Throughout July, ISC2 Insights has focused on trends and issues relating to artificial intelligence (AI). We have collated all the resources we have published this month into one place for ISC2 members and the wider cybersecurity community to share and use going forward.

AI Month on ISC2 Insights highlighted a clear message: AI is not replacing cybersecurity professionals, but it is fundamentally reshaping how they work, the skills they need and the responsibilities they carry. The month brought together exclusive new research, member perspectives, expert interviews and the two-day AI Spotlight event to explore AI’s impact on security operations, governance, workforce development and risk management.

Key Themes from AI Month 2026

One of the strongest themes was the growing importance of human judgement. ISC2 research showed that as AI becomes embedded in cybersecurity workflows, professionals are spending more time validating AI outputs, deciding when to trust recommendations and maintaining accountability for decisions. The findings reinforced that governance, oversight and critical thinking are becoming more valuable, not less, in an AI-enabled environment.

The campaign also explored how AI is redefining cybersecurity roles. Contributors argued that many operational tasks are becoming automated, shifting practitioners away from manual processing and towards supervision, decision-making, risk assessment and organizational alignment. Rather than eliminating careers, AI is driving the evolution of existing roles and creating demand for new skills.

Throughout July, ISC2 emphasized its commitment to developing an AI security certification, with thousands of cybersecurity professionals signing up to help define the knowledge and skills required to secure AI systems and manage AI-related risks.

Your View: The Impact on Cybersecurity Roles

To conclude AI Month, we asked cybersecurity professionals via the ISC2 LinkedIn page what they thought the overall impact of AI would be on their cybersecurity role over the next 12 months?

More than half (60%) of the 875 people that participated said that they see the impact of AI on their role as positive. In contrast, nearly a quarter (22%) said they believed the overall impact on their role would be negative. Even though we were looking at a relatively short-term outlook, a further 13% said they did not know, while just 4% believe that AI will have no impact at all on their role.

All of the articles published this month are below for your future reference and to share with your colleagues and communities:

Research

  • Rethinking AI's Impact on Cybersecurity Roles
    ISC2 conducted a survey of 856 cybersecurity professionals who use AI in their roles. We asked participants questions about how AI is changing the time they spend on security tasks, their perspectives on how entry-level roles may be evolving, whether AI is affecting their workplace-related stress and more.

Level of Concern Around Autonomous AI in Cybersecurity

Events, Videos and Webinars

  • The AI Replay: Curated Picks from ISC2 Webinars
    This series features top AI webinars, ISC2 members can earn CPE credits for watching these webinars.
  • AI’s Cybersecurity Disruptive Influence
    ISC2 Insights talked with chief security evangelist and advisory CISO at Segura Joseph Carson, CISSP, about the technical and operational disruption resulting from the rapid adoption of AI tools and technologies within cybersecurity and more broadly in organizations.
  • AI and Cybersecurity Risk
    ISC2 Insights sat down with security advisor Luca Lumini, CISSP, to discuss AI and cybersecurity risk management.
  • The Cybersecurity Challenges Posed by Agentic AI
    ISC2 Insights talked to CISO, former pentester and offensive security expert Alex Haynes, CISSP about the impact of agentic AI on cybersecurity teams and workflows.
  • Effective AI Threat Modelling
    As AI rapidly becomes embedded across every organization function, as well as being heavily leveraged by bad actors to support their nefarious aims, cybersecurity teams are racing to understand what threats apply -- and how to model them. ISC2 Insights spoke to cybersecurity executive Vincent Romney CISSP, CCSP, CSSLP for his take on the challenge of performing effective threat modelling in today’s AI-centric environment.
  • The Impact of AI on Cybersecurity Panel Discussion
    ISC2 Insights talked with members Christopher Pope, CISSP, CCSP and Daniel Marques, CISSP, about how the rapid adoption of AI is transforming how cybersecurity teams carry out their work, the beneficial role that AI is playing in day-to-day cybersecurity roles and how it is changing roles and responsibilities.
  • Turning AI Risk into Security Strategy
    AI is already embedded in security operations. The challenge now is no longer adoption; it's control. As organizations integrate AI into workflows, tools and decision-making, they're also introducing new risks: reduced visibility, expanded attack surfaces and a growing gap between governance and implementation.
  • Are Incident Response Programs Ready for AI?
    At ISC2’s Spotlight event on AI, Matt Stamper, CEO and CISO advisor for Executive Advisors Group and co-author of the CISO Desk Reference Guide explored the impact of AI on traditional approaches to incident response and whether organizations are approaching both effectively.
  • Taming AI Sprawl and Shadow AI Through Strong Governance
    The ISC2 Spotlight on AI saw an industry panel session explore how strong AI governance practices can help organizations regain control before bad actors can weaponize and exploit these problems. Panelists discussed practical approaches for identifying shadow AI, governance and frameworks, reducing uncontrolled AI proliferation, and the challenges around AI visibility and accountability.
  • The State of AI Security: Why the Stakes Have Never Been Higher
    AI security is a primary focus across ISC2 Security Congress 2026, October 24-28 at the Gaylord Rockies and virtual. You’ll hear firsthand how organizations are applying security thinking to agentic systems, autonomous decision-making and modern detection challenges.

