SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsKey findings:
The report describes a workforce being squeezed from multiple directions at once. AI is automating the repetitive entry-level analysis that once trained junior analysts, regulatory frameworks like NIS2, CMMC, DORA, and DoD 8140 are forcing rapid specialist hiring, and organizations are responding by rebuilding from the top down rather than developing talent internally. That combination concentrates hiring authority and skills at senior levels while leaving broader teams under-skilled, and the very budget and time constraints preventing organizations from closing the gap are the same constraints blocking the training that could fix it. Respondents were surveyed globally, with North America representing 56% of the sample, followed by Europe (16%), Latin America (14%), Asia-Pacific (7%), Africa (6%), and the Middle East (2%). Organizations ranged from fewer than 100 employees (19%) to enterprises exceeding 100,000 staff, and 72% of respondents held cybersecurity or InfoSec leadership roles.
The skills gap is now the dominant concern, cited by 60% of organizations compared with 40% citing an inability to hire enough people, according to the SANS | GIAC 2026 Cybersecurity Workforce Research Report.
74% of organizations report AI has influenced team size or role structure, though the report finds this is mostly driven by efficiency gains and new AI-specific roles rather than headcount reduction, which only 16% cited as an impact.
SOC and security analyst roles lead reductions at 32%, followed by threat intelligence analysts (26%) and incident responders (22%) — roles that have traditionally served as entry points into the field.
Expert and senior roles are cited as most difficult to fill by 27% and 22% of organizations respectively, and 55% of senior hires take six months or longer to fill, as organizations rebuild teams from the top down to meet compliance and AI-driven demands.
Yes. 95% of organizations report regulatory directives are affecting their hiring in 2026, up from just 40% in 2025 — a 55-point increase in a single year.


Launched in 1989 as a cooperative for information security thought leadership, it is SANS’ ongoing mission to empower cybersecurity professionals with the practical skills and knowledge they need to make our world a safer place.
Learn more

GIAC Certifications provide the highest and most rigorous assurance of cybersecurity knowledge and skill available to industry, government, and military clients across the world.
Learn more

















