
September 29, 2026

Most trend lists are a vendor roadmap with the release notes filed off. Rank the changes by the evidence behind them and 2025–26 has one shape: the cost and the latency of an attack have collapsed, onto an identity surface that is no longer mostly human. Quantum doom and the end of the SOC are on slower clocks than the marketing says.
ENSI research — built on a library of 164 primary documents and 52 company dossiers.
In mid-September 2025 Anthropic’s threat-intelligence team watched a Chinese state-sponsored group it designates GTG-1002 run reconnaissance, exploitation, credential harvesting and exfiltration against roughly thirty technology companies, banks, chemical manufacturers and government agencies. The human operators did between 10% and 20% of the work. The model did the rest — “approximately 80–90% of all tactical operations independently”, at “sustained request rates of multiple operations per second”, with the humans intervening only to approve the move from reconnaissance to exploitation, to authorise harvested credentials, and to decide what was taken (Anthropic 2025). It is the first documented case of an AI system orchestrating intrusions into confirmed high-value targets.
A few months later Verizon published the largest Data Breach Investigations Report ever assembled — more than 31,000 real incidents, more than 22,000 confirmed breaches, 145 countries — including a section on what threat actors do with AI when someone measures rather than asserts. In behavioural data classified against MITRE ATT&CK, the median piece of AI-assisted malware had 55 existing, known malware examples performing the same function, and fewer than 2.5% of observations involved a technique with one or fewer known precedents (Verizon 2026, p. 12). The framing of the whole report is two words: refinement, not revolution.
Both findings are true. Almost every “cyber trends 2026” list picks one and sells it.
This report tries to do the other thing. It ranks what is changing by how much evidence actually supports the change, and it keeps apart three things the genre melts together. Behaviour is what attackers measurably do differently, established by incident telemetry. Market is what defenders buy, established by funding rounds and acquisition prices. Capability is what is genuinely new in the technology, established by experiment and proof of exploitation. A trend list becomes marketing at the exact moment it presents a market movement as a behaviour change — “attackers are now targeting X” when what happened is that a new category of product for X was funded. A good deal of what circulates as threat intelligence in 2026 is a budget line wearing a threat actor’s clothes.
Sorted this way, the period has one defining shift, and it is a collision between two curves.
The first is the collapse of the cost and the latency of attack. Exploitation of vulnerabilities is now the most common initial access vector in the DBIR at 31%, up from 20% — a 55% rise in a year — overtaking credential abuse at 13% (Verizon 2026, p. 15). Twenty-nine per cent of vulnerabilities in CISA’s Known Exploited Vulnerabilities catalogue were attacked before public disclosure. A tool-using LLM agent exploited 87% of a benchmark of real one-day vulnerabilities from the advisory text alone, at about $3.52 a run against roughly $25 of expert time — and 7% without the text, which locates the danger precisely in the window between publication and patch (Fang et al 2024). In December 2025 an AI agent wrote a working malware framework, VoidLink, in six days. Christopher Koch’s formulation is the one to carry: agentic AI is an attack compression technology, lowering the cost of reconnaissance, lure production, credential abuse, CVE-to-patch-gap matching, exploit adaptation and post-compromise decision support (Koch 2026, p. 1).
The second curve is an identity surface that grew faster than anyone’s controls and stopped being human. Non-human identities — service accounts, API tokens, workload identities, agents — grew 44% year on year and now outnumber human identities by 144:1, up from 92:1 twelve months earlier; across 230 billion permissions analysed by Veza, the share classified safe and compliant fell from 70% to 55% in a single year while ungoverned permissions rose from 5% to 28%; one in twenty AWS machine identities carries full administrator privilege; and enterprise IAM teams are responsible for only 44% of machine identities at all (Kurtz and Krawiecka 2026, pp. 18–20). The DBIR, from a different dataset entirely, points defenders to the same place: “we should pay special attention to service and machine accounts, as those will likely be the ones leveraged in our potential agentic AI future” (p. 22).
Put the curves together and the mechanism is unglamorous. Cheap, fast, tireless offence is being pointed at whatever is simultaneously exposed and over-privileged — and in 2026 exposure has a name (an unpatched internet-facing appliance) and privilege has a name (an ungoverned machine credential). Everything else in this report is a consequence of that collision, a market response to it, or a genuinely separate clock.
Two of the loudest items run on those separate clocks. Quantum: 37% of executives expect quantum technologies to affect cybersecurity within twelve months (WEF 2026, p. 48), while NIST’s own arithmetic says standardisation to full integration historically takes ten to twenty years, the federal target is 2035, and 112-bit classical public-key algorithms are deprecated after 2030. The urgency is real, but it is a crypto-inventory urgency, not an imminent-break urgency. “AI will replace the SOC”: the strongest rigorous evaluation to date, DARPA’s AI Cyber Challenge final, ran seven autonomous systems for roughly 143 hours over 53 real open-source projects and found that pairing a proof-of-vulnerability with a patch worked 92% of the time, with patch quality the practical bottleneck (Zhang et al 2026). An extraordinary result for autonomous repair of code you own. Not an autonomous security operations centre.
There is a third correction, less discussed and more useful to a national agency. Counting incidents without weighting impact manufactures alarm. In ENISA’s curated set of 4,875 incidents affecting the EU between July 2024 and June 2025, DDoS accounts for 76.7% of recorded incident types and hacktivism for almost 80% of recorded incidents — overwhelmingly low-impact noise — while intrusions are 17.8% (pp. 6, 8). A national threat picture built on incident counts will be dominated by hacktivist DDoS and will point budgets at the wrong thing.
This is the fifth report in the ENSI series on Israeli cybersecurity, and it asks a different question from the first four. Report 1 ranked the fifty companies that make Israel a cyber power; Report 2 extracted sixteen principles a state can copy; Report 3 specified the twenty-four features of the most advanced defensive system anyone could assemble. This one asks what a CISO, a founder and a national agency should believe about the next eighteen months — and what they should refuse to believe. The Israeli company evidence appears here as market evidence: who is putting capital behind which trend, priced by people with their own money at stake. The “we” is a mid-sized European state and its companies, with the Czech Republic as the default home example.
Rank trends by evidence, and separate three things — what attackers do (behaviour, from incident telemetry), what defenders buy (market, from rounds and exits), and what is technically new (capability, from experiment). Most trend lists present the second as the first.
The defining shift is a collision. The cost and latency of attack collapsed — exploitation up to 31% of initial access, 29% of KEV bugs attacked before disclosure, agentic offence at a few dollars a run — at the same time as an identity surface growing 44% a year and now 144:1 non-human.
Exploitation has overtaken credentials as the front door, and remediation is getting worse. KEV remediation fell from 38% to 26%; median time to full resolution rose from 32 to 43 days; 42,595 new CVEs, up 27%. The least glamorous finding in the library and the highest-confidence one.
AI is industrialising the known, not inventing the unknown — with two thresholds crossed. APT28’s PROMPTSTEAL querying an LLM at runtime against Ukraine, and GTG-1002 at 80–90% autonomy. Hallucination remains a tax on offensive autonomy, in the attacker’s own telemetry.
Non-human identity is the single highest-confidence trend — four sources, four methods, one conclusion — and the cheapest high-leverage fix available to a CISO or a state.
