Submitted:
23 April 2024
Posted:
24 April 2024
You are already at the latest version
Abstract
Keywords:
1. Introduction
- We broadened the scope of exposure to ChatGPT, as previously defined in [1], to encompass several non-managerial cybersecurity industry positions and certifications.
- We employed the NICE Framework to assess the primary tasks of four distinct non-managerial cybersecurity roles and to empirically evaluate their potential exposure to ChatGPT’s capabilities, before applying the technological displacement theory to interpret the results, and to investigate the long-term impact of ChatGPT on cybersecurity. We also studied the potential utilization of ChatGPT to pass cybersecurity certificate examination.
- We identified the challenges and limitations obtained from our study and suggested a shift from emphasizing memorization to fostering critical thinking skills for the industry, education, and certification institutions that might be exposed by ChatGPT.
2. Related Works
3. Research Motivation
3.1. Media Coverage of ChatGPT
3.2. Public Opinions of Generative AI in Cybersecurity
3.3. Automation in Cybersecurity
4. Research Methods
4.1. The NICE Framework
- Identify work roles and assess current workforce: Review the NICE Framework to identify relevant work roles for an organization and map existing job titles and responsibilities to the framework.
- Evaluate job requirements and develop job descriptions: Analyze the TKS and abilities associated with each work role to understand job requirements, and create comprehensive job descriptions accordingly.
- Align training, recruitment, and hiring: Align training programs, recruitment and hiring strategies that target candidates with the required skills and knowledge.
- Monitor and adapt to the changes: Regularly review the organization’s use of the NICE Framework and update job roles, job descriptions, and training programs as needed to keep up with the evolving cybersecurity landscape.
4.2. Selection of Cybersecurity Industry Jobs
- GRC consultants help organizations to manage risks and comply with regulations by developing and implementing security policies and procedures. They provide guidance on cybersecurity controls and work to ensure that an organization’s operations are aligned with its security objectives.
- SOC Analysts monitor an organization’s systems and networks for security incidents, analyze security logs, and respond to incidents as they occur. They use a variety of tools and techniques to detect and respond to security threats in real-time.
- Network and Cloud Security Engineers design and implement security solutions for an organization’s systems and networks. They work to ensure that an organization’s data and systems are secure by implementing security controls and monitoring for potential security threats.
- Penetration Testers simulate cyber attacks to identify vulnerabilities in an organization’s systems and networks. They use various tools and techniques to identify potential vulnerabilities and provide recommendations for remediation.
4.3. Selection of Cybersecurity Certifications
4.4. Defining Exposure to ChatGPT
- No exposure (E0) if using the LLM reduces the quality of work, or does not save time while maintaining quality of work.
- Direct exposure (E1) if the described LLM reduces DWA/task time by at least 50%.
- LLM+ Exposed (E2) if the LLM itself alone does not reduce task time by 50%, but additional software built on LLM can achieve this goal while maintaining quality of work, e.g., using WebChatGPT, a ChatGPT plugin with Internet access to access latest information beyond 2021. To date, OpenAI has approved 3 categories of extensions for ChatGPT: web browsing, Python code interpreter, and semantic search.
4.5. Knowledge Optimization
4.6. The Technology Displacement Theory
- Job Loss: We hope to explore the degree to which the introduction of ChatGPT could result in job losses within the cybersecurity field, with a focus on roles that may be more susceptible to this change.
- Skill Obsolescence: We aim to investigate the speed at which the skills of impacted professionals may become outdated, as well as the potential need for reskilling or upskilling.
- Labor Market Shifts: We attempt estimate the possible effects on the cybersecurity labor market, including changed demands for various cybersecurity skill sets, the emergence of new job roles, and shifts in employment sectors.
- Socioeconomic Impact: We will explore the wider socioeconomic ramifications of technological displacement in cybersecurity, such as its influence on productivity, wages, and income inequality.
5. Alignment of Cybersecurity Jobs and Certifications against GPT Capabilities
5.1. Industry Jobs
5.1.1. GRC Consultants
5.1.2. SOC Analysts
5.1.3. Network and Cloud Security Engineers
5.1.4. Penetration Testers
5.2. Certifications
- CISSP: The free CISSP practice quiz7 is publicly available on the (ISC)2 website, and is made up of 10 questions.
