Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By Adrian Culley, Senior Sales Engineer at SafeBreach and an ex-Scotland Yard detective
Cybersecurity continues to mature and evolve, and in this maturity, we see an increasing focus on resilience around the world. As adversaries continue unrestingly in both attacks and innovations, it’s timely to ponder the road ahead and the challenges and opportunities it may bring.
Over the last year, we have seen an aggressive evolution from “Living off the Land’ attacks to “Living off the Blind Spot”. This is a deliberate, meticulously planned operation in which attackers aim to embed themselves in the fabric of the organization-learning its systems and exfiltrating data slowly and carefully enough to become part of the background noise. This can be particularly problematic for operational technology (OT) estates and Purdue architectures, where there is an understandable culture of focus on uptime and production.
Historically, the mantra of many OT engineers has been “If it ain’t broke, don’t fix it.” This is entirely understandable in any environment where production uptime is the primary goal and downtime is often extraordinarily expensive. However, as has been seen this year in the Jaguar Land Rover attack, this can lead to near-catastrophic outcomes with ripples that move through the supply chain for months and years, costing billions to the economy.
In response, OT security is projected to shift from an ancillary concern to a core organizational backbone by 2026, measured alongside safety and throughput as a core performance metric. Executives are now viewing resilience not as a compliance cost, but as a verifiable “profit lever,” demanding proof of payback in terms of audit time saved and downtime avoided.
In addition, global organizations, particularly those operating in the European Union, face escalating regulatory demands via the NIS2 Directive (bolstering cybersecurity) and the Critical Entities Resilience (CER) Directive (enhancing physical resilience of critical entities). By July 17, 2026, Member States must identify the Critical Entities (CEs) within 11 key sectors. This identification creates an urgent time-compression crisis for compliance and implementation that demands continuous, quantitative evidence of resilience rather than episodic audits. The EU Digital Operations Resilience Act and Cyber Resilience Act have also all now embraced this goal, as have many regulated industries globally and progressive elements of critical national infrastructure. In the next 3-to-5 years, it is likely to be standard operating procedure.
Luckily, we now have the ability to continually and safely test critical, live production systems and discover how they can be broken before threat actors do. Continuous automated red teaming (CART), for example, provides the necessary continuous, automated testing framework to generate auditable evidence of control effectiveness against these new regulatory requirements. Adversarial exposure validation (AEV) shifts the compliance discussion from mere implementation documentation to a provably effective security posture, satisfying executive demands for quantified risk reduction.
Breach and attack simulation (BAS) and CART are also valuable, specifically in the convergence of IT and OT networks, where the risk of successful lateral movement attacks into industrial control systems (ICS) is high. Both technologies provide safe, targeted emulation of sector-specific advanced persistent threat (APT) tactics, techniques, and procedures (TTPs) to validate the segmentation and access controls required under these new regulations, especially for the transition from the enterprise IT network to the segregated OT environment.
This is increasingly relevant as we see threat actors pivoting to supply chain attacks and shifting their focus to OT environments. We must reverse this adversary advantage and reverse this trend. Continuous testing is the way organizations can achieve this. The opportunity remains constant: hack, or be hacked. True resilience is delivered by adopting a simple continuous loop of Test, Examine, Remediate, Re-test, Repeat’. In 2026, enterprise organizations must focus on expanding their use of the readily available offensive cybersecurity tools, skills, and techniques-including BAS, CART, and AEV-to help them achieve this.
##
ABOUT THE AUTHOR
Adrian Culley is Head of Engineering, EMEA for SafeBreach . He has over 35 years of Computer Security experience, particularly specialising in Security Operations, Artificial Intelligence, Offensive Security, Threat Intelligence and Malware: in short Cyber Resilence. He is a core member of the OWASP Large Language Model Tope Ten risks working Group.
He is a graduate of the Information Security Group at Royal Holloway, University of London, and an occasional visiting lecturer there. Adrian was previously a Detective with Scotland Yard, working around the world with their Special Operations Directorate, and latterly served with the Computer Crime Unit there. He has also worked directly for the UK Central Government in a global role. He worked for Palo Alto Networks for 5 years as a Consulting Engineer and Head of Industry 4.0. Previously he has also worked for PWC, Trellix, Cybereason, Guidance Software, AccessData and Damballa. Adrian has a strong background in Digital Forensics.
Adrian He has worked with Government, NGO, military, intelligence, law enforcement, and commercial clients around the world. He was awarded by UK Home Office award for his contribution to Risk Management 25 years ago.
A sought after industry commentator, he has been interviewed by CNN, BBC Television, BBC Radio 4 Today program, the Financial Times, Telegraph and Economist amongst others.






