Agentic AI is changing the cybersecurity workday
Agentic AI attacks use software that can plan, adapt and execute multiple steps with limited human supervision. Instead of sending one phishing email or deploying ransomware manually, attackers can automate reconnaissance, impersonation, credential theft and lateral movement as a connected operation.
ITWeb reported on 7 September 2026 that South African organisations need executive-level resilience against more autonomous, AI-driven and orchestrated attacks. The same report noted that fully autonomous ransomware is feasible, although it is not yet the dominant ransomware model. (itweb.co.za)
For cybersecurity professionals, the change is not simply learning another tool. It means making decisions faster, validating machine-generated alerts and understanding how an attack can evolve across email, cloud platforms, endpoints and identities.
1. SOC analysts will investigate behaviour, not just alerts
Security operations centre analysts traditionally review alerts, investigate indicators of compromise and escalate serious incidents. Agentic attacks can generate more activity, change tactics and imitate legitimate users, making isolated alerts less useful.
Employers will increasingly value analysts who can:
- Correlate identity, endpoint, network, email and cloud telemetry.
- Recognise abnormal behaviour, such as unusual login patterns or privilege changes.
- Use SIEM, EDR and threat-intelligence platforms without trusting automated conclusions blindly.
- Write clear incident notes that explain risk to technical and non-technical decision-makers.
A practical example is a convincing supplier-payment email followed by a new cloud login and an attempt to access finance files. The analyst must connect these events into one probable business email compromise case rather than treating them as unrelated alerts.
2. Incident responders will need containment and recovery discipline
AI-assisted phishing and ransomware can shorten the time between initial access and damage. Response teams therefore need strong fundamentals: evidence preservation, account containment, network isolation, threat hunting and tested recovery procedures.
CISA guidance recommends isolating affected systems, identifying compromised accounts, preserving relevant logs and memory, initiating threat hunting and following an approved incident-response plan. (cisa.gov)
The human skill remains critical. An automated system may recommend disabling an account or blocking an address, but responders must judge business impact, preserve evidence and coordinate with legal, communications, executives and affected customers.
3. Security managers will manage resilience, not only prevention
Security managers will be expected to connect technical controls with business continuity. That includes defining who can approve emergency actions, testing backups, reviewing third-party access, improving phishing reporting and running realistic tabletop exercises.
The focus should also extend beyond conventional malware. ENISA reports that AI is being used to improve phishing, social engineering, impersonation and malware-related activity, while malicious AI systems and attacks on AI supply chains are emerging concerns. (enisa.europa.eu)
For South African executives, this makes cyber resilience a governance issue. Leaders need enough technical understanding to challenge assumptions, fund preparedness and decide how much operational risk the organisation can accept.
The practical skills employers will increasingly expect
Whether someone is comparing cyber security short courses in South Africa or planning corporate cybersecurity training South Africa programmes, the most useful learning areas are likely to include:
- Security monitoring with SIEM, EDR and cloud logs.
- Incident response, digital forensics and threat hunting.
- Identity security, phishing-resistant authentication and access control.
- Scripting and automation for repeatable investigations.
- Secure use of AI tools, including data protection and output verification.
- Business communication, risk reporting and crisis coordination.
Training should be assessed through practical labs, simulations and documented incident scenarios, not only theory. For employers, relevant programmes can support workforce capability while fitting into broader Skills Development Levy planning and B-BBEE skills-development objectives. SARS describes SDL as a mechanism intended to encourage workplace learning, while South African B-BBEE guidance recognises skills development as a scorecard element. (sars.gov.za)
Around two-thirds of the way through a learner’s development path, a provider such as Melsoft Academy, which is QCTO-accredited, may be one option to compare alongside other recognised training providers. The important test is whether the course builds job-ready capability through practical cybersecurity work.
What to do next
Learners should choose a pathway that combines networking, Linux, cloud, security monitoring and incident response, then build a portfolio from realistic investigations. HR teams should map training to actual SOC, response and governance gaps, document outcomes and confirm any compliance requirements with the relevant authorities or skills adviser.
Melsoft Academy is QCTO-accredited and offers one possible route for developing practical digital skills. Compare its curriculum, assessment approach and learner support with other options before deciding.