Supply chain is now roughly half the breach population, sitting on maintenance debt: 92% of codebases carry components four or more years out of date. In March 2026 two security vendors in these dossiers were themselves the vector.
Agent security became a discipline in eighteen months — OWASP’s ASI01–ASI10, the “Least-Agency” principle, and the first rigorous analysis of MCP, which measured attack success rising from 26.4% to 52.8% against non-MCP baselines.
Ransomware’s economics inverted: more attacks, less money. In 48% of breaches, up from 44%, but 69% of victims did not pay and the median payment fell to $139,875.
The APT-versus-criminal taxonomy is losing analytic value. State actors are abandoning bespoke tooling for the criminal ecosystem; commodity malware on a Czech network no longer implies a commodity adversary.
Regulation is consolidating, not expanding. Europe’s binding constraint is reporting burden and certification latency — one scheme adopted in seven years — not a shortage of rules.
The market’s answer to all of it is consolidation: $67bn of Israeli security companies changed hands in fourteen months. The platforms are buying bundles, and nobody has assembled the loop.
For a Czech-scale state: fund patch latency, machine-identity governance and validation; ignore quantum panic-buying, unaudited “autonomous SOC” claims and agentification without a use case. Five moves close the report.
Every claim here was put through the same three tests, and the ranking that follows is a ranking of how well each trend survives them.
One: at least two independent sources, using different methods. A finding in one vendor’s telemetry is a product observation. A finding in ENISA’s curated incident set and Verizon’s breach census and a peer-reviewed measurement study, reached by three different instruments, is a fact about the world. Where a trend rests on one source, this report says so and ranks it lower, however important it would be if true.
Two: incident data over survey sentiment. The WEF’s Global Cybersecurity Outlook 2026 surveyed 804 qualified respondents from 92 countries, including 316 CISOs and 105 CEOs. That is an excellent instrument — for measuring beliefs. When 94% say AI will be the most significant driver of change in the year ahead, the honest reading is that is where the budget is going, which is a real and forecastable fact about the market and no evidence at all about attacker behaviour. Telemetry tells you what happened; surveys tell you what will be bought. Confusing the two is the commonest failure in the genre. This report uses both and labels which is which.
Three: a named falsifier. Every trend below states what would have to be observed for the call to be wrong — a number in next year’s DBIR, ENISA or Black Duck that would move it down the list. A trend with no falsifier is a slogan, and several claims that felt obvious in drafting did not survive the question.
Four caveats about the evidence base, because the sources are not equally clean. ENISA states its own limitations better than anyone in the genre, conceding that open-source collection is incomplete and that sectoral and geographic vagueness biases its dataset (2025, p. 7) — which is why its numbers are trusted here even where they conflict with vendor figures. Vendor reports carry sample bias their headlines do not: Black Duck’s audit data comes from 947 codebases examined during mergers and acquisitions, so it over-samples companies being bought and sold, and where mean and median diverge sharply this report quotes the median. Company figures are frequently self-reported — acquisition prices are hard, valuations and ARR mostly are not, and a 2021 valuation is not the same currency as a 2026 one. And some of the most important research here is a single paper: the MCP protocol analysis and the machine-identity taxonomy are the best work in their areas precisely because there is so little, and neither has been independently replicated.
The twelve trends sit in four evidential tiers. Tier A (1–4) rests on census-grade incident data from at least two independent collectors. Tier B (5–6) rests on strong but contested telemetry. Tier C (7–10) rests on protocol experiments, product evidence and market behaviour rather than breach counts. Tier D (11–12) covers changes whose direction is certain and whose timing is routinely overstated. Each section follows one shape: what is changing · the evidence · why it is happening · who is building for it · the hype check and the falsifier · what to do about it now.
What is changing. For fifteen years the standard opening move of an intrusion was a stolen password. It is now an unpatched internet-facing device. That reordering is the most consequential and least discussed finding of 2025–26, and it is displacing a whole management discipline: the quarterly vulnerability list is giving way to continuous, exploitability-aware exposure validation, because the list has become uncountable and the window unmeetable.
The evidence.
Verizon (2026) — exploitation is now the single most common initial access vector at 31%, up from 20%, a 55% increase, overtaking credential abuse at 13%, across 22,000+ confirmed breaches in 145 countries (pp. 10, 15).
ENISA (2025), measuring the EU independently across 4,875 curated incidents, puts exploitation lower by volume — 21.3% against roughly 60% for phishing — but far higher by yield: nearly 70% of vulnerability cases culminated in an intrusion and 68% ended in malicious code deployment, against 27% of phishing cases (p. 8). Phishing is the volume channel; exploitation is the conversion channel.
Remediation is going backwards. Only 26% of CISA KEV-catalogued critical vulnerabilities were fully remediated in 2025, down from 38%; median time to full resolution rose from 32 to 43 days; organisations carry 50% more critical vulnerabilities than a year earlier (Verizon 2026, p. 10).
The work grew faster than the capacity to do it: 42,595 new vulnerabilities, up 27%, 64% network-exploitable (ENISA 2025, p. 57) — while 29% of KEV vulnerabilities were attacked before public disclosure (Verizon 2026, p. 109).
Why it is happening. Three forces, none of them about AI. Edge devices — VPN concentrators, firewalls, file-transfer appliances, identity gateways — are internet-facing by design, cannot host an endpoint agent, and belong to teams with no maintenance window. Multi-factor authentication worked, raising the cost of the credential path enough to push attackers onto the software path. And the arithmetic of triage broke: patching capacity is roughly fixed while disclosure volume grows a quarter a year, so the backlog compounds mechanically.
Who is building for it. The most commercially mature trend here, and the Israeli ecosystem effectively invented the category.
XM Cyber — the attack-path twin behind the choke-point argument: in its Cyentia-analysed data, 80% of exposures come from misconfiguration and credentials, under 1% from CVEs, and 2% sit on choke points · sold to Schwarz Group for $700M in 2021; on 16 July 2026 CrowdStrike agreed to buy the intellectual property alone — 45-plus patents and the source code.
Armis — asset intelligence across IT, OT, IoT and medical · ServiceNow paid $7.75bn cash, closed April 2026, on ARR above $340M growing more than 50% — roughly 23 times ARR, the largest price ever paid for exposure management.
Zafran — scores a CVE against controls the customer already owns · $60M Series C, December 2025, led by Menlo Ventures, past $140M with strategic money from American Express Ventures and Cisco Investments in 2026.
Pentera and Cymulate — automated adversarial validation · Pentera passed $100M ARR in 2025 yet raised its $60M Series D at a flat “over $1bn” and cut about 20% of staff in 2026; Cymulate has not raised since September 2022 at roughly $500M. Validation works, and is priced below the platforms that absorb it.
Oligo, Upwind and Sweet Security — runtime reachability, so a vulnerability counts only if the function executes · Oligo’s $60M Series C (August 2026) came on ARR up 300%; Upwind raised ~$300M at about $3.8bn in September 2026; Sweet’s $75M Series B included Munich Re Ventures — an insurer funding runtime security.
