"Trends of the year" lists tend to mix forecasting, guesswork and marketing. This article does something else: it brings together seven movements that the most widely consulted public reports recorded in 2025 and 2026 and, for each one, explains what it is, why it matters and what to do now, with 2027 on the horizon.
Before we start: where the numbers come from
Each report has its own scope: Verizon's 2026 Data Breach Investigations Report (DBIR) analyses incidents from November 2024 to October 2025; the 2025 ENISA Threat Landscape covers July 2024 to June 2025, with a focus on the European Union. The percentages should not be compared with one another; what matters is the shared direction.
1. AI working for the attacker
Generative AI has not created a new kind of attack; it has made existing ones cheaper and better. The 2025 ENISA Threat Landscape points to the use of language models to refine phishing and automate social engineering, and names phishing (including vishing, malspam and malvertising) as the leading initial intrusion vector, in about 60% of observed cases. Flawless messages and synthetic audio of executives are already routine, as we described in phishing and social engineering in the age of AI.
What to do.
- Process over perception. Payments, changes to bank details and password or MFA resets always require confirmation through a second channel, even when the request seems to come from a director.
- Updated training. Teach people to recognise the out-of-process request and measure the reporting rate, not just the click rate.
2. Vulnerability exploitation has become the front door
For the first time in the DBIR series, the 2026 edition recorded vulnerability exploitation as the leading entry point in the breaches analysed, at 31%, ahead of the use of stolen credentials. Edge devices such as VPNs and firewalls concentrate this risk: they are exposed to the internet and, when they fail, open up the internal network.
What to do.
- Prioritise by what is being exploited. Cross-reference the inventory of exposed assets with CISA's KEV catalog and with EPSS, as we explain in where to start among 48,000 CVEs.
- Short deadlines at the edge. Set specific patch windows for exposed devices and keep a mitigation plan (disable the feature, restrict access) for when the patch is late.
3. Identity is the target
Even with exploitation on the rise, credentials remain at the centre of intrusions: they are what attackers seek in order to move without raising alarms. Microsoft's 2025 Digital Defense Report treats identity as the primary control plane for defence and names phishing-resistant MFA and passkeys as the best safeguards available.
What to do.
- Phishing-resistant MFA where it hurts most. Start with administrators, executives and access to critical systems, using FIDO2/passkeys or certificates, as CISA recommends.
- Privilege under control. Inventory privileged and service accounts, reduce standing permissions and monitor their use — the subject of privileged access management.
4. Ransomware and extortion remain at the top
The 2026 DBIR found ransomware in 48% of the breaches analysed and noted that ransom amounts are falling, with more companies refusing to pay. ENISA, for its part, ranks ransomware as the most impactful threat in the European Union. Paying less does not mean less downtime, and extortion through data leaks works even against companies that restore everything from backup.
What to do.
- Measured recovery. Keep an isolated or immutable copy and time the end-to-end restoration of a critical system (see backup and cyber resilience).
- Decide before the crisis. A response plan with defined roles and a tabletop exercise with the board, legal and communications, including the ransom criteria (details in ransomware and RaaS).
5. Third parties and the supply chain
In the 2025 DBIR, third-party involvement in breaches doubled, from 15% to 30%, and the topic was highlighted again in the 2026 edition. ENISA also records attacks targeting digital dependencies, including the AI supply chain.
What to do.
- Tier suppliers by access. Those connected to the network, to personal data or to privileged credentials get stricter assessment and contract clauses — incident notification with a deadline, right to audit (see third-party risk).
- Treat third-party access as privileged access. Named accounts, MFA and SOC monitoring, revoked when the contract ends.
6. AI agents, shadow AI and model security
The second face of AI is the one the company itself adopts. In the 2025 edition of IBM's Cost of a Data Breach, 13% of organisations reported breaches of AI models or applications, and 97% of those lacked proper AI access controls; one in five reported a breach linked to shadow AI, the use of unauthorised tools. With agents that take actions, the risk is no longer just leakage: OWASP's Top 10 for LLM Applications lists prompt injection as the first risk, and its Top 10 for Agentic Applications for 2026 highlights agent goal hijacking, tool misuse and identity and privilege abuse.
What to do.
- AI inventory and policy. Know which tools and agents are in use, with what data and permissions.
- An agent is an identity. Give each agent its own credential, least privilege, human approval for sensitive actions and a record of what it does, with those logs flowing to the SOC.
The common thread. Six of the seven trends end in the same place: an identity or an access being misused. Knowing who accesses what — people, suppliers and agents — applies to all of them.
7. More specific regulation
In Brazil, 2026 was the year regulation moved from principle to verifiable control. CMN Resolution No. 5,274/2025, with compliance required since 1 March 2026, details mandatory minimum controls for the financial sector, including API security and cyber intelligence (summary in what changed with CMN 5,274). ANPD Resolution CD/ANPD No. 15/2024 sets a deadline of three business days to report relevant incidents involving personal data, and the National Cybersecurity Policy (PNCiber), established by Decree No. 11,856/2023, created the National Cybersecurity Committee to coordinate the country's agenda.
What to do.
- Evidence map. For each applicable requirement, the internal control, the owner and the evidence, ready before the auditor asks.
- A rehearsed incident clock. A response plan that already defines who decides on notifying the ANPD and sector regulators, and how quickly.
What to watch in 2027
Without trying to guess, three movements are already under way and should gain weight. First, AI agents in production, requiring identity governance for machines on a par with that for people. Second, the migration to post-quantum cryptography: in 2024 NIST published the first standards (FIPS 203, 204 and 205) and, in a draft (NIST IR 8547), proposed deprecating RSA and elliptic curves by 2030 and disallowing them by 2035 — the first step is to inventory where cryptography is used. Third, regulators demanding continuous evidence rather than an annual document.
Frequently asked questions
What is the main cybersecurity trend for 2026?
There is no single one, but the reports converge on two points: exploitation of vulnerabilities in exposed systems, which the 2026 DBIR ranked as the leading entry point, and the abuse of identities and credentials, amplified by AI-driven phishing.
Will AI replace the SOC?
No. AI speeds up triage, enrichment and repetitive responses, but complex investigations and containment decisions still require analysts.
Where should a mid-sized company start?
With three high-return measures: phishing-resistant MFA for critical accounts, prioritised remediation of exploited vulnerabilities on exposed assets, and 24×7 monitoring with response capability, in-house or outsourced, such as a SOC/MDR.
Sources consulted on 10 October 2026: Verizon, 2026 Data Breach Investigations Report and 2025 Data Breach Investigations Report; ENISA, Threat Landscape 2025; Microsoft, Digital Defense Report 2025; IBM, Cost of a Data Breach Report 2025; OWASP GenAI Security Project, Top 10 for LLM Applications 2025 and Top 10 for Agentic Applications for 2026; CISA, Implementing Phishing-Resistant MFA; NIST FIPS 203, 204 and 205 and NIST IR 8547 (initial public draft); CMN Resolution No. 5,274/2025; Resolution CD/ANPD No. 15/2024; Decree No. 11,856/2023. This article is educational and does not replace a risk assessment of each organisation's environment.
Official references
- 2026 Data Breach Investigations Report — Verizon
- ENISA Threat Landscape 2025 — ENISA
- Cost of a Data Breach Report 2025: AI oversight gap — IBM
- OWASP Top 10 for Agentic Applications for 2026 — OWASP GenAI Security Project
- Decreto nº 11.856/2023 (Política Nacional de Cibersegurança) — Presidência da República