Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Cyber resilience»Beyond security: how cyber must evolve for the hybrid human–AI workforce (Page 13)
Cyber resilience

Beyond security: how cyber must evolve for the hybrid human–AI workforce

Workforces are rapidly becoming augmented by AI. Javvad Malik examines the security risks emerging from this shift and explains why moving from cyber security to resilience is essential.
February 24, 20266 Mins Read
Digital human identities composed of data figures representing workforce transformation.

There is a specific moment in every security professional’s career when they realise the traditional rulebook has not just been ignored, it has been torn to pieces. Mine arrived last week while watching a colleague engage in a debate with an AI agent over expense policy, while simultaneously being phished by what was almost certainly another AI posing as IT support.

For decades, the cyber security industry has clung to a comfortable, binary premise: humans work inside the walls, threats exist outside, and our job is to keep the two apart. It was a tidy worldview that made for excellent spreadsheets, even if we knew it was fiction. It also framed security as a prevention game, with success measured by what did not happen.

Then AI walked into the office without knocking. It is a reboot of the classic 2010 iPad launch, where executives demanded connection to the corporate network, heralding the age of ‘bring your own disaster’.

What is different this time is scale and speed. AI does not just connect to the network. It makes decisions, generates content, automates workflows, and interacts with data at a pace no human team can match. That reality forces a shift from pure prevention to cyber resilience. We must assume that errors, misuse, and compromise will occur. The objective is not just to block incidents, but to absorb them, adapt, and recover with minimal impact.

The multispecies workforce

The most uncomfortable truth facing modern organizations is that they no longer employ just humans.

Your current headcount includes Peter from Accounts Payable, his three AI assistants (two sanctioned and one very much shadow), a recruitment algorithm, and whatever experimental automation Marketing has hooked up to Slack to bypass a slow internal process.

They are all making decisions. And they are all sharing data.

When Peter’s AI hallucinates a rogue clause into a vendor agreement, or a chatbot leaks PII because a prompt engineer asked nicely, where does the buck stop? Traditional security loves clean lines such as User versus Admin, Internal versus External. But we are now operating in a blended world. We have created a workforce that is part human and part silicon, yet the risk remains entirely ours to manage.

Cyber resilience accepts this ambiguity. It focuses less on drawing perfect boundaries and more on ensuring that when something goes wrong, contracts can be corrected, data exposure contained, and processes restored quickly. In a hybrid workforce, resilience means designing systems that anticipate AI error rates, human bias, and malicious manipulation as normal operating conditions rather than edge cases.

The futility of punitive security

Historically, we have managed security like a digital Alcatraz. If a user clicks a phishing link, we chastise them. If they use unapproved software, we discipline them.

But punishing people for being human is like shouting at water for being wet. It provides a few seconds of emotional release for the security team, but it does not change the outcome. You cannot discipline your way to a secure culture and you certainly cannot punish an AI agent into making safer choices.

From a resilience perspective, the question is not who to blame, but how quickly you can detect, respond, and learn. A clicked phishing link should trigger rapid containment, credential resets, and intelligence sharing. An unsanctioned AI tool should trigger evaluation and governance, not just reprimand. Resilient organizations  treat mistakes as data points that strengthen the system over time.

So what happens when your workforce is 60% human, 40% AI, and rising? You stop pretending that perfection is possible and start engineering for recovery.

Navigating the shadow AI explosion

Shadow AI is not born from malice. It is born from friction. Employees use unsanctioned tools because the approved versions are often slow, restrictive, and designed by people who think user-friendly is a type of malware!

If your IT ticket for an AI request will not be resolved until Q3 2027 but the free version of ChatGPT is open in a browser tab right now, the choice for a busy employee is a foregone conclusion.

Shadow AI is both a risk and a diagnostic signal. It highlights where official processes are too slow to support business reality. Attempting to eradicate the use of AI entirely is unrealistic. Instead, resilient organizations build guardrails that reduce blast radius. They deploy data loss prevention controls, monitor anomalous data flows, and provide sanctioned AI platforms that are as easy to use as their unsanctioned counterparts.

To manage this hybrid reality, we need to view the workforce as a single, unified, complex adaptive system. Securing the blur requires a resilience-first framework:

Govern the decision, not the entity

Governance frameworks must apply to the action, regardless of whether the actor is carbon-based or cloud-hosted. If a human is not allowed to export customer data to a personal drive, their AI assistant should not be able to either. Resilience demands consistent policy enforcement across identities, APIs, and automation.

Design for invisible perimeters

Assume you will never have 100% visibility again. Security must shift toward real-time behavioural monitoring and anomaly detection that tracks patterns across both human and machine activity. Detection and response become as important as prevention.

Build intuitive culture, not just compliance

You teach a child to cross the road by explaining traffic lights, not by screaming at them every time a car passes. The same applies here. You cannot train culture into an AI model, but you can design systems where humans and AI operate within a framework that makes secure behaviour the default. Resilience grows when secure choices are also the easiest choices.

Treat shadow AI as a signal

If half your workforce is using unsanctioned AI, that is not merely a compliance failure. It is evidence that your existing controls are out of step with operational needs. A resilient organization listens to that signal, adapts tooling, and shortens approval cycles so innovation does not outpace governance.

The question is no longer whether your workforce will become a hybrid of human and machine. It already is.

The real question is whether our security models will evolve into resilience-driven architectures that assume compromise, prioritise rapid recovery, and learn continuously, or whether we will keep building expensive walls around a perimeter that vanished years ago.

The workplace has changed. Our job is no longer just to defend it. It is to ensure it can withstand disruption, adapt under pressure, and keep operating when the inevitable incident occurs.

The author

Javvad Malik is Lead CISO Advisor at KnowBe4

Africa Asia Asia Pacific Australasia Europe Middle East North America UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleThe quantum threat is real and it’s not just a future issue
Next Article Two-thirds of security incidents traced back to identity-related weaknesses

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
Corporate Governance Guiding Principles for Board Oversight cover

COSO releases guidance for board risk management and internal control oversight

April 8, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?