人工智能时代:网络安全职位是消亡还是升级? TechButMakeItReal 2025-07-29

人工智能时代的网络安全:炒作与现实

网络安全是下一个被颠覆的领域。这是当前所有文章、图表和人工智能(Artificial Intelligence: 模拟人类智能的机器系统)炒作新闻背后的潜台词。

View/Hide Original English

Cyber security is next. That's the subtext behind every article, every chart, every AI hype headline making the rounds right now.

初级职位消失,分析师被自动化,整个团队被那些不眠不休、从不眨眼、永不倦怠的模型所取代。

View/Hide Original English

Entry-level roles gone. Analysts automated. Entire teams replaced by models that don't sleep, don't blink, and never burn out.

但问题在于,这些说法几乎都没有实际部署数据、团队结构或劳动力市场变化的支撑。

View/Hide Original English

But here's the problem. Almost none of those claims are rooted in actual deployment data, team structures, or labor market shifts.

在本期节目中,我将剖析这些说法,逐一审视每一次裁员、每一项统计数据、每一段引述,并对照实际数据、市场变化以及网络安全团队中七年的人工智能部署经验。

View/Hide Original English

In this episode, I'll dissect those claims, every single one of them, every layoff, every stat, every quote against actual data, market shifts, and seven years of AI deployments on cyber security teams.

最后,我们将查看我们的人工智能信号卡,展示哪些职位正在真正被自动化,哪些正在演变,以及资金流向何处。

View/Hide Original English

And at the end, we're going to look at our AI signal card, showing which roles are really being automated, which ones are evolving, and where the capital is flowing.

让我们深入探讨。

View/Hide Original English

Let's dive in.

举例来说,高盛(Goldman Sachs)2023年关于生成式人工智能的报告预测,到2030年将有3亿个全职工作面临风险,其中网络安全因自动化而被认为是脆弱的领域。

View/Hide Original English

Case in point, Goldman Sachs 2023 report on generative AI predicts 300 million full-time jobs being put at risk by 2030 with cyber security cited as vulnerable due to automation.

位于德克萨斯州奥斯汀的知名美国网络安全公司Crowdstrike宣布裁员5%,称人工智能正在重塑各个行业。

View/Hide Original English

Crowdstrike, a well-known American cyber security company based in Austin, Texas, announces 5% job cut, saying that AI is reshaping every industry.

Reddit上关于网络安全威胁的讨论充满了类似的评论。

View/Hide Original English

Cyber security threats on Reddit are full of comments like these.

这是一个最好的例子之一。

View/Hide Original English

Here's one of the best examples.

Reddit上的一位用户花时间使用clot code进行了一项实验。

View/Hide Original English

A user in Reddit took the time to conduct an experiment using clot code.

他分析了一个WordPress插件的漏洞。

View/Hide Original English

He analyzed a WordPress plug-in for vulnerabilities.

作者指出,目前人工智能在某些细微方面仍面临挑战。

View/Hide Original English

The author notes that currently AI struggles with certain nuanced aspects.

例如,它能生成完美的漏洞利用页面加载,但差距正在迅速缩小。

View/Hide Original English

For example, generated perfect exploit page loads, but the gap is closing fast.

一系列专注于网络安全的在线文章也认同,生成式人工智能(GenAI)将缩小该领域的技能差距,并引用了Gartner等机构的观点,他们认为约50%的初级网络安全职位将被淘汰。

View/Hide Original English

A series of online articles written by sources dedicated to cyber security agree that Genai will reduce the skill gap in the field, citing sources like Gardner who theorize that about 50% of entry-level cyber security positions will be eliminated.

我将对照独立的数据源、现场报告和实际数据来验证这些说法,为您提供一份详细的、有数据支持的分析,以判断哪些是真实的,哪些明显言过其实。

View/Hide Original English

I'll test these claims against independent data sources, field reports, and actual data to give you a detailed data-backed analysis on which of them hold true and which ones are clearly exaggerating.

