Opens in a new tab
vmblog logo 2024 wht (updated)

Cybersecurity Predictions in 2026: Breaches, Agentic AI, and Continuous Governance

Share: 

David Marshall | Published: December 17, 2025

vmblog-2026-prediction-series   

Industry executives and experts share their predictions for 2026.  Read them in this 18th annual VMblog.com series exclusive.  

Cybersecurity is entering a year of reckoning. Breaches are surging, regulations are hardening and AI is reshaping both attack and defense. In 2026, accountability will spread beyond the CISO, governance will move from periodic to continuous, and agentic AI may re-open a new era of risk. 

This won’t be a subtle shift; it will redefine how organisations lead, measure and manage security. So, what should we expect from the year ahead? Panaseer’s experts have outlined key predictions for how the cyber risk landscape is set to evolve in 2026, and what organisations must do to strengthen visibility, governance and control in response. 

Backlash from the �year of the big breach’ will see a major board casualty as CISOs fight back against scapegoating – Jonathan Gill, CEO, Panaseer  

In 2026, a board member at a major corporation will lose their job amid rising breaches and legal scrutiny. This could be at the behest of their company, the courts, or of their own volition, as organizations recognize that cyber risk is a business risk that CISOs can’t shoulder alone. We’ve already seen evidence of this trend, with digital chiefs/CIOs from both Quantus and M&S resigning following cyber attacks this year, as the consequences for breaches have risen after a turbulent 12 months for security.  

Retailers, manufacturers, and airlines suffered major breaches, while regulations like DORA, NIS2, and the EU AI Act tightened accountability. With AI and a growing number of �things’ to protect expanding the attack surface, breaches now have severe financial fallout – Ingram Micro lost an estimated $136 million per day when it was breached, and JLR’s compromise is expected to cost the UK economy more than �2 billion. Security keeps getting harder, and regulators have needed to step in to stop a single point of failure impacting entire interconnected supply chains. Class actions and legal penalties against companies are also becoming a worrying new normal, driven by a regulatory focus on preventing systemic failures.  

As these consequences continue to rise, the industry will move away from the instinct to treat CISOs as convenient scapegoats. The role itself is evolving:  CISOs with the visibility to share accountability across the organization will be better positioned to influence outcomes, ensure those responsible are answerable, and achieve cyber resilience. This visibility also strengthens their ability to defend their position when the business chooses to accept greater risk, resulting in preventable breaches.  

AI advances will put a new face on attack and defense – Jonathan Gill, CEO, Panaseer 

As AI continues to evolve rapidly in 2026, it will transform operations for both cyber attackers and defenders. Familiar attack vectors such as phishing, ransomware delivery, deepfake fraud and software exploitation will be scaled and refined through agentic AI, making it a powerful multiplier for the challenges facing CISOs. Even when autonomously launched attacks contain errors, their sheer volume will increase the likelihood of success – attackers only need to be successful once.  

For defenders, AI will enhance behavioral detection, predictive analytics and incident forensics, while also driving a shift toward proactive cybersecurity that anticipates and mitigates threats before they materialist. From identifying gaps and measuring control effectiveness to translating complex data into insights for business leaders, AI will enable security teams to act with greater precision and speed.  

Ultimately, AI will follow the same route as other technologies, such as cloud: it will be the answer to some questions, but raise many more of its own, and it won’t be the silver bullet for security that many in the industry expect. Governance issues around AI will also persist, as organizations risk becoming overwhelmed by the very technology designed to protect them, as AI weaves its way into all existing technologies, increasing the attack surface. The deployment of AI in defense, and anywhere within an organization, must be underpinned by robust governance. In the absence of comprehensive state regulation, organizations must establish clear oversight for all AI-driven security initiatives.  

Governance, risk and compliance will become continuous as regulations standardize – Jonathan Gill, CEO, Panaseer  

In response to a rapidly changing threat and regulatory landscape, next year will see a fundamental shift in how organizations think about governance, risk and compliance (GRC), going from quarterly and monthly reporting to real-time and continuous. After a tumultuous year where major attacks have dominated the front pages, it’s clear that security is getting significantly harder for CISOs. Businesses need constant information to make informed risk-based decisions and boards, auditors and regulators need constant reassurance over organizations’ risk posture.   

CISOs that stick to rigid, traditional models of GRC will find themselves constantly behind the curve. New threats, regulations and technological developments – such as fresh forms of AI and post quantum security – will rapidly evolve, outpacing reporting cycles and the speed at which CISOs can affect change. Governance and security platforms will have to start communicating with each other in real-time, helping to inform security policies and daily operations, whilst ensuring that both internal and external stakeholders are satisfied that security is up to the required standard. This autonomous compliance will require siloes between people, process and technology to be broken down, ensuring that every element is drawing from a single system of record, with trusted data setting the ground truth.  

This will reflect a broader change: the growth in regulations worldwide, all with broadly the same aims, will result in standardization as bodies agree on best practice and organizations focus on the most stringent requirements to ensure global compliance. This will also drive a “back-to-basics” approach: with security teams focusing on established cyber hygiene to prevent the vast majority of attacks, using AI to compress development cycles, and unite with compliance to focus their energies on controls that mitigate the most complex and dangerous risks.   

Agentic AI will spark the return of the AI Wild WestThordis Thornsteins, Lead AI Data Scientist at Panaseer 

In 2026, Agentic AI will pull businesses back into an experimental phase, where the risks rise as fast as the opportunities. The early days of GenAI resembled a tech “Wild West”. Organizations experimented with AI without fully understanding its limitations, resulting in frequent errors, such as engineers giving valuable source code to ChatGPT, essentially leaking IP to the entire world. Over time, however, organizations brought much of this chaos under control through stronger governance, clearer policies, and more mature operational practices. 

Agentic AI will open the gates again, shifting the risk landscape and raising the stakes even higher. Because these systems act autonomously, there is even less oversight and greater potential for chaos to spiral out of control. Even minor issues, such as authentication faults or misconfigurations within the AI system or its dependent processes, could cascade across companies, exposing sensitive data or triggering unintended actions. As organizations increasingly delegate decision-making to AI agents, these mistakes will be amplified, making proactive governance essential. Gaining complete visibility over the systems AI interacts with, enforcing strict access controls, ups killing teams, and embedding robust governance frameworks will be essential to maintaining innovation while controlling risk, and avoiding a return to the bad old days of the AI Wild West. 

2026 will demand speed, visibility and shared accountability. Those who adopt continuous governance and prepare for AI-driven risk will stay in control. Those who don’t may find the future decided for them.

##