Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By John Xereas, Chief Information Officer, Nightwing
Each year, the cyber landscape reaches a new level of unprecedented speed, scale, and complexity, and 2026 will be no exception. AI will continue to accelerate both offensive and defensive capabilities, giving organizations no choice other than to evolve at the same pace or risk being exposed. The pressure is on as adversaries exploit legitimate tools, unconventional attack surfaces, and machine-speed automation, while defenders face tighter budget restraints and growing mission demands. In light of these persisting challenges, organizations must proactively look ahead to ensure they are well-positioned and prepared to combat the cyber threats that the new year brings.
To better understand what lies ahead, I connected with leaders across Nightwing, who shared their expectations for 2026. Check out their insights below as they analyze how organizations can navigate the cyber attack landscape in the new year.
Scaling mission impact amid rising threats
“The rapid expansion of advanced analytics, generative AI, and hyperscale capacity is unfolding even as the federal government seeks to control spending via budget and staff reductions. For national security leaders, the challenge is to deliver greater mission impact at scale, even as cyber threats grow more complex and resources tighten. Meeting that mandate requires tremendous infrastructure, process, and cultural maturation to adapt and evolve at speed.
The rise of stealthy �Living-off-the-Land’ attacks in 2025 showed how adversaries can weaponize legitimate system functions, a wake-up call that demands more adaptive, behavior-based defenses. And as AI becomes central to mission execution, leaders must govern its use as carefully as they deploy it, ensuring the tools that drive efficiency do not become new vectors of risk.
In 2026, success will depend on how effectively organizations harness technology to stay ahead. Mature agentic AI frameworks will be key, integrating multi-sensor intelligence, orchestrating workflows, and empowering human operators to execute MDR and SOC functions at scale. By year’s end, these systems will not just offer an advantage; they will define mission success.” – Chris Jones, CTO, Nightwing
Navigating an accelerating cyber arms race
“The cyber domain remains locked in an arms race, with offensive and defensive capabilities continually escalating against one another. While defenders push hardening techniques deeper into the hardware layer, attackers meet this resistance with amplified creativity, motivation, and capacity, relentlessly innovating to find and exploit new seams.
In the year ahead, attack surfaces will continue to expand into unique and unconventional opportunities, further challenging defenders. The specific ecosystems targeted will be driven by the economics of the attack, focusing on what is most cost-effective to achieve the adversary’s goals. AI-augmented approaches will only compound this problem, significantly testing the limits of current-generation defensive solutions. Addressing this national security imperative requires measurable outcomes and the dismantling of long-standing barriers that have kept government, defense, and industry from collaborating at speed.” – Tim Zentz, Vice President of CODEX at Nightwing
Staying ahead as machine-speed threats and quantum risks collide
“The threat landscape is undergoing an intense shift, driven by the widespread adoption of artificial intelligence by our adversaries. Nation-state campaigns orchestrated by agentic AI systems are moving at machine speed, shrinking dwell time and overwhelming manual responses. Organizations will have no choice but to address the automation imperative, shifting to intelligence-driven detection, automated triage, and rapid AI-enabled threat hunting to keep pace.
This upcoming year will test defenders on two fronts: the immediate challenge of AI-driven automation and the long-tail risk of quantum disruption. Together, they define a year where preparation must outpace innovation. The quantum threat is no longer theoretical, and �Harvest Now, Decrypt Later’ activity makes clear that the data most at risk is the data being stolen today. With NIST’s post-quantum standards finalized, 2026 must also be the year leaders move from awareness to action, establishing quantum-readiness teams, building cryptographic inventories, prioritizing long-lived sensitive data, and piloting hybrid classical-PQC deployments.” – Nick Carroll, Cyber Incident Response Manager, a Nightwing
++
The formula for cyber defense success in 2026 is clear: organization leaders must efficiently operationalize AI, strengthen cross-industry collaboration, and shift from reactive defense to intelligence-driven, automated, and quantum-ready security postures. Standing still is not an option; building proactive cyber resiliency will be crucial now more than ever heading into this next year.
##
ABOUT THE AUTHOR
John Xereas began his career in medicine, focusing on the laboratory side of medical research. Eventually, he gravitated to the more technical aspects of the profession such as data, networks, and telecommunications. He came to understand that the ways technology can be applied are only limited by one’s creativity and innovation. So, when he decided to apply his knowledge to information systems and pivot his career, it wasn’t a great leap. Today he uses his love of technology and the rigor of his early medical experience to provide Nightwing the state-of-the-art solutions it uses daily to enable customer mission success.
John serves as Vice President and Chief Information Officer at Nightwing, responsible for the company’s technology ecosystem and for ensuring its availability, continuity, and security across all business units. John previously oversaw Raytheon’s largest cybersecurity program while working in the Raytheon Cybersecurity Intelligence and Services business. Prior to that, he was at General Dynamics Information Technology and CSRA, where he was a Vice President managing federal contract portfolios exceeding $2 billion.
John holds master’s degrees in information systems and international trade and transactions, as well as a bachelor’s degree in medical technology, from George Mason University. He has earned multiple industry technical and management certifications. John enjoys travel, both domestic and international, with his family whenever he can get away.