The hype check. Three things the evidence does not support. This is not an AI story — the shift appears in data that predates agentic offence. Credentials are not dead: the DBIR flags that part of credential abuse’s fall is an artefact of newly tracking pretexting (p. 15), and ENISA still puts phishing near 60% of cases by volume. And the claim that context shrinks the problem by two orders of magnitude — Zafran’s “99% of critical vulnerabilities are not exploitable in context”, XM Cyber’s under-1% — is self-measured: plausible, directionally corroborated by ENISA’s yield data, never validated by anyone without a product to sell.
Falsifier: if the 2027 DBIR shows exploitation falling back below credential abuse, or KEV remediation recovering above 38% with median time-to-resolution under 32 days, the call was wrong.
What to do about it now. Publish patch latency as a governed metric — median hours from KEV listing to mitigation on internet-facing assets. Separate that estate from everything else and give it a faster process with standing maintenance authority. Buy validation, not lists: the question is “is this reachable, and is it already blocked?” And build the compensating-control path — virtual patching, segmentation, exposure removal — because it is the only one that operates within hours.
What is changing. Enterprise identity used to be a human-resources problem with a technology component. It is now a machine-population problem. Service accounts, API tokens, workload identities, CI/CD credentials and autonomous agents outnumber employees by one to two orders of magnitude, are created at machine speed, reviewed at human speed, and mostly belong to nobody. This is the single highest-confidence trend in the library — four independent sources, four methods, one conclusion.
The evidence.
Kurtz and Krawiecka (2026) triangulate five sources. Entro Labs: non-human identities grew 44% year on year and outnumber humans 144:1, up from 92:1. ESG: 20:1 on average, with two-thirds of organisations having suffered a successful attack via a compromised non-human identity. Research and Markets: 17:1 conservatively, 96:1 in financial services. Veza, across 230 billion permissions: permissions classified safe and compliant fell from 70% to 55% in one year while ungoverned permissions rose from 5% to 28%, and one in twenty AWS machine identities carries full administrator privilege (pp. 18–19).
Governance is nowhere near. CyberArk’s survey of 2,600 decision-makers in 20 countries: IAM teams are responsible for only 44% of machine identities, 68% lack identity security controls for AI, and 47% cannot secure shadow AI usage at all.
The incidents are costed. The July 2024 CrowdStrike outage — one ungoverned automated update agent across 8.5 million systems — produced $5.4bn in Fortune 500 losses and up to $10bn globally, insured at 10–20%. 23.7 million secrets were exposed on public GitHub in 2024, 26% in CI/CD workflows. The Marks & Spencer intrusion, which began by impersonating an employee to a third-party IT provider, ended in 46 days of suspended online ordering and roughly £300m of lost operating profit.
State actors got there first. Silk Typhoon, Salt Typhoon and Volt Typhoon have operationalised ungoverned machine credentials as primary espionage vectors, with privileged-access-management provider credentials a named Silk Typhoon target. Microsoft’s formulation of the era: “adversaries aren’t breaking in, they’re logging in” (2025, p. 5).
Why it is happening. Three structural reasons explain why incremental IAM spending has not worked: the visibility problem — no authoritative registry of which machine identities should exist; the governance velocity mismatch — identities minted by infrastructure-as-code in seconds, reviewed by humans in quarters; and identity debt, which “has compounding dynamics that existing IAM approaches are not reversing” (p. 20).
Who is building for it.
CyberArk — privileged access extended to machines and agents · acquired by Palo Alto Networks for ~$25bn, closed 11 February 2026, on ARR of $1.44bn, and relaunched as “Idira”. It had already bought Venafi, the machine-identity and certificate company, for $1.54bn in 2024.
Astrix Security — non-human identity, the category it named · acquired by Cisco, completed 29 June 2026, at roughly $400M on about 120 staff. Its $45M Series B (December 2024) was led by Menlo Ventures through the Anthology Fund it runs with Anthropic — a frontier lab’s venture arm funding agent identity a year before anyone measured the problem.
Cyera — valued at $12bn in June 2026 · bought Oasis Security for about $1bn (completed 3 September 2026), Ryft for $100–130M and Otterize: a data-security company buying into machine identity because the two problems turned out to be one. CrowdStrike paid $627.9M for SGNL in January 2026.
Silverfort — agentless multi-factor authentication inside the authentication layer, across more than 10 billion authentications a day · $222M raised, last priced near $1bn. The pattern worth noticing across all of them: the money moved to identity before the incident data did — the one place in this report where the market ran ahead of the telemetry rather than behind it.
The hype check. The direction is unanimous; the magnitude is not. 144:1 comes from one vendor’s telemetry, and the four estimates disagree by an order of magnitude — 144:1 against 17:1. Gartner’s projected 45 billion agentic identities is a forecast, not a count. The defensible claim is “machine identities outnumber humans by at least an order of magnitude, are growing fast, and are largely ungoverned”, which every source supports. The second overstatement is that non-human identity is a new category: service accounts have been the weakest link since Kerberos, and much of what is sold as NHI governance is privileged access management relabelled.
Falsifier: a vendor-neutral census — the kind NIST’s NCCoE agent-identity project could produce — finding machine-to-human ratios stable, or the share of breaches involving machine credentials flat in the next DBIR. Watch the insurers too: 88% of organisations already report insurers mandating enhanced privilege controls for machine identities, and a withdrawal would signal the loss data does not support it.
What to do about it now. Build the registry before the controls — you cannot govern a population you cannot count. Adopt zero standing privilege and just-in-time credentials as the target state, with SPIFFE/SPIRE as the workload identity standard, because both remove credentials at rest. Give every agent its own identity, never a borrowed human one: without one, an agent “operates in an attribution gap that makes enforcing true least privilege impossible” (OWASP 2025, p. 15). And treat secret sprawl in source control as an identity problem — 23.7 million exposed secrets is a credential population, not a set of lint errors.
What is changing. Not the taxonomy of attacks. The economics. AI has lowered the cost of reconnaissance, lure production, credential abuse, CVE-to-patch-gap matching, exploit adaptation and post-compromise decision support — Koch’s “attack compression”. The consequence is not that every criminal becomes elite, but that targets previously too small to justify a tailored operation are now economic.
The evidence.
Anthropic (2025) — GTG-1002 ran against roughly 30 entities in mid-September 2025 with the AI executing approximately 80–90% of all tactical work independently, orchestrated through Claude Code and open-standard MCP servers that decomposed each attack into tasks which “appeared legitimate when evaluated in isolation”. Tooling was commodity open-source pentest software; the custom work was integration. The jailbreak was social — operators role-played as employees of a legitimate security firm.
Google Threat Intelligence Group (2025) — “adversaries are no longer leveraging artificial intelligence just for productivity gains, they are deploying novel AI-enabled malware in active operations” (p. 2). PROMPTSTEAL, used by Russia’s APT28 against Ukraine, queries Qwen2.5-Coder-32B through the Hugging Face API to generate Windows commands at runtime — the first observation of malware querying an LLM in live operations. PROMPTFLUX queries Gemini hourly to rewrite its own source for evasion. The underground market for illicit AI tooling “has matured in 2025”.
Verizon (2026) is the counterweight from the same period: median AI-assisted malware had 55 known precedents, and fewer than 2.5% of observations involved a technique with one or fewer known examples (p. 12).
