Cybersecurity has stopped being a purely technical topic. It is now a budget line, a legal obligation and, increasingly, a question of whether your staff can tell a real colleague from a synthetic one on a video call. This guide walks through the cybersecurity trends that shaped 2026, using published figures from IBM, Verizon, Gartner, the FIDO Alliance and EU regulators.
Key Takeaways
- The global average cost of a data breach reached $4.99 million in 2026, a record after two years of decline.
- Unpatched known vulnerabilities have overtaken stolen passwords as the leading way attackers get in.
- Attackers use AI to industrialise old tactics rather than invent new ones, and deepfake calls are now a mainstream fraud channel.
- Shadow AI, meaning AI tools employees adopt without approval, showed up in 43% of breached organisations.
- Fewer ransomware victims pay than at any point on record, but the ones who do pay more.
- Fixed deadlines now exist for post-quantum cryptography and for EU product security rules.
What Changed in 2026
Two things separate 2026 from the years before. Defenders lost ground on speed, taking longer to find and contain breaches than in any of the previous five years. And artificial intelligence stopped being a talking point, becoming a measurable factor on both sides of the fight. That combination explains most of what follows.
What a Breach Actually Costs Now
IBM’s Cost of a Data Breach Report 2026 put the global average at $4.99 million per breach, up 12% year on year and a record high. The United States sits far above that at $11.5 million, more than double the global figure. The previous year’s average had fallen to $4.44 million, so this is a reversal rather than a continuation.
The reason matters more than the headline. Detection and containment now takes an average of 247 days, up from 241, ending five consecutive years of improvement. Every extra day is more data taken, more systems touched and more notification work later.
Supply chain compromise was the second most common way in and tied for the longest lifecycle at 258 days. If a supplier is breached, you often find out late.
What Companies Are Spending
Gartner forecast worldwide end-user spending on information security at $248.9 billion for 2026, growing 12.7% in constant currency and reaching a projected $372.6 billion by 2030. The fastest growing categories are all cloud related, and securing AI itself is the only segment whose growth rate accelerates every year through 2030.
Read that alongside your own stack. If your spending has shifted to the cloud but your controls have not, the gap is where incidents happen. Our overview of cloud computing trends covers where those workloads are moving.

How Attackers Are Getting In
The 2026 Verizon Data Breach Investigations Report analysed real incidents rather than opinions, which makes its ranking of initial access methods the most useful list in security.
Unpatched Software Overtook Stolen Passwords
Exploitation of known vulnerabilities accounted for 31% of breaches and is now the leading initial access method, ahead of credential abuse at 13%. That is a reversal of the pattern most security awareness training still assumes.
The gap is a patching problem, not a discovery problem. Only 26% of known exploited vulnerabilities were fully remediated during 2025, down from 38% the year before. These are flaws that are publicly catalogued and actively used in attacks. Most organisations know about them and have not closed them.
In practice, your patch backlog is a bigger risk than your password policy. Start with internet-facing systems: firewalls, VPN gateways, file transfer tools and remote access appliances.
People Are Still Involved in Most Breaches
Some 62% of breaches involved the human element: someone clicked, someone was tricked, someone misconfigured something. Attackers have moved from obviously suspicious messages toward pretexting, building a plausible business story and slotting into an existing conversation thread. A fake invoice query inside a real email chain is far harder to spot than a badly spelled prize notification.
Third Parties Widen the Blast Radius
Roughly 48% of breaches involved a third party, a 60% increase year on year. Your security is now partly your vendors’ security. Keep a list of suppliers with access to your systems or data, know what each one can reach, and require breach notification timelines in contracts.
Attackers Are Using AI, and It Shows
The honest version of the AI threat story is less dramatic than the headlines and more worrying. Verizon found that attackers are not inventing new categories of attack. They use AI to speed up and scale roughly fifteen existing techniques each: better phishing text, faster reconnaissance, more targets per hour.
IBM measured the effect on outcomes. One in four malicious breaches involved AI in some form, a 56% jump in a single year, and those breaches cost around $6 million on average, about a million more than the baseline.

Deepfakes Moved From Novelty to Fraud Channel
The clearest documented case remains the engineering firm Arup, where a finance employee in Hong Kong joined a video call with what appeared to be senior colleagues and authorised 15 payments totalling roughly $25 million. Every other participant was synthetic. The Financial Times reported the case in May 2024 and Arup confirmed it.
