Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By Andre Piazza, Cybersecurity Strategist at BforeAI
For decades defenders have relied on threat intelligence feeds that require threats to be detected before action could be taken. This meant that at the time that a new IOC was shared, victims would have already been made because feeds operated right of boom. In order to be actionable, these feeds would typically need to be enriched with incremental data and then correlated, which were incremental burdens to security teams, further increasing the lag in acting on the indicators.
This is no longer the case in 2026.
The Emergence of Predictive AI
Today, with advances in computing, big data, and the emergence of Predictive AI, we can finally predict attacks and become masters of our own future. This technology predicts sources of cyberattacks by observing the internet every 10 minutes, collecting a snapshot of the network metalayer: more than 140 parameters for every infrastructure on the globe, such as DNS records, BGPs, ASNs, IPs, and tracking movement among cloud providers. Through a proprietary machine learning algorithm that scores each infrastructure as malicious or benign, this intelligence can be integrated directly into security stacks to enable automatic, preemptive blocking or disruption of threats. This is not predictive analytics: it makes sense of an external surface, and it takes into account behavior and a graph of associations, comprising a much more sophisticated model. Also, this doesn’t create the cognitive burden evidenced by generative AI: it doesn’t create endless text for humans to read, no “AI fatigue” for analysts.
Predictive Feeds Will Encompass Millions of Fresh IOCs
Traditional feeds cover hundreds of thousands of right-of-the-boom IOCs. A predictive feed will provide millions of IOCs, thanks to the expanded coverage and methodology. That same methodology expands not only the count, but also the earliness of IOCs. In an independent study provided by DNSFilter, IOCs in a predictive feed were found to be “identifying threats before others by more than three weeks” when compared to more than 40 traditional feeds, as a median. This means that, come 2026, coverage of feeds will multiply and threats can be acted upon much earlier, thanks to predictive threat intelligence (PTI).
Accuracy Will Finally Be Table Stakes in Threat Feeds
Accuracy matters in threat intelligence because of the cost of making a mistake. It has traditionally been the elephant in the room, where vendors would struggle to objectively measure a level of accuracy to their feeds. Historically, this is one of the strongest reasons why defenders would manually block specific IOCs: the lack of trust in the accuracy of the feeds.
Predictive feeds change that. Using machine learning algorithms and large graph databases, it will finally make predictions that are accurate enough to trust into automation. In the same study mentioned previously, DNSFilter shows how false positive rates (FPRs) can be as low as a fraction of a percent in a predictive feed, crushing the status quo in the industry that demanded IOCs to be augmented and correlated.
Highly Targeted IOCs Will Be Highly Visible
According to Gartner in the latest Market Guide for Security Threat Intelligence Products and Services, “End users have realigned their expectation of intelligence, they no longer want to be flooded with generic indicators, but instead want a curated set of indications they can focus on.”
Traditional feeds did not have this particular focus. They were oriented toward collecting IOCs that would impact a larger audience. The good news is that in 2026 predictive technologies will help organizations curate highly targeted IOCs that impact their assets, including the supply chain. Take the example of Signify, a large manufacturing company: it implemented BforeAI PreCrime Defense for that purpose. “In the first six months, 41 threat vectors were predicted and preemptively neutralized, saving an estimated $12 million by avoiding costly business disruptions, legal proceedings and reputational damage.” according to Gartner.
Autonomous Responses Will Liberate Security Teams
Threat intelligence feeds exist to drive effective defensive action. Gartner experts articulate this vision for the future: “As the volume of available data grows, there will also be an intensifying focus on curation and actionability, ensuring that intelligence is filtered, contextualized and prioritized to drive timely, effective responses.”
As we discussed, false positives or negatives are a big detractor when automating aspects of a defense program because they create noise and irreversible consequences to the business and brand’s reputation. Given their high accuracy and earliness, predictive IOCs will be used to automate actions without a human in the middle. This provides a significant advantage to defenders, who now have the time to choose (or automate) a preemptive action: block, disrupt, or takedown such infrastructure.
There are companies that have brought predictive threat intelligence to operate in an autonomous way. Quad9, a large DNS Services provider, has implemented a predictive feed to prevent their customers from being exposed to online threat, blocking website resolution of domains deemed malicious by the feed. The company reports that “a large botnet attack was blocked by prediction shared more than a month earlier. The attack lasted 24 hours and produced 94,000 unique resolutions per minute. 30 days later, Quad9 had registered more than 365 million hits” from this attack, all prevented by this technology.
There’s also the case of a well known brand with a global presence in manufacturing. After a few weeks after a behavioral, predictive feed was adopted, systems detected the presence of an intruder attempting to exfiltrate data to a location deemed as malicious by the AI. This attack was deemed as a 30 million dollar ransomware attempt that was successfully averted by the combination of the predictive threat intelligence provided by the AI, integrated with SIEM and TIP. The indicators of compromise (IOCs) used in the attack were predicted malicious by the AI 9 months in advance, underscoring the accuracy and the value of such AI-driven predictions to organizations.
What Predictive Threat Intelligence Will Look Like in 2026
Besides the examples above, some predictive IOCs are publicly available through BforeAI’s Threat Reports. These reports focus on emerging phishing, malware, and brand-abuse campaigns, highlighting how newly registered or recently changed domains are used in large-scale fraud before they become widely known. These reports typically describe attacker infrastructure patterns (such as domain registration behaviors and hosting choices), provide technical IOCs, and show timelines demonstrating that BforeAI detected malicious domains days or weeks before conventional feeds or public blocklists. They also emphasize business impact by quantifying potential financial losses, user exposure, or fraud volume that could have occurred without preemptive blocking.
##
ABOUT THE AUTHOR
Andre Piazza is a cybersecurity strategist and thought leader championing the shift from reactive defense to predictive, AI-powered security. With over two decades of experience uniting technology, strategy, and innovation, he helps global enterprises anticipate and disrupt cyber threats before they strike.
He focuses on redefining how organizations use data, automation, and machine intelligence to create preemptive defense systems and resilient digital ecosystems. A leading voice in predictive cybersecurity, Andre speaks and writes about how AI-driven intelligence is reshaping the future of cyber defense and enabling a proactive security posture across industries.





