Cybersecurity is often treated as a technology problem: buy the right tools, secure the network, and monitor for threats. Those tools matter, but they are only part of it.
Security also depends on the people who manage systems, handle sensitive information, respond to incidents, and decide how new technology will be used. As organizations modernize and adopt AI, cybersecurity has become a workforce strategy issue, not just an IT priority.
Modernization Creates Risk
Most organizations rely on a mix of legacy applications, cloud services, vendor platforms, and custom integrations. Over time, that environment becomes difficult to manage and even harder to see clearly.
Systems don’t always communicate. Data lives in several places. Employees create workarounds when established processes slow them down. A platform purchased for one department may introduce another access point the security team must monitor.
TM Floyd has previously discussed how organizations often add technology faster than they build strategy. Disconnected platforms, fragmented data, and unclear ownership create operational problems and potential security gaps.
Technology may flag unusual activity; however, someone still must decide what it means and what should happen next.
AI Raises the Stakes
AI can analyze data, automate tasks, and support faster decisions. It also raises questions about access, privacy, oversight, and governance.
AI didn’t create most organizations’ existing system problems—it exposed them.
IBM’s 2026 Cost of a Data Breach Report found that one in four malicious breaches studied was AI-enabled. Across the global study, the average cost of a data breach was $4.99 million, while AI-enabled breaches averaged $6 million.
AI can help security teams respond, too. IBM found that extensive use of AI and automation in security operations reduced breach costs by an average of $1.93 million. These tools can help teams detect threats, investigate suspicious activity, and contain incidents faster, but they still require people who know how to use and monitor them.
Skills Matter More
Adding staff may help an overextended team, but headcount doesn’t show whether the right capabilities are in place.
SANS and GIAC’s 2026 cybersecurity workforce research found that cybersecurity skills gaps now outweigh staffing shortages. Organizations may need expertise in cloud security, identity management, compliance, incident response, employee training, or AI governance. One broad job description can’t realistically cover it all.
Build the Right Team
Here are five ways to start building your cybersecurity workforce strategy:
- Identify the systems, data, and operations that matter most
- Map existing capabilities
- Clarify ownership
- Develop employees where training makes sense
- Bring in specialists when full-time expertise isn’t necessary
TM Floyd & Company can help connect your cybersecurity and AI technology plans with the talent needed to support them. Contact us to learn more about how we can support your team.
Resources
Most Companies Are Adding Technology Faster Than They Are Building Strategy | TM Floyd & Company
Cost of a Data Breach Report 2026 | IBM
2026 Cybersecurity Workforce Research Report | SANS Institute and GIAC