Survey data suggests this is no longer rare. In a Gartner survey of 302 cybersecurity leaders published in September 2025, 62% of organisations reported a deepfake incident in the previous twelve months. A follow-up Gartner survey of 297 CISOs found 41% had seen a deepfake used with social engineering on an audio call and 35% on a video call. Pindrop, analysing 1.2 billion calls for its 2025 Voice Intelligence report, recorded deepfake fraud attempts in contact centres rising more than 1,300% during 2024, from about one a month to seven a day.
The defence is a process, not a product. Require a second channel for any payment change or urgent transfer request: a callback to a number already on file, or approval in a system the caller cannot influence.
AI on the Defensive Side
The same technology cuts both ways. Organisations using security AI and automation extensively reduced breach costs by about $1.93 million and shortened breach lifecycles by 65 days compared with organisations using none, according to IBM’s 2026 report.
That effect comes mainly from triage. Security teams drown in alerts. Tools that group related signals and surface the handful of events that matter buy back the hours that decide whether an intrusion is caught on day two or day eighty. Distributed architectures such as a cybersecurity mesh exist for the same reason: to make scattered systems observable from one place.

Shadow AI Is the New Blind Spot
Shadow AI means employees using AI tools that IT never approved: a chatbot for drafting client emails, a transcription service for meetings, a code assistant plugged into a repository. It is the same pattern as shadow IT in remote work, with a sharper edge, because the data usually leaves the building.
IBM found shadow AI incidents in 43% of breached organisations in 2026, up from 20% the year before. Among organisations that suffered an AI-related breach, 92% lacked proper access controls on their AI systems, and only 40% of organisations overall use access controls to protect AI models and data. Some 21% had a security incident involving their own AI models or applications, up from 13%.
Banning the tools rarely works, because people adopt them to get work done. Approving a small set, saying clearly what data may go into them and logging usage works better. A written AI governance model gives that decision somewhere to live, and our guide to AI ethics at work covers what employees should be told.
Identity Is the Front Line
Identity and access management, usually shortened to IAM, is the set of systems that decide who can reach which application and data. Privileged access management is the stricter version for administrator accounts. When credential abuse still accounts for 13% of breaches and 62% involve a person, this is where controls pay back fastest.

Good IAM does three unglamorous things. It gives IT an audit trail of who accessed what, which regulators ask for. It limits the damage an insider can do. And it removes access when someone leaves, the step most often missed.
Passkeys Went Mainstream
Passkeys replace passwords with a cryptographic key stored on your device and unlocked by a fingerprint, face scan or PIN. Because there is no shared secret to steal, phishing a passkey does not work the way phishing a password does.
On World Passkey Day in May 2026, the FIDO Alliance reported an estimated 5 billion passkeys in use worldwide. Its survey of 11,000 consumers and 1,400 enterprise decision-makers across ten countries found 90% awareness and 68% of organisations either deploying or actively rolling out passkeys for employees. Fully passwordless remains the exception at 28%.
If you do one thing this quarter, move administrator accounts to phishing-resistant authentication. Our guide to biometric authentication for remote work covers the practical trade-offs, and decentralized identity looks at where the model goes next.
Zero Trust in Practice
Zero trust assumes the attacker is already inside and verifies every request instead of trusting anything by network location. It is less a product than a design principle, and it is why a stolen laptop on the corporate Wi-Fi no longer means free access to everything.
The practical version is unexciting: strong authentication everywhere, least privilege by default, network segmentation so one compromised machine cannot reach finance systems, and logging that lets you reconstruct what happened. We cover it in more depth in our guides to zero-trust architecture, zero-trust adoption and how businesses are implementing it. For distributed teams, cybersecurity in remote work covers the home network side of the same problem.
Ransomware: Fewer Victims Pay
The economics of ransomware shifted. Chainalysis, which tracks payments on public blockchains, recorded about $820 million in ransom payments during 2025, down from $892 million in 2024 and well below the $1.25 billion peak in 2023. Roughly 28% of victims paid.
Incident response data from Coveware shows the payment rate falling further through the year, reaching 20% in the fourth quarter of 2025, an all-time low. Victims who do pay tend to be those with no viable backups, and their payments have risen: Coveware recorded an average of $591,988 and a median of $325,000 in that quarter.
