Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What should organisations do when AI/ML skills are…
Governance, Ownership & Risk

What should organisations do when AI/ML skills are in short supply across the security team?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: Governance, Ownership & Risk

Organisations should build a targeted upskilling plan instead of waiting for the market to catch up. Start with practical training on threat detection, investigation workflows, and safe use of AI-assisted tools. Then pair learning with role-specific exercises so analysts can apply new knowledge quickly. This narrows the gap faster than generic courses or broad hiring campaigns alone.

How to close an AI skills gap without waiting for hiring

When AI and machine learning expertise is scarce, the practical move is to build capability around the security work itself. Teams usually learn faster when training is tied to live tasks such as alert triage, investigation notes, tuning detections, and safe use of AI-assisted tooling. That makes the gap narrower, sooner, and easier to measure.

Generic AI theory rarely changes day-to-day security output. The better starting point is role-relevant fluency: what analysts need to recognise, what they need to verify, and where AI can speed work without weakening judgement. This is especially important when the team is already stretched and cannot absorb long training cycles.

Targeted upskilling also works better when it is sequenced. Foundational concepts come first, then supervised practice, then repeated use on real queues and cases. That approach reduces the common failure mode where people understand the vocabulary of AI but still cannot apply it safely under operational pressure.

What training should focus on first

The first priority is not model building, it is operational competence. Security teams benefit most from training that improves detection, investigation, and decision quality: reading outputs critically, checking for false confidence, validating source data, and knowing when to escalate rather than trust an automated suggestion.

For teams using AI-assisted tools, the training should also cover safe interaction habits, especially around sensitive data, prompt content, and output verification. A tool can be helpful and still produce bad decisions if analysts treat it as an authority instead of an assistant. That is why practical exercises matter more than slide-based awareness sessions.

A useful pattern is to pair each skill with a working example. For instance, analysts can practise reviewing an AI-generated triage summary, compare it with raw telemetry, and document where the model helped and where it introduced ambiguity. That creates muscle memory in the same workflow where mistakes would otherwise surface later.

If the organisation is also building or evaluating AI security capability, the AI Security Platform Buyer's Guide is a useful way to structure vendor and capability assessment around real operational needs rather than feature lists.

How to make upskilling stick in a security team

Training only pays off when it is embedded into the team’s operating rhythm. Short enablement sessions, paired reviews, and scenario drills work better than one-off courses because they connect learning to specific tickets, alerts, or investigation steps. The team should be able to show a before-and-after improvement in speed, judgement, or consistency.

Ownership also matters. A manager or lead analyst should define the skill gap, choose the priority workflows, and decide how progress will be checked. Without that structure, training tends to drift into broad AI enthusiasm, which sounds modern but does not improve security outcomes.

It also helps to focus on one capability cluster at a time. Start where the pressure is highest, such as detection tuning or investigation support, then expand into automation review, AI tool governance, or model-risk awareness only after the team can use the first skill reliably. That avoids spreading the effort too thinly.

If the environment includes AI agents or autonomous workflows, the Agentic AI Security Policy Template can help translate policy intent into role boundaries, oversight expectations, and safe-use rules that analysts can actually follow.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8, NIST CSF 2.0 and NIST AI RMF set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-17 — Security Awareness and Skills TrainingTraining the team on AI-assisted security workflows is a security-skills issue.
Recommendation — Build role-based training that matches analysts to the workflows they perform.
NIST CSF 2.0PR.AT-01 — Personnel are provided with awareness and training so that they can perform their cybersecurity dutiesThe question is about closing a skills gap through structured training.
Recommendation — Deliver targeted training tied to analysts' actual security duties and workflows.
ISO/IEC 27001:2022A.6.3 — Information security awareness, education and trainingThe subject is improving team capability through formal training and reinforcement.
Recommendation — Provide role-specific education and training aligned to the security tasks people perform.
NIST AI RMFGOVERN — GOVERNUsing AI safely in security operations needs governance over roles, oversight, and accountability.
Recommendation — Define AI use boundaries, review ownership, and escalation paths before broad rollout.

Practitioner Guidance

What to prioritise: Build training around the security tasks that AI will actually touch, not around AI concepts in isolation. The fastest gains usually come from better triage, better investigation discipline, and better judgement over automated outputs.

What to verify: Before calling the programme effective, verify that analysts can explain why they trust or reject an AI-assisted output, can reproduce the underlying evidence, and can complete the workflow without relying on ad hoc expert rescue.

Common mistake: Treating AI upskilling as a one-time learning event. In practice, the capability must be reinforced in live work, or the team will retain vocabulary without gaining operational confidence.

Practitioner takeaway: The goal is not to make everyone an AI specialist, but to make the team safer and faster in the exact workflows where AI will influence security decisions.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org