Cybersecurity in 2026: What we predicted, what surprised us, and what’s next

Cybersecurity in 2026: What we predicted, what surprised us, and what’s next

By   |  8 min read  | 

At Palo Alto Networks, we are privileged to sit at the intersection of cybersecurity technology, business, and outcomes. We speak to hundreds of customers, partners, analysts, and other experts every day about threats, tools, and solutions, so we’re often asked for our opinions on what’s next for cybersecurity.

But when technology leaps forward, it can create trends whose impact and speed are much harder to forecast. The sudden changes to the cybersecurity landscape in the first half of 2026 are a good example of this, leaving many playing catch-up in some areas. 

To illustrate the salience of these changes, let’s take a look back at our predictions for this year, as outlined by our Chief Security Intelligence Officer, Wendi Whitmore, in her late-2025 article ‘2026: The Year of the Defender’, and see which have come true, which haven’t, what’s surprised us, and what’s next.

The new age of deception: The threat of AI identity

The role of frontier AI in shaping cyber risk and vulnerabilities has become far more significant in 2026, impacting many of our predictions. AI identity is just one significant part of that.The transition from human identities to non-human identities (NHIs) is not only well underway but progressing even faster than we predicted in late 2025. The ratio of NHIs to human identities was 82:1, now it’s a staggering 109:1. We’ve all had to step up our capabilities in pressure testing identity systems to simulate bad actors’ increasing use of NHIs in their attacks. It’s a trend our CyberArk acquisition did anticipate, however, leading us to build our new Idira platform around identity.

Thankfully, our access to new frontier AI models via our participation in Project Glasswing has allowed us to model some of these emerging attack vectors. It’s a good thing we can, because in the last few months, identifying who – or what – is really in a network has become one of the most pressing challenges in cybersecurity. Finding out the truth can feel like discovering you’ve got thousands of employees you didn’t know you’d hired.

The new insider threat: Securing the AI agent

Wendi’s warning about the urgent need to secure autonomous agents has more than played out, as agents have become the ultimate force multiplier. Hijacking and escalating privileges occur at machine speed, and it’s now clear we have to move away from thinking of this as a technology issue. Clearly, it’s a governance issue that must be given even more consideration in the C-suite and at board meetings. 

In fact, I think strong governance will soon become a critical differentiator among organisations, determining their ability to onboard new virtual employees without any HR function, written job function, or pre-established permissions to review. Guardrails, policies, and processes will need to be updated and reimagined from the start. If you want a great executive-level perspective on this, check out our latest Peer Insights guide on governing AI and agentic systems at enterprise scale. It contains an excellent set of observations and recommendations from organisations that are re-architecting governance in the agentic AI era.

The new opportunity: Solving the data trust problem

Data poisoning is where 2026 reality differs most from our predictions: The issue has become even more pronounced than we predicted. As an industry, we still don’t have the right tools to fully stop poisoned data. This puts even more pressure on organisations to focus on data security posture management and AI security posture management. 

What we’ve learned in the past six-plus months is that none of us can afford to give AI models and agents unfettered access to the full suite of data we use to run our businesses and make mission-critical decisions. We must control their access, and we all need to use the lessons of frontier AI to secure our data pipelines, probing for lineage, provenance, sovereignty, and model behaviour. Until recently, too many organisations still had silos between data security and AI security. Now, we’re seeing AI governance committees being created to help bridge those silos in order to ensure the data is fully trusted. That has forced DevOps, security, IT, and business stakeholders to the table at the same time, and that’s a good thing. But much more remains to be done to fully solve the data trust problem.

The new gavel: AI risk and executive accountability

One of the cybersecurity areas evolving most quickly in 2026 is executive accountability. This is now a board-level issue, as it must be in order to resolve issues as fundamental as determining liability for a rogue AI agent. There has been a lot of conversation around merging the roles of chief AI officer and chief risk officer into the single executive position of chief AI risk officer. I believe this will happen quickly in the coming months; once again, frontier AI has raised the stakes for everyone.

Regulations such as NIS2 and DORA (Digital Operational Resilience Act) already carry some level of executive liability; the AI Act adds another layer of accountability and highlights the point that European organisations are governing and adopting simultaneously. But it’s important that we think of governance as far more than a regulatory compliance requirement. Regulations are the bare minimum guidelines organisations should strive to meet, and even with their rapid evolution, regulations aren’t able to match the speed of cyber risk, so don’t let regulatory pressure alone drive your governance practices – follow and anticipate where cyber risk is going.

The new countdown: The quantum imperative

Trying to predict when quantum’s potentially huge impact on cybersecurity will show its face is incredibly difficult. As Wendi pointed out, ‘silent data exfiltration’ isn’t a hypothetical issue but one that must be part of every organisation’s cyber risk assumptions. Customers, however, aren’t paying as much attention to it as perhaps they should.

In part, that’s due to the fact that frontier AI has pulled so much focus in cyber risk discussions that it’s been easy to miss other important challenges – such as quantum. We still talk a lot about ‘Q-Day,’ when we’ll see the migration happening in full force, but not much real action is being taken – yet. We receive the most interest and questions about quantum from customers in financial services and critical infrastructure; they understand the cascading effect it is likely to have throughout their enterprises. But keep in mind that attackers are doing their homework by experimenting with quantum to run inventory checks on which encryption tools are blocking their attacks. Don’t underestimate the persistence and ingenuity of hackers, which will allow them to evolve their quantum strategies very quickly.

The new connection: The browser as the novel workspace

In many ways, the escalation of browser security as an area of importance is overdue. For years, organisations have been dealing with contractors, virtual employees, in-house employees – all using personal devices to access data, applications, and services through the browser. But relatively few organisations have made browser security a priority. That’s unfortunate. The browser is the new operating system: the unsecured door every enterprise has and everyone uses. 

Our predictions for 2026 included the emergence of the agentic browser, and that has now gone mainstream. But so has the idea of browser-based attacks. After all, it’s the natural converging point of humans, agents, and data. This has been particularly evident in recent months as more and more organisations embed AI into their browsers as a way to boost productivity, innovation, and efficiency. This will put even more emphasis on zero trust as the enforcement layer, and the first step in deploying zero trust today should be the secure browser. There’s no better way to secure data, applications, and access.

A final thought: What’s around the corner?

One thing we know for sure is that the advantage we all, as defenders, have built up and tried to leverage through understanding frontier AI will be compromised by attackers within the next few months. Once we’ve lost that advantage, our best defensive position will be to achieve the highest possible data quality, which we believe will be aided significantly by Precision AI® and the huge amount of data telemetry we possess.

Another thing we’re all going to see is agent-on-agent conflict. We can easily envision battles between competing agents – and even between frontier AI systems. We’re going to have all-out battles of defensive and offensive AI, each operating autonomously. But the role of the human expert will be critical to resolving this conflict. Without smart, experienced, and innovative people supervising in the background, agent conflict is going to be very messy and often unresolved.

Finally, real-time assurance is going to become a key issue. How can organisations achieve truly real-time assurance and make it a mainstream function? We have to keep driving down metrics like MTTR to single-digit minutes, and that will be driven less by policies and more by telemetry.

One thing is certain: The next six months will be very important. I hope we can report back to you next year about the great progress our industry has made.

Haider Pasha is vice president and chief security officer for EMEA at Palo Alto Networks.

STAY CONNECTED

Connect with our team today