A Reflection on the Evolution of CTFs and Cyber Security Careers
Why the Capture-The-Flag leaderboard is no longer measuring what we said it was — and what to do about it.
Last week, I had the privilege of being a panel guest at the primeCTF-Africa 2026 Awards, hosted by CyLab Security Academy, together with Hamza Parvez. This article provides highlights of the discussion and a reflection on why the Capture-The-Flag (CTF) leaderboard is no longer measuring what we said it was, and what to do about it.
I went into the discussion having looked at the impact of AI in today's Jeopardy-styled CTF challenges. For example, in August 2025, Anthropic disclosed a quiet experiment where they had entered Claude into a series of CTF competitions with almost no scaffolding:
In picoCTF, the model finished 297th out of 10,460 teams, inside the top three percent globally. In the HackTheBox AI vs Human bracket it solved nineteen of twenty challenges and placed fourth among all AI teams. At the Western Regional Collegiate Cyber Defense Competition it finished sixth out of nine, against college teams that had spent a semester preparing. Four months later, an agent called Cybersecurity AI captured the $50,000 top prize at Neurogrid and reached first place across five major circuits in one calendar year.
The Jeopardy-style CTF no longer measures what we claim it measures. The skill it was built to teach — reading an unfamiliar system and forming a useful hypothesis under time pressure — is still real. However, the assessment instrument is broken, and the community is in denial about it. Therefore, the hardest question in a CTF in 2026 is not on the scoreboard — it is in your own head.
It surfaced during the panel discussion, framed by my colleague almost in passing: "CTFs are not mandatory. No one forces anyone to play. You need to talk to yourself and understand, am I playing to learn, or am I playing for the points?" Moreover, the theme of whether AI should be banned from CTFs came to the surface. The honest answer is not a policy, it is a posture. And the posture is yours, not the platform's.
That single shift shaped most of what followed. It is also the part of the conversation that will age the best.
Resources and workforce access
Why are so few African students accessing bug bounty platforms, remote SOC roles, freelance pentest work?
During the discussion session, many students kept referring to the uncomfortable situation of not having access to the same opportunities as their counterparts across the seas. My answer to this binding constraint was not on the matter of skill — it is tied to the infrastructure for getting paid.
In Kenya recently, there has been discourse about payment accounts across PayPal and other financial providers belonging to freelance security professionals being frozen. People who built real bug-bounty careers are watching their payout rail close in real time, while remote SOC contracts assume a registered entity that can invoice in USD. For freelance pentest roles, there is increasing screening for EU or US residency before a résumé is even reviewed. These are not pipeline problems; rather, they are plumbing problems. Until the conversation treats them as plumbing, the same think pieces keep being written.
There is another half to that picture. Many aspiring professionals see the glamour of the ten-thousand-dollar payouts; what is hidden is the work that produced them. The path is usually three months on a single bug, rebuilt in a lab, triangulated across platforms so the triage has nothing to do but acknowledge. There is no shortcut. There is a path, and it is unglamorous, and it works.
What AI is actually doing to the CTF format
In 2025, AI agents took first place across multiple major CTF circuits. Some instances include the Cybersecurity AI agent capturing a $50,000 top prize at the Neurogrid event, while Anthropic's Claude placed in the top three percent of picoCTF with almost no scaffolding. Various research papers have converged on the same observation — wrap a frontier model in a plan-and-execute loop with a few specialised tools, and Jeopardy-style CTFs become a solved game.
That does not mean CTFs are over. It means the leaderboard is no longer measuring what we said it was measuring. A high ranking now reflects some mix of three things — security reasoning, tool literacy, and orchestration of agents. All useful, however, they are very different skills. When a CTF badge is earned, it no longer tells you which one a competitor relied on.
AI provides the opportunity to carry out reconnaissance on steroids if you understand what you are doing. If you do not, the model hallucinates, the hallucination gets copy-pasted, and the rabbit hole turns out to be self-dug.
The constructive direction, the one worth defending, is that competitions need brackets. An AI-permitted bracket that scores the solution narrative, not only the flag. A no-AI bracket under monitored conditions, that still highlights raw human technique. A hybrid attack-and-defense bracket where the environment changes faster than a single-shot agent can keep up. Publish all three and we can stop relying on one leaderboard that tells one story.
Cybersecurity mentorship
During the conference, I was part of a mentorship session with students from across Africa. A key subject was elevated during our conversations — do universities keep cybersecurity education theoretical on purpose, as a way of skill-trimming so only the most determined students break through?
The honest answer is no. The theoretical bias is the legacy shape of how education evolved, layered with a cost-benefit calculation about building physical labs for cohorts where utilisation will be uneven. The more useful answer is what the students who break through actually do. They do not wait for the university to fix it. They notice the gap, fill it with other resources such as TryHackMe, HackTheBox, Microsoft Azure Labs and AWS Labs, and write up what they learn, publishing it themselves.
Visibility in the industry is infrastructure. Every African cybersecurity student in those rooms had skills. Most did not have a public trace of those skills that a hiring manager in Nairobi or Berlin could find on a Tuesday afternoon. That is the gap that closes a career.
The landscape is reshaping
CTF leaderboards as a hiring signal are degrading fast. The signal is moving to write-ups, to live exercises, to interview tasks with constrained tool access. Treating a top-100 finish as a proxy for unusual security ability runs on assumptions that broke in 2024.
The African opportunity is now more about plumbing than about pipeline. There is no talent shortage. There is a payment-rails problem, an invoicing-entity problem, and a visibility problem. The platforms, the regulators, and the universities that solve those three will own the next decade of African cybersecurity hiring.
AI is changing what to learn, not whether to learn. Judgement under uncertainty, accountability, context fluency, communication with non-technical stakeholders — these are the parts that are not automatable on any visible horizon. Aim there deliberately.
Originally published on LinkedIn
Raha Mawazo is an information security professional based in Nairobi, writing on security governance, operations, and the African security pipeline. Get in touch.