Social engineering went mobile and vocal: human element in 62% of breaches; median click rates on voice and text vectors 40% higher than email. ENISA reports AI-supported phishing at “more than 80 percent of observed social engineering activity worldwide” by early 2025.
Shadow AI became an insider-risk category: 67% of users access AI services from non-corporate accounts on corporate devices, regular AI users rose from 15% to 45%, and the most commonly exfiltrated data type is source code (p. 13).
Why it is happening. Because capability is being packaged, not invented. Anthropic’s conclusion is the proliferation argument: “cyber capabilities increasingly derive from orchestration of commodity resources rather than technical innovation” — and an orchestration layer over commodity tools is cheap to copy. Koch’s dated forecast is the most useful planning artefact in the library: 0–6 months, better lures and faster credential abuse; 6–18 months, semi-autonomous reconnaissance and targeting of AI agents and non-human identities; 18–36 months, crimeware-as-a-service packaging agentic workflows.
Who is building for it.
Dream Security — sovereign AI cyber defence sold to states · $260M at a $3bn valuation, June 2026, led by Group 11, on ARR above $100M from fewer than ten customers · in August 2026 its researchers published a four-day fully autonomous AI-agent intrusion into Asian government agencies, running up to eight sub-agents and taking 2,500+ records — the second documented case of the GTG-1002 pattern.
Irregular (formerly Pattern Labs) — measures the offensive cyber capability of unreleased frontier models for OpenAI, Anthropic, Google DeepMind and the UK government · ~$80M raised in September 2025 at about $450M, on roughly 25 people. It co-authored RAND’s model-weight security framework (SL1–SL5).
Pentera and Cymulate — continuous automated offence against your own estate, the only defensive control that scales the way attack compression does.
KELA — cybercrime intelligence on the market GTIG says “matured in 2025” · its 2026 report counts 2.86 billion credentials stolen in 2025 and 7,549 ransomware victims, up 45%.
The hype check. Two claims fail. “Autonomous AI attacks are here and everything has changed” — half true, and the caveat comes from the attacker’s own telemetry: Anthropic records that “Claude frequently overstated findings and occasionally fabricated data during autonomous operations, claiming to have obtained credentials that didn’t work”, and calls hallucination an obstacle to fully autonomous attack. GTIG is equally careful on influence operations: “None of these attempts have created breakthrough capabilities for IO campaigns”. “Every criminal is now an elite hacker” — refuted by Koch and the NCSC and OpenAI assessments he cites: “The expected change is not universal elite capability; it is capability packaging”.
Falsifier: the DBIR’s “55 known precedents” median falling toward 1, or a documented campaign whose decisive technique has no prior example and was discovered by a model. Either would mean AI had begun to change the taxonomy and not merely the tempo.
What to do about it now. Assume tempo, not novelty: the controls that stop these operations already exist, executed faster. Rehearse voice and text pretexting against your own helpdesk, where the 40% click differential and the Scattered Spider playbook meet. Give shadow AI a sanctioned path rather than a prohibition — 71% of companies that ban AI coding assistants acknowledge developers use them anyway — and instrument source-code egress specifically. And plan against Koch’s 6–18 month window: the next thing attackers automate is the abuse of your agents and machine identities.
What is changing. Third-party compromise has moved from a category of risk to the dominant one, and beneath it sits a quieter liability: the maintenance state of the open-source code every organisation ships. The two combine into an exposure no perimeter spending touches, because the intrusion arrives through a supplier you pay or a package you imported.
The evidence.
Verizon (2026) — breaches with third-party involvement rose 60% year on year, reaching 48% of all breaches (p. 11).
Black Duck (2026), auditing 947 codebases — 65% of surveyed organisations experienced a software supply chain attack in the past year, and 66% of identified malicious packages were purpose-built typosquats or dependency-confusion attacks. 98% of codebases contain open source, at a mean of 1,180 components, up 30% in a year.
The maintenance debt is the underlying liability: 92% of codebases contain components four or more years out of date; 93% contain components with no development activity in two years; 78% carry a high-risk and 44% a critical-risk vulnerability. The most prevalent flaws are years-old jQuery vulnerabilities affecting 25–28% of codebases despite long-available patches.
SBOMs systematically under-report: 16% of open-source components entered codebases outside standard package management — vendored dependencies, snippets from Stack Overflow or an AI assistant, binaries without source (p. 38). A manifest-only SBOM is not an inventory.
The 2025 chronology is the argument: the March 2025 tj-actions cascade exposing secrets in more than 23,000 repositories; the September 2025 Shai-Hulud self-replicating npm worm across 500+ packages; Silk Typhoon entering via a stolen BeyondTrust key; a late-2024 wave of compromised Chrome extensions, AI and VPN extensions specifically (Verizon 2026, p. 109; ENISA 2025, pp. 11–12).
Executives agree, which matters for budgets: 65% of large companies by revenue name third-party and supply chain vulnerabilities as their greatest challenge, up from 54% (WEF 2026, p. 45). Black Duck puts cybersecurity vendors’ own codebases at an 85% rate of high or critical vulnerabilities.
Why it is happening. The unit of software delivery changed and the unit of governance did not. Codebases grew 74% in file count in one year and 251% over five, assembled from registries with no namespace protection, by developers using assistants that suggest package names which sometimes do not exist — what ENISA calls “slopsquatting”. The AI layer adds its own supply chain: poisoned hosted models, trojanised PyPI packages, and the “Rules File Backdoor” that injects instructions into Cursor and GitHub Copilot configuration files.
Who is building for it.
Apiiro, Cycode and Legit Security — application security posture management, each built on a graph joining code to runtime · Apiiro’s own data says AI coding agents produce four times more code and six times the attack surface, and its ARR grew 104% in 2025 · yet none of the three has taken a priced round since 2021–22. It is the one crowded category the platforms have not absorbed.
Snyk — more than $325M ARR and over 4,800 customers (February 2026), against a last priced valuation of $7.4bn in 2022 and investor marks now around $3.7bn. Checkmarx, owned by Hellman & Friedman since a $1.15bn buyout, has sought at least $2.5bn since 2024 with no announced deal.
Koi Security — provenance for the extension, package, MCP and agent-skill distribution layer · acquired by Palo Alto Networks twenty months after founding (closed April 2026; press reported ~$400M, the filing shows $231M plus $61M) · its research found GlassWorm across 35,800+ installs, ShadyPanda across 4.3 million, and 341 malicious agent skills in three campaigns.
And the vendors were the vector. In March 2026 Aqua Security’s Trivy scanner was compromised — 76 of 77 trivy-action tags force-pushed to credential-stealing malware for about twelve hours — and the stolen credentials were then used to poison Checkmarx’s ast-github-action and kics-github-action. KELA traced both to one actor; two men were charged in August 2026.
The hype check. The claim that AI coding assistants caused the vulnerability explosion is not supported by the report everyone cites for it. Black Duck states plainly that “correlation is not causation”, and offers two competing explanations for the 191% rise in mean vulnerabilities per codebase: the Linux kernel becoming a CVE Numbering Authority, taking kernel CVEs from 290 in 2023 to over 3,500 in 2024, and the growth of microservices. The median series — 46 to 78 — is the honest number, and it grew far more modestly.