- CISA: The free CISA practice quiz8 consisted of 10 questions, and ISACA explicitly claimed that they were at the same difficulty level of the actual exams.
- CEH: The free CEH practice quiz9 included 5 questions.
- CISM: The free CISM practice quiz10 consisted of 10 questions, and ISACA also explicitly claimed that they were at the same difficulty level of the actual exams.
6. Discussion
6.1. Major Themes Identified
6.1.1. ChatGPT Excels in Tasks Related to NLP, but Not in Critical Thinking
6.1.2. Jobs and Certifications Relying Heavily on Static Knowledge More Exposed to ChatGPT
6.2. Implications for the Industry
6.3. Implications for the Education Sector Teaching Cybersecurity
6.4. Long-Term Impact of ChatGPT on Cybersecurity Using the Technological Displacement Theory
6.4.1. Job Losses
6.4.2. Skill Obsolescence
6.4.3. Labor Market Shifts
6.4.4. Mixed Socioeconomic Impacts
6.4.5. Summary
6.5. Limitations of This Study
7. Conclusion
Funding
Data Availability Statement
Conflicts of Interest
Abbreviations
| AI | Artificial Intelligence |
| CISA | Certified Information Systems Auditor |
| CISM | Certified Information Security Manager |
| CISSP | Certified Information Systems Security Professional |
| CEH | Certified Ethical Hacker |
| DWA | Detailed Work Activities |
| DOI | Digital Object Identifier |
| GRC | Governance, Risk, and Compliance |
| ISC | International Information System Security Certification Consortium |
| LLM | Large Language Model |
| MCQ | Multiple-Choice Questions |
| MDPI | Multidisciplinary Digital Publishing Institute |
| NICE | National Initiative for Cybersecurity Education |
| NIST | National Institute of Standards and Technology |
| NLP | Natural Language Processing |
| OSCP | Offensive Security Certified Professional |
| OSINT | Open Source Intelligence |
| Portable Document Format | |
| SIEM | Security Information and Event Management |
| SOC | Security Operations Center |
| XDR | Extended Detection and Response |
References
- Eloundou, T.; Manning, S.; Mishkin, P.; Rock, D. GPTs are GPTs: An Early Look at the Labor Market Impact Potential of Large Language Models. arXiv preprint arXiv:2303.10130, arXiv:2303.10130 2023.
- Zamfirescu-Pereira, J.; Wong, R.; Hartmann, B.; Yang, Q. Why Johnny can’t prompt: how non-AI experts try (and fail) to design LLM prompts. Proceedings of the 2023 CHI conference on human factors in computing systems (CHI’23), 2023.
- MacNeil, S.; Tran, A.; Hellas, A.; Kim, J.; Sarsa, S.; Denny, P.; Bernstein, S.; Leinonen, J. Experiences from using code explanations generated by large language models in a web software development e-book. Proceedings of the 54th ACM Technical Symposium on Computer Science Education V. 1, 2023, pp. 931–937.
- Martin, C.; DeStefano, K.; Haran, H.; Zink, S.; Dai, J.; Ahmed, D.; Razzak, A.; Lin, K.; Kogler, A.; Waller, J. ; others. The ethical considerations including inclusion and biases, data protection, and proper implementation among AI in radiology and potential implications. Intelligence-Based Medicine, 2022; 100073. [Google Scholar]
- Smith, G. The intelligent solution: automation, the skills shortage and cyber-security. Computer Fraud & Security 2018, 2018, 6–9. [Google Scholar]
- Atiku, S.B.; Aaron, A.U.; Job, G.K.; Shittu, F.; Yakubu, I.Z. Survey on the applications of artificial intelligence in cyber security. International Journal of Scientistic and Technology Research 2020, 9, 165–170. [Google Scholar]
- Bécue, A.; Praça, I.; Gama, J. Artificial intelligence, cyber-threats and Industry 4.0: Challenges and opportunities. Artificial Intelligence Review 2021, 54, 3849–3886. [Google Scholar] [CrossRef]
- Truong, T.C.; Diep, Q.B.; Zelinka, I. Artificial intelligence in the cyber domain: Offense and defense. Symmetry 2020, 12, 410. [Google Scholar] [CrossRef]
- Newhouse, W.; Keith, S.; Scribner, B.; Witte, G. National initiative for cybersecurity education (NICE) cybersecurity workforce framework. NIST special publication 2017, 800, 181. [Google Scholar]
- Petersen, R.; Santos, D.; Wetzel, K.; Smith, M.; Witte, G. Workforce framework for cybersecurity (NICE framework) 2020.