The lesson is straightforward. Tested, offline backups turn a ransomware attack from a business crisis into an expensive weekend. Untested backups are a plan, not a defence. Restore something real, on a schedule, and time how long it takes.
The Quantum Deadline Is Now a Date
Quantum computers capable of breaking today’s public-key encryption do not exist yet. The risk is that encrypted data stolen now can be decrypted later, which matters for anything with a long confidentiality life: contracts, medical records, intellectual property.
NIST has set a timetable. Its guidance deprecates RSA, ECDSA, EdDSA, Diffie-Hellman and ECDH from 2030 and disallows them entirely from 2035. Replacement standards, including ML-KEM for key exchange and ML-DSA for signatures, are published and shipping in mainstream cryptographic libraries.
For most businesses the 2026 task is inventory, not migration: find where you use public-key cryptography, which vendors control it, and when each supplier plans to switch. Our guides to quantum-safe encryption and quantum computing and future workflows go into the detail.
Compliance Deadlines You Cannot Ignore
Regulation moved from principle to date. The EU Cyber Resilience Act, which sets security requirements for products with digital elements, brought in reporting obligations for actively exploited vulnerabilities on 11 September 2026, with full application on 11 December 2027. If you sell hardware or software into the EU, this is a product requirement, not an IT policy.
NIS2 continues to expand cybersecurity duties across eighteen sectors as member states finish transposing it into national law, with management bodies personally accountable in several implementations. DORA has applied to EU financial entities since 17 January 2025, and supervisory attention has shifted to third-party risk and resilience testing.
Privacy rules run alongside all of this. Our overviews of data privacy trends, employee data rules, privacy compliance frameworks and data localization laws cover the wider picture, while EU AI Act compliance and AI regulation deal with the AI-specific duties.
The Skills Gap Changed Shape
The shortage is no longer mainly about headcount. In the 2025 ISC2 Cybersecurity Workforce Study, 62% of respondents reported significant or critical skills shortages, up from 44% a year earlier, while only 34% said staffing levels were adequate. The largest gaps were AI skills at 41%, cloud security at 36%, risk assessment at 29% and application security at 28%.
Meanwhile 39% of organisations had a hiring freeze. Most teams will not be given more people, so training the people they have is the realistic route. Some 28% have already integrated AI tools into security operations, and 63% of those report meaningful productivity gains.
Where Emerging Technology Actually Helps
Extended detection and response, or XDR, pulls signals from endpoints, email, cloud services and network tools into one place, so related events are seen as one incident rather than four unrelated alerts. Given that detection time is now the main cost driver, this is the category aimed most directly at the problem.
Blockchain gets cited constantly in security marketing. Its genuine contribution is narrow but real: tamper-evident records. Where you need to prove a log or a credential has not been altered after the fact, a distributed ledger does that well. It does not stop phishing, patch your servers or protect your cloud storage. Our pieces on blockchain HR records and IoT in business operations show where the honest use cases sit.
A Practical Order of Work
If the list above feels long, this is the sequence that maps to the evidence:
- Patch internet-facing systems first, and track known exploited vulnerabilities specifically.
- Move administrator and finance accounts to phishing-resistant authentication.
- Add a mandatory callback step for payment and bank-detail changes.
- Test a full restore from backup and record how long it took.
- List the AI tools staff actually use, then approve a supported set with clear data rules.
- Map which suppliers can reach your systems, and what happens if one is breached.
- Inventory where you rely on public-key cryptography, ready for the 2030 deadline.
None of these needs a large budget. Most need someone to own them and a date.
Conclusion
The 2026 picture is not one of exotic new attacks. It is old attacks running faster, against organisations that are slower to notice and more entangled with suppliers and cloud services than five years ago. Costs are at a record, detection times are rising again, and the human element still sits behind most incidents.
The encouraging part is that the effective responses are known and mostly boring: patch what is exposed, verify who is asking, keep backups you have actually restored, and know which AI tools your staff use. Digital trust is built the way it always was, by making the dull things reliable.
Found this useful?
Make SmartKeys a preferred source on Google, and our articles will surface more often in your Top Stories, AI Overviews, and AI Mode.
Add as Preferred Source







