Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By David Bellini, co-founder and Chief Executive Officer for CyberFOX
In 2026, the community of security professionals must face a hard reality. Although the concept of Zero Trust is impressive on paper, achieving it in practice is not possible for most mid-market businesses, which operate with tighter budgets and fewer personnel.
“Zero Trust” was born from the desire to eliminate implicit trust in users, hoping to validate every user, device, and connection. In theory, it appears to be the holy grail of protection techniques. However, for the average organization, Zero Trust has become an impossible standard and an aspiration that does not match the everyday realities of modern IT. The concept has been stretched to the point where insurance companies, auditors, and vendors use it as a quick way to refer to “perfect security.” Yet perfection is impossible in environments where the IT director also handles help desk tasks and compliance and often becomes the accidental CISO.
The higher the expectations of cyber insurance carriers, the more refined the attacks will be and creates an even bigger gap between theory and practice. The insurance carriers are demanding more extensive questionnaires, stricter controls, and even greater adherence to the ideals of Zero Trust, which is just impossible for businesses to meet with the meager personnel local governments, small businesses, or regional service providers have.
Under these conditions, the concept of “Zero Trust” is more of a dream than a framework because, with the best of intentions, there are often unforeseen consequences, such as revoking admin rights, requiring multi-factor authentication on all networked devices, or relying on constant verification, which ultimately locks out users or impairs their productivity. The demarcation line between protecting the system and protecting the device is thin, but if breached, workarounds will happen, causing the system to fail.
That’s why the future lies in what I call “Pragmatic Trust.” Pragmatic Trust focuses on building multi-layered automated barriers that get as close to “Zero Trust” as possible without sacrificing user-friendliness or needing a large team of security experts to implement. Pragmatic Trust understands that the journey, not just the goal, is what matters in the world of cybersecurity.
When it comes to the mid-market, Pragmatic Trust emphasizes automation, simplicity, and visibility over complexity and buzzwords, starting with its technology stack. The application of solutions that silently enforce policies in the background, integrated into the workflow rather than an afterthought, is part of the meaning of Pragmatic Trust. Technologies that scale from 10,000 down to 100 are also part of its interpretation.
The role of AI will be to accelerate both aspects of the equation. Attackers are already employing AI solutions to automate reconnaissance, design more convincing phishing attacks, and exploit vulnerabilities more quickly than before. However, the same technology can also be used to defend against attacks by enabling the use of AI solutions to enhance identity management, detect anomalies well in advance, or automate remediation, for example.
Ultimately, success in the year 2026 and beyond will not be achieved by those who have the most budget to invest in “tools” or who tick the most “compliance” boxes. Instead, success will be achieved by those who “Simplify, Automate, and Make Progress,” who instead focus on their own journey toward greater protection, rather than trying to attain the impossible promise of “Zero Trust.”
Cybersecurity should serve the business, not the other way around. As an industry, we need to stop designing for an ideal world that doesn’t exist and start building solutions for the one that does.
In the end, the question isn’t “How close are we to Zero Trust?” but “How much safer are we than we were yesterday?” In 2026, the companies that can answer that with confidence through practical, usable, and measurable progress will be the ones that truly move the security needle forward.
##
ABOUT THE AUTHOR
David Bellini is a co-founder and the Chief Executive Officer for CyberFOX. Serving as the Chief Operating Officer and working with his brother Arnie Bellini, the duo spun the ConnectWise software company out of their Tampa-based IT service provider more than four decades ago. David most recently served as the President of International Sales and Operations where he spearheaded and managed the international expansion for ConnectWise. David was a major contributor in the private equity firm Thoma Bravo acquiring ConnectWise in 2019.