AI的承诺与现实:自动化、模式识别与错误减少

关于网络安全预测的证据通常围绕三个方面展开。

View/Hide Original English

The evidence when it comes to cyber security predictions are generally framed around three areas.

端到端自动化,即人工智能被宣传为几乎无需人工监督即可分类、调查和修复事件。

View/Hide Original English

End-to-end automation, where AI is promoted as being able to triage, investigate, and remediate incidents with little or no human oversight.

卓越的模式识别。这种说法基于机器学习在检测细微或新兴威胁以及减少错误和疲劳方面能超越人类的信念。

View/Hide Original English

Superior pattern recognition. The claim rests on the belief that machine learning can outperform humans at detecting subtle or emerging threats and reduction of error and fatigue.

鉴于人工智能不会经历倦怠或注意力不集中,人们常说它能够取代容易出现这些问题的分析师。

View/Hide Original English

Given that AI does not experience burnout or lapses in concentration, it is often said to be able to replace analysts who are susceptible to such issues.

现在,让我们谈谈人工智能真正能做什么。

View/Hide Original English

Now, let's talk about what AI is truly capable of doing.

人工智能系统可以持续分析大量的日志、网络数据和用户活动流,以标记异常和潜在威胁。

View/Hide Original English

AI systems can continuously analyze vast streams of logs, network data, and user activities to flag anomalies and potential threats.

机器学习模型可以根据风险背景和潜在业务影响对事件进行分类和优先级排序。

View/Hide Original English

Machine learning models can classify and prioritize incidents based on risk context and potential business impact.

随着人工智能模型的学习和适应,它们可以减少不必要的警报数量,从而降低分析师的疲劳度并减少漏报。

View/Hide Original English

As AI models learn and adapt, they can decrease the volume of unnecessary alerts, lowering analyst fatigue and missed signals.

人工智能工具可以连接端点、网络、电子邮件和云服务中分散的数据点,揭示人类需要更长时间才能识别的关系和攻击路径。

View/Hide Original English

AI tools can connect disperate data points across endpoints, networks, emails, and cloud services, uncovering relationships and attack paths that would take humans much longer to recognize.

先进系统确实通过威胁情报(Threat Intelligence: 关于潜在或现有威胁的信息)为安全分析师提供了更丰富的预置上下文。

View/Hide Original English

Advanced systems do offer security analysts richer contexts upfront through thread intelligence.

一旦事件得到验证,人工智能系统可以执行预定义的遏制或缓解步骤,例如隔离端点、禁用受损账户、阻止IP地址,几乎无需人工干预。

View/Hide Original English

Once incidents are validated, AI systems can execute predefined containment or mitigation steps such as isolating endpoints, disabling compromised accounts, blocking IPs with little to no human intervention.

人工智能可以在事件发生后生成详细的文档,说明采取了哪些响应措施以及吸取了哪些教训。

View/Hide Original English

AI can generate detailed documentation after the incident, which response actions were taken and lesson learned.

AI在网络安全中的实际部署与应用

现在,让我们看看有多少公司已将人工智能实际整合到其团队的网络安全工作中,以及它是否真的有效。

View/Hide Original English

Now let's look how many companies have actually integrated AI into cyber security on their teams and whether it's actually working.

在这一部分,我将引用一份非常新的研究数据,该研究由美国非营利组织ISC2(International System Security Certification Consortium: 国际信息系统安全认证联盟,全球最大的IT安全组织)进行。

View/Hide Original English

For this section, I will be getting my data from a very recent study conducted by a US-based nonprofit organization called ISC2, International System Security Certification Consortium, described as the world's largest IT security organization.

这是一份非常有力且可信的报告,恰逢本视频发布之际,已被新闻媒体广泛引用。

View/Hide Original English

This is a very strong and credible report that has been widely cited by news sources just in time for the video.

该研究基于对436名在美国各种规模组织中工作的网络安全专业人士的见解。

View/Hide Original English

The study is based on insights from 436 US-based cyber security professionals working at organizations of all sizes.

