-and-white exercise: requirements still have to be interpreted, applied to a specific organization and translated into decisions and controls. Frameworks can support that judgment, but they cannot replace it.
Saurabh Misra: Cybersecurity professionals also need business understanding, clear communication and sound judgment. Security teams are most effective when they can connect a technical weakness to its potential business impact, explain the risk in plain language and help leaders select a practical response.
Krutik Poojara: Because many security teams are short-staffed, security professionals often have to wear multiple hats. The same person may be involved in incident response, penetration testing, vulnerability management, threat modeling and recommending remediation. That makes analytical thinking, red team skills and development skills especially valuable. Sometimes you are working with cloud engineers to develop secure configurations. Other times you are responding to incidents such as DDoS attacks or account takeovers. You may also be sitting with developers to perform threat modeling and identify security issues before the application is deployed. Because of that, I think cybersecurity professionals need to be technically versatile and comfortable working across different teams.
ISACA Now: Only 31% say that most applicants for cyber jobs are well qualified for the position for which they are applying. What type of training or support should organizations provide to get new employees up to speed who might not have optimal qualifications coming in?
Ekaterina Zuckermann: Teach them the organization before teaching them another framework. They need to understand what the company actually does, which outcomes cannot fail, what data and technology support those outcomes and where different departments experience real operational pain. Formal training has value, but it cannot substitute for meeting the people who run the business and seeing how work actually happens. Controls designed from frameworks or “best practice” without that anchor in operational reality often create friction rather than security. When a control prevents people from doing necessary work, they find a way around it – and the workaround may create more risk than the control was intended to reduce.
Catherine Bwire: I don’t think we should expect every new hire to arrive fully formed, particularly in a field that is dynamic and changes as quickly as cybersecurity. Organizations should combine structured onboarding and role-based training with mentoring, practical exposure and opportunities to learn from experienced practitioners. I would also encourage organizations to hire for potential and learning agility rather than focusing only on qualifications someone already has on paper.
Krutik Poojara: I don’t necessarily think that a lack of traditional qualifications means someone is not capable of succeeding in cybersecurity. There is a lot of talent out there, and security itself is changing every day. For experienced professionals, organizations should look at the skills and experience they already have and identify how those skills can transfer into security. For people who are new to the field, organizations can provide structured onboarding, mentorship, hands-on training and opportunities to work on real-world security problems. I also believe skills development is a leadership responsibility. Leaders should create an environment where people can continuously learn and grow rather than expecting every new employee to come in fully qualified. We often say that humans are the weakest link in security, but I believe humans can also be the strongest line of defense when they have the right training, support and awareness.
ISACA Now: Only 13% of respondents do not use artificial intelligence in their security operations. What have you observed as the most useful ways in which security practitioners are integrating AI into their workflows?
Krutik Poojara: AI is definitely helping reduce the time required for many security tasks. Things that previously took weeks or months can sometimes be accelerated to days, particularly around analysis, research and security tooling. One area where I am personally using AI is reducing false positives from Static Application Security Testing (SAST) tools. I built an AI-powered orchestrator that takes findings from SAST tools and performs a confidence-based analysis to determine how likely each finding is to be a false positive. It analyzes the context around the finding and provides a confidence assessment that helps security engineers prioritize which findings require deeper investigation. This helps reduce the amount of time security teams spend manually triaging findings and allows them to focus their attention on vulnerabilities that are more likely to be real and actionable.
Ekaterina Zuckermann: At the moment, I see a lot of organizations treating artificial intelligence as the shiny new tool rather than starting with the problem it should solve. AI can accelerate analysis, identify patterns and process large volumes of security information, but its output is only as trustworthy as the data, context and expertise surrounding it. Effective use requires control over data quality, people capable of recognizing when the output is wrong and clear validation before AI-generated conclusions influence security decisions.
Saurabh Misra: AI is most useful when it reduces repetitive analysis. This includes summarizing alerts, grouping related incidents, analyzing large volumes of logs, identifying patterns across identity, endpoint and cloud data and preparing investigation timelines. Its primary value is not replacing analysts, but allowing them to spend more time validating risks, understanding context and responding to important threats.
ISACA Now: How far along do you think organizations are in striking the right balance between humans and AI in how they set up their security programs for success?
Harshad Kadam: Not very far, and mostly because organizations are balancing the wrong thing. The conversation is about how much work to hand to AI and how much to keep with people, but the incidents that matter aren’t happening because a human was out of the loop – they’re happening because nobody can see what the agent did. What you can verify about an agent is its behavior, not its intent; its stated reasoning is just another output you’d have to trust. So detection belongs where its actions are observable – at the network layer and at the tool-call boundary – not in the model’s own explanation of itself. Until that’s in place, you’re not striking a balance, you’re just deciding how much you’re willing to not watch.
Saurabh Misra: Most organizations are still at an early stage. AI is increasingly built into security tools, but governance, data quality, access controls, testing, monitoring and clear accountability often lag behind adoption. The right balance keeps people responsible for high-impact decisions while using AI for speed and scale. Success should be measured by better decisions and fewer missed risks, not simply by the number of AI features deployed.
Catherine Bwire: I believe organizations are still finding the right balance. AI can give security teams tremendous speed and scale in areas such as detection, analysis and response, but human judgment remains critical when decisions involve risk, context, ethics and business impact. For me, the goal is not AI replacing people but AI helping people make better decisions faster, with humans retaining accountability and oversight.
Krutik Poojara: I think most organizations are still in the early-to-middle stages of finding the right balance. AI adoption is moving much faster than security teams are adapting their processes around it. Developers are increasingly using AI to write code, which means the volume and speed of software development has increased significantly. Security teams now have to keep pace with that velocity. If development teams are using AI to generate more code, security teams also need AI-assisted capabilities for code analysis, vulnerability triage, threat modeling, detection and incident response. We are moving toward a model where it is not simply AI versus humans, but AI-assisted development versus AI-assisted security. Both sides are using AI to increase their productivity, but the security team still needs to make sure the increased development velocity does not introduce increased risk. I think the right balance is keeping humans in the loop for decisions that require context, judgment and accountability.