The conversation, hosted by Alec Brust on "The Digital Decode," features Presidio CTOs Dan Lorman and Mike Brown discussing the 2026 cybersecurity outlook. Dan Lorman presents a top-10 list of trends synthesized from 125 vendor reports, with the number-one trend being the rise of autonomous AI agents that execute multi-step attacks. Other key trends include AI-powered social engineering, post-quantum cryptography urgency, fully automated ransomware, AI insider threats, and the convergence of advanced persistent threats with cybercrime. Mike Brown emphasizes the criticality of speed and scale in defense, noting that attackers leverage automation for rapid exploits. He highlights identity as the new perimeter and browser-based zero-trust workspaces as abstract security architectures. Brown also discusses supply chain risks from third-party integrations and his personal predictions: data chain of custody to ensure cryptographic provenance and trust in data, and quantum cryptography pilots in financial services, spurred by NIST standards and regulatory compliance. Dan Lorman awards top vendor reports, with Trend Micro ranked first for its comprehensive 39-page PDF, and praises Gartner's prediction that AI may foster lazy thinking, leading to AI-free skills assessments. The episode underscores the need for vigilance, resilience, and proactive investment in AI and quantum security measures to counter evolving threats.
Hi everyone, happy new year and welcome back to the digital decode brought to you by Presidio and our partners over at Cisco. Once again, I'm your host, Alec Brust, and before I jump into our first topic of 2026, I do have one little announcement, and that is that the digital decode is now on YouTube. If you are interested in watching us decode all things tech, you can head over to the Presidio YouTube account for all of our episodes moving forward, including this one. So now to jump into our first topic of 2026 with the new year, there is always come in these new opportunities in the tech industry, but there are also a ton of challenges that come along with those opportunities, especially in the cyber security space. And that's why today I'm joined by return guest, Presidio C. So Dan Lorman, as well as new guest to the show, Presidio C. So Mike Brown to talk about the 2026 cyber security outlook. There's a ton on the horizon, so Dan, I'll hand it over to you to kick us off. But first of all, I just just talked to our audience for a little bit. Why is this so important? We do these predictions. Everyone's doing these predictions. We see these predictions and reports every year about this outlook. But why is it so important to our audience? Yeah, I mean, thanks, Alex, for being back with you. It's good to be with Michael again. I just really think every year, you know, it is around the holidays in the January people say, you know, it's the same as last year. You know, same only worse and that kind of a thing. But the reality is we make predictions in every area of life, you know, whether it be weather, financial forecast, I'm sure people out there listening care about their stock market portfolio and what they're investing in and not investing in and with our careers and so many different areas of life. And cyber security has become front and central for every type of type of technology now, you know, AI, of course, is huge with the big theme in 26. We're going to be talking a lot about that. But really, I would just say that, you know, with cyber security becoming so important, it is like something that can help listeners. And I every year, I have an opportunity, I've been doing this now for 12 years and really looking at across the industry, not just prosidio predictions, but what are all the top vendors saying in this year, we looked at 125 reports from all around the world, top vendors, we rank them, we looked at them, you know, what are the trend of the trends, if you will. And then what's most important and then you know, this can help people with their careers with their, it's isn't just about marketing, it really is, you know, what's happening next, because if you know what's going to happen next, just like with your stock portfolio, it's going to help you invest, it's going to make good decisions. And for security leaders, for technology leaders, help you build your roadmap for planning 2026, and what are you going to invest in, what are you going to spend your time on, what should you not be spending your time on. And when you look across the industry, there really are some important trends that everyone should be paying attention to. So use this, you're not going to agree with everything, you're going to disagree with some, but use this to help your career personally and your company and your business. I mean, absolutely, you know, it hits people, when we talk about cybersecurity, it's hitting these large enterprises, but then it also trickles down all the way to the individual. So it's important from an individual aspect in business and across the tech industry, but in a ton of different industries as well. So you did talk about what you've been seeing across all of these reports, do you have a top 20, a top 10 that you're looking at right now. Yeah, we do. We have a top 10. And by the way, you can get these a Lormon on cyber security government technology magazine. I've got a weekly blog, Lormon on cyber. You can go out there. We'll put a link to that in the in the notes. And so you can go out and you can read these two reports. And you know, I'm just going to quickly run through what the trend of the trends are. So what are all these vendors saying. And then we can dive into some specific predictions, but number one, which may or may not be a surprise to listeners rise of a gentick AI attacks autonomous AI agents will execute multi-step operations and interact with real systems turning compromised agents into powerful independent attack vectors. So that's the number one across all the vendors number two AI powered social engineering. So deep fake services and hyper personalized AI will revolutionize business email compromise and extortion scams. We saw a lot of that in 25. We're going to see more than 26 making deception nearly impossible to detect. There's only going to get worse. It's