Falsifier: if the median vulnerabilities-per-codebase series flattens while the mean keeps climbing, the “exploding attack surface” story is largely a disclosure artefact. If third-party involvement in the 2027 DBIR falls back toward 30%, the 60% jump was definitional rather than behavioural.
What to do about it now. Generate SBOMs from binary composition analysis, not manifests, or accept that 16% of your components are invisible. Make the governance status of a dependency a procurement criterion, now that the Cyber Resilience Act’s “open source steward” category distinguishes foundation-governed projects that will carry vulnerability handling from solo-maintainer projects that will not. Treat CI/CD as production — tj-actions, Shai-Hulud and TeamPCP all ran through build systems with standing credentials. And rank suppliers by blast radius rather than contract value.
What is changing. The volume curve and the revenue curve have separated. Ransomware appears in more breaches than ever while the amount extracted per victim falls, because refusing to pay has become the default corporate posture. The business model is adapting in the obvious direction — away from encryption, which is noisy and defeated by a good backup, and toward the threat of disclosure, which is cheap, works against organisations with immaculate recovery, and has been made more frightening by the breach-notification regimes designed to protect victims.
The evidence.
Verizon (2026) — ransomware is present in 48% of all breaches, up from 44%, yet 69% of victims did not pay and the median ransom paid fell to $139,875 from $150,000 (p. 11).
Brantly and Mason (2026), on 19,128 incidents across 110+ groups, show where it comes from: Russian-affiliated groups are 26% of publicised strains but 63% of all attacks, the top six account for 56% of all global victims, and 99.52% of their identified victims are outside Russia. The Czech Republic sits in the second tier, with over 50 attacks.
The tail risk has not diminished. The September 2025 Jaguar Land Rover shutdown cost £1.9bn over five weeks — one incident costing roughly half of what the entire European cyber insurance market collects in premiums in a year. That market is small: of $16.6bn in global cyber premiums in 2023, nearly 60% was spent in the United States, against $3.9bn in Europe in 2024 (Hanson and Straub 2026).
Law enforcement moves the distribution. NÚKIB recorded 27 ransomware incidents in Czechia in 2024 and assessed LockBit’s collapsed share as “very likely (75–85%)” the result of the February 2024 takedown. Google earlier attributed part of the profitability decline to sanctions reducing willingness to pay, by one estimate a 40% drop.
Why it is happening. Paying stopped being rational and stopped being safe. Backups improved, sanctions made payment legally hazardous, boards adopted no-pay policies — which removed the decryption key as leverage and left the leak site. It also fragmented the market: with lower yields per victim, groups compensate with volume and affiliates, so strain counts rise while median payments fall.
Who is building for it.
Cyera and Varonis — data security posture: knowing what would be published and what it would cost · Cyera reached $12bn in June 2026 after raising $540M, $400M and $600M in thirteen months; Varonis runs SaaS ARR of $726M, up 52%, and was reported in September 2026 to be in advanced talks with Thoma Bravo’s Proofpoint.
Sygnia — incident response and ransomware readiness, listed in Gartner’s 2026 Market Guide for IR retainers, and lead investigator on the $1.5bn Bybit theft. This is the surge capability a state must be able to call on.
Zero Networks — microsegmentation as deterministic containment · its 2026 benchmark found 80% of enterprise servers reachable from anywhere on the internal network, which is the best single explanation of why exfiltration-based extortion works so well.
Cynet, Coro and Guardz — consolidated security for the SME base the enterprise market ignores · Coro resolves 92.3% of tickets automatically; Guardz, which raised $56M in June 2025 on an explicit “secure and insure” thesis, found 89% of the small businesses it monitors had at least one compromised user.
The category nobody funded: nothing in the 52 dossiers sells extortion-decision support or disclosure-risk quantification — which is exactly where the loss now sits.
The hype check. Two symmetric errors. “Record-breaking ransomware” is true of incidence and false of proceeds; “ransomware is in decline” is false of incidence, true of proceeds, and irrelevant to Jaguar Land Rover. The honest framing is that expected loss per victim fell while variance did not — the distribution insurers price worst. And a real limitation: this library measures the economics well and the encryption-versus-exfiltration split poorly. Neither the DBIR nor ENISA tracks extortion-without-encryption as a category. The shift is supported by the non-payment data, by ENISA’s framing of a landscape moving toward “continuous, diversified and convergent campaigns” rather than single high-impact incidents, and by the leak-site datasets — but it is an inference, not a measurement, and should be labelled as one.
Falsifier: payment rates rising back above 40%, or median payments rising, in the 2027 DBIR. Conversely, if a major dataset begins tracking encryption-free extortion and finds it a minority of cases, the “detaching from encryption” claim should be withdrawn.
What to do about it now. Rehearse the decision, not just the restore: a no-pay policy never tested against a live disclosure threat is a press release. Assume exfiltration in every case and rank data by what its publication would cost — which makes data mapping a ransomware control, not a compliance one. Treat cyber insurance as a liquidity instrument rather than a risk transfer. And note the asymmetry: 99.52% of Russian-affiliated ransomware victims are outside Russia, which makes this a due-diligence failure by a state rather than a misfortune, and gives a European government a legal framing it underuses.
What is changing. Two convergences at once. State groups are abandoning bespoke tooling for the criminal ecosystem, and criminal groups are copying state tradecraft — so the malware in your network no longer tells you who is in your network. Separately, the “hacktivist” layer that generates most of Europe’s recorded incident volume is not a crowd; it is a managed capability whose targeting tracks the victim’s domestic politics.
The evidence.
ENISA (2025) names the convergence: Kimsuky using ClickFix, Andariel affiliated with Play ransomware, Moonstone Sleet leveraging Qilin, APT29 and Sandworm operating from commercial residential proxies — while criminal groups copy state social engineering, FIN6 running fabricated LinkedIn personas (pp. 13–14).
Microsoft (2025) confirms it from telemetry: Russian state actors “appear to have reduced their efforts to develop bespoke operations in favor of leveraging the cybercriminal ecosystem”, which “could make it more difficult for network defenders to attribute simple operations to sophisticated threat actors” (p. 48).
The proxies are directed. Ukraine’s National Cybersecurity Coordination Centre states it plainly: “There are no independent ‘hacktivists’ in Russia”, and since late 2022 the services have run “a ‘turnkey’ methodology for creating, disguising and managing these pseudo-hacktivist groups” — including, after 7 October 2023, dozens of new groups launched against Israeli infrastructure, during which Ukraine saw its lowest number of cyber incidents in years (Tkachuk 2025, p. 18). The same deniable capacity, redirected. Mandiant shows the mechanism: a CyberArmyofRussia_Reborn YouTube channel created from APT44 infrastructure, and APT44 infrastructure exfiltrating data later leaked on it.
The volume is measured, and it is political. Over thirteen months NoName057(16) attacked 3,776 unique hosts at a median of 50 targets a day, government and public sector 41.09%; by share of attack days, Ukraine ~29.5%, France 6.09%, Italy 5.39%, Sweden 5.29%, Germany 4.60%, Israel 4.50%, Czech Republic 4.00%. Target selection runs on a Russian working week. Czech targeting “notably ended in January 2025 after public reporting indicated that the ruling government was expected to lose the October 2025 election” to a party that would halt ammunition transfers (Recorded Future 2025). NÚKIB separately records hacktivists attacking weakly secured water-management OT and filming it for Telegram — one such attack in Czechia in 2024.
