Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By Jeffrey Wheatman SVP Cyber Risk Strategist, Black Kite
As global supply chains become digital battlegrounds, Black Kite experts reveal four predictions that will redefine how organizations manage vendor and ecosystem risk in 2026.
One major manufacturer will suffer an eight-figure financial losses from a supply-chain cyber incident
Most manufacturers continue to focus on traditional supply chain risks, such as labor shortages, safety compliance, sanctions violations, and logistics disruptions, as these challenges are highly visible, heavily regulated, and long-standing compliance priorities. In contrast, cyber risks within the supply chain (vulnerabilities, ransomware susceptibility, and other digital exposures) are often underprioritized. This is evident by the fact that manufacturing remains ransomware’s number-one target for the fourth consecutive year with supply chain exposure being a significant driver. Given this, we predict to see one major manufacturer suffer an eight-figure financial loss from a supply chain-related cyber incident in 2026.
Third-Party and Supply-Chain Cyber Risk Will Become a Boardroom Priority
We predict that supply-chain and third-party cybersecurity risk will move firmly into the boardroom agenda in 2026. Recent high-profile incidents, including the F5, Salesloft/Drift, breaches, Jaguar Landrover and Asahi breaches, have demonstrated how a single vendor failure can trigger widespread operational disruption and reputational damage across the supply chain. As a result, boards are beginning to view supply-chain resilience not as a technical concern, but as a fundamental business risk. Expect to see boards ask CSO/CISOs to include visibility into cyber risk in their supply chains and to share high risk exposures, along with greater investment in continuous vendor monitoring and the ability to quickly mitigate potential exposures. The conversation will evolve from “Do we have controls in place?” to “How do we continuously validate the cyber health of our entire ecosystem?”
50% of AI Vendors Will Fail as Rising Costs Drive Consolidation
By the end of 2026, we predict that as much as half of today’s AI vendors will go out of business, leaving customers stranded with unsupported and deeply embedded technologies. The market is oversaturated with small AI startups, many founded by lean teams and backed by short funding cycles, that will be unable to survive intense competition and cost pressures. The cost of computers is being driven up by major AI providers like OpenAI, Anthropic, and Google, which will force consolidation. This consolidation will also reshape the broader business landscape. Smaller and mid-sized companies will find themselves priced out of embedding AI into their operations, unable to compete or innovate at the pace of larger, better-funded enterprises.
The Rush to Adopt AI will Outpace Security, Expanding Risk Across the Supply Chain
The rapid push to embed AI into every workflow, driven by top-down pressure to innovate, increase productivity, and stay competitive, will create increased opportunities for attackers. While some companies will attempt to impose strict AI governance requirements, existing AI risk frameworks remain fragmented and inconsistent across industries. For many, assessing AI vendors and your vendors’ use of AI remains a highly manual and complex process, often viewed as too disruptive to procurement and innovation. As businesses across all industries integrate AI vendors at record speed, threat actors will increasingly exploit the expanding web of interconnected AI systems. Every layer of the supply chain is now experimenting with AI, multiplying exposure across ecosystems. Small, specialized AI providers with deep data access but weak security will become high-risk links throughout the vendor network.
As the supply chain becomes the new frontline of cybersecurity, resilience will depend on three things: continuous visibility, reliable risk intelligence, and the ability to turn data into action. 2026 will mark a turning point in how organizations view and manage third-party cyber risk. The future won’t belong to those who react fastest after a breach – it will belong to those who see it coming.
##
ABOUT THE AUTHOR
A strategic thought leader with extensive expertise in cybersecurity, Jeffrey Wheatman is regarded foremost as an expert in guiding public sector clients and Fortune 500 companies in connection with their cyber risk management programs. In his current role as Cyber Risk Evangelist at Black Kite, Jeffrey works to get the message out about the business impact of third-party risk and solutions to treat those risks. Prior to joining Black Kite, Jeffrey was a Vice President in Gartner’s Research and Advisory Group for 15 years, where he worked with clients to build and improve their security programs, assessing risk, focusing on reporting on program status, stakeholder engagement, and bridging the connection between technology and cybersecurity risk. Jeffrey has authored approximately 150 research notes read by more than 6,000 clients. For four years, Jeffrey also served as the Chair of the North America Security and Risk Management Summit, Gartner’s 2nd largest conference with 4000 attendees annually. Earlier in his career, Jeffrey contributed as Practice Manager, Information Security for Gotham Technology Group, and as a Principal Consultant, Information Security, with ThruPoint, Inc.






