Who Will Keep Us Safe? Rethinking Cybersecurity Competencies for AI-Transformed Work in SMEs and Small States
Synopsis
Cybersecurity is ultimately a human challenge. The ability of organisations to defend themselves depends on the competencies of their people -- yet the competency frameworks designed to support workforce development have not kept pace with how artificial intelligence is transforming what cybersecurity work actually demands. This doctoral research investigates this transformation, focusing on two underserved contexts: small and medium-sized enterprises (SMEs), where one person may be responsible for all security functions simultaneously, and small states, where constrained labour markets and full EU regulatory obligations create a structural mismatch that generic frameworks cannot address. Building on prior empirical research among 235 Slovenian organisations that documented widespread competency gaps and multi-dimensional barriers to their resolution, the research will develop and empirically validate a new competency model designed for AI-augmented cybersecurity environments in SMEs and small states. This paper presents the research plan and explicitly invites feedback on its design and open methodological questions.