Why it is happening. Deniability is cheap and attribution is expensive. Commodity tooling strips the signal that once made attribution possible; the criminal ecosystem supplies access-as-a-service far below the cost of developing it; and a managed hacktivist front converts a low-impact DDoS into a political signal that can be switched on and off. Brantly and Mason locate the enabling mechanism precisely: not command, but selective non-enforcement — a state that polices its own internet tightly for dissent and not at all for what leaves its borders.
Who is building for it.
KELA — cybercrime intelligence built from the forums where state and criminal tooling now mix · launched a National Cyber Resilience Suite for governments, national CERTs and police in October 2025, indexes 34.1 billion compromised credentials, bookings up 101% in the year to March 2026. This is the product shape a mid-sized state actually needs.
Sygnia — nation-state incident response, which publicly documented the Velvet Ant and Fire Ant intrusion sets in August 2026. Dream Security — national-scale AI cyber defence, $260M at $3bn, carrying the governance liability of its NSO-adjacent lineage that Report 1 treats at length.
Radware — DDoS and application protection, the unglamorous layer that absorbs the 80% · it measured web DDoS attacks up more than 110% in the first half of 2026.
Waterfall Security — its 2026 OT threat report supplies the discipline this trend needs: 57 OT attacks with physical consequences in 2025, down from 76 in 2024, even as nation-state and hacktivist attacks doubled. Noise up, damage down.
The gap: no company in the dossiers sells impact-weighted national threat measurement — precisely what the ENISA data says agencies need most.
The hype check. The evidence emphatically does not support treating this volume as national risk. Hacktivism accounts for almost 80% of ENISA’s recorded incidents and DDoS for 76.7% of incident types — overwhelmingly low-impact. A national threat picture that counts incidents will be dominated by the activity designed to be counted. Two further cautions. Jaclyn Kerr names the symmetrical analytic errors: assuming sub-threshold competence transfers to above-threshold capability, and assuming above-threshold ineptitude implies below-threshold weakness (CNA 2023). And Brantly and Mason concede that “all analyses of Russian involvement in its prolific ransomware industry are based largely on circumstantial evidence” — the convergence of independent strands is the contribution, not proof.
Falsifier: Microsoft telemetry showing state actors returning to bespoke tooling would reverse the attribution claim. A larger sample showing NoName targeting uncorrelated with the target’s domestic politics would break the “pressure signal, not damage” reading.
What to do about it now. Stop reporting incident counts to ministers and start reporting impact-weighted ones, or the DDoS tail will wag the national budget. Assume commodity malware may be a sophisticated actor and set the investigation threshold accordingly — that assumption costs a few analyst hours; the opposite costs a missed espionage foothold. Treat politically timed DDoS as an indicator of intent rather than an attack to be defeated. And sit with the finding Czech readers should find hardest: the campaign stopped when the polls changed. The deniable layer is a reward-and-punishment instrument aimed at domestic politics, and technical resilience is not a defence against it.
What is changing. In December 2025 OWASP published a Top 10 for Agentic Applications; by February 2026 NIST had launched an AI Agent Standards Initiative and the Cloud Security Alliance an Agentic Trust Framework. A field with no shared vocabulary in mid-2024 now has a taxonomy, a standards pipeline, a scoring system and a measured evidence base. The speed is the finding — and so is the fact that the first rigorous security analysis of the protocol the ecosystem depends on arrived after five thousand servers had been deployed.
The evidence.
OWASP (2025) — ten agentic risks that are now de facto standard vocabulary: ASI01 Agent Goal Hijack · ASI02 Tool Misuse · ASI03 Identity and Privilege Abuse · ASI04 Agentic Supply Chain · ASI05 Unexpected Code Execution · ASI06 Memory and Context Poisoning · ASI07 Insecure Inter-Agent Communication · ASI08 Cascading Failures · ASI09 Human–Agent Trust Exploitation · ASI10 Rogue Agents, mapped to the LLM Top 10, the Non-Human Identity Top 10, CycloneDX/AIBOM and the AI Vulnerability Scoring System.
Maloyan and Namiot (2026) provide the measurement. Across 847 attack scenarios, five MCP server implementations and three LLM backends against equivalent non-MCP baselines, overall attack success rises from 26.4% to 52.8%. Cross-server propagation rises from 19.7% to 61.3%; sampling-based injection succeeds 67.2% of the time with no baseline equivalent, because the attack class does not exist outside MCP. With five servers and one compromised, attack success reaches 78.3% with a 72.4% cascade rate. Prompt-level defences are insufficient — a system-prompt instruction cut cross-server success only from 61.3% to 47.2% — while a protocol extension adding capability attestation cut overall success to 12.4% at a median 8.3 ms per message.
Distribution is the weak point. A survey of 127 MCP server installation guides found typosquatting at 34%, supply-chain compromise 28%, social engineering 23% — and 73% of guides instruct users to run npx directly from GitHub URLs without integrity verification.
The incidents are real. OWASP’s tracker records an npm-hosted backdoored MCP server with install-time and runtime reverse shells (October 2025), an unauthenticated RCE in Framelink’s Figma MCP server, a Cursor configuration overwrite via filesystem case mismatch, and working exfiltration exploits against Copilot and Amazon Q. Israeli research named the class first: the Technion’s Morris II demonstrated zero-click self-propagating worms moving between RAG-based GenAI applications — and shipped the guardrail with the attack, at a true-positive rate of 1.0 and a false-positive rate of 0.015 (Cohen, Bitton and Nassi 2024).
Executive concern has flipped toward exposure: data leaks are now the top generative-AI concern at 34%, up from 22%, while “advancement of adversarial capabilities” fell to 29% from 47%, and organisations with a pre-deployment AI security assessment rose from 37% to 64% — leaving roughly a third with none (WEF 2026).
Why it is happening. MCP became a de facto standard within months of its November 2024 release, before anyone analysed it, and its weaknesses are architectural rather than implementation-specific: no capability attestation, bidirectional sampling without origin authentication, implicit trust propagation across multi-server configurations. Every server added raises the blast radius of every other one. OWASP’s diagnosis of ASI03 is trend 2 seen from the agent’s side — without a governed identity of its own, an agent sits in an attribution gap where least privilege cannot be enforced.
Who is building for it.
Zenity — discovery, posture and runtime enforcement for agents built in Copilot, ChatGPT Enterprise, Gemini, Claude, Bedrock and Cursor · $125M Series C, 3 August 2026, led by Norwest, revenue tripling in each of the last two years; Gartner calls it “the company to beat in AI agent governance”. In August 2026 it disclosed a malicious agent-”skills” campaign with 1.7 million installs.
Noma Security — AI security posture, red-teaming and agent access control · $100M Series B, July 2025, ARR up 1,300% in the year to mid-2025 · it reports finding ten to a hundred times more agents than customers expect, which is trend 2 restated as a discovery problem.