因此,员工规模超过10,000人的大型企业组织在人工智能和网络安全的应用方面处于领先地位,其中37%的企业积极使用人工智能平台。

View/Hide Original English

So enterprise organizations with staff size over 10,000 employees lead the adoption of AI and cyber security with 37% actively using AI platforms.

员工规模在2500到10,000人之间的中大型公司以及100到2500人之间的小型公司,各自的采用率均为33%。

View/Hide Original English

Mid to large companies between 2 and a half to 10,000 employees and smaller companies between 100 and 2 and a half thousand each with 33% adoption.

最小规模的组织则最为保守,有23%表示没有计划评估人工智能安全工具。

View/Hide Original English

The smallest organizations happen to be the most conservative with 23% reporting no plans to evaluate AI security tools.

那么,人工智能在网络安全团队中被用于哪些方面呢?

View/Hide Original English

Now what is AI being used for on cyersack teams?

人工智能在网络监控入侵检测中的应用最为广泛。

View/Hide Original English

AI is being used the most in network monitoring and intrusion detection.

这涵盖了日志和数据密集型功能,人工智能在其中执行重复且耗时的工作,为检测、端点保护和响应(Endpoint Protection and Response: 保护和响应网络中各种终端设备的安全威胁)、漏洞管理(Vulnerability Management: 识别、评估和修复系统漏洞的过程)以及威胁建模(Threat Modeling: 系统化地识别、评估和缓解潜在安全威胁的过程)提供快速响应和反应时间。

View/Hide Original English

This covers log and data heavy functions where AI performs repetitive and timeintensive work, produces fast responses and reaction times for detection, endpoint protection and response, vulnerability management and threat modeling.

所有这些任务都涉及分析大数据集,以监控实时网络信息。

View/Hide Original English

All of these tasks involve analyzing large data sets for monitoring real-time network information.

最后是安全测试(Security Testing: 评估系统安全性以发现漏洞和弱点的过程),这对网络安全人员来说是一项非常耗时的任务。

View/Hide Original English

And lastly, security testing, which is a very time-consuming task for cyber security personnel.

人工智能可以加快测试效率,并确保其正确执行。

View/Hide Original English

AI expedites the efficiency of testing and ensures that it's being done correctly.

如果你将公司声称使用人工智能的目的与人工智能的实际能力进行对比,你会发现两者是匹配的,人工智能确实在网络安全领域被广泛应用。

View/Hide Original English

If you map what the companies claim to be using AI for to what AI can actually do, you will see that these things are matching and AI is truly being used for a lot of things, cyber security.

你可能会想,好吧,那么你之前说的并非全是炒作,网络安全确实正在被取代。

View/Hide Original English

And you may go, okay, so what you said before isn't really hype after all. and cyber security is indeed being replaced.

等等,让我们谈谈历史趋势。

View/Hide Original English

Hold up, let's talk about historic trends.

历史趋势:AI与网络安全融合之路

人工智能从2018年开始被广泛整合到科技公司的网络安全团队中,并在2020年代初期实现了快速加速和广泛整合。

View/Hide Original English

AI began being widely integrated into cyber security teams at tech companies starting 2018 with rapid acceleration and widespread integration occurring in the early 2020s.

最初两年,其特点是利用机器学习工具进行威胁检测和自动化响应,例如阻止可疑活动、隔离受影响的端点以及行为分析。

View/Hide Original English

The first two years it was marked by machine learning tools for thread detection and automated responses like blocking suspicious activity, isolation affected endpoints and behavioral analytics.

在2020年至2022年间,人工智能发展到实时分析(Real-time Analytics: 实时处理和分析数据以获取即时洞察的技术),能够实时分析海量数据,使网络安全团队能够扩展事件分类和响应能力。

View/Hide Original English

Between 2020 and 2022, AI evolved to realtime analytics, analyzing massive volumes of data in real time and allowing cyers teams to scale incident triage and response.

