Group Purchasing
Group Purchasing

What Happens When AI Gives Us Answers Before We’ve Learned How to Ask the Questions?

Authored byBryan Simon
Bryan Simon

I use AI—a lot. I also find myself arguing with it—a lot. There isn’t a day that goes by when that doesn’t happen, and I don’t expect that to change any time soon.

That may sound strange, but I think it illustrates something important about where we are headed in cybersecurity.

It is undoubtedly true that AI can provide an extraordinary amount of information in seconds. It can explain a protocol, analyze code, suggest a configuration, interpret a log entry, or recommend how to secure a system. And I guess that is what we have become accustomed to in an instantly gratified world.

But receiving an answer and knowing whether that answer is right are two very different things.

Sometimes an AI response is simply wrong. But more interesting are the times when the answer is technically correct but misses an important subtlety. Perhaps it doesn’t account for how something behaves in a particular environment. Maybe the recommended best practice it tells me about has an operational consequence that isn’t immediately obvious. Experience teaches us to recognize those nuances.

That’s why I can argue with AI.

But it raises a question I think our industry needs to take seriously: Where will the expertise required to challenge AI come from?

I entered this field before cybersecurity was a career path. How did I learn? By experimenting. When a new operating system came out, I would explore every setting I could find—every nook and cranny—because I wanted to understand what it did. When I bought a new wireless router, I didn’t stop at the basic configuration pages. I opened the advanced settings. If I didn’t understand something, I researched it. I experimented. Sometimes I broke things. Then I figured out why. And I still do that today. Every single day.

I wasn’t alone. Many of us learned that way. We became active participants in understanding the technology around us.

Now consider that today’s senior cybersecurity practitioners didn’t start as senior practitioners either. They accumulated experience by doing the work: configuring systems, troubleshooting networks, investigating incidents, making mistakes, asking questions, and learning from people who had already encountered some of those problems themselves.

And now further consider what happens as AI begins performing more of the work traditionally assigned to junior practitioners. We certainly gain productivity. But if someone can’t get the junior-level opportunity through which experience is developed, how do we eventually produce the senior practitioner who is expected to validate what the AI is telling us?

I don’t think the answer is to use less AI. I think the answer is to become much more deliberate about how we develop expertise alongside it.

I’ve never been as excited as I am today about the future of our industry. There has never been more information available to someone who wants to learn cybersecurity. There are extraordinary free resources. There are labs we can build ourselves. And now we can have an AI tutor available virtually whenever we want one.

But access to information isn’t the same thing as expertise.

And expertise isn’t simply knowing more.

In cybersecurity, what ultimately matters is what we can do with what we know. We need to take that understanding and turn it into practical defense — defense that makes sense for the systems we’re protecting, the adversaries we’re facing, and the risks that actually matter to our organizations.

You see, there is rarely one universally “right” security answer. A control that makes perfect sense for one organization may be impractical, unnecessary, or even counterproductive for another. Understanding that distinction requires more than knowing what a technology does. It requires judgment. And today, AI cannot substitute for that judgment.

This is one of the reasons I believe practical, real-world cybersecurity education matters even more—not less—as AI becomes more capable. Good training shouldn’t simply give you more answers. It should help you understand the technology underneath those answers, give you opportunities to apply what you’re learning, and expose you to the lessons and context accumulated by practitioners who have already spent years doing the work.

That’s what I continue to strive for as the author of SEC401: Security Essentials. I don’t want someone to leave my classroom simply knowing more about cybersecurity. I want them better equipped to understand their environment, assess its risks, make defensible decisions, and turn what they’ve learned into practical security improvements. And I want them prepared to keep exploring, questioning, experimenting, and building the experience that no six-day course—nor AI—can simply hand them.

So, yes: Use AI. I certainly do.

But learn enough to argue with it.