Opens in a new tab
vmblog logo 2024 wht (updated)

Adtech lessons applied to human risk in 2026

Share: 

David Marshall | Published: December 23, 2025

vmblog-2026-prediction-series   

Industry executives and experts share their predictions for 2026.  Read them in this 18th annual VMblog.com series exclusive. 

By Nicole Jiang, co-founder and CEO, Fable Security

For years, the cybersecurity industry assumed human behavior could not be changed, but that assumption is being turned on its head. 

In 2026, cybersecurity training will finally take its cues from an industry that has long mastered influencing behavior at scale: adtech. Adtech has spent decades learning how to read signals, predict intent, and deliver the right message at the exact right moment. Security teams will begin doing the same. Instead of relying on generic, one-size-fits-all content, organizations will begin using real-time behavioral signals to deliver immediate and personalized guidance at the exact moment risky behavior occurs. And just as marketers fine-tune timing, tone, and communication channel for maximum impact, security teams will use data to understand what actually drives people to take safer actions. 

Security training is shifting from a compliance check-box activity to true behavior change, powered by timely nudges, ongoing reinforcement, and constant experimentation. The prediction is simple. In 2026, cybersecurity will stop treating people as the weakest link and start using proven behavioral science to turn them into one of the strongest defenses. 

Security will center on human behavior, not just technology: Change Healthcare was not the only organization that struggled with getting people to take the right security action. Changing security behavior has a notorious reputation of being nearly impossible among security professionals. The thing though, is that behavior change is a honed science in fields like Adtech. Under the hood, the fields share the same goal: getting the right message to the right person at the right time, in a way that actually drives behavior. If we can get someone to buy a pair of shoes, we can get them to secure their account. 

Personalized interventions will further replace generic and basic training: Let’s start with personalization. In adtech, platforms analyze browsing behavior, purchase history, and any other contextual tidbits they can learn to figure out what to show you-and when. In security, the stakes are higher, but the logic still applies. If someone has engaged in insecure behavior-admins sharing passwords, an executive reusing login credentials, a money-handler answering the call of a fake vendor, an employee forwarding work documents to their personal account, or simply someone missing important software updates-that’s the kind of behavior signal we want to act on. And the more specific and contextual, the better. 

Continuous experimentation and improvements will define and drive security programs: Finally, we brought with us one of the most powerful habits from adtech: experimentation. In the ads world, everything is tested: subject lines, image formats, message length, emoji usage, delivery cadence. We test what grabs attention, what drives engagement, what sustains behavior change, and what quietly fails. The result is a human risk platform that doesn’t just throw security messages at people. It adapts, iterates, and optimizes-just like the best-performing systems in adtech. Because changing behavior isn’t about telling people what to do. It’s about understanding what works, and doing it smarter each time. 

More security programs will use data on employee behavior to optimize intervention: Beyond intervening in problematic behavior on a just-in-time basis, people will be further studied to see when they are generally most likely to engage with training-what time of day, over what communication channel, and even based on what message is sent or tone used-all to shape and optimize interventions so they are fully understood. It turns out one size doesn’t fit all. 

The result is a human risk platform that doesn’t just throw security messages at people. It adapts, iterates, and optimizes-just like the best-performing systems in adtech. Because changing behavior isn’t about telling people what to do. It’s about understanding what works, and doing it smarter each time.

##

ABOUT THE AUTHOR

Nicole Jiang 

Nicole Jiang is the co-founder and CEO of Fable Security, the human risk platform that shapes employee behavior in real time. She was previously a founding team member and Head of Product at Abnormal Security, where she scaled the company from pre-revenue to a $5B valuation. Earlier in her career, Nicole held product and engineering roles at Mixpanel, Microsoft, Palantir Technologies, and Pixlee, building products across AI, SaaS, and security. She holds an engineering degree from the University of Waterloo.