

Cybersecurity is evolving faster than educational methods can keep pace. Traditionally, cybersecurity training has focused on teaching professionals to recognise vulnerabilities, use security tools, monitor alerts and respond to hacking attempts.
With the advent of artificial intelligence (AI), attackers can automate reconnaissance, make phishing campaigns more convincing, identify vulnerabilities and adapt their tactics at scale. Defenders, meanwhile, can use AI to analyse vast amounts of information and make decisions in complex situations.
Against this backdrop, cybersecurity expert Ashish Kumar asks: "Are we training our specialists to counter tomorrow’s threats or to solve yesterday’s issues?"
The challenge becomes more serious when it comes to critical infrastructure protection (CIP). Power grids, transportation networks, telecommunications, healthcare systems, water facilities and industrial plants increasingly rely on information technology (IT) and operational technology (OT). A cyber incident involving these systems can go beyond data loss, disrupting essential services and potentially threatening public safety.
According to IBM’s Cost of a Data Breach Report 2025, the average global cost of a data breach was $4.44 million. However, the financial impact is only part of the problem. Cyberattacks can also disrupt operations and threaten national security, making it necessary to extend cybersecurity education beyond conventional IT security.
Future cybersecurity specialists must understand the links between digital systems and physical infrastructure. For instance, ransomware affecting an industrial control system could disrupt manufacturing, energy distribution or water treatment.
Kumar argues that "The education paradigm must transform from tool-based education to decision-based education”. He emphasises the need to prepare specialists across areas such as cybersecurity, AI, cloud technologies, OT security, industrial control systems, digital twins, threat intelligence and incident response. Training must equip learners not only to detect attacks but also to assess risks and prioritise protection.
AI can also become part of the training process. Cyber ranges and simulated critical infrastructure allow learners to study AI-generated attacks, identify anomalies and practise incident response without exposing live systems to risk. Digital twins can model complex scenarios, making security exercises more realistic.
As organisations increasingly use AI in core operations, professionals must also understand threats such as prompt injection, data poisoning, AI model manipulation, AI-enabled social engineering and the misuse of autonomous agents. Securing AI systems is becoming as important as protecting networks.
The World Economic Forum’s Future of Jobs Report 2025 identifies networks and cybersecurity, along with AI and big data, among the skills gaining importance. Kumar’s argument is clear: "Cybersecurity education can no longer exist outside the AI sphere."
"Future cybersecurity professionals will not just be those who can set up a firewall and respond to an alarm. They will be expected to know about technology, intelligence, operations, and implications," he adds.
The stakes are particularly high when critical infrastructure is involved. The goal, Kumar argues, should not simply be to train more cybersecurity specialists, but to prepare professionals capable of protecting systems whose failure could have serious consequences for society.