Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By Sam Peters, Chief Product Officer, IO (formerly ISMS.online)
The year ahead is going to be defined not by a cycle of new threats, but by the reckoning that follows them. The pace of innovation has outstripped the pace of governance. Organizations have rushed to adopt AI, cloud platforms, and connected systems faster than they’ve built the frameworks to manage them responsibly.
The result is an expanding attack surface and a shrinking margin for error. Risk has been woven into every business decision and model running without human oversight. In 2026, cybersecurity will stop being a technical discipline and start becoming a core pillar of corporate governance.
Here are five forces I believe will define that shift:
1. Agentic AI Risk and Governance Will Break Through to Executive Awareness
We’ll likely see the first major “AI governance” scandal in 2026 – when an autonomous or semi-autonomous AI tool causes a security or compliance breach. That moment will push boards to finally treat AI like any other business risk, with real oversight, risk models, and accountability.
Recent research shows 95% of respondents say they’re investing in AI governance, but only 21% have prioritized responsible AI usage policies. More than half (54%) admit they adopted AI too quickly and are now struggling to rein it in.
2. Identity, Access, and Privilege Controls Become the New Perimeter
With hybrid work, APIs, and AI agents multiplying, identity has become the new attack surface. In 2026, attackers will target machine credentials and service accounts as aggressively as human users.
Zero trust will move from buzzword to baseline, covering people, processes, and AI systems alike. You can’t protect what you can’t authenticate, and this year, identity management is security management.
3. Legacy and Unpatched Systems Remain a Massive Achilles’ Heel
Despite record spending on cybersecurity, old vulnerabilities will still cause the biggest damage. Many ransomware and data breach incidents will trace back to outdated software, misconfigurations, or unpatched systems – problems that scale as organizations expand to the cloud and edge.
According to The State of Information Security Report 2025, 31% of organizations suffered a data breach in the past year, with unpatched vulnerabilities as a key factor. Digital transformation must include legacy modernization, or those old systems will keep undoing your best efforts to stay secure.
4. Cyber Insurance Tightens – and Proof Becomes the Price of Entry
Cyber insurance has long been a backstop for risk transfer. But next year, coverage will depend on provable, ongoing security maturity, not just a certificate or audit report.
Insurers will demand continuous evidence of control performance. Organizations that can’t provide it will face higher premiums or reduced coverage. Compliance will become the cost of insurability.
5. Regulatory and Standards Fragmentation (Not Convergence)
Don’t expect global harmony on cyber and AI regulation. The U.S., EU, and China will continue taking distinctly different paths, which means multinational organizations must build adaptable compliance frameworks that flex across jurisdictions.
Global convergence isn’t happening; but compliance convergence is possible. The right compliance platform can unify multiple frameworks, helping businesses manage risk efficiently even when regulators don’t agree.
Next year we’ll see accountability become inseparable from security. AI will demand oversight. Identity will define the perimeter. Legacy systems will test resilience. Insurers will expect proof, and regulators will continue to diverge.
The organizations that win won’t just be the fastest to adopt new technologies – they’ll be the ones disciplined enough to govern them.
##
ABOUT THE AUTHOR
Sam Peters is chief product officer at IO (formerly ISMS.online). He is one of the longest-serving members of the team, with over 20 years experience bringing SaaS solutions to market. Prior to joining the company, Peters worked as general manager of an eLearning SaaS provider, head of schools ICT applications for a local authority, and product owner for an e-payments provider. Peters is fascinated by new technology and loves solving problems.