going to be harder to know what's real, what's fake. So the three of the shifts of post quantum security. There's been a lot of talk about post quantum, but the organization's must accelerate the transition to post quantum cryptography to defend against harvest now, the crypt later strategies and sophisticated adversaries. So you're going to start seeing more and more quantum projects showing up in companies around the globe. And that's really got to be a priority. Before that that's surprising. It's back for another round ransomware, but ransomware will become fully automated in 2026. So ransomware will revolve into AI driven operations that scam exploit and extort with minimal human input focusing on intelligent data exploitation over encryption. A number of people say a number of reports will dive into that a little bit later, but talk about the getting rid of the encryption completely with ransomware. It's just really just jumping straight to extortion, which is pretty scary, but you're seeing a lot of that. Number five, AI insider threats autonomous AI agents will privileged access will become the new insiders requiring specific AI firewalls to prevent them from becoming vulnerabilities. So AI agents, you know, doing functions. And we got to make sure we're monitoring them. Number six, converges, convergence of advanced persistent threats, APTs and cybercrime nation state actors and criminal gangs will share infrastructure and payloads, blurring attribution and accelerating the scale of global cyber operations. And go through four more here three. And then the top 10 will get Mike's view on these, but supply chain infrastructure targeting attacks on global logistics satellite communications and smart transportation systems will increase turning outages industry strategic weapons for geopolitical influence. Number eight was browser based zero trust workspaces. So more browser based attacks as the browser becomes a primary enterprise operating system security will shift towards cloud native models and enforce zero trust directly within the browser. Number nine, nine and 10 number nine, after fee of critical thinking widespread gen AI usage will cause a surge of lazy thinking leading 50% of organizations to implement AI free risk skills skills assessments for hiring. And then last but not least identity identity is the new perimeter with traditional VPNs collapsing identity based security and zero trust networks, Ctna will become the primary defense against automated session hijacky. So those are the top 10 trends. And then I'll let you catch your breath there for a second, because that is a ton. This is a ton of good info there, but Mike, I'm really interested in kind of what are your takes on those top 10. It's definitely very broad. I'll zoom in on a couple of identity is huge because you have to know who has access to what and what systems are on your network. And then overall and everything is AI it's not surprising for anyone over there and multiple aspects at one theme I definitely see with your predictions is the offensive side. So it sets things like AI social engineer and you have your agent agente AI attacks and then ransomware you got the automated ransomware I think it all leads to a landscape where speed and scale are critical to defend against these types of attacks. My background is financial services and you know everything there is about it was about seconds then micro seconds and milliseconds so speed is critical. I think it's the same thing there. The attackers have speed at their side and they are more nimble and then defensively you know identity is a new perimeter that was that and I think was the browser zero trust workspace. What that show in me is that security architecture is becoming more abstract so it's less metric network centric than we used to have cybercrime that's it's very very very broad theme but I think automation is going to help attackers with things like fraud that's I know it I can do it a lot quicker and everything but I'm also thinking about more sophisticated things like money laundering. You know we're seeing you know Monday laundering campaigns are more like a foreign exchange trading desk right now where they convert currency to currency and smaller denominations and you know in different aspects just to kind of hide the money trail you can go from Bitcoin to Ethereum. And then we've done nominations make harder to contextualize all of that and then eventually to one of the lesser traceable currencies like Monero that's things we're seeing a lot more right now. Final one I'll just touch base on his supply chain so things like SAS and especially the third party integrations there are I see misamplifiers and what I mean by that it gives attackers exponentially more targets to go after. Not just the one company that has the third party integration or the SAS vulnerability but think about any company that uses a third party and has that a vulnerability so attacks can become automated end to end from like reconnaissance all the way to execution they can automation attack they'll get all the users that have a vulnerability out there can scan the network scan the internet and look for vulnerabilities but also deploying the attacks simultaneously or. or no, sub-second or in a few seconds. So your probability for a successful attack, it just went up significantly. No, that's great. And, you know, it seems like cyber security attacks are going to be like you said a lot quicker. We're going to have to react a lot more. And I just curious out of those 10 trends and Dan, keep me honest here, I want, I don't want to call these your favorite predictions that you're seeing for 2026. But what are you seeing as kind of, I don't know, maybe the most top of mind, the most important things that maybe, you know, big organizations should look after. Yeah, I actually did give awards at the end. So I will, I do have some favorite predictions. I will jump to that in a moment. But I want to make sure listeners know that this isn't just about individual predictions. Those were trends. I do want to highlight kind of the top reports from the top vendors. So we do a ranking. And when we look at the ranking, it's not just that we don't know what's going to happen in the future. So I