Left Arrow Icon
All articles

Speeding Up Security Work Could Undermine the Next Generation of Defenders

The Security Digest - News Team
Published
July 26, 2026

Helen Patton, Cybersecurity Executive Advisor at Cisco, argues that measuring AI by speed alone starves the security talent pipeline and does little for the organizations stuck below the security poverty line.

Credit: The Security Digest

Make The Security Digest one of your go-to sources on Google

Google Icon
Add The Security Digest on Google
Quote Icon
We need to be intentional about building these skills in the people we’re hiring as part of our AI strategy, not in spite of it.

Helen Patton

Cybersecurity Executive Advisor

Helen Patton

Cybersecurity Executive Advisor
Fortune 100 Enterprise Technology Company

Somewhere right now, a junior analyst is watching an AI close out the tickets they were hired to learn on. Leadership calls it productivity, and the dashboard agrees. What the dashboard doesn't show is where the next generation of defenders comes from once the learning work is gone.

Helen Patton is a Cybersecurity Executive Advisor at one of the world’s largest networking and enterprise technology companies, a former CISO of the company's security business group, and before that, she served as CISO at The Ohio State University for seven years. Two decades across banking, higher education, and technology made her a persistent critic of the industry's favorite workforce statistics, including the hundreds of thousands of open jobs narrative. "There are jobs available, but they're not entry level jobs. They're usually asking for somewhere between 8 and 15 years of security experience."

"Sometimes you need to lift something, so you get a robot to do the lifting. Sometimes you go to the gym because you need to exercise the muscles so that you can continue to lift. Just because AI can do something may not mean that we want AI to do it," Patton says.

Repetition is the curriculum

The gym framing borrows from an argument circulating in security circles, and Patton reaches for it because leadership keeps optimizing the wrong metric. "We've got leadership saying hurry up and use AI, and we're going to measure success in terms of how much work can be done and how quickly. In pushing for that, they're overlooking workforce development, pipeline, and career progression," she says.

Entry-level roles absorb most AI-related cuts, younger workers know it, and the restructuring reshaping SOC teams lands on exactly the seats where careers begin. Patton sees the pendulum swinging back. "In doing that repetitive entry level work, that's where people learn what the job is, what the implications are, where the edge cases are. We need to be intentional about building these skills in the people we're hiring as part of our AI strategy, not in spite of it."

AI plays the generalist

Security inverts how other professions grow. Doctors and lawyers start general and specialize late. Technologists go deep early, in identity or vulnerability management or GRC, then broaden into architecture. AI enters that ladder from the top. "If we do AI right, and I'm not convinced we're doing AI right yet, it will help senior people do systems integration better, but it won't necessarily help junior people do specialization that much better."

The asymmetry cuts against the layoff logic: the deep expert gets more valuable as general work gets absorbed. "AI at its core is about generalized knowledge, not specialized knowledge," Patton says. "AI may augment the specialist, but it's not going to do the specialist work directly."

Below the security poverty line

The augmentation pitch collides with the average American security team, fewer than 10 people by her count. Vendors selling the AI-native SOC rarely price in who reviews the output. "Even if you stick a whole bunch of AI agents next to a human in a small security team, those agents will still have outputs, and someone is still going to have to oversee those outputs. Under-resourced security teams don't have time for that." Unmanaged, it becomes one more queue that gets abandoned.

Most organizations sit below the security poverty line, Wendy Nather's term for teams lacking the money, political support, and knowledge to defend themselves, and Patton is blunt about it. "More organizations are below the security poverty line than above it." When frontier models began finding vulnerability chains nobody had surfaced, everyone was told to get their own AI to find and patch first. "The small companies aren't going to do that. Even if they've got that one geeky guy on the security team who can program his own agent, it's still not going to happen."

Her nearer-term bet runs through managed providers. "I can see managed security service providers introducing AI into a smaller organization, getting the processes working, getting the AI tuned up, and then transferring that knowledge into the organization."

Security as a common good

None of it substitutes for the discipline underneath. Business processes stretch across third parties with their own third parties, a supply mesh where change coordination matters more than another automation layer and where security outcomes still hinge on people outside the security team. "We call it foundational, and no one does it very well," Patton says.

The fix she lands on is economic. "Until we recognize that security is a common good, and I mean that in an economic sense, a common good that requires community investment and community support, organizations below the poverty line are still going to be below the poverty line."

AI, she thinks, could finally make pooled defense practical. "AI can do stuff at community scale that benefits everybody. That may be the path we need to go. Nobody wants to do that unless there's money in it, so we may have economic disincentives to help ourselves."