Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By Jose Lazu, CMD+CTRL Security
Modern software development is moving faster than ever. AI is being integrated into nearly every application layer, APIs power critical business workflows, software supply chains are increasingly complex, and regulatory oversight is intensifying. Meanwhile, attackers are advancing in speed, sophistication, and scale.
Yet amid these challenges, there is cause for optimism. Application security (AppSec) is evolving from a compliance-driven checkbox to a strategic enabler of business resilience. Organizations that invest in targeted, hands-on training are building capabilities that protect data, strengthen culture, and anticipate emerging threats.
As we look ahead to 2026, several trends are shaping the most effective AppSec programs, reflecting both real-world attacks and shifting development practices. These are the 10 most critical areas of application security training to prioritize in the new year.
1. Securing AI and Emerging Workloads
AI-powered features are now embedded across search, chatbots, decision engines, and more. With this innovation comes a new attack surface and vulnerabilities including prompt injections, model poisoning, and data leakage. Organizations must train teams to secure AI features at every layer, from API integrations to runtime sandboxing, ensuring that AI outputs are safe and predictable.
OWASP’s updated guidance emphasizes the critical need to manage AI/ML risks, including model integrity, supply chain vulnerabilities, and exposure of sensitive data. Companies that fail to account for these risks may ship high-profile products with exploitable flaws.
2. API Security: Protecting the Modern Interface
APIs remain the connective tissue of enterprise systems-and the most targeted surface by attackers. Broken Object-Level Authorization (BOLA), inadequate authentication, and lack of throttling continue to drive breaches.
In the coming year, effective programs will focus on authorization design, abuse detection, and rate-limiting strategies. These programs will help developers and security engineers to anticipate misuse before it reaches production. Immersive exercises, such as hands-on cyber ranges, allow teams to experience attacks safely, reinforcing these critical skills.
3. Software Supply Chain Risk and SBOMs
Recent incidents, from PyPI backdoors to compromised build artifacts, underscore the risk inherent in modern software supply chains. Organizations must train developers to generate and verify Software Bills of Materials (SBOMs), vet dependencies, secure CI/CD pipelines, and detect malicious code early.
OWASP’s 2025 Top 10 continues to highlight supply chain exposures as a high-impact risk, reinforcing that software security begins long before a single line of proprietary code is written.
4. Identity and Access Misconfigurations
High-profile breaches often stem not from zero-days, but from misconfigured identity and access controls. Missing MFA, overly broad permissions, and improper OAuth or OpenID Connect implementations remain common pitfalls.
Training programs should emphasize identity-aware threat modeling, session management best practices, and least-privilege enforcement, ensuring developers can design applications that anticipate misuse rather than react to it.
5. Cloud-Native and Ephemeral Security
In 2026, secure development extends beyond code into the very environments where applications execute. Modern applications increasingly run in Kubernetes clusters, containers, and serverless functions, where misconfigurations and secret leaks are prime targets. Teams need to understand deployment-layer risks, Kubernetes RBAC policies, infrastructure-as-code validation, and secrets management.
6. Advanced Secure Coding Practices
Traditional vulnerabilities like SQL injection and XSS persist, but subtle flaws like race conditions, unsafe concurrency, and business logic errors are becoming more prevalent. Training must go beyond general guidance, teaching language-specific secure patterns, validation techniques, and secure design practices that reflect the realities of modern development.
7. Real-World Breach Analysis and Threat Modeling
Effective AppSec programs ground learning in actual incidents, illustrating the consequences of poor controls. From ransomware across enterprise networks to session hijacking and social engineering, understanding the full lifecycle of attacks-with real-world examples-reinforces why proactive threat modeling matters.
8. Threat Modeling & Security Architecture
Developers are increasingly expected to shift left, applying frameworks such as STRIDE or LINDDUN to assess risk before a single line of code is written. Embedding security in architecture and design, rather than patching defects post-deployment, is becoming the standard.
9. Client-Side Security
Front-end applications handle sensitive data, authentication flows, and business logic, yet remain vulnerable. OWASP 2025 emphasizes threats on the client side, including:
- DOM XSS and Content Security Policy (CSP);
- Mobile data leakage prevention;
- Anti-clickjacking, HSTS, and browser headers; and
- Securing client-side API access
Developers must understand these risks and integrate mitigations into every layer.
10. Compliance Alignment
Simultaneously, regulatory frameworks such as NIS2, PCI DSS 4.0, TRAIGA, and SEC disclosure rules are increasingly shaping development practices. Security training that combines compliance literacy with technical capability ensures organizations meet obligations while building resilient software.
Preparing for 2026
The coming year will demand pragmatic, experiential, and integrated training programs that reflect the full spectrum of modern risk-from AI and APIs to supply chain and compliance. Organizations that invest in hands-on learning, breach-informed exercises, and cross-functional security leadership will be best positioned to meet the challenges ahead.
From Knowledge to Behavior
Knowledge alone is not sufficient. High-fidelity cyber ranges let teams explore vulnerabilities in realistic applications, experiment safely, and internalize the consequences of insecure design. By complementing traditional training with hands-on exercises, organizations move from awareness to actionable skill, reinforcing secure practices that persist in production.
Empowering Security Champions
The most effective AppSec programs rely on people who can influence, communicate, and lead. Technical proficiency alone is no longer enough. Champions must articulate risk to non-security teams, guide threat modeling sessions, and navigate trade-offs between speed and safety to shape a culture of security across the enterprise.
For enterprises seeking to stay ahead of evolving threats, the lesson is clear: 2026 belongs to the organizations that go beyond the checkbox to make security a fundamental capability.
##
ABOUT THE AUTHOR
Jose Lazu is an innovative and dynamic product leader with over a decade of experience driving customer-focused solutions in the cybersecurity space. Currently serving as Associate Director of Product Management at CMD+CTRL, he brings a creative, data-driven approach to shaping product vision, launching strategic roadmaps, and fostering cross-functional collaboration. With a strong foundation in stakeholder management, product strategy, and team building, Jose has consistently delivered results across roles at Security Innovation and beyond. He’s known for his original thinking, unshakable accountability, and deep commitment to trust and camaraderie in every team he leads.





