Business leaders in every industry are racing to adopt AI. But while they get excited about the technology’s potential to transform their work, they’re now also confronting an uncomfortable truth: that malicious actors who could harm their business are also using AI to devise ever-more sophisticated cyber attacks.
“AI is not only a superpower for defenders and organisations; it is also a superpower for criminals,” says Haris Pylarinos, CEO and founder of Hack The Box, a global cyber readiness platform which helps organisations develop and measure the capabilities of human and AI cyber teams .
“We are seeing a lot more attacks because of AI. AI can give defenders a significant advantage, but simply adopting it is not enough. The organisations that gain the most will be those investing in the people who know how to direct it, challenge its output and step in when needed.”
Much like some of AI’s most exciting applications, cyber threats are also evolving at breakneck speed, and technical leaders are learning that building real resilience requires a combination of modern tools and human skill and expertise.
This means that simplistic arguments that frame business decisions around “employees versus automation” break down when it comes to cyber readiness, a field where workforce capabilities are central to successful AI investment and adoption.
Building readiness
Hack The Box, which counts more than 800 enterprise customers and a global community of over 4m cybersecurity professionals, helps organisations develop, exercise and measure the capabilities of their cyber workforce through threat-informed learning, hands-on labs and live-fire environments designed to reflect real-world attacks.
“You build readiness by practising under realistic conditions repeatedly. When an incident happens, the team is not encountering that pressure for the first time,” says Pylarinos.
“When an incident occurs, you've practised so many times that you already know how to respond, instead of trying to figure out what to do in a crisis where stress levels are extremely high.”
You cannot measure performance by the days you've avoided a breach.
By engaging its users with regular, simulated cyber threats, Hack The Box also helps chief information security officers (CISOs) prove they’re building organisational resilience, even when it may appear to be business as usual.
“We measure performance by metrics like how fast and how many vulnerabilities penetration testers find in a regular [simulated] pentest,” says Pylarinos.
“Measuring the days you haven't been hacked is not an effective method. You might be hacked today, in a year, or in five years. You cannot measure performance by the days you've avoided a breach.”
Human expertise
And while some might assume that modern cyber tools, powered by today’s most advanced AI models, might be able to fully automate cyber threat prevention, Hack The Box’s platform is built to keep human skill and experience as a part of the process.
“Just as a pilot needs a flight simulator before flying a plane, cybersecurity teams need platforms like Hack The Box to test their human skills and AI capabilities safely and realistically,” says Gibb Witham, the company’s president.
AI effectiveness is directly tied to the user's domain skill: experts can prompt models better and accurately QA the outputs.
This is partly because sophisticated cyber attackers are themselves using a combination of AI and human intelligence, meaning that fully automated defences would likely be outsmarted quickly.
“Cybersecurity is unique because there is a constant, intelligent adversary also utilising AI,” says Witham.
“AI effectiveness is directly tied to the user's domain skill: experts can prompt models better and accurately QA the outputs. Technology leaders shouldn't evaluate AI in a vacuum. Instead, measure the domain capability of your professionals, as higher skill levels yield much greater leverage from AI.”
A new training paradigm for the AI age
The need for human expertise to combat modern cyber threats is one reason business leaders shouldn’t seek to simply replace their employees with AI.
“The companies that fail will be the ones that just install AI everywhere expecting it to solve their problems. The companies that prevail will be the ones that truly invest in the human behind the wheel,” says Pylarinos.
Hack The Box is seeing how AI is transforming not just how attackers work, but how defenders prepare themselves to combat these threats, requiring a whole new training paradigm for a world where humans are constantly working alongside agents.
The companies that prevail will be the ones that truly invest in the human behind the wheel.
“It requires a new level of investment in training and experimentation, to ensure that combined teams of humans and agents are competent and achieve their goals in a productive and efficient way for the business,” says Pylarinos. “Realistic cyber environments give teams a safe place to practice that interaction, measure performance and understand where AI accelerates the work and where human judgment remains essential.”
And, by regularly giving human experts a secure environment, with and without agents, to test their cyber defence skills, their capacity for keeping the threats out is increasing exponentially.
“A normal human without AI could probably go through ten critical alerts per day. With AI, they will be able to handle 20, 40, or 50… The impact is clear,” says Pylarinos.




