Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By Keatron Evans, VP of Portfolio Product at Infosec Institute
As we close 2025, AI has moved from the boardroom buzzword to everyday reality. This shift is even more urgent and disruptive when we talk about cybersecurity.
For years, we have talked about AI’s potential for talent in cybersecurity. Now, AI is actively rewriting what it means to build a career in this field. The reality? If you are not paying attention, you are already behind.
While AI is accelerating expectations, we still see a problematic widening of skills gap. In fact, the global cybersecurity talent shortage has reached record levels with an estimated 4.8 million unfilled cybersecurity jobs worldwide in 2025. This gap is defining the next era of cyber talent.
From threat actors scaling faster than defenders to the explosion of deepfakes to career roles being rewritten, cybersecurity is seeing a fundamental shift. Professionals at every level are now engaging with AI differently, as the entire talent landscape undergoes a structural reset.
Expectations for 2026: AI as the talent multiplier
In 2026, we’ll move far beyond using AI as a supplemental tool for occasional queries. Entry-level roles that we’ve traditionally positioned as foundational – SOC analysts, security administrators, even help desk positions with security responsibilities – will rapidly evolve into hybrid AI-powered ones.
The reality is that newcomers won’t just need to understand how to craft good prompts. They need to grasp the core architecture of how these systems actually operate. This includes the progression from machine learning to traditional AI to generative AI to AI workflows, and ultimately to AI agents, which are already gaining serious traction heading into next year.
But there’s a darker side driving this urgent need for AI upskilling. Malicious actors have never waited for the industry to catch up; today that rings even more true. They are already using AI to accelerate the sophistication of their attacks. Deepfakes, in particular, are moving from proof-of-concept curiosities to front-and-center threats. We’ve already seen AI-generated voices and videos used in social engineering attacks that resulted in significant financial losses. In 2026, deepfake-driven fraud will explode as the technology becomes even more accessible and convincing.
Organizations are simply not prepared for this new threat landscape, and the awareness gap around AI-powered attacks is dangerously wide across levels, departments and roles.
AI literacy as a new baseline requirement
All of this sets the tone for 2026. With a deeper focus on AI, this will be the year when “basic AI literacy” transforms from a nice-to-have into a baseline requirement. Security professionals who don’t develop more targeted AI skills will find themselves outpaced by threats that evolve at machine speed. That means going beyond using AI tools to actually understanding how they work, how to automate them and how adversaries weaponize them.
Although caution to navigate AI in cybersecurity is the rule, the good news is that the hiring landscape is evolving to match the fast-paced shifts in cyber reality. AI-powered skills verification is finally moving beyond credentials and degrees to assess what really matters: can someone actually do the job? Do they know the basics? Are they capable of being trained in targeted skills?
This creates a new path, a more direct one, that allows to better understand talent’s capabilities, from demonstrable skills to employment, ensuring organizations get the know-how they need while opening doors for professionals who can prove their skills, regardless of their background.
The bottom line: AI skills become a must
The workforce redesign is already happening. AI has evolved from an optional tool into an integrated layer across every security function
Organizations that thrive will treat AI as a core competency, not an add-on. The professionals who succeed will understand not just how to use AI, but how to reason with it, automate through it, and defend against those who weaponize it.
As we navigate 2026, AI skills won’t only enhance cybersecurity careers but will determine them in the long run.
##
ABOUT THE AUTHOR

Keatron Evans is at the forefront of AI-driven cybersecurity innovation. As VP of Portfolio Product at Infosec, he leads the development of cutting-edge solutions that are redefining industry standards. With over 20 years of experience, Keatron brings a unique blend of expertise:
- AI pioneer: AWS-certified Generative AI Subject Matter Expert
- Product visionary: Drives Infosec’s AI-integrated cybersecurity product strategy
- Cybersecurity expert: Author of “Chained Exploits: Advanced Hacking Attacks from Start to Finish”
- Intelligence sector innovator: Founding member of an AI company that developed offensive cybersecurity tools for U.S. intelligence organizations
Keatron is a sought-after speaker at major industry events like the RSA Conference and a trusted expert for media outlets including CNN and Fox News. His forward-thinking approach focuses on harnessing AI to create adaptive cybersecurity solutions, positioning him as a key influencer in the private and public sectors. Beyond his professional pursuits, Keatron is an avid martial artist and musician, bringing a multifaceted perspective to his innovative work in technology and leadership.