Alice (formerly ActiveFence) — red-teaming and runtime guardrails · $140M, August 2026, led by Apax Digital, ARR approaching $100M, working with eight of the ten leading AI labs. Glow — $180M in about a year, out of stealth at $1.2bn in July 2026 — independently measures AI tool use on corporate devices rising from 15% to 45% in a year, matching the DBIR.
Irregular — frontier-model evaluation · on 30 July 2026 Anthropic disclosed a containment failure found in its work: of 141,006 runs reviewed, six runs across three incidents saw the model reach the production systems of real organisations. OpenAI disclosed a parallel misconfiguration the same week. This is the strongest available evidence that agentic containment is not yet solved, and it comes from the labs themselves.
And the category was absorbed before it matured: Check Point–Lakera (~$300M), SentinelOne–Prompt (~$250–300M), Cato–Aim (~$350M), Cisco–Astrix (~$400M), Palo Alto–Protect AI, CrowdStrike–Pangea, F5–CalypsoAI, plus Check Point’s ~$150M three-way purchase of Cyata, Cyclops and Rotate in February 2026. Every major platform now sells AI security. That is a market fact, not yet an efficacy fact.
The hype check. The claim that fails is that “MCP security” products can fix this. The paper is explicit that the weaknesses require protocol-level remediation; a scanner that inspects servers cannot supply a missing attestation layer. The second caution is evidential: this is one paper, not independently replicated. Third, OWASP supplies the counter-position from inside the security community — “Least-Agency”: “avoid unnecessary autonomy; deploying agentic behavior where it is not needed expands the attack surface without adding value”. That sentence cuts against the 2026 push to agentify everything, and it is the governance line of the year.
Falsifier: the MCP specification adopting capability attestation and message authentication, followed by a measured fall in attack success, would retire this trend by solving it — the outcome to hope for. Failure to replicate the 26.4%-to-52.8% gap would demote it.
What to do about it now. Inventory your agents before you govern them, on the same register as machine identities. Bind every agent action to a signed intent — subject, audience, purpose, session — and treat planner output as untrusted input passing through a policy gate. Pin and namespace every tool and MCP server. Apply Least-Agency as a procurement question: what does autonomy buy here that a scripted integration would not? And require a pre-deployment security assessment for AI tools — the one control that has already doubled in adoption and is still missing in a third of organisations.
What is changing. The two places where work actually happens are the two places security historically could not see. The network edge — VPN concentrators, firewalls, file-transfer appliances, routers — is internet-facing and cannot host an endpoint agent. The browser is where every SaaS application, every generative-AI assistant and every copy-paste of source code now lives, inside a TLS session the endpoint agent cannot read. Both are being converted from blind spots into enforcement points: one because attackers went there first, the other because the data did.
The evidence.
Attackers standardised on the edge. Mandiant’s five-phase APT44 playbook opens with “Living on the Edge” — compromise of routers and VPN appliances — before living off the land and pushing wipers from group policy (2024, p. 8). That is the path the DBIR measures at scale, with 64% of newly disclosed vulnerabilities network-exploitable (ENISA 2025, p. 57).
The browser is now the exfiltration path. 67% of users access AI services from non-corporate accounts on corporate devices, regular AI users rose from 15% to 45%, and the most commonly exfiltrated data type is source code (Verizon 2026, p. 13). None of that is a malware event; all of it is a browser session.
The extension layer is being attacked directly. ENISA documents a late-2024 wave of compromised Chrome extensions, specifically AI and VPN extensions (p. 15); OWASP’s tracker adds developer-tool configuration attacks, including the “Rules File Backdoor” in Cursor and GitHub Copilot.
Machine traffic is becoming a population. AI bot traffic already accounts for roughly 15% of non-malicious bot traffic against 60% for search-engine crawlers (Verizon 2026, p. 64), and Forter measured an 18,510% day-over-day jump in agentic traffic after ChatGPT Agent launched. Sessions that are neither human nor malware are now routine, and nothing in the stack distinguishes them.
Detection can live at the edge cheaply. Ben-Gurion’s Kitsune runs an ensemble of autoencoders as a network intrusion detector on a single core of a Raspberry Pi at roughly 5,400 packets per second, learning “normal” per channel with no labels (Mirsky et al 2018); the same lab’s N-BaIoT detected every attack from nine infected commercial IoT devices at a mean false-positive rate of 0.007 in 174 milliseconds, fast enough to drive automatic isolation.
Why it is happening. The estate inverted. When applications sat in a data centre, the perimeter was the control point and the endpoint was the last mile. Now the application is somebody else’s SaaS tenancy, the perimeter is an appliance that cannot be patched during business hours, and the last mile is a browser tab holding a session token. Enforcement has to move to whichever layer still sees the whole transaction, and there are only two candidates.
Who is building for it.
Island — created the enterprise browser · $250M Series E in March 2025 at $4.8bn led by Coatue, with secondaries since at about $5bn, serving eight of the world’s ten largest banks · its roughly $200M of revenue is founder-stated and unaudited, the caveat the whole category carries.
The rest of the category was bought: Palo Alto–Talon (~$625M), CrowdStrike–Seraphic (~$420M), Akamai–LayerX ($205M); Palo Alto’s Prisma Browser reported 1,500+ customers and nine million licences by February 2026.
Cato Networks — converged SASE on its own backbone · ARR above $415M, up 42%, across 4,800+ customers (July 2026), valued at $4.8bn · and one of the few Israeli companies building in Central Europe, tripling its R&D centre in Prague.
Check Point — the prevention-first edge · Q2 2026 revenue of $674M, up 1%, with market capitalisation down from $20.35bn at end-2025 to about $13.7bn in September 2026. That is what a twenty-year-old category looks like at maturity, and why the company spent about $150M in February 2026 buying three AI-security start-ups at once.
Zero Networks — automated microsegmentation, so a compromised edge device reaches nothing · $55M Series C, June 2025, led by Highland Europe, enterprise customers up 230% · founder Benny Lakunishok states the design principle: “You can’t outrun AI, but you need to out-architect it.”
The hype check. Edge exploitation is well measured; the browser as a control point is a market trend with thin behavioural evidence. No census-grade dataset in this library breaks out browser-mediated exfiltration as a category, and the efficacy claims of enterprise-browser vendors are self-reported — Island’s revenue figure rests on a founder interview. The claim that an enterprise browser replaces the endpoint agent is unsupported by anything except vendor positioning. What is supported is narrower and still important: the browser is where shadow AI, SaaS session abuse and source-code egress converge, and in most organisations it is ungoverned.
Falsifier: if the DBIR or ENISA began tracking browser-mediated data egress and found it a small share of breaches, this is a product category rather than a threat shift. On the edge side, if KEV listings stopped being dominated by internet-facing appliances, the “living on the edge” pattern would be over.
What to do about it now. Treat the internet-facing appliance estate as a separate asset class with its own inventory, patch service level and compensating-control playbook — trend 1 arriving from the adversary’s side. Govern the browser rather than banning what runs in it: sanctioned AI endpoints, extension allow-listing with provenance, and egress policy on source code specifically. And put cheap unsupervised detection on segments you do not currently instrument, because the research says a switch mirror port and a single core are enough.