- Fowler, J.; Evans, N. Using the NICE framework as a metric to analyze student competencies. Journal Of The Colloquium For Information Systems Security Education, 2020, Vol. 7, pp. 18–18.
- Jones, K.S.; Namin, A.S.; Armstrong, M.E. The core cyber-defense knowledge, skills, and abilities that cybersecurity students should learn in school: Results from interviews with cybersecurity professionals. ACM Transactions on Computing Education (TOCE) 2018, 18, 1–12. [Google Scholar] [CrossRef]
- Ngambeki, I.B.; Rogers, M.; Bates, S.J.; Piper, M.C. Curricular Improvement Through Course Mapping: An Application of the NICE Framework. 2021 ASEE Virtual Annual Conference Content Access, 2021.
- Patnayakuni, N.; Patnayakuni, R. A Professions Based Approach to Cybersecurity Education and the NICE Framework. Investigating Framework Adoption, Adaptation, or Extension National CyberWatch Center Digital Press ID NCC-2020-CSJ-02 csj.nationalcyberwatch.org, 2020; 82. [Google Scholar]
- Saharinen, K.; Viinikanoja, J.; Huotari, J. Researching Graduated Cyber Security Students–Reflecting Employment and Job Responsibilities through NICE framework. European Conference on Cyber Warfare and Security, 2022, Vol. 21, pp. 247–255.
- Dash, B.; Ansari, M.F. An Effective Cybersecurity Awareness Training Model: First Defense of an Organizational Security Strategy. Int. Res. J. Eng. Technol.(IRJET) 2022, 9. [Google Scholar]
- Jacob, J.; Wei, W.; Sha, K.; Davari, S.; Yang, T.A. Is the nice cybersecurity workforce framework (ncwf) effective for a workforce comprising of interdisciplinary majors? Proceedings of the 16th International Conference on Scientific Computing (CSC’18). Las Vegas, USA., 2018.
- Paulsen, C.; McDuffie, E.; Newhouse, W.; Toth, P. NICE: Creating a cybersecurity workforce and aware public. IEEE Security & Privacy 2012, 10, 76–79. [Google Scholar]
- Coulson, T.; Mason, M.; Nestler, V. Cyber capability planning and the need for an expanded cybersecurity workforce. Communications of the IIMA 2018, 16, 2. [Google Scholar] [CrossRef]
- Hott, J.A.; Stailey, S.D.; Haderlie, D.M.; Ley, R.F. Extending the National Initiative for Cybersecurity Education (NICE) Framework Across Organizational Security. Investigating Framework Adoption, Adaptation, or Extension National CyberWatch Center Digital Press ID NCC-2020-CSJ-02 csj. nationalcyberwatch.org, 2020; 7. [Google Scholar]
- Estes, A.C.; Kim, D.J.; Yang, T.A. Exploring how the NICE Cybersecurity Workforce Framework aligns cybersecurity jobs with potential candidates. The 14th International Conference on Frontiers in Education: Computer Science and Computer Engineering (FECS’18). Las Vegas, USA., 2018.
- Teoh, C.S.; Mahmood, A.K. Cybersecurity workforce development for digital economy. The Educational Review, USA 2018, 2, 136–146. [Google Scholar] [CrossRef]
- Baker, M. State of cyber workforce development. Technical report, Carnegie Mellon University, 2013.
