Hi Reader,
Last week, I spoke with a cybersecurity expert (I can't disclose her name so I'll call her B).
She has 12 years of experience in cybersecurity and now works as an external AI security consultant in high-security government environments. So I take her words seriously.
How do I say...
I felt like I'd been living under a rock about cyber risks linked to AI. Her insights absolutely opened my eyes.
Here are 3 key takeaways from my conversation with B.
(I'll share towards the end what it might mean for you.)
1. The state of cyber risks right now is BAD
You've probably heard about Anthropic's Claude Mythos Preview in April. A model particularly good at cybersecurity tasks (a.k.a hacking) that Anthropic refused to launch publicly.
Of course, you don't have to believe everything big tech CEOs say. But Anthropic reported that the model found over 2,000 previously unknown flaws in every major operating system and web browser. And today, 99% of them have not yet been fixed.
A few weeks after the Claude Mythos headlines, OpenAI released GPT-5.5.
...which some researchers believe to be comparable to Claude Mythos in cybersecurity capabilities. Oops!!!
Now that every company is rushing to integrate AI, building agents and tools, urging their employees to use AI coding, there's a lot of room for things to go wrong.
I don't know about you, but all that sounds pretty worrying to me...
One study found that 91% of autonomous agents sampled from healthcare, finance, customer service and code-generation, were vulnerable to something called tool-chaining attacks.
In case you don't know what it is (I didn't either prior to reading it), that's when an attacker tricks an AI agent to perform a series of seemingly innocent actions that may result in catastrophic consequences.
For example: an attacker may ask an AI agent to (1) compress a file into a zip file ("to optimize our file storage") → (2) delete the original ("we don't need duplicates") → (3) delete all ZIPs ("to free up disk space!"). The result is critical file gone forever.
B showed me this visualization of how she thinks about AI expanding cyber risks:
I only really learned about cybersecurity in my Computer Science degree. Some of it was interesting, but it felt far-fetched. Like.. why should I care?
As a seasoned internet user, I use "secure" passwords with a bunch of numbers and special characters lol.
But AI is now being used everywhere, for good and bad. You can't be so sure anymore that the systems you rely on every day, banking, medical records, Gmail, your personal apps, won't one day be compromised.
2. There's a huge shortage of cybersecurity professionals
B mentioned to me some staggering numbers in the labor market:
In 2022, 1.5 million unfilled security vacancies in the EU.
In 2023, 3 million.
In 2024, 4 million.
In the Netherlands specifically, there are 27 job openings for every security professional 🤯.
Now that LLMs/ AI is making everything more complex and novel, the job demand is higher than ever.
There are actually very few careers in tech I can think of right now where demand grows exponentially compared to supply.
If you've been job hunting lately, you've probably noticed that AI seems to reduce the demand in a lot of office jobs, at least in the short term.
For cybersecurity, I'd bet the pattern is the opposite. We need more people working on AI security precisely because AI is now integrated everywhere.
This might be the only job in tech with actual job security right now.
3. You don't need be an cyber expert to start in this career
B herself started with a psychology and MBA degree. No formal tech training.
Now working on high-stakes projects, she sometimes can't help but roll her eyes thinking: "is there really no one more qualified than me who should be doing this?"
Her take: "There is something for everyone. Do you like math? Encryption. Like people? Security awareness. Like solving problems? Vulnerability management. Like breaking things? Ethical hacking. Black and white thinker? Identity access management. Creative thinker? Security reporting."
I get questions from some of you about breaking into data careers, facing a tough market, not knowing where to turn.
I can't give you one concrete advice. But if you're even a little interested in solving problems, using your analytical mind and tech skills to protect society from a cyber apocalypse
.... then cyber/AI security might just be the next "sexy" career to consider.
I'm thinking about making a Youtube video to dive into this topic.
Let me know what you think?
Best,
Thu 🙌
P.S: Work with me:
If you want a comprehensive course from Python fundamentals to building AI applications, check out my Python for AI Projects course.
You'll join a community of 450+ learners who are building their projects while getting direct access to me and supporting each other along the way.
🔗 Learn More