Opens in a new tab
vmblog logo 2024 wht (updated)

2026 Will Demand Smarter Governance and Strategy, Not More Security Tools

Share: 

David Marshall | Published: February 3, 2026

vmblog-2026-prediction-series   

Industry executives and experts share their predictions for 2026.  Read them in this 18th annual VMblog.com series exclusive. 

By Kyle Wickert, Field Chief Technology Officer at AlgoSec 

The more digitally connected an organization is, the more complicated its security risks can get. And while it’s natural to be concerned, adding yet another tool to the stack isn’t the answer. Instead, 2026 should be the year companies prioritize the technology and solutions that will help them grow with the industry and adapt to enterprise landscape developments. 

Shadow Cloud Will Become The Biggest Security Gap, and the Solution Isn’t More Tools 

Shadow cloud environments – stemming from cloud infrastructure spun up by business analysts or project teams outside of formal IT oversight – will become the single most worrisome security gap for enterprises. As companies expand across public cloud, on-premises environments and SD-WAN, infrastructure is essentially growing faster than security teams can inventory it. But the real issue isn’t visibility alone – it’s that connectivity intent is being defined in too many places, or not defined at all. 

The problem isn’t a lack of security tools. It’s the absence of a single, authoritative view of how applications are allowed to communicate across every environment they touch. Adding more point solutions only increases fragmentation, making shadow cloud harder – not easier – to control. 

As more organizations come to understand this problem, teams will shift to automatic onboarding, unified policy governance and intelligent automation. Implementing processes that immediately identify and model every new cloud account, platform or workload will enable companies to significantly shrink threats outside their line of sight. 

Security Teams Will Shift From Building Policy to Vetting Automated Decisions 

As intelligent automation tools mature from an efficiency booster into a governed, risk-reduction solution, security engineers will chart a new course. Instead of manually building policy, they’ll focus on vetting and guiding machine-generated decisions in 2026. 

We’re already seeing a move toward “self-healing policies,” where automation identifies and tightens overly broad rules or unused access without human intervention. The model’s ability to shrink the attack surface continuously, not just during scheduled audits, is driving its skyrocketing popularity. The global self-healing networks market size was valued at $1.20 billion in 2024 and is projected to reach $8.89 billion by 2032, exhibiting a compound annual growth rate of 28.6% during the forecast period. 

But automation without governance simply accelerates risk. AI must operate within clearly defined safety boundaries, informed by institutional knowledge and real-world blast-radius analysis. A “trust but verify” model allows machines to handle routine decisions at scale, while humans apply judgment only where it matters – shifting security roles from maintenance to strategy.

Agentic AI Will Fuel the Need for Segmentation Across East-West and North-South Traffic 

Increasing usage of agentic AI will be one of the most transformative and destabilizing shifts in enterprise security next year, intensifying the need for strict segmentation across both east-west and north-south traffic. Telecommunications infrastructure leader Nokia is predicting a potential surge in uplink data traffic that could overwhelm current network infrastructure if preparations are not prioritized. Rising demand for hybrid on-device and cloud tools will far exceed the 5-15 Mbps uplink most networks provide today. 

Unlike predictable service communication patterns, autonomous AI agents will initiate new connections, request data and interface with external systems with the speed and scale of machines, mimicking human behavior in unpredictable ways. Consequently, traditional logical access controls won’t be enough. 

To manage this risk, organizations must extend zero trust principles into the network layer – defining exactly which agents can talk, which applications they can access, and how far their connectivity can extend. Just as importantly, they must be able to prove these controls continuously, not via static snapshots or PDFs. 

As 2026 approaches, organizations will be pushed to adopt stronger governance, intelligent automation, and disciplined network segmentation to stay ahead of new and emerging threats. 

## 

ABOUT THE AUTHOR 

Kyle Wickert, Field Chief Technology Officer at AlgoSec, is a skilled information security professional and pre-sales engineer with over 15 years of information security experience. Kyle specializes in network technologies, automation, and information security.