CISO’S CORNER The conversations I’ve been having with security leaders this year have a different quality to them. It’s not that the threats are unrecognizable – ransomware, supply chain compromise, credential abuse have been on every CISO’s radar for years. What’s changed is the velocity, the compounding complexity, and the fact that the consequences are no longer purely technical. Regulatory frameworks now place personal liability on the executives who sign off on security programs. A breach isn’t just an incident anymore – for some CISOs, it can be the start of a legal process.

At the same time, attackers are operating with tools and automation capabilities that didn’t exist at a meaningful scale eighteen months ago. The combination of an evolving threat landscape and a tightening regulatory environment is genuinely recalibrating the risk calculus for security leadership. With that in mind, here are the five threat areas I believe deserve serious strategic attention in the second half of 2026 – and the decisions security leaders actually need to make to address them.
For the past two years, most of the AI conversation in security focused on the defensive side: automated triage, smarter detection, analyst augmentation. What’s now undeniable is that attackers have adopted it faster and with fewer constraints. According to the World Economic Forum’s Global Cybersecurity Outlook 2026, 87% of organizations now rank AI-related vulnerabilities as the fastest-growing cyber risk – not a future concern but a present one.
This isn’t about science-fiction autonomous malware anymore but more mundane yet more dangerous threats. AI enables adversaries to craft phishing content that bypasses traditional detection at scale, generate convincing deepfakes for fraud and social engineering, and iterate on attack payloads faster than defenders can update signatures. In practice, attacks that once required skilled human operators can now be templated and launched at volume by less sophisticated threat actors.
The strategic implication is sobering: many defensive programs were designed for human-speed threats. AI-accelerated attacks expose assumptions about detection windows, response timelines, and the effectiveness of controls that rely on attacker mistakes. Security leaders need to audit whether their threat models actually account for this speed asymmetry – or whether they’re still calibrated for 2022.
Ransomware isn’t new, and for a period it looked like law enforcement pressure on major groups might bend the curve. The 2025 Verizon Data Breach Investigations Report shows the opposite happened, based on more than 22,000 security incidents. Ransomware grew 37% year-over-year and is now present in 44% of confirmed breaches. The Ransomware-as-a-Service model has proven resilient: when groups disappear, affiliates reconstitute under new banners within weeks.
What’s changed tactically is the layering of extortion pressure. Double and triple extortion – encrypting data, threatening to publish it, and now explicitly threatening to notify regulators and affected parties on behalf of the victim – has become standard practice. Attackers have realized that under NIS2, DORA, and the SEC’s four-day disclosure rule, they can amplify pressure by triggering compliance consequences alongside operational disruption.
Earlier this year, a ransomware attack on the University of Mississippi Medical Center forced all 35 of its clinic locations to close and cancel scheduled surgeries statewide. The operational impact went well beyond data and posed a direct threat to patient safety. Responding to these attacks is no longer primarily a matter of data recovery but increasingly a question of operational continuity, and security programs that haven’t modeled that shift in targeting logic are behind.
Third-party involvement in breaches has doubled to 30% in the 2025 DBIR – a figure that, on its own, tells you something important about where perimeter thinking has broken down. According to SecurityScorecard’s 2025 Supply Chain Cybersecurity Trends survey, more than 70% of organizations reported experiencing a material security incident originating from a third party in the past year. For many of those, the compromised entry point wasn’t a vendor with access to sensitive data in an obvious sense. It was a managed service provider, a software dependency, or a cloud platform that had access to something no one had formally risk-assessed.
The European Commission and Dutch government agencies both confirmed breaches this year through critical zero-day vulnerabilities in Ivanti’s endpoint management software – a supply-chain exposure affecting customers globally. NYC Health + Hospitals reported a breach to unauthorized access gained through a third-party vendor, with attackers present in the environment for more than ten weeks before detection.
The challenge supply-chain risk poses for security programs is structural. You can invest heavily in your own controls but still be exposed through a vendor you haven’t assessed in two years, or a library that was compromised last month. Mature third-party risk management requires continuous visibility into what vendors have access to, regular re-assessment rather than point-in-time questionnaires, and clear contractual obligations around breach notification. Most programs aren’t there yet.
According to the 2025 DBIR, credential abuse and exploitation of vulnerabilities are now the two leading initial attack vectors – accounting for 22% and 20% of breaches respectively. Read that alongside the finding that 46% of corporate credential exposure now originates from personal, non-managed devices and the picture becomes clearer: the idea of a well-defined, controllable perimeter has been functionally obsolete for some time, but many security architectures haven’t fully caught up.
MFA adoption has improved, but MFA fatigue attacks – where adversaries generate repeated authentication requests until a user approves one to stop the noise – have demonstrated that technical controls alone aren’t sufficient when they can be socially engineered at scale.
Credential-based breaches, particularly those leveraging sessions stolen from personal devices, bypass many of the controls organizations assumed would protect them.
The strategic shift here is conceptual as much as technical. If identity is the new perimeter, it needs to be managed with the same rigor we once applied to network boundaries – continuous monitoring of authentication patterns, behavioral anomaly detection, zero trust architecture that doesn’t assume a valid credential means a legitimate user, and an honest assessment of which privileged accounts are actually exposed.
This is the shift that I think gets insufficient attention relative to its significance. The regulatory environment around cybersecurity has fundamentally changed what it means to be accountable for security outcomes – and the accountability now reaches individuals, not just organizations.
NIS2, fully enforceable across EU member states, ends the traditional delegation model. Executive management is required to actively supervise security risk management, and individuals can be held personally liable for violations – even absent actual damage – if it can be shown they approved inadequate measures. DORA, which came into effect in January 2025, places ultimate ICT risk management responsibility on the management body of financial institutions. The SEC’s cybersecurity disclosure rules require public companies to report material breaches within four business days and to disclose governance and risk management processes annually.
These aren’t compliance box-checking exercises. They represent a substantive shift in how boards and regulators view cyber risk – as a governance failure when things go wrong, not merely an operational one. For CISOs, this changes the calculus around two things: what you document, and what you escalate. Security decisions that were once made at the operational level now need to be traceable, communicated to leadership, and defensible. The question is no longer just “Do we have the right controls?” but “Can we demonstrate the process by which we made these decisions?”
Across these five threat areas, a few strategic imperatives stand out clearly.
First, attack surface visibility needs to be continuous and real-time, not periodic. The breaches that repeatedly make headlines trace back to assets no one was watching – unknown exposures, unreviewed vendors, shadow infrastructure. You cannot defend what you cannot see.
Second, risk prioritization needs to move beyond severity scores. Defenders working from decontextualized vulnerability lists spend resources on findings that don’t represent real exploit paths, while missing the ones that do. Correlating vulnerability data with exposure, business criticality, and validated exploitability is what separates security programs that manage risk from those that manage paperwork.
And thirdly, regulatory readiness needs to be embedded into the security program rather than managed as a compliance function running alongside it. The programs that will handle the coming years of regulatory scrutiny are those where governance documentation, executive visibility into risk, and incident response procedures are already operational – not scrambled together when a disclosure deadline is four days away.
There’s a temptation, particularly in moments of threat landscape acceleration, to reach for more tools, more coverage, and more controls. Some of that is warranted. But the security leaders I’ve watched navigate hard situations well are the ones who invested in better decision-making infrastructure – who know what they own, know what’s actually exploitable, and can articulate to their board and their regulator precisely how risk decisions were made.
The threat landscape has shifted and that’s something we need to face. But whether our programs shift with it or keep fighting the last war is still a choice we get to make.
