Hack The Box Blog | Cybersecurity News

The Unappraised Half of the Cyber Workforce: Building Readiness for Human and Agentic Teams

Written by SportyBartlett | Oct 6, 2026, 9:00:00 AM

Cybersecurity teams are undergoing a fundamental transformation as AI agents join human teams in active operations and augment our skills. The cyber workforce is evolving, including two kinds of worker: human and agentic.

 

While enterprises maintain clear performance management frameworks to hire, train and assess human talent, AI agents often enter production environments on the strength of a single static benchmark or vendor demonstration. Once deployed, these agents often operate indefinitely without ongoing evaluation against the specific job roles they were assigned to perform.

 

This dynamic creates a significant operational blind spot. Model architectures change, software harnesses update, user prompts and data sets evolve, and threat vectors shift continuously. An AI agent that demonstrated proficiency last quarter may degrade over time or fail entirely when exposed to emerging adversarial tactics. If agents perform security work, they must be held to verifiable occupational standards and re-appraised as conditions change or given a termination date. Enterprises require a new operating discipline for this workforce. We call it Agentic Worker Competence.

 

Yet evaluating agent capability represents only half of the equation. As autonomous systems take on greater execution responsibilities, human domain expertise naturally pivots toward direction, verification, and strategic intervention. Access to AI tools is not a replacement for competence and judgement. Modern security professionals require the critical judgment to know when to trust an agent, when to challenge its outputs, and when to manually take control.

 

This is where Agentic Operator Competence Scoring comes in. Measuring the judgment behind AI-assisted work, rather than simply tracking tool adoption. Together, these methodologies underpin Cyber Workforce Development for Human and Agentic Teams: developing people, understanding agent capability, and building confidence in how both perform together under real-world stressors and challenges.

 

"AI does not remove the need for cyber expertise. It changes where that expertise matters most. The strongest security teams will not be the ones that simply deploy the most AI. They will be the ones with people who have the judgment to direct it, verify its work, and step in when needed. And with agents that are held to the same standards as the people they work beside. Cyber readiness now means building confidence in both," said Haris Pylarinos, founder and CEO of Hack The Box.

The four hidden operational failures

Without structured validation of both human operators and autonomous tools, AI integration introduces subtle risks that rarely trigger traditional security monitoring. Operational queues continue to move and Security Operations Center (SOC) dashboards remain green while underlying team capability quietly degrades.

  • Automation bias: Practitioners gradually cease challenging agent outputs, relying passively on automated recommendations without verifying underlying assumptions.
  • Skill atrophy: As routine tasks are automated, operators lose the hands-on practice needed to validate agent outputs or intervene effectively during system failures.
  • The "missing middle": Automating entry-level analysis eliminates the traditional apprenticeship pathways through which junior analysts develop into senior experts.
  • Silent agentic drift: Agent execution degrades as underlying models, software dependencies or target environments evolve, even while infrastructure monitoring tools report normal operations.

 

Solving these challenges requires more than simply deploying additional tools. It demands a clear framework for how human judgment and agent execution evolve together under real-world pressure.

Defining Agentic Worker Competence

Applying rigorous standards to autonomous systems requires a clear operational definition. Agentic Worker Competence is recurring, evidence-based proof that an AI agent can perform the job it was designed to do under realistic conditions. A one-time assessment is not enough. As models, tools, data, operating environments and threats change, agents must be continuously pressure-tested against the job framework, responsibilities and performance standards assigned to them.

 

Agentic Worker Competence fills the critical operational gap between granting an agent permission to act and verifying its ongoing performance on the job.

 

Redefining Roles: Developing the AI-Augmented Operator

 

The professionals responsible for directing AI effectively are already on the enterprise payroll. Their day-to-day work has transitioned from execution alone to directing, validating, and governing agentic operations across many disciplines, from SOC analysis to penetration testing and incident response.

 

To support this transition, existing industry job functions must be re-anchored around human-agent workflows and continuous assessments. By mapping these responsibilities to established framework standards such as the National Initiative for Cybersecurity Education (NICE) Workforce Framework for Cybersecurity and the Department of War (DoW) Cyber Workforce Framework (DCWF), organizations can establish clear competency metrics for AI-augmented security roles.

 

This is why Hack The Box is pioneering a new approach to established cyber roles around this shift, developing an AI-augmented role architecture that integrates AI capabilities and maps them to established workforce frameworks.

 

Measuring Operator Competence & Appropriate Reliance

 

Evaluating agent capability alone tells only half of the story. Security leaders must also determine whether security personnel possess the judgment required to oversee autonomous assets effectively.

 

That goes beyond knowing how to prompt a model. An operator can be comfortable using AI tools yet fail to recognize a plausible but fundamentally flawed analysis. Equally, over-intervening in valid AI workflows eliminates the speed and efficiency benefits that automation was intended to deliver. The real skill is appropriate reliance and judgement.

 

Agentic Operator Competence Scoring moves beyond course completion metrics to evaluate how effectively practitioners direct AI in real-time scenarios:

  • Can the practitioner identify subtle errors in an agent's analytical logic?
  • Do they allow approved, automated decisions to proceed without unnecessary friction?
  • Do they understand the technical rationale behind an agent's recommended action?
  • Can they direct AI operations toward an objective without compromising scope, cost, or risk boundaries to the business?
    Confidence and competence look identical until an agent makes a critical error. Measuring human judgment provides enterprise leaders with clarity on whether AI adoption is genuinely building resilience or merely masking an over-reliance on automation.

Three Dimensions of Workforce Readiness

To build operational resilience, security leadership must evaluate readiness across three interconnected dimensions:

  • The human: Does the practitioner possess the domain expertise required to direct AI assets, validate outputs, and intervene when logic fails?
  • The team: Can human operators and AI agents collaborate seamlessly when handoffs, escalations, and decisions occur under operational pressure?
  • The agent: Can the autonomous system execute its assigned role reliably, and does that performance hold as environments and threat vectors evolve?

 

Hack The Box benchmark research demonstrates this necessity. In recent evaluation runs, autonomous AI agents ranked among top-performing technical teams in sheer speed, yet elite human-led teams consistently maintained superior overall task completion rates and strategic judgment. Organizations that develop human capability and agent capability together achieve far greater resilience than those relying on technology in isolation.

The Path Forward

AI agents are rapidly transitioning from experimental tools to core components of the workforce. As autonomous systems gain broader access to network environments, corporate data, and operational workflows, executive boards are asking direct questions regarding risk management, cost efficiency, and performance assurance.

 

Assuming that an AI agent's initial deployment performance will remain sufficient indefinitely is no longer an acceptable strategy. Realistic, repeatable evaluation is essential both before expanding operational responsibilities and as autonomous platforms evolve.

 

Hack The Box launched AI Range in December 2025 to provide a controlled environment for evaluating AI capabilities against realistic cybersecurity challenges. AI Range Enterprise Edition extends that principle to organizations that need to understand how their agents perform against the cybersecurity roles they are being asked to support.

 

The broader mandate for security leaders is clear: true workforce readiness requires human judgment, reliable AI agents and evidence that both can perform effectively together as a unified workforce.

Learn how to evaluate and upskill your human and agentic security teams with Hack The Box's Cyber Workforce Development Solutions.