can, you know, you can great, maybe at the end of the year, but it's also the way they put it in formats. They do PDFs. They have graphics, you know, interactive formats, multiple channels. And then they have references. So for example, the number one report this year, best report of the year was again, Trent Microw. I think they won for the last five years. They do a great report. It's a 39 page PDF. They have over a hundred references. So if you want to say, well, back this up, where does this come from? How do we connect the dots? You can go and look at the stories. You can go and look at details. And their top three were AI will become a top attack vector, executing voltage step attacks, automating, fishing and social engineering. So again, we've heard that a lot. Number two, vibe coding will increase risk of insecure code unless fully reviewed by humans. Interesting. And then supply chain and insider threat converge with cloud remaining a prime target. So, you know, those are their top trends, but again, they have they have a lot of different material that you can dive into in the report. All of these are linked to in the report. We're going to give you the link to number two. Second best report this year was Google Cloud Mandient. Their five top areas were adversaries fully embraced AI, prompt injection, manipulate AI agents, paradigm shifts, supercharged security analysts and enterprise virtualization is under threat. That's Google. It's a lot of really good YouTube videos. You can go to their executives on that as well with Google. Number three was watch guard. They were a smaller company, but they always do great reports. They're a lot of fun. They actually have a lot of humor in there. But they're five a little bit different. Crypto ransomware goes extinct, which is interesting. OSS open source software uses AI for supply chain protection. CRA mandates spark secure by design. ZTNAs which is zero trust starts to replace traditional VPNs and AI literacy becomes core cyber skill for many. So again, we for all of us, we got to learn AI. Four was Fortinet. Their top five predictions were autonomous AI agents run cyber attacks, attack lifecycle shrinks to minutes. J and AI accelerates data extortion, critical infrastructure ransomware will expand and identity becomes a primary attack surface, which again, you see that a lot. And then I wanted to mention number five, I mentioned Gartner. One of the things that people say, well, why are Gartner and Forrest the Forrest is number six? Well, this is also what we do in this analysis. This is all free. This is all free material. You can get all these reports online. You don't have to pay for these. Obviously Gartner and Forrest are in IDC and a lot of the others have great paid reports. But it could cost tens of thousands or even hundreds of thousands of dollars for some of those. So this is free material that Gartner made available. It's really good. Couple four here. I want to mention that I'll give you my favorite from Gartner. And geopolitical volatility increases cyber risk. We're seeing that around the world right now with what just happened in Venezuela, what's going on in Iran right now. Poor security fuel ransomware and ATO, AI adoption introduces new data and risks and incident response overload weekends resilience, which is an interesting one because resilience is obviously front and center. My favorite one overall, this mansion, I want to get Michael is actually presidios on the list too, like 23 or 23, 23. I want to hear Michael's predictions, which were great by the way. I think he did a really outstanding job. I want to hear those. But I will say my favorite one of all the reports was from Gartner. It was it AI is making us lazy. And it kind of prompts, you know, it gives you action. It gives you like something to do homework for and not to be lazy. I mean, AI is a great tool. We're obviously advocates of AI. But if you're just going to rely on AI, hopefully it's not writing, it doesn't write any of my blocks. But writing material for you, use it as a tool. It can help. But don't let it make you lazy. And the fact that 50% of organizations will start actually doing skills assessments without any AI, I think that speaks volumes. And so I really like Gartner's predictions as well. But Michael, watch it tell us what your predictions were. And they do show up in the list with Procedio. It's all in the Procedio website I know in the blog section. And what were your top predictions? Yeah, thanks, Dan. I was a little disappointed. I wasn't the top prediction, but the Gartner one I have. Sorry, absolutely. I'm not that I. They deserve first place. That was a great one on there. So I'm going to stay away from the AI predictions that I put in there as well. One I'd focus on is the data chain of custody track and work cryptographic provenance. Kind of a big thing to take, but with AI and deep fakes, I think the biggest problem or one big problem is actually trust. Like how do you know the data is real? So data chain of custody is like a digital paper trail for content and information. It can show where the data came from. It shows who touched it and whether it changed or not and a whole history of changes on there. So you can think of it kind of like blockchain where you have cryptographic proof of who the data is from. It shows any edits and who access the data and why. So instead of just trusting companies can prove their data as authentic. And the technology has been there for a while, but it's not really a technology push. I feel this and it's on my list because I think regulators, cyber insurance, reputation or risk and you know, fear of manipulated data is really pushing that to the top. And I feel over time this is going to become slowly become a standard feature behind the scenes for most of. Now the second one it was on your top 10 and was on my list as well and it's it's passionate for me is quantum cryptography. So my prediction is a little selfish because I'm a financial services background, but quantum cryptography pilot and financial services. And why this made my list or what's really pushing it is this finalized their post quantum encryption algorithms. So you have the world economic forum. You have the FS ISAC and many of the other