theCUBE analysts frame AI security skills gap as a resilience challenge at Black Hat
At Black Hat USA, theCUBE analysts said AI-speed attacks demand stronger context, governance and human oversight, though no workforce shortfall was quantified.
By Colin Brandt · Enterprise Reporter
· 3 min read
At Black Hat USA 2026 in Las Vegas, theCUBE Research analysts Krista Case and Jon Oltsik framed the AI security skills gap as a cyber-resilience problem that cannot be solved through additional headcount alone. In theCUBE’s Aug. 5 kickoff broadcast from Mandalay Bay, they said security teams need better threat context, business-process knowledge and AI-assisted controls as attackers’ capabilities accelerate.
The comments were an analyst assessment, rather than a measurement of the security labor market. No independent workforce survey or primary dataset in the available material establishes the scale of an AI-specific skills shortage, or shows that it is a shared conclusion among Black Hat USA attendees.
Case, theCUBE Research’s principal analyst and practice lead for cyber resilience and security, said frontier AI models are increasing the speed and scale at which attackers can operate, leaving defenders less time to respond. Oltsik’s response was to focus on intelligence about adversaries’ tactics and on defensive controls, rather than treating staffing as the sole answer.
What did theCUBE analysts say about the AI security skills gap?
Oltsik identified AI penetration testing for agentic applications and AI governance roles as areas organizations may need to develop. Case argued that people should remain involved in decisions, describing a combined human-and-AI approach as more capable than either operating separately.
Their wider framework tied technical security work to operational priorities. Oltsik described cyber resilience as work at the intersection of technology and the business: teams must identify critical processes, decide what downtime or reduced capacity can be tolerated, and establish compensating controls. That approach aligns with the view that enterprise security is a program, not a product, spanning technology, people, procedures and recovery planning.
In the broadcast, Oltsik pointed to virtual patching as one possible control where AI helps identify vulnerabilities at scale. He also advised CISOs to arrive at vendor meetings with defined requirements, including questions on model choices, developer training and guardrails. Case said organizations should plan for the possibility that attackers breach an environment and maintain the ability to operate through disruption.
Black Hat itself put AI’s dual role at the center of its Aug. 4 AI Summit, describing it as a tool for detection, automation and response as well as an enabler of faster attacks. That is event framing, not independent market evidence, but it supplied the context for theCUBE’s discussion.
SiliconANGLE’s recap of the session cited a 22-second median interval from initial access to full compromise, attributing the figure to Mandiant’s M-Trends 2026 report and comparing it with more than eight hours in 2022. The primary Mandiant report was not included here, so the number cannot be independently verified from the available evidence.
For security leaders, the practical takeaway from Case and Oltsik’s comments is to evaluate AI security work against specific operating needs: what the business must keep running, which threats matter to that environment, and where human review remains necessary. Their analysis does not establish a quantified workforce crisis, but it does describe a changing mix of security capabilities.
This story draws on original reporting from SiliconANGLE.