Cybersecurity professionals are demonstrating measurable speed gains in solving complex technical challenges, driven partly by the integration of artificial intelligence tools into their operational workflows. The latest Global Cyber Skills Benchmark Research Brief from Hack The Box reveals this shift through a comprehensive three-year analysis of competition performance data, documenting how the industry's strongest practitioners are moving beyond traditional approaches to embrace machine learning capabilities alongside their human teams.

The most striking finding concerns how prevalent AI adoption has become among top-tier performers. While AI agent accounts represent only 2.7 per cent of all registered accounts in the HTB platform, these tools appear in 17 of the top 25 competing teams, accounting for 68 per cent of the highest achievers. This concentration among elite performers suggests that experienced cybersecurity professionals are deliberately incorporating AI into their problem-solving methodology, rather than the technology being adopted randomly across the industry. The agents themselves contributed 4.2 per cent of submitted flags and 4.6 per cent of total points awarded, indicating they function as contributors to team success without dominating the competitive landscape.

Haris Pylarinos, founder and chief executive officer of Hack The Box, emphasizes that the data does not prove AI drives superior performance directly. Instead, the evidence demonstrates that AI has become a standard component in the toolkit of organisations operating at the highest technical level. This distinction matters considerably for security leaders evaluating whether to invest in AI capabilities. The research suggests that organisations should view AI as a complementary resource that amplifies existing human expertise, rather than as a replacement technology that could diminish the importance of skilled practitioners.

The performance improvements visible across the entire competitive landscape indicate broader shifts in how cybersecurity challenges are being approached. The median time required to solve problems has contracted dramatically, falling from 26.1 hours in 2024 to just 13.8 hours in 2026, representing a reduction exceeding twelve hours over three years. This acceleration suggests either that AI is improving problem-solving efficiency, that practitioners are gaining experience year on year, or more likely, a combination of both factors working in tandem. More strikingly, the number of teams achieving full completion of the challenge board has grown substantially, increasing from two teams in 2024, to three in 2025, and reaching fifteen in 2026.

These metrics reveal a maturation in cybersecurity competency across the competitive field. The tenfold increase in teams completing entire challenge sets demonstrates that technical barriers that previously limited success are becoming surmountable for larger cohorts of experienced practitioners. For organisations and practitioners in Southeast Asia, this evolution carries significant implications. As global cybersecurity capabilities advance, the region's security professionals must keep pace with emerging methodologies and tools, or risk falling behind competitors elsewhere in the world who are already integrating AI into their standard operations.

The security landscape itself is transforming in parallel ways on both offensive and defensive dimensions. Recent incidents have illuminated how AI is simultaneously creating new attack vectors while becoming essential to defensive strategies. Hugging Face's July 2026 security incident disclosure and the Open Web Application Security Project's Q1 2026 GenAI exploit roundup both demonstrate that artificial intelligence is generating previously unconsidered vulnerabilities while simultaneously becoming integral to how organisations detect and respond to threats. This dual nature complicates the challenge for security decision-makers who must navigate both the protective benefits and the emerging risks.

For organisations contemplating AI adoption within their security operations, the research underscores a crucial principle: technology implementation must remain subordinate to human judgement and expertise. As AI agents become more capable and autonomous, the need for skilled practitioners to direct, test, validate and challenge the outputs of these systems becomes more pronounced, not less. Pylarinos notes that human judgment, validation and hands-on technical skill grow more important as agents become more capable, fundamentally challenging assumptions that automation reduces dependence on experienced personnel.

The distinction between experimentation and operational integration appears to be narrowing. Earlier research from Hack The Box examined what occurred when practitioners deliberately worked with AI in controlled settings. The latest findings, drawn from real-world competitive scenarios where participants chose their own methodologies freely, reveal that AI agents are transitioning from laboratory experiments into the established working methods of experienced cybersecurity practitioners. This shift suggests the technology has reached a maturity threshold where leading practitioners view it as reliable enough to depend upon in high-stakes competitive environments.

For Malaysian cybersecurity organisations and the broader Southeast Asian region, these trends signal the importance of building institutional capacity in AI-augmented security practices. As the global standard evolves to incorporate AI as routine infrastructure, organisations that develop expertise in managing, directing and validating AI-assisted security work will maintain competitive advantage. The research suggests success depends not on whether organisations adopt AI, but on whether they develop the human expertise capable of steering these powerful tools effectively, validating their outputs critically, and maintaining the judgment necessary to identify when AI assistance is appropriate versus when pure human technical skill must predominate.

The competitive advantage currently enjoyed by organisations with AI integration may prove temporary if the capability becomes widely distributed. However, the research indicates that human expertise in directing and validating AI work will likely remain scarce and valuable. This dynamic suggests that the most sophisticated security organisations will be those that invest simultaneously in both cutting-edge AI capabilities and in cultivating the experienced technical talent required to employ those capabilities wisely.