ISACs. Their highlight and a quantum is a top emerging risk. I was, are you not emerging? It's a current risk now. And I predict we're going to see control tests of quantum key distribution and probably some close post quantum encryption methods and decryptions in financial services. And you know, this test will test for interoperability, performance and then finally what drives a lot is regulatory compliance. So the large global banks that I know a lot of them have teams of quantum researchers already they're on staff. They're doing a lot of interesting stuff, but with NIST, I think that's going to be the catalyst and it's going to make 2026. Remember it is the year that financial institutions and other critical infrastructure start building defenses for the quantum error. No, no, super interesting. Like Dan said, you can go ahead and check out our blog that we have on presidio.com for all of our predictions and also links to a ton of those reports that Dan mentioned. And I will include that in the show notes for everyone. You know, this is just a super interesting topic every single year. You know, as I'm the social media manager here at presidio. And so I'm not very much in tune to all the cybersecurity things that you guys deal with every day. But it seems like it's getting more and more, you know, ingrained with AI in, you know, our society. And I see it on social media all the time. You got to be more vigilant. These videos are looking real and real are every day. And so I know that that trickles into the cybersecurity space as well. Dan, do you have anything else that you want to say before we tie off here? Yeah, I was about great job. Mike, I thought those were great, great, great list. And it is number 22. I said 23 earlier. So it's right there. It's, it's, it's, we'll put the links up to these, to these reports. And you can see all the links to all of the different ones that are free and are available online from all the vendors across the industry globally. I did want to mention one more than I thought was interesting. And this is category was at the end, I give awards for the different ones. And this was brought, um, runner up in the category of scariest, but still believable, which I thought was impractical as well. So this, this is from the deal, Israel, Israel, co-founder of NCT of armist and his, his, um, his prediction was AI powered financial system manipulation. So let me read this real quickly. Autonomous trading bots and AI driven deepbakes will manipulate stock markets, commodities, and cryptocurrency ecosystems by impersonating regulators or company executives, AI systems will trigger false earnings reports, disseminate false corporate announcements, falsify investor briefings, or simulate market crashes. The result, global financial instability with second scale losses that human operators cannot contain. That's pretty scary. Now, he's not saying he's not saying a stock market crash there. He's just saying we're going to have somewhere along the 2026. We're going to have a blip that's going to probably make the front page of the Wall Street Journal or something that's going to really cause a lot of turmoil to say the least. So I think the lesson from that one, whether that happens this year, and some of these, by the way, we always say some of these may happen 26. Maybe it's 27. Maybe it's 28. But the trends are interesting is to always check your facts, check your sources. And I tell people, people, there's a ton of great advice in these reports. We don't get into a lot of the advice with the predictions, which come with a lot of these reports. Some of it is marketing and sales. I'll admit that. But some of it is really good advice. It's like, you know, if something seems unbelievable, it probably is not true. So make sure you're checking your sources. Make sure that you're checking from an identity perspective. Who's really sending that? It's probably not really your nephew or your niece. You're talking London, who needs wire money to that because they're in jail. That's probably not really happening. I said, "Kill it, I guess." But, you know, those fake messages, you know, have that family word that you know, right? That you can know that it's just really my niece who's asking me for money. So yeah, I mean, those are the kinds of things we all need to be really careful of because deep fakes are getting more and more powerful. I just wanted to close with that, but really appreciate Allocque leading this in the time to be able to share some of these predictions. Absolutely, Dan. I love that. I think that next time we do this, you know, for 2027, I'm going to need you to do that award section again. That's great. That definitely is super scary. But no, thank you again for coming on to the podcast. I always love having this conversation. And we will make sure to keep tabs on all of these trends that we discussed in today's episode throughout the year and see, you know, how they play out, how our predictions play out. And I'm sure I'll be saying, you know, some more blogs from you, Dan on our website. And we will touch base again next year to discuss the predictions in 2027. But I guess any other closing remarks before I close out the podcast for today. No, nothing from me. I want to thank you, Alex for having me on. Thank you, Dan, for including me in the list. And this has been a great time. Thank you. Awesome. Yeah. It was great having both of you on, Michael, for your first time. Dan, I know we've done this a couple times. So it was always great having you on. But thank you, everyone so much for tuning in again to the digital decode. As I said earlier, please go check out our Presidio YouTube page. This episode and every episode moving forward will now be available to watch on our channel. You can also explore our educational content and case studies on our YouTube page. Please rate and subscribe to the digital decode wherever you get your podcasts. And remember to follow Presidio on Instagram and LinkedIn for the latest updates. Thanks again. Thank you. Thank you. [MUSIC]
Podcast Summary
Key Points:
The 2026 cybersecurity outlook highlights AI-driven threats as the top trend, including autonomous AI agents executing multi-step attacks and AI-powered social engineering using deepfakes.