此外,人工智能系统还提高了预测攻击的能力。

View/Hide Original English

Also, AI systems improve their ability to predict attacks.

从2023年至今,人工智能经历了广泛采用和自主安全(Autonomous Security: 无需人工干预即可自动检测、响应和缓解威胁的安全系统)。

View/Hide Original English

Starting 2023 until present, AI went through widespread adoption and autonomous security.

例如,Dark TraceCrowdstrike等平台现在能够生成完全自主的响应。

View/Hide Original English

Platforms like Dark Trace and Crowdstrike, for example, now produce fully autonomous responses.

生成式人工智能(GenAI)正被防御者和攻击者用于更智能的深度伪造(Deepfakes: 利用人工智能生成虚假图像、音频或视频的技术)、网络钓鱼和大型语言模型(LLM: Large Language Model: 拥有数亿甚至数十亿参数的深度学习模型)中毒,这催生了对快速威胁建模和攻击场景模拟的需求。

View/Hide Original English

Jedi is being used by both defenders and attackers for smarter deep fakes, fishing, LLM poisoning, which creates the need for rapid threat modeling and simulation of attack scenarios.

所有这一切都表明,人工智能和网络安全并非新生事物。

View/Hide Original English

All of this is to say that AI and cyber sec is not new.

它在过去七年里一直在发展,这甚至早于ChatGPTPerplexity以及所有“AI优先”的时代。

View/Hide Original English

It's been making its way for the past 7 years and this is before Chad GBT, before Perplexity, before AI first everything.

因此,在我们本系列回顾的所有技术专业中,网络安全是一个非常好的例子,因为它并非两年前才开始。

View/Hide Original English

So, of all tech specializations we're reviewing in this series, cyber sec is a really good example because it didn't start 2 years ago.

人工智能在网络安全领域已经使用了很长时间。

View/Hide Original English

AI and cyber security has been used for a long time.

好的,既然人工智能和网络安全已经存在了一段时间,那么团队规模在过去七十年里肯定一直在缩小,对吗?

View/Hide Original English

Okay, so AI and cyber sec has been around for a while. So teams must have been shrinking for the past 70 years, right?

让我们看看。

View/Hide Original English

Let's see.

裁员真相:AI对网络安全职位的冲击

从最近的裁员数据来看,美国主要科技公司在网络安全运营中整合人工智能,将直接导致初级和重复性操作职位的裁员。

View/Hide Original English

Looking at the recent layoff data, AI integration and cyber security operations at major tech companies in the US is set to directly contribute to layoffs in entry-level and repetitive operational roles.

但这究竟意味着什么呢?

View/Hide Original English

But what does this really mean?

微软(Microsoft)在2025年5月和7月裁减了其全球技术员工的3%。

View/Hide Original English

Microsoft cut 3% of its global tech force in May and July 2025.

网络安全领域的具体裁员数字未披露,但内部报告和外部分析证实,随着基于人工智能的安全系统规模扩大,安全运营和手动监控职位是受影响的职位之一。

View/Hide Original English

CyberSack numbers are not disclosed, but internal reporting and external analysis confirm that security operations and manual monitoring roles are among those affected as AI based security scales up.

亚马逊(Amazon)在2025年7月至少裁减了AWS(Amazon Web Services: 亚马逊云计算服务)内部数百个职位,其中包括安全运营部门。

View/Hide Original English

Amazon at least hundreds of jobs eliminated within AWS including security operations units in July 2025.

同样,网络安全领域的具体数字未披露。

View/Hide Original English

Again, specific numbers for cyersack were not disclosed.

Meta在2024年裁员约5%,其中包括安全运营中心(SOC: Security Operations Center: 负责监控、检测、分析和响应网络安全事件的部门)和信任与安全团队。

View/Hide Original English

Meta laid off about 5% of workforce in 2024, including sock and trust and safety teams.

