Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By Chirag Shah, Global Information Security Officer & DPO, Model N
Identity is becoming the central control plane for everything from humans to machines to integrations. This shift is good for security, but it creates an attractive single point of failure. Cybercriminals will go straight for identity infrastructure, and they’ll do it with AI that creates nuanced, adaptive attacks.
Protecting against these threats will require speed and stringent Zero Trust principles, especially when it comes to vendor integrations.
Identity Will Become the Control Plane and the Primary Target
Identity now governs access and trust across users, systems, integrations and environments. This shift strengthens security in a cloud-first world. Identity-centric approaches enable companies to move away from implicit trust models and institute Zero Trust principles. Technology teams can more accurately enforce least privilege access for both people and machines.
However, this centrality makes identity the highest value target. If a hacker can get in, they inherit trust across environments. Cybercriminals will leverage next-gen tools including AI to carry out their attacks.
AI-Enabled Cyberthreats Will Become Faster, Quieter and More Personal
In 2026, most cyberattacks will blend automation with a strong understanding of human behavior. The barrier to producing convincing phishing campaigns is already low, and generative models are making it trivial to tailor messages to individuals at scale. These campaigns will likely become continuous, adaptive and personalized in a way that overwhelms traditional detection.
Autonomous reconnaissance will become common. Agentic systems can already map environments, identify weak points and test simple exploits without much human guidance. As these tools mature, the early stages of an attack chain will be far faster and less noisy.
Some attacks won’t even involve breaches as data poisoning moves from research papers into real incidents. Increasing reliance on AI for internal decision-making makes corrupting training data a way to manipulate outcomes without accessing the underlying systems.
Security Fundamentals Still Matter, but Response Speed Must Change
When it comes to system protection, agentic AI will not replace foundational security practices in 2026. Good segmentation, patching, key management and monitoring will still matter.
However, the pace of defense must increase. Agentic AI enables rapid-fire attacks, compressing the early stages from hours or days into minutes. Technology teams need systems that can react in real time with automated containment, policy adjustments and triage. Human teams can remain in control, but they can’t be the bottleneck to responding to these accelerated cyberthreats.
Agentic AI will also force companies to rethink what “normal” behavior looks like across users and networks. Security models need to understand typical patterns of activity in much greater depth, rather than relying on static rules or signatures.
Vendor Management Will Shift from Compliance to Continuous Security Enforcement
The new cybersecurity threats increase the risks tied to vendor systems and shared integrations. Companies are moving away from implicit trust models, but vendor integrations remain one of the last areas without continuous verification.
In 2026, more companies will move to Zero Trust for their vendor access, implementing short-lived credentials, enforced identity controls and much tighter monitoring of cross-tenant API traffic.
Organizations will also begin to view supply chain risk as a core security function, rather than a compliance checkbox. Companies will put more pressure on vendors to prove they’re operating securely. This change will lead to broader adoption of software bills of materials, routine integrity checks and more aggressive contractual requirements for incident reporting.
CISOs Take Formal Ownership of AI Governance
As AI moves from experimentation to regular use, governance gaps will translate directly into security and business risk. Right now, AI governance and model security sit in a gray zone between security teams, data science groups and legal departments. The CISO is the natural fit to define guardrails, approve deployments and monitor misuse. But many organizations haven’t set up the structure or expertise to support that function yet. Organizations need to address this gap as quickly as possible.
Looking Ahead
Regulations will only add to these challenges in 2026. Legislation will accelerate faster than many organizations expect. Reporting rules, assurance requirements and expectations around board oversight will keep tightening. Companies must approach security as an operational shift rather than a compliance project.
Security fundamentals still matter, but speed will define success as AI elevates attack strategies. Automated containment and real-time policy changes will keep defenders in control without slowing them down.
##
ABOUT THE AUTHOR
As the Global Information Security Officer & DPO at Model N, Chirag Shah’s primary objective is to ensure the company’s adherence to security, compliance, and privacy obligations. Chirag spearheads the development and implementation of comprehensive security strategies that harmonize with business goals and objectives.
With over 26 years of experience, Chirag has successfully led and managed security, compliance, and risk management programs across diverse industries and businesses of varying sizes, ranging from small enterprises to Fortune 500 companies. Throughout his career, Chirag has accumulated extensive expertise in Global Information Security, Security Compliance, Risk Management, and Privacy Management at both strategic and operational levels.





