There is a specific moment in every security professional’s career when they realise the traditional rulebook has not just been ignored, it has been torn to pieces. Mine arrived last week while watching a colleague engage in a debate with an AI agent over expense policy, while simultaneously being phished by what was almost certainly another AI posing as IT support.
For decades, the cyber security industry has clung to a comfortable, binary premise: humans work inside the walls, threats exist outside, and our job is to keep the two apart. It was a tidy worldview that made for excellent spreadsheets, even if we knew it was fiction. It also framed security as a prevention game, with success measured by what did not happen.
Then AI walked into the office without knocking. It is a reboot of the classic 2010 iPad launch, where executives demanded connection to the corporate network, heralding the age of ‘bring your own disaster’.
What is different this time is scale and speed. AI does not just connect to the network. It makes decisions, generates content, automates workflows, and interacts with data at a pace no human team can match. That reality forces a shift from pure prevention to cyber resilience. We must assume that errors, misuse, and compromise will occur. The objective is not just to block incidents, but to absorb them, adapt, and recover with minimal impact.
The multispecies workforce
The most uncomfortable truth facing modern organizations is that they no longer employ just humans.
Your current headcount includes Peter from Accounts Payable, his three AI assistants (two sanctioned and one very much shadow), a recruitment algorithm, and whatever experimental automation Marketing has hooked up to Slack to bypass a slow internal process.
They are all making decisions. And they are all sharing data.
When Peter’s AI hallucinates a rogue clause into a vendor agreement, or a chatbot leaks PII because a prompt engineer asked nicely, where does the buck stop? Traditional security loves clean lines such as User versus Admin, Internal versus External. But we are now operating in a blended world. We have created a workforce that is part human and part silicon, yet the risk remains entirely ours to manage.
Cyber resilience accepts this ambiguity. It focuses less on drawing perfect boundaries and more on ensuring that when something goes wrong, contracts can be corrected, data exposure contained, and processes restored quickly. In a hybrid workforce, resilience means designing systems that anticipate AI error rates, human bias, and malicious manipulation as normal operating conditions rather than edge cases.
The futility of punitive security
Historically, we have managed security like a digital Alcatraz. If a user clicks a phishing link, we chastise them. If they use unapproved software, we discipline them.
But punishing people for being human is like shouting at water for being wet. It provides a few seconds of emotional release for the security team, but it does not change the outcome. You cannot discipline your way to a secure culture and you certainly cannot punish an AI agent into making safer choices.
From a resilience perspective, the question is not who to blame, but how quickly you can detect, respond, and learn. A clicked phishing link should trigger rapid containment, credential resets, and intelligence sharing. An unsanctioned AI tool should trigger evaluation and governance, not just reprimand. Resilient organizations treat mistakes as data points that strengthen the system over time.
So what happens when your workforce is 60% human, 40% AI, and rising? You stop pretending that perfection is possible and start engineering for recovery.
Navigating the shadow AI explosion
Shadow AI is not born from malice. It is born from friction. Employees use unsanctioned tools because the approved versions are often slow, restrictive, and designed by people who think user-friendly is a type of malware!
If your IT ticket for an AI request will not be resolved until Q3 2027 but the free version of ChatGPT is open in a browser tab right now, the choice for a busy employee is a foregone conclusion.
Shadow AI is both a risk and a diagnostic signal. It highlights where official processes are too slow to support business reality. Attempting to eradicate the use of AI entirely is unrealistic. Instead, resilient organizations build guardrails that reduce blast radius. They deploy data loss prevention controls, monitor anomalous data flows, and provide sanctioned AI platforms that are as easy to use as their unsanctioned counterparts.
To manage this hybrid reality, we need to view the workforce as a single, unified, complex adaptive system. Securing the blur requires a resilience-first framework:
Govern the decision, not the entity
Governance frameworks must apply to the action, regardless of whether the actor is carbon-based or cloud-hosted. If a human is not allowed to export customer data to a personal drive, their AI assistant should not be able to either. Resilience demands consistent policy enforcement across identities, APIs, and automation.
Design for invisible perimeters
Assume you will never have 100% visibility again. Security must shift toward real-time behavioural monitoring and anomaly detection that tracks patterns across both human and machine activity. Detection and response become as important as prevention.
Build intuitive culture, not just compliance
You teach a child to cross the road by explaining traffic lights, not by screaming at them every time a car passes. The same applies here. You cannot train culture into an AI model, but you can design systems where humans and AI operate within a framework that makes secure behaviour the default. Resilience grows when secure choices are also the easiest choices.
Treat shadow AI as a signal
If half your workforce is using unsanctioned AI, that is not merely a compliance failure. It is evidence that your existing controls are out of step with operational needs. A resilient organization listens to that signal, adapts tooling, and shortens approval cycles so innovation does not outpace governance.
The question is no longer whether your workforce will become a hybrid of human and machine. It already is.
The real question is whether our security models will evolve into resilience-driven architectures that assume compromise, prioritise rapid recovery, and learn continuously, or whether we will keep building expensive walls around a perimeter that vanished years ago.
The workplace has changed. Our job is no longer just to defend it. It is to ensure it can withstand disruption, adapt under pressure, and keep operating when the inevitable incident occurs.
The author
Javvad Malik is Lead CISO Advisor at KnowBe4