被裁掉的职位是那些处理日常事件和政策工作流程的。

View/Hide Original English

Laid-off roles were the ones handling routine incident and policy workflows.

在小型公司或非FANG(Facebook, Amazon, Netflix, Google: 指代大型科技公司)企业中,数据也类似,公司层面裁员比例在5%到20%之间,具体的网络安全裁员数字未提及,但受影响的职位包括安全团队中的技术文档撰写人员、手动报告和监控职位。

View/Hide Original English

Data among smaller companies or non-fang enterprises is similar between five to 20% layoffs on the company level specific cyber security numbers not cited but the affected rules include technical writers in security teams manual reporting and monitoring rules.

有趣的是,与面向客户支持、质量保证(QA)或软件工程等其他技术职位相比,离岸外包(Offshoring: 将业务流程转移到海外国家)或近岸外包(Nearshoring: 将业务流程转移到邻近国家)的趋势并不那么明显。

View/Hide Original English

What's interesting is that offshoring or nearshoring is not nearly as pronounced compared to other tech rules such as customerf facing support QA or software engineering.

因此,尽管人工智能已整合到网络安全团队中,裁员确实影响了网络安全职位,但公平地说,它们受到的影响与其他科技行业职位一样多,而受影响最大的职位集中在手动监控、日常事件处理和基本漏洞管理方面。

View/Hide Original English

So while AI has been integrated into cyersack teams and the layoffs have indeed affected cyersack rules in all fairness they've been affected just as much as all other rules across the tech industry and the most affected rules are in manual monitoring routine incident handling basic vulnerability management.

所有这些都是人工智能能够客观上做得更好的例行性和重复性工作。

View/Hide Original English

All of this is routine and repetitive work that AI can't objectively do better.

现在让我们看看团队构成在过去几年中是如何变化的。

View/Hide Original English

Now let's see how the team composition has changed over the years.

团队构成演变:从2018到2025

这是2018年美国一家中型技术原生公司典型的网络安全团队构成。

View/Hide Original English

Here's a typical cyber security team composition at a midsize technative company in the US as of 2018.

2020年,我们看到了云安全工程师(Cloud Security Engineer: 负责设计、实施和维护云环境安全措施的专业人员)等职位,特别是在软件即服务(SaaS: Software as a Service: 通过互联网提供软件应用的服务模式)、基础设施即服务(IaaS: Infrastructure as a Service: 提供虚拟化计算资源的服务模式)和平台即服务(PaaS: Platform as a Service: 提供开发和部署应用所需平台的服务模式)领域。

View/Hide Original English

In 2020, we're seeing roles such as cloud security engineer, especially in software as a service, infrastructure as a service, and platform as a service.

由于云计算的普及和远程工作的激增,这个角色成为了团队的核心。

View/Hide Original English

This role emerged as a core role on the team due to the explosion of cloud adoption and remote work.

随着数据隐私(Data Privacy: 保护个人信息不被未经授权访问或使用的实践)法规如GDPR(General Data Protection Regulation: 欧盟通用数据保护条例)和CCPA(California Consumer Privacy Act: 加州消费者隐私法案)变得更加突出,治理、风险与合规(GRC: Governance, Risk, and Compliance: 确保组织遵守法律、法规和内部政策的框架)团队的工作量也随之增加。

View/Hide Original English

GRC expanded their workload as data privacy such as GDPR, CCPA became more prominent.

通常,团队由6到18名专职人员组成,具体取决于公司规模、云采用速度和行业法规。

View/Hide Original English

Usually the teams range from six to 18 people of dedicated staff depending on the company's size, pace of cloud adoption and industry regulations.

2023年,安全架构师和安全工程师之间的界限变得更加清晰。

View/Hide Original English

In 2023, the delineation between security architect and security engineer became much more pronounced.

在2023年之前,这两个角色通常合并为一个。

View/Hide Original English

Prior to 2023, those was often merged into one role.

SOC分析师(SOC Analyst: 负责监控、分析和响应安全事件的专业人员)一和二合并为一个。

View/Hide Original English

Sock analyst one and two merged into one.

