Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By Mike Hamilton, Field CISO with Lumifi Cyber
Predictions for 2026 must account for changes in the federal government, and the impact on cybersecurity in the private and public sectors. With reduced regulatory activity from the sector risk management agencies (e.g., the EPA regulates the water sector), the cessation of election security monitoring, the expiration of both the information sharing act of 2015 and the state and local cybersecurity grant program significant shifts in cybersecurity are critical. Additionally, the recent executive order, which places the responsibility for infrastructure protection and disaster management squarely on state and local government means our ecosystem of critical infrastructure protection will have to change. The urgency of these changes is exacerbated by the geopolitical situation in the world, and the increasingly aggressive cyber actions against our critical infrastructure: notably water, energy, healthcare and manufacturing.
Prediction-States will compensate:
- Grants – States like California have already set up grant programs for Tribal and local governments, to compensate for the loss of the state and local cybersecurity grant program. This assistance is vital to ensure the continuity of operations for water/waste management, communications for law enforcement and public safety, and other critical services. Other states will follow suit, depending on the health of those states’ budgets.
- Regulation: Following New York’s example, primarily by the Department of Financial Services (DFS), states will begin to regulate their own critical sectors. This will primarily be applied to healthcare, financial services, and public utilities, leaving out those that will continue to be regulated federally such as energy generation. This will result in a patchwork of regulatory requirements that will be difficult for the private sector to comply with nationally and there will be calls for renewed regulation at the federal level.
- Incident response for significant cyber disruption: With the loss of key services from CISA that include incident response assistance, states will create volunteer corps of responders. The model that many states are reviewing is that of Wisconsin, and their Cyber Response Team as well as Michigan’s Cyber Civilian Corps. While both these initiatives are a decade old, both have worked through difficult issues such as credentialing and indemnification for volunteers and serve as a model that other states can emulate.
- Information sharing: States will need to create a safe harbor for private sector organizations to share information on cyber incidents, such that those disclosures do not cause regulatory or civil action, and do not hurt those organizations’ competitiveness. While some insulation can be provided, it is noteworthy that states cannot guarantee insulation from federal enforcement such as the Federal Trade Commission’s false claims act.
- Statewide cyber telemetry: Because of the criticality of the services provided by local governments, states will develop operation centers that provide low-cost or no-cost cyber monitoring for local governments, public utilities, rural healthcare, and school districts. These organizations are within the purview of the States to monitor; however, the private sector will not be included. This will give States the telemetry needed across their geographies to identify early reconnaissance, active compromise campaigns, and act to minimize the impact of incidents. This will create a sea change in how local governments are monitored and deprecate them as a market for private sector managed security services. Initiatives such as the PISCES project will likely expand into multiple states to additionally provide work force development for cyber analysts.
- Deterrence: A bill proposed by Republican legislators would empower private sector companies to “hack back” against adversaries, using a “letter of marque” that would immunize them from legal action from doing so. While this is not likely to move forward because of international norms, it is likely that State National Guards will be brought to bear on this type of deterrence.
These changes also create opportunities for managed security service providers. Because of the economic hits sustained through tariffs, loss of Medicaid funding, and evaporation of key international markets, private sector organizations are increasingly loath to carry employees and this includes cybersecurity practitioners. As a result, more will turn to MSSP, MDR, and professional service providers to handle impact minimization and resilience, risk management and compliance.
AI is coming into products, with many trained on LLMs that simulate attack traffic and are mapped to the Mitre ATT@CK framework. These NDR and SIEM products produce high-fidelity alerts and are an improvement over signature- and rules-based alerting. In SOC operations, we will see the advent of the Tier-1 AI SOC agent. These agents will ingest alerts and create tickets, perform the first-pass investigation, and route the ticket to a human analyst for confirmation and response. This will lead to a measurable reduction in the mean time to detect and mean time to respond. We are already seeing SIEM platforms treat AI agents and AI Bots as distinct from users, accounts and assets, further underscoring this new way of thinking about security.
Finally, because of the loss of Medicaid funding the healthcare sector will find it even more difficult to prioritize investment in cybersecurity controls, leading to high risk in (primarily) rural healthcare and one extortion incident is likely to drive them out of business altogether. This funding shortfall and increased risk will drive a consolidation in the healthcare sector, with rural hospitals, clinics, and critical access facilities being acquired for pennies on the dollar.
##
ABOUT THE AUTHOR
Mike Hamilton is a Field CISO with Lumifi Cyber, which provides managed and professional cybersecurity services. His roles have included Managing Consultant for VeriSign Global Security, CISO for the City of Seattle, Policy Adviser for Washington State, and Vice-Chair of a DHS government coordinating council for critical infrastructure protection.






