Artificial intelligence is rapidly becoming standard equipment for the world's top cybersecurity practitioners, according to new research from Hack The Box, a global leader in cyber skills development. The 2026 Global Cyber Skills Benchmark Research Brief, which analysed three years of competition data, reveals that elite teams are solving cybersecurity challenges substantially faster than before and increasingly leveraging AI agents as part of their operational arsenal. The research provides the most concrete evidence yet of how AI has transitioned from emerging technology to working practice within the professional cybersecurity community.
The scale of AI adoption among high-performing teams is striking. While AI agent accounts represent just 2.7 per cent of all registered competitors, they comprise 68 per cent of the top 25 performing teams—a disproportionate concentration that signals deliberate integration by experienced practitioners. These AI agents were responsible for 4.2 per cent of submitted solutions and 4.6 per cent of total points awarded, demonstrating measurable contribution to competitive outcomes. Yet the research stops short of claiming causation, instead framing AI as one element within a broader tactical approach deployed by organisations with the deepest expertise.
Haris Pylarinos, Founder and Chief Executive Officer of Hack The Box, emphasised that the data reflects AI's role as a complement to human expertise rather than a replacement. "Our data shows that AI is appearing most often alongside some of the strongest practitioners, not instead of them," Pylarinos stated. "As agents become more capable, human judgement, validation and hands-on technical skill become more important, not less." This distinction carries profound implications for cybersecurity training and workforce development across the region, suggesting that future practitioners require not just technical capability but the maturity to evaluate and direct algorithmic outputs.
The performance gains tracked across the three-year period are substantial and raise questions about competitive dynamics in cybersecurity. The median time required to solve challenges has more than halved, falling from 26.1 hours in 2024 to 13.8 hours in 2026. Equally telling is the dramatic increase in teams achieving perfect scores. Only two teams completed the entire challenge board in 2024, three in 2025, but 15 teams managed full completion in 2026. These metrics point to either significant skill elevation among practitioners or, more likely, a combination of improved methodologies—including AI-assisted approaches—and deeper industry maturity.
For Southeast Asian cybersecurity leaders and policymakers, the Hack The Box findings arrive at a critical moment. The region has positioned itself as increasingly crucial to global digital infrastructure, from financial technology hubs in Singapore to manufacturing centres in Malaysia and Thailand. The integration of AI into cybersecurity operations presents both opportunity and risk. On one hand, AI can accelerate threat detection and response at a time when human expertise remains scarce and costly. On the other, the very same technologies are creating new attack surfaces, as evidenced by recent high-profile incidents.
The dual nature of AI's cybersecurity impact cannot be overlooked. Hugging Face's July 2026 incident disclosure and OWASP's Q1 2026 GenAI exploit roundup illustrated that adversaries are weaponising the same AI capabilities that defenders employ. Threat actors leverage large language models and autonomous agents to craft sophisticated phishing campaigns, automate reconnaissance, and develop exploits at speed previously impossible. This arms race dynamic means that organisations cannot assume AI adoption alone confers advantage; instead, cybersecurity effectiveness depends on practitioners who understand both the capabilities and blind spots of these tools.
The research distinguishes between two forms of evidence regarding AI and cybersecurity performance. Earlier Hack The Box work conducted controlled experiments examining how practitioners performed when explicitly working with AI assistance. The current findings draw from organic competition data where participants freely chose their own approaches, creating a more authentic picture of how the industry is actually adopting these technologies. This shift from laboratory conditions to real-world deployment choices reveals that AI has moved beyond novelty status and into the operational methodologies of organisations competing at the highest level.
For cybersecurity teams in Malaysia, Singapore, and across ASEAN, the practical implications are significant. The research suggests that AI competency—not just technical knowledge but the ability to direct, validate, and critically evaluate AI-generated outputs—is becoming a core requirement for professional advancement. Teams seeking competitive advantage cannot simply purchase AI tools and expect superior performance. Instead, organisations must invest in training that develops human judgment alongside technical skills, creating practitioners capable of understanding when to deploy AI and when human intuition and expertise remain irreplaceable.
The findings also highlight emerging skills gaps that governments and educational institutions must address urgently. If AI agents account for nearly 70 per cent of top-tier teams yet constitute only 2.7 per cent of total participants, a significant capability gap exists between elite performers and the broader cybersecurity workforce. This disparity threatens to create a two-tier security landscape where well-resourced organisations leverage AI effectively while underfunded or less sophisticated teams fall further behind. For developing economies in the region seeking to build robust cybersecurity capacity, the risk is that AI adoption becomes another factor widening the divide between haves and have-nots.
The trajectory evident in Hack The Box data suggests that AI integration in cybersecurity will intensify. As agents become more sophisticated and more practitioners gain experience deploying them, the competitive pressure to adopt will increase. However, the research offers a crucial counterbalance to hype-driven narratives about AI replacing human expertise. Instead, it demonstrates that the most successful organisations treat AI as a force multiplier requiring human direction. This insight should guide investment decisions, training priorities, and policy frameworks across Southeast Asia as the region navigates its cybersecurity future.
