AI Today

AI and Human Collaboration: The Future of Cybersecurity Testing

Exploring the balance between automation and human expertise in security assessments.

AI and Human Collaboration: The Future of Cybersecurity Testing — article image

The Full Story

As cybersecurity threats grow more sophisticated, the approach to security testing is also evolving. A recent report by Cobalt reveals notable changes in how South African businesses are conducting these assessments. While many organisations initially turned to AI for their penetration testing needs, the reliance on fully automated systems has dramatically decreased.

In 2025, 29% of organisations exclusively used AI for testing, but by 2026, this number plummeted to just 9%. This shift highlights concerns about the effectiveness of automated security scans, with 78% of professionals noting that automated tools often fail to identify critical vulnerabilities. The report illustrated the difference between identifying a vulnerability—simply a point of weakness in a system—and understanding the pathways potential attackers could exploit to infiltrate a network.

Effective cybersecurity requires not just lists of vulnerabilities but an understanding of how those vulnerabilities interact in a potential exploit. This need is where human insight becomes indispensable. Recent data reflects that the less skilled the tester, the more automation aids the process, while high-skill testers see less benefit from automation.

Consequently, organisations are now leaning towards a hybrid model that combines the breadth of coverage provided by AI with the nuanced judgement of human operators. This approach ensures thorough assessments and accurate identification of threats. Furthermore, continuous testing without qualified personnel raises alarms of its own; an empty report can give businesses a false sense of security without addressing the vulnerabilities present.

The upcoming King V governance framework, effective from January 2026, underscores the importance of accountability and transparency in data testing, emphasising that boards must have clear insights into what is being tested and by whom. This evolution in cybersecurity testing signifies a crucial phase where AI assists in managing vast amounts of data, but human operators remain central in interpreting results and providing context. The balance between automation and human validation will shape the landscape of cybersecurity moving forward, ensuring a more resilient defence against the growing array of cyber threats.

As the industry advances, leaders must prioritise the integration of both technologies, ultimately enhancing their security postures in an ever-changing digital environment. Future assessments will likely revolve around this collaboration, making security more robust than ever before, and highlighting the need for continued investment in both technology and human expertise to safeguard organisations against potential vulnerabilities and cyber threats. To maintain a proactive stance, companies must remain vigilant and continually assess their security frameworks, ensuring they are equipped with both the automated tools and skilled personnel needed to combat current and emerging threats effectively.

Why It Matters

The integration of AI in cybersecurity testing underscores the necessity for human judgement in security assessments, enhancing the defence against cyber threats while ensuring comprehensive coverage and accurate reporting. Governance frameworks like King V set new standards for accountability in this critical area.

What's Next

In the coming months, South African companies will likely begin implementing the new governance standards outlined in King V, reinforcing the need for transparency in cybersecurity efforts and a continued focus on balancing AI automation with human oversight.

Sources