Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By Joe Evangelisto, CISO, NetSPI
This year, AI moved from edge experimentation into everyday workflows, access to systems became more distributed than ever, and decisions made outside of both IT and security teams increasingly shaped organizational risk. At the same time, expectations have changed. Boards are asking deeper more complex questions, insurers are demanding more controls as well as proof over promises, and regulators are narrowing the gap between policy and practice. Long-standing assumptions about trust, visibility, and control are being tested. Five areas in particular will shape where leaders choose to invest and how resilient their environments become.
1. AI will move from free-for-all experimentation to safeguarded application
AI is now embedded across most business functions often adopted at a rate faster than IT and security teams can keep up with. In many organizations, AI gets adopted through a mix of approved tools, open platforms, and employee-driven experimentation. Its footprint is growing quickly, and recent research shows how wide the gap between adoption and proper governance has become. Only 17% of organizations have basic automated controls in place to prevent sensitive data from being shared with public AI tools, leaving most employees free to paste proprietary or regulated information into AI systems without technical safeguards.
In 2026, customers, boards, and regulators will expect AI systems to be treated with the same discipline as any other critical technology. Security teams will spend more time deciding where models belong, whether they should run in-house or rely on third parties, and how data moves through them. Additionally, attention will shift toward validating outputs, testing for unexpected behavior, and limiting how sensitive information can be exposed through user input as well as protecting against malicious attacks, and technical flaws or weaknesses. Thus far, AI governance has been found largely in policy decks and planning documents, rather than in daily operations. As more teams encounter close calls or accidental data exposure through AI tools, that will change. Organizations that set up basic guardrails early will face fewer surprises as their AI usage continues to increase.
2. Zero Trust and identity management will rise as indispensable disciplines
Zero Trust has been part of the security conversation for years, yet many environments only reflect pieces of the approach. Policies exist, but few organizations regularly confirm that access controls are working the way they should. As identity and verification technologies advance and organizations’ technology environments expand, the gap between strategy and implementation will become increasingly difficult to justify demanding more thorough inventory, visibility, and control.
In 2026, security leaders will look beyond promises and toward proof. They will want to know who has access to what, why that access exists, and whether it is still appropriate. This scrutiny will extend beyond employees to the growing number of external contractors, non-human identities, and automated processes operating inside enterprise environments.
Service accounts, APIs, and AI-driven workflows already move significant amounts of data, often through small integrations that receive limited attention. These connections may seem relatively low risk in isolation, but when viewed as part of a broader structure, they can provide an easy pathway into much larger, critical systems. Machine identities will also need to be managed with the same level of care and consideration as human users. For many organizations, that will require a mindset shift. Zero Trust cannot be treated as something that is finished once a project is closed; it must be treated as an always-on operating model. Teams that regularly monitor, validate, and adjust identities and access will find themselves in a much better position when something occurs.
3. Cyber insurance will influence security decisions upstream
Cyber insurance is no longer something organizations can treat as a safety net and forget about. Premiums are skyrocketing, and requirements are becoming stricter, with insurers digging deeper before they offer coverage on reasonable terms. Policy language and coverage specifics are becoming increasingly tough, with many policies leaving organizations exposed to major financial impacts of cyber incidents; offering limited support for ransomware services, incident response, and/or legal costs; and failing to pay out if it’s decided key controls were not maintained. To meet these growing and increasingly complex demands, proactive security measures will become more essential. These discussions will also show up earlier in budget and planning conversations.
Organizations that comply with recognized industry frameworks, keep accurate asset inventories, and routinely test their controls will be in a much stronger position than those that don’t. Insurers are looking for signs that security controls hold up in real conditions, not just written policies. As they take a closer look, gaps will show up in places where controls were assumed to work but never tested. Those that get ahead of this now will benefit from more financial flexibility to share with other priorities, while those operating on old assumptions are likely to see costs rise and choices narrow.
4. Supply chain risk will stay a boardroom matter
Supply chain security is no longer viewed as a narrow technical issue. Boards increasingly recognize that exposure often enters through vendors, APIs, or inherited software components rather than through core systems. With 30% of all breaches found to have involved third-party organizations in some form, leaders will expect direct answers to basic questions about who has access to data, how those connections work, where dependencies exist and what controls and protections are in place.
Security teams will need a clearer picture of their extended environment. As organizations rely more heavily on external services, especially when it comes to AI, informal trust and one-time reviews will not be enough. Vendor assessments, dependency mapping, data flow reviews, and contract reviews will become increasingly routine. Governance will also grow to matter just as much as the technology itself, particularly when it comes to renewal terms, breach notification timelines, and transparency requirements. Organizations with a consistent review process will be far less surprised (knowing their exposure), and far more prepared (understanding their responsibilities vs the partners’ responsibilities), when a partner becomes the source of an incident.
5. Insider risk will reflect new ways of working
Insider threats are changing as remote work and AI-driven deception grow. According to the 2025 Verizon Data Breach Investigations Report, close to 88% of breaches involve stolen credentials. Increasing anecdotes demonstrate current hiring processes are too lax, with bad actors and nation-state hackers becoming onboarded employees who exploit granted access to sensitive systems and information. When you add inconsistent contractor management processes, a range of organizational weaknesses emerge that make it increasingly difficult to establish trust.
By 2026, many organizations will depend more on behavioral signals, better onboarding and offboarding practices, and closer teamwork to manage the growing risk. Education will remain important, along with programs that tackle the pressures leading to insider incidents. This is one of the most complex areas of security since it sits at the intersection of people, processes, and technology. Addressing this matter is now imperative and will necessitate collaboration with HR and relevant stakeholders throughout the organization to ensure an appropriate solution.
The outlook for security in 2026
Resilience will depend on pairing new technology with clear processes and governance, explicit and strategic ownership, and real-world validation. Teams that address the growing gaps early will benefit from more flexibility as expectations rise, while those that wait will feel the pressure much sooner. Accomplishing this goal will require comprehensive support, both financial and cultural, as well as coordinated efforts from the executive team to ensure a successful result.
##
ABOUT THE AUTHOR
Joe Evangelisto is the Chief Information Security Officer at NetSPI, overseeing IT, security, and GRC. With 25+ years in IT and the past five focused on security and compliance, he specializes in transforming organizations and building high-performing teams. Joe is a frequent speaker at cybersecurity events and panels and brings deep expertise in IT leadership, operations, and business management across federal, nonprofit, life sciences, and tech sectors.