- Dawson, M.; Taveras, P.; Taylor, D. Applying software assurance and cybersecurity nice job tasks through secure software engineering labs. Procedia Computer Science 2019, 164, 301–312. [Google Scholar] [CrossRef]
- Liu, F.; Tu, M. An Analysis Framework of Portable and Measurable Higher Education for Future Cybersecurity Workforce Development. Journal of Education and Learning (EduLearn) 2020, 14, 322–330. [Google Scholar] [CrossRef]
- Dwivedi, Y.K.; Kshetri, N.; Hughes, L.; Slade, E.L.; Jeyaraj, A.; Kar, A.K.; Baabdullah, A.M.; Koohang, A.; Raghavan, V.; Ahuja, M.; others. “So what if ChatGPT wrote it?” Multidisciplinary perspectives on opportunities, challenges and implications of generative conversational AI for research, practice and policy. International Journal of Information Management 2023, 71, 102642. [Google Scholar] [CrossRef]
- Bozkurt, A.; Xiao, J.; Lambert, S.; Pazurek, A.; Crompton, H.; Koseoglu, S.; Farrow, R.; Bond, M.; Nerantzi, C.; Honeychurch, S. ; others. Speculative Futures on ChatGPT and Generative Artificial Intelligence (AI): A Collective Reflection from the Educational Landscape. Asian Journal of Distance Education, 2023. [Google Scholar]
- Jakesch, M.; Hancock, J.T.; Naaman, M. Human heuristics for AI-generated language are flawed. Proceedings of the National Academy of Sciences 2023, 120, e2208839120. [Google Scholar] [CrossRef] [PubMed]
- Ali, A.; Septyanto, A.W.; Chaudhary, I.; Al Hamadi, H.; Alzoubi, H.M.; Khan, Z.F. Applied Artificial Intelligence as Event Horizon Of Cyber Security. 2022 International Conference on Business Analytics for Technology and Security (ICBATS). IEEE, 2022, pp. 1–7.
- Rajasekharaiah, K.; Dule, C.S.; Sudarshan, E. Cyber security challenges and its emerging trends on latest technologies. IOP Conference Series: Materials Science and Engineering. IOP Publishing, 2020, Vol. 981, p. 022062.
- Alsmadi, I.; Easttom, C. The NICE cyber security framework; Springer, 2020.
- Collins, R. Technological displacement and capitalist crises: escapes and dead ends. Political Conceptology 2010, 1, 23–34. [Google Scholar]
- Hyötyläinen, M. Labour-saving technology and advanced marginality–A study of unemployed workers’ experiences of displacement in Finland. Critical Social Policy 2022, 42, 285–305. [Google Scholar] [CrossRef]
- McGuinness, S.; Pouliakas, K.; Redmond, P. Skills-displacing technological change and its impact on jobs: challenging technological alarmism? Economics of Innovation and New Technology, 2021; 1–23. [Google Scholar]
- Sorells, B.; others. Will robotization really cause technological unemployment? The rate and extent of potential job displacement caused by workplace automation. Psychosociological Issues in Human Resource Management 2018, 6, 68–73. [Google Scholar]
- Fourie, L.; Pang, S.; Kingston, T.; Hettema, H.; Watters, P.; Sarrafzadeh, H. The global cyber security workforce: an ongoing human capital crisis 2014.
| 1 | At the time of this article, the free version of ChatGPT uses GPT-3.5 architecture, whereas the paid version uses GPT-4 architecture. All experiments in this study were conducted using the paid version. |
| 2 | |
| 3 | |
| 4 | |
| 5 | |
| 6 | |
| 7 | |
| 8 | |
| 9 | |
| 10 | |
| 11 |


| Vendor | Abbr. | Full name | Min work experience |
Popularity | |
|---|---|---|---|---|---|
| Seek | |||||
| (ISC)2 | CISSP | Certified Information Systems Security Professional |
5 years | 9,282 | 1,133 |
| ISACA | CISA | Certified Information Systems Auditor | 5 years | 1,359 | 696 |
| EC-Council | CEH | Certified Ethical Hacker | 2 years | 445 | 320 |
| ISACA | CISM | Certified Information Security Manager | 5 years | 308 | 511 |
| Offensive Security | OSCP | Offensive Security Certified Professional | N/A | 370 | 486 |
| Exposure | Job task | Certifications | |
|---|---|---|---|
| Skill | Knowledge | ||
| No exposure (0) |
LLM does not reduce the time to perform the skill. |
LLM does not help with knowledge presentation. |
LLM cannot be used to pass the exam. |
| LLM+ exposure (0.5) |
LLM combined with additional software can partially (⪈ 50%) perform the skill. |
