Opens in a new tab
vmblog logo 2024 wht (updated)

Five cybersecurity predictions for 2026

Share: 

David Marshall | Published: December 5, 2025

vmblog-2026-prediction-series   

Industry executives and experts share their predictions for 2026.  Read them in this 18th annual VMblog.com series exclusive. 

By Christopher Robinson, Chief Security Architect, OpenSSF 

In 2026, security teams will face a year shaped by AI, human risk, and new compliance pressures. These five predictions outline what’s ahead for the year in cybersecurity, and where IT and security professionals should be focusing their attention next year. 

1. An AI orchestrated breach will become a headline event, again

AI moves significantly faster than a traditional enterprise can keep pace. Bad actors can link chatbots, agents, and automated processes together to create attacks that pivot and adjust mid flight. AI will be just as helpful to the bad guys as it is to a user. With access to literally all the knowledge of the internet at its LLM fingertips, and a fleet of specialized agents ready and willing to conduct specialized tasks for the attacker, expect more headlines about AI-driven attacks in 2026. 

2. The human element will stay a top breach driver

Industry studies, like the Verizon Data Breach Incident Report (VDBIR), have continually shown that the majority of cybersecurity breaches can be attributed to people, not technology. Oftentimes, the human element is the root cause over some exotic zero-day vulnerability. The 2024 VDBIR report saw that 68% of all reported data breaches could be attributed to “the human element.” That includes a whole spectrum of vulnerabilities from user errors and mistakes – like clicking on a phishing attack – all the way to the most extreme scenarios, like malicious insiders.  

We can never effectively secure a system without securing the humans that use it (or the humans that program the AI that uses those systems). Programs that secure the humans who use systems, through awareness, process, and practical controls will see the most impact. 

3. SBOMs shift from creation to assurance and aggregation

Software Bill of Materials (SBOMs) will continue to have growing relevance in 2026.  OpenSSF has participated with the global community on this topic for quite some time now. The industry has reached the point where creating SBOMs is not the main issue, instead security professionals are grappling with how to aggregate and combine multiple SBOMs into something that provides actionable data. The SBOMit project is seeking to integrate these critical documents with in-toto-based digital attestations to help imbue SBOM receipts with higher degrees of assurance. 

There is valuable data floating in software builds and publication pipelines. Tools like SBOMit will help downstream consumers get more actionable information about how their software was created and handled prior to deployment. For 2026, any additional layers of assurance should be elevated and prioritized in the face of faster, more automated tech stacks. 

4. MLSecOps increases in importance across teams, departments

AI development is software development. This is true regardless of whether a user is operating ML, LLMs, generative AI, agentic systems, MCP, or A2A. The knowledge from securing traditional software applies, and will continue to apply. There is so much knowledge and experience in DevSecOps that directly applies to protecting these new techniques and tools – we call that MLSecOps. 

A wrinkle that MLSecOps revealed is the many non-traditional “developers” and parties involved in using and producing AI. There are so many people without security backgrounds or knowledge participating in activities like vibe coding or chatbots that might be unknowingly leaving the door open for attacks. IT leaders and their teams must prioritize secure coding best practices and risk-based thinking as they decide what data to feed into models. Public LLMs are not private, so once data is shared with these tools it is impossible to pull back. Companies and organizations with MLSecOps guardrails in place will fare better in the next 12 months than others. 

5. The Cyber Resilience Act (CRA) continues a global push for compliance

CRA is a blueprint, and many governments are watching. In 2026, expect regulators and governments to harmonize with the EU, putting similar requirements in place for their own nations. The European Union Agency for Cybersecurity (ENISA) and the European Union (EU) will be shaping how projects and manufacturers talk about and coordinate vulnerabilities in projects, globally. Timelines are very tight for manufacturers, but ideally all will benefit from more public information about vulnerabilities in the components and products people use daily. This is a global effort to protect consumers of modern technology. 

Next year, larger manufacturers will continue preparing while many small and midsize suppliers will race to stand up product security practices and secure by design requirements. This will be a bigger challenge for small and medium businesses, though they still have time. Effectively participating and engaging with critical upstream projects is the biggest priority for all manufacturers, which will take time, patience, and effort, and will not be done overnight.  

Looking at these trends holistically, they point to a 2026 in which cybersecurity returns to the fundamentals, just perhaps at greater scale and speed. AI will raise the stakes on both offense and defense, but security can’t be an afterthought in innovation. Organizations that take time to invest now in securing people, pipelines, and practices will be better prepared. The goal for the year ahead might be simple, but definitely not easy. Industry collaboration and continuous iteration will fortify organizations and their products against what’s ahead.

##

ABOUT THE AUTHOR

Christopher Robinson 

Christopher Robinson (aka CRob) is the Chief Security Architect for the Open Source Software Foundation (OpenSSF). With over 25 years of experience in engineering and leadership, he has worked with Fortune 500 companies in industries like finance, healthcare, and manufacturing, and spent six years as Program Architect for Red Hat�s Product Security team.