首席信息安全官(CISO: Chief Information Security Officer: 负责组织信息安全战略和实施的高级管理人员)作为高管职位的引入。

View/Hide Original English

The introduction of chief information security officer as a seuite role.

安全工程师的职责范围扩大到网络团队之外,开始将集中式安全功能与嵌入式专家相结合。

View/Hide Original English

Security engineer scope of responsibilities expanded outside of network teams began blending centralized security functions with embedded specialists.

例如,将安全分析师嵌入到产品或云团队中。

View/Hide Original English

For example, embedding security analysts into product or cloud squads.

作为一名产品经理(PM),我可以证实这一点。我在2023年是一名平台产品经理,我与安全团队的合作变得更加紧密。

View/Hide Original English

As a PM, I can attest to this. I was a platform PM in 2023 and my collaboration with security teams became much closer.

这是我第一次真正感受到“左移原则”(Shift Left: 在软件开发生命周期的早期阶段就考虑并解决安全问题)的推动。

View/Hide Original English

This was the first year when I truly felt that push to shift left concept.

如果你没有听说过左移原则,它实际上可以应用于许多方面,但核心概念是,在这种情况下,在发布产品更新、自动化和人工智能以及警报分类和事件工作流程之前,你就要尽早开始考虑安全问题。

View/Hide Original English

In case you haven't heard about the shift left concept, it can apply to numerous things really, but the core concept is that you start thinking about, in this case, security early on before you release product updates, automation and AI and alert triage and incident workflows.

分析师越来越多地审查和调整自动化发现。

View/Hide Original English

Analysts increasingly reviewing and tuning automated findings.

渗透测试(Pentesting: Penetration Testing: 模拟黑客攻击以发现系统漏洞的安全测试)和威胁情报用于进行主动测试,以领先于不断演变的威胁。

View/Hide Original English

Pentesting and thread intelligence to handle proactive testing to stay ahead of evolving threats.

典型的团队规模非常相似,由7到20名专职安全人员组成。

View/Hide Original English

Typical team size is very similar, 7 to 20 people of dedicated security staff.

2025年。大多数例行事件检测、警报分类、报告和漏洞扫描都由人工智能平台处理。

View/Hide Original English

2025. Most routine event detection, alert triage, reporting, and vulnerability scanning are handled by AI platforms.

典型的团队规模是5到12名专职安全人员。

View/Hide Original English

The typical team size is 5 to 12 dedicated security folks on the team.

安全角色被嵌入到产品和IT团队中,以确保所有部署都考虑安全问题。

View/Hide Original English

Security roles are embedded within product and IT teams to ensure security is addressed in all deployments.

左移安全成为标准。

View/Hide Original English

Shift left security is a standard.

人工智能风险和对抗性防御是主要优先事项,催生了新的专业规则。

View/Hide Original English

AI risk and adversarial defense are major priorities prompting new specialized rules.

持续的技能提升。所有团队成员都被期望在人工智能安全管理和云原生防御方面保持高度熟练。

View/Hide Original English

ongoing upscaling. All team members are expected to maintain high fluency in AI security management and cloudnative defense.

因此,正如你所看到的,尽管人工智能已经整合到网络安全中多年,但其功能并未消失,也未被完全自动化或取代。

View/Hide Original English

So as you can see despite AI being integrated into cyersack for quite a few years now the function isn't gone, isn't automated and isn't replaced.

未来展望:网络安全领域的挑战与机遇

最后,让我们看看未来5年的网络安全趋势。

View/Hide Original English

Lastly, let's go through the cyersack trends for the next 5 years.

网络安全被广泛认为是未来5年科技行业中人才短缺最严重的领域之一。

View/Hide Original English

Cyber security is widely cited as the industry that will experience one of the highest shortages in the tech industry in the next 5 years.

多家出版物引用了巨大的数字。

View/Hide Original English

Multiple publications site huge numbers.

