Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By Matt Keating, head of AI security, and Jason Madigan, Director, Commercial Cloud Security, Booz Allen
As the threat landscape continues to evolve, 2026 is shaping up to be a defining year for the cybersecurity industry, and a dangerous year for organizations that don’t take the time to reevaluate their defense strategies. Attackers are only getting faster and more complex – and companies are expanding their digital attack surface now more than ever.
This past year was only a preview of what we can expect to see in 2026. Ransomware groups doubled down on social engineering with groups like Scattered Spider leading the way from phishing emails to phony phone calls. At the same time, companies are dealing with more blind spots than ever with complex digital infrastructures from multi-cloud, to sprawling API use, to AI adoption. As gaps continue to widen, attackers are moving from double extortion to total disruption, and companies are finding themselves down millions of dollars due to the downtime of cyberattacks.
Defense strategies will need to be rebuilt for the evolution of threats we’re facing. These are what should be the biggest focus areas for security leaders in the year ahead:
Human Threat: The Weakest Link
Humans remain the easiest pathway for attackers to exploit. Even the most sophisticated technical defenses can be bypassed when an employee clicks a malicious link, shares credentials over the phone with a convincing impersonator, or falls for a well-crafted social engineering scheme. To prepare for AI-generated attacks, such as deepfakes and automated phishing, organizations must introduce new controls, many of which are AI-powered, while reinforcing existing security awareness and bolstering conventional detection measures.
Organizations should invest in ongoing security education that moves beyond annual compliance training to create a culture of vigilance. At the same time, technical safeguards like multifactor authentication, email filtering, and behavioral analytics will continue to provide essential layers of protection. By combining informed employees with robust technical controls, organizations can significantly reduce their exposure to attacks targeting the human element.
Cloud: A Force and a Soft Spot
With cloud as the backbone for most modern organizations, it has unlocked a new level of speed and innovation – but it inevitably also brings increased risk. The complexities of multi-cloud architecture make it impossible to fully secure environments end-to-end, leaving wide open blind spots for attackers to exploit. Security models designed for traditional infrastructure often fail to account for the shared responsibility nuances of cloud environments, resulting in gaps around privileged access, software dependencies and poorly secured backups that contain the entirety of an organizations recovery capabilities. Under these conditions, a successful cloud attack can be more damaging than a typical breach, resulting in major financial exposure, regulatory penalties, business interruption, incident response costs, and more.
To build resilience, organizations will need to move from reactive to proactive approaches. This can be done by reducing dependencies on single cloud providers, implementing systematic monitoring of regulatory developments across their operational footprint, and building security architectures with outside breaches and insider threats in mind. This will also require ensuring cloud resilience plans are established within broader risk management frameworks to show clear metrics, ownership, and allow for stakeholder visibility. While risk can never be fully eliminated, there’s importance in anticipating it, and focusing on preparation.
Outages: The Biggest Test of Security Resilience
Although 2026 will bring many challenges, outages will prove to be the biggest. We’ve seen platforms fail for reasons as simple as a misconfigured update, or as severe as a complex, targeted cyberattack. With huge dependencies on major cloud and other infrastructure providers, this puts the industry in a dangerous spot because these outages aren’t just bothersome but can be extremely hard to come back from. The effects push security teams to reconsider how they currently measure resilience.
One of the biggest gaps currently lies in lack of preparation. Outage aftermath will greatly affect those that don’t understand their environment or how to prioritize the entire organization’s response during a crisis. This means that in 2026, planning will need to be a requirement. I predict security teams will be pushed to reassess their entire resilience playbook – from expanding vendors to modernizing failover plans – and abandoning outdated expectations.
Defining Success in 2026
In an accelerating threat landscape, it’s essential to learn from the past to prepare for the future. As attackers zero in on cloud vulnerabilities and human weak spots, defenders must adjust their strategies accordingly. As we see more successful attacks, they also need to be prepared for the inevitability that an outage is coming – whether that’s from a cyber attack or a simple misconfiguration from a highly relied-upon provider. Security teams will need to put a strong focus on education, reinforce the fundamentals, and expand resilience planning to keep up with a quickly evolving threat landscape.
##





