Opens in a new tab
vmblog logo 2024 wht (updated)

Four Network Security Shifts That Will Define 2026

Share: 

David Marshall | Published: December 31, 2025

vmblog-2026-prediction-series   

Industry executives and experts share their predictions for 2026.  Read them in this 18th annual VMblog.com series exclusive. 

By Vincent Stoffer, Field CTO at Corelight

As security teams look ahead to 2026, the pressure points are already clear. AI is reshaping both offense and defense. Geopolitics is driving a new wave of pre-positioning in critical infrastructure. SOC workflows are starting to change as autonomous agents mature. And post-quantum cryptography (PQC) is moving from federal policy to enterprise planning.

Here are the four shifts that will matter most for network defenders.

1. The Agentic SOC Becomes Operational, But Only With the Right Data

Early experiments with “agentic SOC” tooling were everywhere in 2024 and 2025. In 2026, the training wheels will come off.

Major cloud and security platforms are already shipping agents that can triage alerts, summarize investigations and automate routine SOC steps. Next year, these capabilities will become part of day-to-day work in larger security operations centers. Expect:

  • Autonomous triage of commodity alerts
  • Automated hypothesis generation that blends endpoint, identity and network telemetry
  • Analysts moving into supervisory roles, validating and correcting agent output

But none of this works without clean, consistent data. If telemetry is incomplete or fragmented, these agents will hallucinate relationships, miss obvious threats, or overwhelm analysts with noise.

The SOCs that benefit in 2026 will be the ones that standardize their data pipelines now, especially around network and identity sources. Automation is finally real, but the foundation has to be right.

2. Geopolitics Drives a New Phase of Critical Infrastructure Risk

The last few years have shifted the geopolitical risk conversation around cybersecurity from hypothetical to concrete. U.S. and allied agencies have detailed how China-backed actors, including Volt Typhoon, quietly embedded themselves in communications, energy, transportation and water systems. The goal appears to be access and persistence, not theft. But it’s also clear that this pre-positioning is preparing to disrupt critical infrastructure in the future.

Russia’s attacks on Ukrainian grid operations have shown how this trend can play out. Power stations, transmission lines and telecom systems continue to see targeted strikes paired with cyber operations designed to degrade resilience. Which country (or business) will be targeted next? In response:

  • Companies must assume that OT, cloud and enterprise networks are all part of the attack surface
  • Pre-positioning becomes a default risk, even for organizations not tied to defense sectors
  • Incident response planning has to include upstream infrastructure providers and cross-border dependencies

Geopolitical risk is now operational risk. Network observability and incident response planning have to reflect that reality.

3. AI-Accelerated Attacks Push Defenders Toward AI-Native Detection

Offensive use of large language models is no longer theoretical. Pen testers and red teams are using AI to speed reconnaissance, generate phishing content, identify misconfigurations and automate vulnerability discovery. Commodity adversaries will not be far behind.

In 2026, the curve steepens:

  • Exploit development accelerates as automated fuzzing and model-assisted code analysis mature
  • Legacy tech debt, including unpatched EOL Windows 10 systems, becomes a reliable entry point
  • Attackers chain small weaknesses faster than human defenders can review them

Defenders cannot rely on human-only analysis to keep pace. We need to fight fire with fire, and while defenders are currently behind, it just takes a few great new tools or use cases to start turning the tables. Companies need to shift focus to AI-native detection that looks across network, identity and application data for weak but correlated signals. The most effective early use cases will be:

  • Detecting lateral movement and privilege escalation before payload execution
  • Identifying abnormal data flows in east-west traffic
  • Rapid, automated alert prioritization and even containment when indicators align

This is where high-quality network telemetry becomes decisive. AI can amplify and link weak signals to our great advantage, but only if it has a complete picture of what “normal” looks like.

4. PQC Shifts From Federal Mandate to Enterprise Reality

Post-quantum cryptography has been on the federal agenda for years, but 2026 is when mainstream enterprises start treating it as a real program.

Federal agencies are already required to inventory cryptographic systems and prepare migration plans. NIST has selected several PQC algorithms for standardization, CISA has published guidance for automated cryptographic discovery, and vendors that serve the federal space are beginning to ship PQC-ready builds.

This pressure will spill into the commercial market in 2026. Boards, auditors and regulators will ask basic questions about quantum-safe readiness, especially for industries with long data confidentiality requirements.

Enterprises will not complete migrations next year, but they will be expected to start. That means:

  • Building a full inventory of cryptographic assets across applications, services and embedded systems
  • Identifying the highest risks for “harvest now, decrypt later” exposure
  • Understanding vendor roadmaps and how PQC will affect interoperability and performance

Getting a start now will buy companies years of runway, otherwise companies may be forced into a rushed transition when we enter a post-quantum encryption world.

What Security Leaders Should Prioritize in 2026

Across these four shifts, several themes repeat:

  • Data quality determines AI value. Agentic SOCs and AI-native detection only work when data is complete and coherent.
  • Assume breach and quiet persistence. Nation-state actors are already in networks; detection strategy has to reflect that.
  • Treat 2026 as a planning year. PQC, AI adoption and SOC automation all require long-term design, not one-off tools.

The landscape is getting more complex. But defenders finally have new capabilities, from autonomous SOC agents to quantum-safe cryptography, that can put them ahead of the next wave of threats, if they build with intention now.

##

ABOUT THE AUTHOR 

Vincent Stoffer 

Vincent Stoffer is the Field CTO at Corelight, the fastest growing provider of Network Detection and Response (NDR) solutions. He joined the company in 2016 in the first customer-facing role at the company, helping to scale the organization from startup to industry leader. He also served as a product management leader, bringing the sales, success, research, and engineering teams together to deliver world-class security products to Corelight customers. Vince previously held security engineering and network management positions at Lawrence Berkeley National Laboratory and Reed College. He attended Pitzer College in Claremont, CA, graduated with a bachelor’s degree in Humanities from University of Oregon, and he holds the CISSP, GCIH and GCIA certifications.