LLM combined with additional software can partially (⪈ 50%) present the knowledge. |
LLM combined with additional software can be used to pass the exam. |
| Direct exposure (1) |
LLM alone can partially (⪈ 50%) perform the skill. |
LLM alone can partially (⪈ 50%) or fully present knowledge. |
LLM alone can pass the exam. |
| Symbol | Description |
|---|---|
| T | Tasks |
| K | Number of knowledge points |
| S | Knowledge |
| Human specific knowledge | |
| LLM assisted knowledge | |
| Number of human-specific knowledge available, where | |
| Number of LLM-assisted knowledge available, where | |
| M | Number of skills available, where |
| Weight factor | |
| Assessments, where |
| Task list | Body of knowledge |
Skillsets | |||
|---|---|---|---|---|---|
| Task | Exposure | Knowledge | Exposure | Skill | Exposure |
| Establish and maintain effective GRC frameworks |
0.67 | Cybersecurity fudnamentals |
Direct (1) | Risk management | LLM+ exposed (0.5) |
| Compliance and regulations |
Direct (1) | Problem solving and time management |
No exposure (0) |
||
| Legal knowledge and ethics |
Direct (1) | Governance and policy development |
Direct (1) | ||
| Auditing and assessment |
Direct (1) | ||||
| Knowledge of the client, their environment and preferences |
Direct (1) | Communication, presentation and media literacy |
Direct (1) | ||
| Project management | LLM+ exposed (0.5) |
||||
| Task list | Body of knowledge | Skillsets | |||
|---|---|---|---|---|---|
| Task | Exposure | Knowledge | Exposure | Skill | Exposure |
| Monitor and analyze security events and incidents |
0.39 | Advanced cybersecurity |
Direct (1) |
Using SIEM tools | LLM+ exposed (0.5) |
| Incident detection and response |
LLM+ exposed (0.5) |
||||
| Threat intelligence |
LLM+ exposed (0.5) |
Basic forensic analysis |
LLM+ exposed (0.5) |
||
| Scripting and automation |
Direct (1) |
||||
| Knowledge of the client and their baseline norms |
LLM+ exposed (0.5) |
Communication skills |
Direct (1) |
||
| Problem solving and time management |
No exposure (0) |
||||
| Task list | Body of knowledge | Skillsets | |||
|---|---|---|---|---|---|
| Task | Exposure | Knowledge | Exposure | Skill | Exposure |
| Design, implement and maintain secure network and cloud infrastructures |
0.8 | Advanced cybersecurity |
Direct (1) |
Incident detection | Direct (1) |
| Network and cloud technologies and best practice |
Direct (1) |
Network or cloud diagnoses |
Direct (1) |
||
| Identity and asset management |
Direct (1) |
Scripting and automation |
Direct (1) |
||
| Data protection | Direct (1) |
Communication skills |
Direct (1) |
||
| Legal and regulatory compliance |
Direct (1) |
Problem solving and time management |
No exposure (0) |
||
| Task list | Body of knowledge | Skillsets | |||
|---|---|---|---|---|---|
| Task | Exposure | Knowledge | Exposure | Skill | Exposure |
| Pentesting and reporting |
0.27 | Advanced cybersecurity |
Direct (1) |
Using forensic tools and software |
No exposure (0) |
| Problem solving and time management |
No exposure (0) |
||||
| Legal knowledge and ethics |
Direct (1) |
Timeline analysis and artifact correlation |
LLM+ exposed (0.5) |
||
| Knowledge of the client via reconnaissance and OSINT |
No exposure (0) |
Analytical skills | LLM+ exposed (0.5) |
||
| Communication skills and storytelling, presentation and media literacy |
Direct (1) |
||||
| Vendor | Abbr. | Exam format |
Exam marking | ChatGPT attempts with practice questions |
|||||
|---|---|---|---|---|---|---|---|---|---|
| Lowest | Highest | Passing | Scaled | Exposure | Score | Result | |||
| (ISC)2 | CISSP | MCQ | 0 | 1000 | 700 | Direct | 9/10 | pass | |
| ISACA | CISA | MCQ | 200 | 800 | 450 | Direct | 10/10 | pass | |
| ISACA | CISM | MCQ | 200 | 800 | 450 | Direct | 7/10 | pass | |
| EC-Council | CEH | MCQ | 0 | 1000 | 700 | Direct | 4/5 | pass | |
| Offensive Security | OSCP | Lab-based | 0 | 100 | 70 | × | No exposure | N/A | fail |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2024 by the author. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).