67%的公司存在技能差距。

View/Hide Original English

67% of companies experience skill gap.

全球网络安全专家短缺超过400万。

View/Hide Original English

World shortage over 4 million cyber security specialists.

70%的公司将网络风险增加归因于技能差距。

View/Hide Original English

70% of companies attribute increased cyber risk to the skills gap.

因此,无论你往哪里看,都会发现网络安全是人工智能时代的重要职业。

View/Hide Original English

So wherever you look, you will see that cyber security is the job of the AI era.

我们将讨论初级专业人员的要求如何变化。

View/Hide Original English

We will talk about how the requirements are changing for the junior specialists.

但看在上帝的份上,请停止恐慌。

View/Hide Original English

But for the love of God, please stop panicking.

如果有什么东西不会消亡,那就是网络安全。

View/Hide Original English

If there is anything that's not dying, it's cyber sec.

人为因素。

View/Hide Original English

The human factor.

听着,我知道每个人都在为人工智能抢走我们的工作以及所有悲观的头条新闻而恐慌,但老实说,这并不是目前网络安全领域正在发生的事情。

View/Hide Original English

Look, I know everybody's freaking out about AI taking over our jobs and all the doom and gloom headlines, but honestly, that's not what's happening in cyber security right now.

现实要有趣得多。

View/Hide Original English

The reality is much more interesting.

随着人工智能变得更智能,网络犯罪分子也变得更狡猾。

View/Hide Original English

As AI gets smarter, the cyber criminals are getting smarter, too.

我们正在看到大量以前不存在的攻击向量。

View/Hide Original English

And we're seeing a ton of attack vectors that did not exist before.

而且我们甚至还没有开始触及人工智能未来将如何使用的皮毛。

View/Hide Original English

And we haven't even started scratching the surface of how AI will be used as the time goes on.

我们仍处于人工智能监管的早期阶段。

View/Hide Original English

We're still in the early stages of AI regulation.

美国甚至还没有适当的联邦法律来规范它。

View/Hide Original English

The US does not even have proper federal laws governing it yet.

但当这些法规真正出台时,网络安全团队将面临大量工作。

View/Hide Original English

But when those regulations do hit, it's going to be a lot of work for cyber security teams.

我是吃过苦头才明白的。

View/Hide Original English

I learned this the hard way.

这要追溯到人工智能热潮之前几年。

View/Hide Original English

This was years back before the AI boom.

我当时正在开发一款金融科技产品,该产品在欧洲运营。

View/Hide Original English

I was working on a fintech product and that product operated in Europe.

GDPR(General Data Protection Regulation: 欧盟通用数据保护条例)简直让我抓狂。

View/Hide Original English

And GDPR literally drove me insane.

每个月、每个季度都有新的规则、新的法规和新的变化,我们不得不一次又一次地审计我们的整个产品以保持合规。

View/Hide Original English

Every month, every quarter, there were new rules, new regulations, and new changes, and we'd have to audit our entire product all over again to stay compliant.

而且那甚至不是一个人工智能产品。

View/Hide Original English

And that wasn't even an AI product.

而且攻击面正在爆炸式增长。

View/Hide Original English

And attack surfaces are exploding.

到2027年,几乎一半的首席安全官(CSO: Chief Security Officer: 负责组织整体安全战略和运营的高级管理人员)将不得不将其职责范围大大扩展到传统网络安全之外,因为监管压力和攻击面正在激增。

View/Hide Original English

By 2027, almost half of chief security officers are going to have to expand way beyond traditional cyber security because the regulatory pressure and attack surfaces are exploding.

因此,人工智能非但没有扼杀网络安全职位,反而使其比以往任何时候都更加复杂和不可或缺。

View/Hide Original English

So instead of AI killing cyber security jobs, it's actually making the field more complex and essential than it's ever been.

AI时代网络安全专家的生存之道

如何保持竞争力?这是人工智能时代网络安全的记分卡。

View/Hide Original English

How to stay afloat? Here is a scorecard for cyber security in the age of AI.

