Opens in a new tab
vmblog logo 2024 wht (updated)

2026: The Year Security Becomes Foundational

Share: 

David Marshall | Published: November 6, 2025

   

Industry executives and experts share their predictions for 2026.  Read them in this 18th annual VMblog.com series exclusive. 

By Rob Forbes, Field CISO, Stratascale 

What will define security in 2026? What opportunities and challenges will shape the year ahead? From boardroom accountability to AI governance and Zero Trust, we’ll explore the trends transforming security from a function to a foundation.

1. Security as a Foundational Layer in 2026 

The real story of 2026 will be?elevation and accountability. Security will continue the trend towards a permanent element or even member at the board table, not just as a risk report but as a business enabler. Boards are realizing that gaps in cybersecurity literacy are strategic liabilities, prompting a new wave of education, oversight committees, and security fluency among directors. 

Practically, we’ll see more alignment between business strategy and risk appetite: security inputs will influence M&A evaluations, AI deployments, and product roadmaps. Yet integration will remain uneven. Many organizations will still be wrestling with legacy architectures, talent shortages, and cultural inertia. Security will be?foundational in intent?but still?aspirational in execution – the scaffolding of a future-state enterprise where trust is systematically earned, not granted by default.  

2. Trends Reshaping Security Program Structures  

Three macro trends are forcing organizations to rethink their security programs:  

  • Agentic AI and Autonomous Systems:?As AI systems act independently, security programs must shift from perimeter defense to?governance of autonom?- focusing on explainability, attribution, and containment. Defining the role of Human in the Loop (HitL) will also be critical for the success of these capabilities.  
  • Fragmented Infrastructure:?With hybrid, multi-cloud, and edge computing, the security architecture must become federated and composable. The traditional central SOC model evolves into distributed detection fabric, leveraging AI and Zero Trust shared context across domains.  
  • Regulatory and Board Pressure:?Boards now expect quantifiable assurance of cyber resilience. Security reporting is transitioning from compliance snapshots to continuous risk telemetry – making security metrics part of business KPIs.  

These forces are collapsing silos between the business, IT, risk, and operations, driving a move toward “cybersecurity as an operating system” for the enterprise. 

3. Misconception About Zero Trust  

The biggest misconception remains that Zero Trust is a product or a destination. In 2026, the leading organizations will recognize it as the modern living breathing cybersecurity model – an adaptive framework where each access decision is contextually earned based on identity, device, network, application, and data state.  

The shift we’ll see is from checkbox adoption (“we deployed ZTNA, so we’re Zero Trust”) to?measurable earned trust?through dynamic access scoring and micro-perimeter visibility. Enterprises will mature from?Zero Trust as architecture?to?Zero Trust as behavior – woven into business culture, metrics, and design philosophy. 

4. The Evolving Role of the CISO 

In 2026, I predict we’ll see the role of CISO role become increasingly more pragmatic, data-driven, and operationally integrated. The next generation of security leaders will lean heavily into?AI across the board – not as a shiny object, but as a force multiplier for their teams and a necessity to keep pace with autonomous threats and compressed breach of timelines.  

At the same time, CISOs will work to offset the?tools maturity paradox: years of investment in complex technology stacks have outpaced maturity in?people and process. The pendulum will swing back toward fundamentals – governance, risk, and compliance (GRC) – as organizations realize that effective security depends as much on accountability and execution as on innovation.  

We’ll also see a strong push to?operationalize Zero Trust?as an ongoing program rather than a technology implementation. With the average breach now measured in single-digit minutes, CISOs will focus on tightening the connective tissue between identity, detection, and response. The emphasis shifts from building higher walls to ensuring decisions, telemetry, and containment happen at machine speed. 

## 

ABOUT THE AUTHOR 

Rob Forbes 

Rob Forbes is a seasoned cybersecurity leader with over three decades of experience in the industry. Currently serving as a Stratascale Field CISO, he acts as a trusted advisor to clients, aligning security strategies with business goals to increase cyber resiliency through practical guidance and solutions. Prior to Stratascale, Rob held multiple cybersecurity roles at Fortune 500 organizations, consulting firms, and enterprise software organizations. He is passionate about identity and zero trust and is a veteran of the United States Air Force.