Opens in a new tab
vmblog logo 2024 wht (updated)

Privilege Sprawl and Identity Debt Are Reshaping Cybersecurity

Share: 

David Marshall | Published: December 19, 2025

vmblog-2026-prediction-series   

Industry executives and experts share their predictions for 2026.  Read them in this 18th annual VMblog.com series exclusive. 

By Morey J. Haber, Chief Security Advisor at BeyondTrust

We’re scarcely midway through the 2020s, but without doubt, the decade has left an indelible mark-in the way of seismic technology shifts, attacks reaching new heights of audacity through deepfakes and AI, and world-shaking breaches.

Amidst this turbulent landscape, identity emerged as the single most important factor driving modern defensive strategies. Some key identity-based challenges that now define the modern risk landscape are:

  • The Rise of Identity Debt: Unmanaged and / or excessive permissions across the enterprise have created a massive, technical security burden that organizations are struggling to gain control over.
  • The Explosion of Privilege Sprawl: The rapid expansion of cloud services, automation, and agentic AI is exponentially increasing the number of non-human identities, creating a dangerous surge in broad, unmanaged privileges.

The 2020s have also proven that the identity layer is the primary target for threat actors, from nation states to bored teenagers. We’ve seen high-stakes identity-layer compromises, sophisticated cloud-targeted nation-state attacks, and other headline-worthy threats, along with an influx of new regulatory frameworks (SEC, NIS2/DORA, EU AI Act, etc.) scrambling to keep up.

Thus, security’s focus has increasingly shifted towards identity-first security, with the realization that every digital identity (human and non-human) has some level of privilege and that access that needs to be managed and protected. Beyond this, we’ve also witnessed world-stopping technological malfunctions that laid bare the fragility of interconnected systems.

With 2025 coming to a close, let’s dive into the trends we expect to shape and redefine the cybersecurity landscape through 2026 and well into the next decade.

Cybersecurity Meets Geopolitics and Global Economics

Governments around the world will consider implementing a tax or tariff on digital services (including streaming services and software) that are produced, distributed, hosted, and supported outside of their geographic borders within the next year. We have already seen some indications of impacts to movie studios.

Not a day goes by without tariffs hitting the news. While governments negotiate the rates we pay in excess for physical products, we’ve been fortunate to not pay tariffs on digital services and software-yet. However, since the pandemic, this potential revenue stream has been established in several regions, as well as in some U.S. states. Some governments have already made their move, and we believe more will soon impose tariffs on digital services as they push for innovation and product development to occur within their borders.

The enforcement of these tariffs may open the doors for new industries that focus on monitoring consumption-based processes and collect appropriate fees for taxation. This is akin to paying for the amount of data consumed on a mobile device before unlimited plans were available. If you consider how ubiquitous streaming, software, and digital services have become across the globe, it’s only a matter of time before the lack of digital sovereignty translates into taxation. 

AI Accelerates and Challenges Human Boundaries

In the next year, nearly every technology we operate (consumer and enterprise) will be connected to agentic AI. This fusion will create value, while also dramatically expanding the attack surface. In essence, AI will become the new middleware in most organizations.

The adoption rate of Internet of Things (IoT) technology in our homes-from smart cameras to thermostats-and operational technology (OT) in our businesses was measured in days, not the years or decades it took for technologies like electricity, television, radio, and the internet. Following this precedent, agentic AI is expected to dominate our lives in days by 2026. This technology will tout benefits, from booking travel to optimizing the temperature in our homes. While some agentic AI may really help for many use cases, other uses will turn out to be empty promises, or may actually make things worse.

Further, the rush to deploy agentic AI everywhere will lead to a proliferation of attack vectors, breaches, and new security concerns due to excessive privileges, confused deputy problems, and a general lack of guardrails instrumented during typical secure-by-design processes. The speed-to-market push for agentic AI will leave cybersecurity as an afterthought, and will force users to contend with rapid adoption rates and escalating security threats.

Account Poisoning: The Next Evolution of Financial Fraud

In the next year, we’ll witness a ramp-up in attack vectors poisoning consumer and business accounts as threat actors find novel ways to insert fraudulent billers and payees-or worse, modify existing ones. These cybercriminals will process funds via third-party brokers and link them to transactions that exfiltrate funds.

Attacks on personal and business financial accounts are nothing new. Online banking and digital transactions have become the norm for receiving and paying e-bills over the last two decades. It’s not uncommon for trusted billers and payees to be compromised by threat actors seeking to siphon funds destined for legitimate sources. While this is just one example, we expect account poisoning to rise next year because currently, financial organizations only defend against account attacks  at an individual level.

The “poison” comes from a high degree of automation that allows for the creation of payees and billers, the requesting of funds, and linking to other online payment processing sources. This entire attack vector will occur due to weaknesses in online financial systems, the exposed nature of accounts (if the credentials or routing and account numbers are compromised), and the ease with which automation can obfuscate a transaction in a current account.

This will require greater diligence in identity confidence for any changes in a user’s financial accounts, especially with regards to automation, where poor secrets management could be leveraged to attack accounts in bulk.

Conclusion

As we look ahead, one truth stands out. Identity sits at the center of every major shift reshaping cybersecurity, from geopolitical pressures to the rapid spread of agentic AI and the evolution of financial fraud. Organizations that prioritize identity security and enforce least privilege across human and non-human accounts will be best positioned to navigate the volatility ahead. The next year will reward those that build resilience, modernize their controls, and confront privilege sprawl with intention. The BeyondTrust team has been making security predictions for more than 10 years, and the patterns remain clear. Identity is the new battleground, and building a mature identity security strategy will define who stays secure and who is left exposed in the decade to come.

##

ABOUT THE AUTHOR

Morey Haber 

Morey J. Haber is the Chief Security Advisor and lead identity and technical evangelist at BeyondTrust. He has more than 25 years of IT industry experience and has authored five books in the Attack Vectors series. He previously served as BeyondTrust’s CISO, CTO, and VP of Product Management.