初级和例行职位的自动化风险为8到9分;中级和专业职位的风险为4到5分;需要上下文、创造力、推理和行业专业知识的高级职位风险最高为1分。

View/Hide Original English

Risk of automation entry level and routine rules 8 to nine. mid-level and specialized 45 and advanced roles that require context, creativity, reasoning, and industry expertise one at most.

现在,我想谈谈关于初级专家不再有需求的问题。

View/Hide Original English

Now, I would like to address the point around junior specialist being out of demand.

不,不,不,不,不,不,不,不。

View/Hide Original English

No, no, no, no, no, no, no, no.

那些技能停留在2020年的初级专家确实不再有需求。

View/Hide Original English

Junior specialists, the skill set of which remained in 2020 are out of demand.

这是真的。

View/Hide Original English

That's true.

但初级职位并不会消失。

View/Hide Original English

But junior roles aren't going anywhere.

它们只是不再是五年前你看到的那些职位了。

View/Hide Original English

They're just not the same roles you saw 5 years ago.

初级专家需要哪些技能呢?

View/Hide Original English

Which skills will be needed for junior specialists?

人工智能原生SOC分析师:与人工智能平台协作,增强安全信息和事件管理(SIEM: Security Information and Event Management: 结合安全信息管理和安全事件管理功能的系统)。

View/Hide Original English

AI native sock analyst working with AI platforms to enhance security information and event management.

人工智能威胁情报分析师:专注于通过管理大量的威胁指标数据集,帮助训练和验证人工智能模型。

View/Hide Original English

AI threat intelligence analyst focus on helping train and validate AI models by managing large data sets of threat indicators.

自动化和安全编排专家:支持安全自动化脚本的开发和维护。

View/Hide Original English

Automation and security orchestration supporting the development and maintenance of security automation scripts.

人工智能治理和合规助理:很可能是一个初级职位,确保用于安全领域的人工智能系统符合道德和合规预期。

View/Hide Original English

AI governance and compliance associates most likely an entry-level role ensuring AI systems used in security are operating in alignment with ethical and compliance expectations.

安全测试助理:测试人工智能驱动的安全工具的健壮性,包括评估它们对对抗性输入的响应。

View/Hide Original English

Security testing assistance testing the robustness of AIdriven security tools including evaluating their response to adversarial inputs.

云安全支持分析师:与人工智能增强的云安全监控工具协作,确保关键云服务和数据存储库的安全性、可用性和防御能力。

View/Hide Original English

Cloud security support analysts working with AI enhanced cloud security monitoring tools to ensure the safety, availability and defense of key cloud services and data repositories.

人工智能只是清除了繁琐的工作,但它并没有取消网络安全。

View/Hide Original English

AI just bulldozed the busy work, but it did not cancel cyber security.

它提升了网络安全的水平。

View/Hide Original English

It leveled it up.

唯一被淘汰的工作是那些“点击此处进行分类”的例行工作。

View/Hide Original English

The only gigs that are getting axed are click here to triage rules.

但那些要求你智胜由大型语言模型(LLM: Large Language Model: 拥有数亿甚至数十亿参数的深度学习模型)驱动的攻击,或将全新攻击转化为固若金汤的防御措施的工作,则变得至关重要。

View/Hide Original English

But the jobs that ask you to outsmart an LLM powered attack or turn brand new attacks into bulletproof controls just became missionritical.

所以,停止无谓的恐慌,开始模型测试,并在ChatGPTGDPR相遇的领域占据主导地位。

View/Hide Original English

So stop doom scrolling, start model testing, and own the space where GBT meets GDPR.

在评论中告诉我你们的想法。

View/Hide Original English

Let me know what you guys think in the comments.

一如既往,希望这有所帮助。

View/Hide Original English

As always, I hope this was helpful.

下次再见。

View/Hide Original English

Till next time.

📌 文中提及的人物和组织