Opens in a new tab
vmblog logo 2024 wht (updated)

Seven Cybersecurity Predictions for 2026

Share: 

David Marshall | Published: November 17, 2025

   

Industry executives and experts share their predictions for 2026.  Read them in this 18th annual VMblog.com series exclusive. 

By TK Keanini, CTO, DNSFilter 

AI and other technology and ecosystem shifts are transforming cybersecurity at a fundamental level. DNSFilter talked with its internal team of cybersecurity and technology specialists to discover what’s ahead on the threat landscape. Their predictions highlight the need for a proactive security strategy that is agile enough to meet the challenge of generative AI and its impact on security. Companies must be willing to implement new tools and methods as needed. Seeing just beyond the cybercrime horizon will empower companies to stay ahead of emerging threats and safeguard their future. From this discussion, my team and I’ve compiled seven predictions for the coming year.

Data troves will enable more effective attacks 

Cybercriminals are combining contextual data and noisy data to create and launch sophisticated and personalized attacks. For example, by pairing PII (including personal and healthcare information) with geolocation data, attackers can make intelligent deductions about your daily life and design increasingly targeted and convincing campaigns to trick you. These bad actors may be able to determine that you recently injured yourself and are undergoing physical therapy at a specific clinic. Then, those bad actors could send a malicious email impersonating that clinic, which includes detailed, convincing information. This will make you far more likely to click, respond or take the action the threat actor wants you to take. – Constantin Jacob, manager, engineering, security intelligence and solutions.

A tipping point for MSPs to embrace AI

AI has shifted from an emerging trend to the backbone of how companies operate, secure and scale. The DNSFilter network saw a 69% increase in AI traffic over the last 12 months. For managed service providers (MSPs) in the coming year,  survival and success will depend on offering AI-powered services. Failure to adapt will result in being outpaced. 

Businesses are using AI in innumerable ways to make workflows more efficient, and MSPs need to create these AI automations. Providing education on how to use AI and build AI automations for their clients is a massive opportunity, but there’s a challenge: they must do this in addition to everything they’re already offering. However, for MSPs that pull this off, there’s a lot of money to be made while they strengthen their reputation and differentiate their company in an ever-growing ecosystem.  – Mikey Pruitt, Global Partner Evangelist.

Organizations will have to rise to the DNSSEC challenge 

ICANN plans significant DNSSEC upgrades for 2026, such as a new root key and enhanced operational coordination. The organization intends to address the critical infrastructure integrity and resilience of the global DNS via these upgrades. However, low adoption rates mean that the majority of DNS traffic will be vulnerable to many threats, including forgery, hijacking and cache poisoning. As root-level security strengthens, attackers will increasingly shift their focus downstream to these weak links, making unsigned domains a main target for systemic exploitation. If DNSSEC adoption isn’t accelerated, attackers will gain the upper hand. Pressure is mounting for domain administrators, and DNSSEC will become a must-have. – Mikey Pruitt, Global Partner Evangelist.

AI becomes a stronger, more sophisticated enemy 

In 2026, attackers will use AI to their advantage, augmenting old threats while creating new ones. They will perfect classic attacks like phishing, and we will see the advent of flawless, deepfake-powered phishing and AI that chains minor bugs into major breaches – at machine speed. This will lead to autonomous attacks where a bad actor states a goal, and an AI agent achieves it by rewriting its own code to bypass defenses in real time. The only response is to fight fire with fire. Security teams must accelerate the shift to AI-driven behavioral detection, a strict Zero Trust architecture, and phishing-resistant identity controls as the last line of defense. – TK Keanini, CTO.

Security will become embedded in company culture

Employees won’t be passive participants in cybersecurity going forward. Each person will be expected to be a proactive defender, constantly ready to do battle. Cybersecurity will shift from being a compliance checkbox to a shared mission. The most secure companies will be those where employees understand that they are partners to the cybersecurity team, not just policy followers, creating a culture of performance-driven defense.  – TK Keanini, CTO.

AI will challenge credibility, bringing authenticity to the fore 

Deepfakes will soon destroy trust itself, as we’ll no longer be able to believe what we see. AI will continue to blur the line between reality and fabrication, and bad actors will weaponize human psychology (including social proof, urgency and authority) through flawless fake faces and voices. The classic CIA triad of “Confidentiality, Integrity, Availability” can’t be sustained. In 2026, authenticity will emerge as cybersecurity’s fourth pillar, defining the next era of digital trust.  – TK Keanini, CTO.

Finding and removing CSAM and other harmful content will become a steeper challenge

Attempted access of CSAM (child sexual abuse material) has grown 44% on the DNSFilter network over the last year – the only content category within DNSFilter that is always blocked. 

As AI models become more sophisticated, unmoderated AI image generation will make it increasingly difficult to identify vectors of direct harm. And though photo identification and age regulation laws for certain websites are meant to help protect minors, the fact is that these crackdowns may actually make it harder to trace, find and remove victims’ content. Why? Those rules are likely to drive users away from more standard “open forums” into more private and shared servers.

Whats the solution? Tech companies and cybersecurity organizations can play a key role by working with organizations like the Internet Watch Foundation and others to block content at the DNS layer. – Gregg Jones, intelligence analyst lead

Fully equipped

These predictions reveal a pivotal shift for cybersecurity teams, but they also reveal a huge growth opportunity for those who are willing to adapt. AI, new attack vectors and market shifts will force changes in security strategy. Forewarned is forearmed, and it’s our hope that our predictions will help readers adapt where needed to secure their organizations’ futures. 

## 

ABOUT THE AUTHOR 

TK Keanini 

TK Keanini is the Chief Technology Officer at DNSFilter where he leads product management, customer support, engineering, and security intelligence toward ongoing innovation and growth, focusing on customer needs and feedback to determine product direction.