Opens in a new tab
vmblog logo 2024 wht (updated)

The Great Shift: Cybersecurity Predictions for 2026 and the New Era of Threat Intelligence

Share: 

David Marshall | Published: January 23, 2026

vmblog-2026-prediction-series   

Industry executives and experts share their predictions for 2026.  Read them in this 18th annual VMblog.com series exclusive. 

By Mitchell Johnson, Chief Product Development Officer, Sonatype

As we look back on 2025, AI and open source have fundamentally changed how software is built. Generative AI, automated pipelines, and ubiquitous open source have dramatically increased developer velocity and expanded what teams can deliver – while shifting risk into the everyday decisions developers make as code is written, generated, and assembled.

Organizations must acknowledge this shift and embrace an AI-powered SDLC, ensuring the right guardrails are embedded directly into the flow of development. Legacy “shift left” approaches haven’t kept up. Moving security checks earlier often just moves friction earlier, without integrating security into how developers actually work.

In 2026, progress will depend on embedding security intelligence directly into the developer flow. Model Context Protocols (MCPs) enable this by creating a shared, machine-readable understanding of code, components, policies, and risk across developer tools, agentic AI systems, and security platforms. This allows developers – and the AI systems supporting them – to receive guidance at the moment decisions are made, not after the fact.

At Sonatype, we see MCPs as foundational to a true shift-left model: one where developers move faster with confidence, security becomes a natural part of building software, and governance is enforced through intelligence rather than interruption. The challenge ahead isn’t choosing between speed and safety – it’s making the secure path the easiest one to take.

++ 

Brian Fox, CTO and Co-Founder:

“As the future of long-standing, government-backed organizations like NIST, CISA, and MITRE grows uncertain, the cybersecurity industry stands at a pivotal moment. The expiration of the Cybersecurity Information Sharing Act and the potential defunding of the CVE program signal a glaring shift in how the industry coordinates, communicates, and defends against adversaries. At the same time, blurred lines between state and private actors present the opportunity for hackers to target “offensive” players as targets for attacks. 

As a result, 2026 is set to welcome a new era of threat intelligence, one defined not by a centralized authority but by the strength of private-public collaboration, modernized infrastructure, and sustainable investment. It’s the organizations that value transparency, shared standards, and secure frameworks that will keep pace. Those who cling to legacy, centralized structures will quickly find themselves outmatched, outperformed, and out of luck.” 

++ 

Antoine Harden, Regional Vice President of Federal:

“In 2026, �secure by design’ will become table stakes for federal teams managing the inherent risks of open source software. Facing shrinking timelines and expanding mandates, agencies increasingly rely on open source and AI tools to develop at scale. But as usage of these tools grows, so does their potential for exploitation if not deployed securely. The winners of this new era in software will be those who prioritize governance and visibility from the onset. 

While federal policy has accelerated momentum toward safer development, federal agencies must move beyond awareness to embed security into every stage of design or risk opening the door to attackers. This is especially critical as AI model integrity now extends beyond code to encompass machine learning pipelines and training data. Just as teams govern software components, they must ensure AI systems are trustworthy by design, prioritize transparency, enable governance, verify data integrity, and eliminate unapproved code.” 

++ 

The future of cybersecurity intelligence won’t be anchored in legacy structures-it will be shaped by a community willing to rethink how trust, collaboration, and rapid threat assessment work in practice. The opportunity now is to design a more resilient and adaptive model, one capable of meeting the realities of the decade ahead. 

## 

ABOUT THE AUTHOR

Mitchell-Johnson 

Mitchell has more than 25 years of experience as a developer, architect, team-builder and leader across a variety of high-growth roles in technology, data, product, and mergers and acquisitions, including stints at eVestment a Nasdaq Company, Equifax, Grant Thornton and Delta Air Lines. As Chief Product Development Officer at Sonatype, Mitchell oversees the strategic direction and development of the Sonatype platform, ensuring customers are empowered to create secure software without sacrificing speed and innovation. Mitchell comes to Sonatype from MAXEX, the mortgage industry’s first centralized exchange for trading residential mortgages. Prior to MAXEX, Mitchell served as Chief Technology Officer at eVestment, where he was part of the leadership team responsible for scaling a high-growth, high-margin SaaS and data business that sold to Nasdaq.