Member Voices

  • Why Segmentation Alone Isn't Enough to Stop AI-Enhanced Attacks
    How do we protect our networks and data vaults from modern multi-vector, AI-enhanced attackers? As Nicholas DiCola, CISSP argues, it takes more than static segmentation and perimeter firewalls; defenders need a living tapestry of controls to outmaneuver evolving tactics.
  • Why This is the Year Roles Start to Re-Platform and How to Keep Teams Ready
    The most recent ISC2 Cybersecurity Workforce Study confirmed a shift that many cybersecurity professionals have been feeling for years: that AI has moved from experimental tooling into the operational core of security teams. Here’s what that looks like in practice, according to Gerhard Kessel, CISSP.
  • We Have AI Everywhere but Control Almost Nowhere
    For years, Ali Nouman, CISSP, held the view that his job was fairly contained: secure the infrastructure, manage identities, keep an eye on where data was flowing and make sure someone could always answer “who’s responsible for this.” The whole control model was built on the assumption that people knew what they were protecting. He explains how and why AI broke that assumption.
  • Building Data Trust in an AI-Driven World
    Early in the career of Neha Chandnani, CC, data security felt straightforward. Protect the network, lock down endpoints and restrict access – because, if the perimeter was secure, the data inside it was assumed to be safe. Today, data moves constantly across cloud platforms, third-party services, APIs and AI pipelines.
  • The Impact Of AI-Driven Cybersecurity Tools on Workforce Roles, Regulatory Accountability and Resilience
    Vaishali Mutalik, CISSP has watched cybersecurity teams quietly undergo one of the most significant role shifts of their careers – not because of a new regulation or a major breach, but because AI quietly entered the operational core of security work.
  • Cyber Judgement – Securing the Human Layer in the Age of Synthetic Legitimacy
    AI is no longer only a future risk or a theoretical topic. On the front line, AI is already changing how attacks look and feel. Sachiko Hasumi, CISSP, CCSP, argues that we may be missing another serious problem, the gradual erosion of human trust.
  • Why AI Agents Demand a New Workforce Model
    Today, the question is not how many people sit on a security team, but whether the people already there can account for actions that machines now perform on their behalf, writes Nik Kale, CISSP.
  • The Real AI Risks are the Assumptions We Stop Challenging
    For more than 17 years, Deinkumo Liberty, CC, has worked in safety-critical operations across offshore and onshore drilling facilities. He shares the most important lesson learned; how disciplined organizations make decisions when the consequences of getting them wrong are unacceptable.
  • AI Adoption is Not Cybersecurity Maturity – My Lessons from the Field
    Nearly a third of respondents to an ISC2 study said their teams have already integrated AI security tools into their operations. As Vu Van Than, CISSP, SSCP, CC argues, it raises a critical question. What if the real risk is not that cybersecurity teams are adopting AI too fast, but that we are adopting it before we’ve learned how to question it?
  • Securing Retrieval-Augmented Generation Systems in the Cloud
    Retrieval-Augmented Generation (RAG) has become one of the most practical ways for organizations to extend large language models with their own data. As Charles Chibueze, CISSP and Omorinsola Goriola, CISSP explain, such systems pose a multitude of risks as they process proprietary documents, accept free-form user prompts, integrate with cloud APIs and generate responses that can directly influence real-world actions.

AI Security Certification

Professional Development

Features and Guides

The Conversation Continues

This collection of articles, research and webinars highlights the tight integration of AI and cybersecurity. As the conversation continues within ISC2 Insights and on social media, we remain committed to delivering timely insights that help cybersecurity professionals lead and learn about the constantly evolving AI technology and threat landscape.

For You, By You: Join Us and Build ISC2's AI Security Certification

As cybersecurity professionals evolve and adapt their skillset and job functions because of AI, ISC2 has announced the development of a new AI security certification to recognize and benchmark AI skills and competence within the cybersecurity workforce.

The AI security certification development process presents an opportunity for cybersecurity professionals to input into the process and help define parameters for the certification.

This is your moment to play a defining role at the foundation of this new certification:

  • Contribute to identifying the knowledge, skills and abilities necessary to securely design, implement and manage AI systems
  • Creating questions for a pilot exam
  • Participate in publicly available pilot exams to help ensure it accurately validates a candidate capabilities

For more information about the ISC2 AI security certification program and how to contribute to the various development activities taking place, go to https://www.isc2.org/new-ai-certification.