Ransomware is evolving into fully automated operations focused on data extortion rather than encryption, while post-quantum cryptography becomes urgent due to "harvest now, decrypt later" strategies.
Identity-based security and browser-based zero-trust workspaces are replacing traditional VPNs, as identity becomes the new perimeter.
Supply chain attacks are amplified by third-party integrations and SaaS vulnerabilities, enabling automated, large-scale exploits.
AI-induced "lazy thinking" is predicted to lead 50% of organizations to implement AI-free skills assessments for hiring.
Top vendor reports (e.g., Trend Micro, Google Cloud Mandiant, WatchGuard, Fortinet, Gartner) emphasize AI adoption risks, geopolitical volatility, and the need for resilience.
Presidio's predictions include data chain of custody for cryptographic provenance and quantum cryptography pilots in financial services, driven by NIST standards and regulatory compliance.
Summary:
The conversation, hosted by Alec Brust on "The Digital Decode," features Presidio CTOs Dan Lorman and Mike Brown discussing the 2026 cybersecurity outlook. Dan Lorman presents a top-10 list of trends synthesized from 125 vendor reports, with the number-one trend being the rise of autonomous AI agents that execute multi-step attacks. Other key trends include AI-powered social engineering, post-quantum cryptography urgency, fully automated ransomware, AI insider threats, and the convergence of advanced persistent threats with cybercrime.
Mike Brown emphasizes the criticality of speed and scale in defense, noting that attackers leverage automation for rapid exploits. He highlights identity as the new perimeter and browser-based zero-trust workspaces as abstract security architectures. Brown also discusses supply chain risks from third-party integrations and his personal predictions: data chain of custody to ensure cryptographic provenance and trust in data, and quantum cryptography pilots in financial services, spurred by NIST standards and regulatory compliance.
Dan Lorman awards top vendor reports, with Trend Micro ranked first for its comprehensive 39-page PDF, and praises Gartner's prediction that AI may foster lazy thinking, leading to AI-free skills assessments. The episode underscores the need for vigilance, resilience, and proactive investment in AI and quantum security measures to counter evolving threats.
FAQs
Vibe coding refers to developers casually writing code with AI assistance without thorough human review. This increases risk because AI-generated code may contain vulnerabilities that are not caught unless fully reviewed by humans, as highlighted in Trend Micro's top predictions.
AI social engineering uses deepfake services and hyper-personalized AI to create highly convincing scams, such as realistic voice or video impersonations. This makes it extremely hard for victims to distinguish between real and fake communications, escalating extortion and business email compromise.
Traditional ransomware encrypts files and demands payment for decryption, while fully automated ransomware skips encryption entirely and focuses on intelligent data exploitation and extortion. It operates with minimal human input, using AI to scan, exfiltrate, and threaten to leak sensitive data.
As the browser becomes a primary enterprise operating system, security must shift to cloud-native models that enforce zero trust directly within the browser. This approach replaces traditional VPNs and protects against session hijacking by verifying every access request.
It is a digital paper trail that tracks where data came from, who touched it, and any changes made, using cryptographic proof. This ensures data authenticity and is driven by regulatory, insurance, and reputation pressures to combat AI-generated deepfakes.
NIST's finalized post-quantum encryption algorithms will catalyze controlled tests of quantum key distribution and new encryption methods in financial services. These pilots will focus on interoperability, performance, and regulatory compliance, with large global banks already having quantum research teams.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.