Cybersecurity professionals are increasingly turning to artificial intelligence tools to accelerate their work, according to fresh research from Hack The Box, a global platform for developing and validating technical security skills. The 2026 Global Cyber Skills Benchmark Research Brief, analysing competition data spanning three years, demonstrates that AI integration has moved beyond experimental pilots into the mainstream toolkit of the industry's strongest practitioners. The findings carry significant implications for how organisations across Malaysia and Southeast Asia approach their own security operations, particularly as regional businesses face mounting pressure to defend against sophisticated cyber threats with limited technical resources.

The research presents a striking picture of AI's penetration at the elite end of the cybersecurity talent spectrum. Although AI agent accounts represent merely 2.7 per cent of all registered participants in HTB competitions, these tools show far greater prominence among the highest performers. Seventeen of the top 25 teams, equating to 68 per cent, had incorporated at least one AI agent into their operation. This concentration at the top suggests that advanced practitioners, already skilled in cybersecurity fundamentals, are leveraging AI to augment rather than replace their capabilities. The AI agents accounted for 4.2 per cent of submitted solutions and 4.6 per cent of total points earned, indicating they contribute meaningfully but remain supplementary to human effort rather than dominant forces.

Critically, the research distinguishes between correlation and causation. HTB emphasises that the data does not prove AI adoption directly causes superior performance. Instead, the findings reveal that sophisticated cybersecurity teams are making deliberate choices to incorporate AI into their methodologies. This nuance matters significantly for organisations evaluating their own technology investments. The implication is that high-performing teams possess the judgement and experience needed to deploy AI effectively, whereas teams lacking foundational expertise may struggle to extract genuine value from such tools. For Malaysian enterprises and regional institutions building security capabilities from scratch, this underscores the continuing importance of developing human expertise rather than assuming technology alone solves security challenges.

Haris Pylarinos, Founder and Chief Executive Officer of Hack The Box, articulated a crucial principle emerging from the research: AI is appearing alongside the strongest practitioners, not replacing them. He emphasised that as AI agents become increasingly capable, the opposite of what some might intuitively expect occurs. Rather than diminishing the value of human judgment and hands-on technical skill, advanced AI capabilities actually elevate the importance of these human elements. Security practitioners must now develop the ability to direct AI tools effectively, scrutinise their outputs critically, and validate recommendations before implementation. This shift places a premium on a different class of expertise: the ability to work intelligently with intelligent systems.

Performance metrics across the HTB competition landscape have undergone dramatic transformation over the three-year period. The median time required to solve security challenges has plummeted by more than 12 hours, declining from 26.1 hours in 2024 to 13.8 hours in 2026. This 47 per cent improvement in speed represents a substantial acceleration in how quickly elite practitioners can diagnose and remediate security problems. Simultaneously, the number of teams achieving complete mastery of the challenge board has expanded sevenfold, rising from just two teams in 2024, through three in 2025, to fifteen in 2026. These metrics suggest that the combination of improved tools, including AI, and evolving practitioner capabilities is fundamentally reshaping how quickly security challenges can be addressed.

The broader cybersecurity landscape is becoming increasingly complex in ways that make AI integration both more attractive and more risky. Recent incidents underscore this dual nature. Hugging Face's July 2026 incident disclosure and OWASP's Q1 2026 roundup of generative AI exploits both demonstrate that AI systems themselves create new attack surfaces and vulnerability vectors. Simultaneously, these same AI capabilities prove essential for mounting effective defensive responses. For security leaders across the region, this paradox presents a central challenge: they must incorporate AI into defensive operations to remain competitive, whilst simultaneously understanding and mitigating the fresh risks these systems introduce. The equation has become more complex than simple adoption versus rejection.

For organisations seeking to strengthen their cybersecurity posture, the research offers practical guidance. The priority is not merely acquiring and deploying AI tools, but ensuring that the security teams using these tools possess the foundational knowledge and judgement to direct their deployment effectively. This requirement elevates the importance of ongoing technical training and skill development. A team equipped with strong fundamentals can leverage AI to accelerate routine tasks and amplify their capabilities. A team lacking these fundamentals may find that AI tools generate plausible but flawed recommendations, creating a false sense of security that masks underlying vulnerabilities.

The progression from HTB's earlier controlled research to this latest open competition analysis reveals a significant transition in how AI is being integrated into professional security practice. Earlier experiments examined what happens when practitioners deliberately work with AI under structured conditions. The current study captures organic adoption patterns, where competitors freely chose whether and how to employ AI agents. This shift from laboratory conditions to real-world competition reveals that experienced practitioners have moved beyond viewing AI as an experimental capability. Instead, they are incorporating it into their standard working methods, suggesting the technology has crossed a threshold from novelty to utility.

The implications for the Southeast Asian cybersecurity landscape are substantial. Across Malaysia, Singapore, Thailand, and Indonesia, organisations are racing to build security capabilities as digital transformation accelerates and regulatory requirements tighten. The HTB research suggests that investing solely in acquiring the latest security tools, including AI platforms, will produce disappointing results without corresponding investment in human expertise. The most effective security operations will be those that combine strong foundational knowledge, critical thinking skills, and strategic deployment of AI agents as force multipliers. This understanding should guide how regional organisations allocate resources across recruitment, training, technology, and operational processes.

Looking forward, the central challenge for security leaders involves maintaining human expertise and judgment as AI capabilities advance. As these systems become more sophisticated and more pervasive, the tendency will be to trust them more readily and scrutinise them less carefully. The HTB findings suggest the opposite approach is correct: greater AI capability demands greater human expertise in validation and direction. Organisations building their security teams should prioritise recruiting and developing professionals who possess both strong technical fundamentals and the critical thinking skills necessary to work effectively with AI. The future of cybersecurity belongs not to those who choose humans or AI, but to those who skilfully integrate both.