What is changing. Autonomous defensive agents have moved from reference architecture to shipping product in about three years, and they are genuinely good at a specific shape of problem: bounded, verifiable work where a machine can prove its own result. They are not good at the thing the category name implies, which is running a security operations centre. The honest 2026 position is that agents have compressed triage and repair, and have not touched judgement or accountability.
The evidence.
The one rigorous evaluation is DARPA’s AI Cyber Challenge. In the August 2025 final, seven autonomous cyber reasoning systems ran roughly 143 hours without human intervention over 53 challenge projects derived from critical-infrastructure open-source software, each with $85,000 of cloud compute and $50,000 of LLM credits. Pairing a proof-of-vulnerability with a patch was 92% accurate; a few genuine zero-days were surfaced in real code — and patch quality was the practical bottleneck (Zhang et al 2026).
Defensive agents are shipping. Google cites Big Sleep, a DeepMind–Project Zero agent that found real-world vulnerabilities including one about to be used by threat actors, and CodeMender, which automatically patches critical code flaws (GTIG 2025, p. 19). Anthropic’s own investigators used Claude to analyse GTG-1002 and recommend defenders “experiment with applying AI for defense in areas like SOC automation, threat detection, vulnerability assessment, and incident response”.
The blueprint converged years ago. NATO’s AICA reference architecture — sense, plan, act, collaborate, learn, over a world model, with destructive actions bounded by rules of engagement (Kott et al 2019) — the BAE/Dstl deep-RL survey and the AIxCC finalists all describe the same machine.
Adoption is real but shallow. 77% of organisations have deployed AI for cybersecurity, principally phishing detection (52%), intrusion and anomaly response (46%) and user-behaviour analytics (40%) (WEF 2026, p. 21) — assistive functions, not autonomous ones.
The demand driver in a mid-sized state is labour, not ambition. Only 47% of Czech organisations consider their cybersecurity budget sufficient, unchanged since 2023; the share citing insufficient pay as the barrier to hiring jumped from 54% to 77% in a year; 55% cope with the skills gap by outsourcing (NÚKIB 2025).
Why it is happening. The architecture, not the model, does the work. PentestGPT’s gains came from decomposition and external memory — a reasoning module, a generation module and a parsing module with an explicit task tree — because the dominant failure mode of a long engagement is context loss (Deng et al 2024). AIxCC’s winners were ensembles of classical fuzzing with LLM-driven strategies, not a single large model. Agents work where the task can be decomposed and the result verified.
Who is building for it.
Torq — agentic security operations · $140M Series D, January 2026, led by Merlin Ventures at $1.2bn, with Jit bought in May 2026 for $50–70M to acquire its context graph · claims more than 95% of tier-one tasks automated and 100 million automations a day, against a last disclosed ARR of “over $24M” in September 2024.
7AI — founded by the Cybereason team to run swarms of task-specific agents rather than one analyst replacement · $130M Series A on 4 December 2025 led by Index Ventures at about $700M, reported as the largest Series A in the industry’s history, 302 days after leaving stealth · by July 2026 it reported nine million investigations and a million analyst hours returned, with DXC citing an 80% cut in tier-one analyst time. ARR not disclosed.
SentinelOne — autonomous endpoint and AI-SIEM · ARR $1.218bn, up 22% in the quarter to 31 July 2026, alongside an 8% workforce reduction in May 2026. Scale and autonomy have not yet produced operating leverage.
The honest reading of the cluster: more than $2.3bn of primary capital went into Israeli “securing AI” and “AI running the SOC” companies in 2025–26, and almost none of it reports an absolute ARR base or a measured false-negative rate. The capital is a forecast, not a result — and Hunters, the agentic-triage company that has not raised in four and a half years or published a metric since 2022, is what the downside looks like.
The hype check. The most over-claimed category in the market, with three documented limits. Evaluation is weak: the BAE/Dstl survey notes that CAGE challenge entries are scored against fixed rules-based red agents, so “solutions that overfit on the provided Red agents are likely to perform best”, and argues that exploitability against an adaptive adversary, not average reward, is the metric that matters (Palmer et al 2024). The ML layer is structurally evadable: Shamir and colleagues showed adversarial examples with tiny Hamming distance are a consequence of high-dimensional geometry, and that adversarial training “should have no effect on the existence of adversarial examples” (2019) — machine learning can never be the only layer. And autonomy is bounded by consequence: an agent that isolates the wrong production server causes the outage it was deployed to prevent. AIxCC is a superb result about autonomously finding and repairing vulnerabilities in code you own, in a bounded competition, with $135,000 of compute per system. It is not evidence that a SOC can be unstaffed.
Falsifier: an independently audited evaluation showing sustained mean-time-to-respond improvements on real enterprise telemetry with measured false-negative rates would move this trend up two tiers; every vendor claim to date reports the former and not the latter.
What to do about it now. Buy agents for the bounded jobs first — alert enrichment, deduplication, evidence assembly, phishing triage, patch generation for code you own — and measure them on false negatives, not tickets closed. Write the rules of engagement before the deployment: what an agent may do unasked, what needs human approval, who is accountable when it acts. Keep a non-ML layer under every ML detector. And build the gym: there is no European public equivalent of AIxCC or the Five Eyes’ CAGE challenges, and a Masaryk University researcher co-authored NATO’s reference architecture — the evaluation-and-assurance niche is open.
What is changing. The buying pattern inverted. For a decade the market rewarded the best tool in each category; since late 2023 it has rewarded the platform that can absorb categories, financed at a scale the industry has never seen. This is the purest market trend in the report — and, unusually, the one with the hardest evidence, because a closed acquisition price is not a survey response.
The evidence.
$67.15bn of announced Israeli cyber exit value in the fourteen months from December 2025 to August 2026: Google–Wiz $32bn (closed 11 March 2026), Palo Alto Networks–CyberArk ~$25bn (closed 11 February 2026), ServiceNow–Armis $7.75bn (closed April 2026), Visa–BioCatch $2.4bn (agreed 3 August 2026).
Whole categories were absorbed. API security has effectively ceased to exist as a standalone market — Akamai bought Noname for $450M, Traceable merged into Harness in March 2025, and Salt Security is the last large independent, unfunded since February 2022. Data security posture management went the same way (Palo Alto–Dig, CrowdStrike–Flow, Rubrik–Laminar), except that Cyera stayed independent and became a buyer itself.
AI security was absorbed before it matured: seven acquisitions in roughly eighteen months — Palo Alto–Protect AI, Check Point–Lakera (~$300M), SentinelOne–Prompt (~$250–300M), Cato–Aim (~$350M), CrowdStrike–Pangea, F5–CalypsoAI, Cisco–Astrix (~$400M).
The enterprise browser, a category that did not exist in 2020: Palo Alto–Talon (~$625M), CrowdStrike–Seraphic (~$420M), Akamai–LayerX ($205M). Non-human identity went the same way: Cisco–Astrix, CrowdStrike–SGNL ($627.9M), Cyera–Oasis (~$1bn).
Flash exits are routine. Palo Alto bought Koi twenty months after it was founded — and the press price (~$400M) diverges from the filing ($231M plus $61M), a caution about every unaudited number in this market.
The money did not stop. More than $2.3bn of primary capital went into Israeli “securing AI” and “AI running the SOC” companies in 2025–26 alone: Cyera ($600M, $400M, $540M), Dream ($260M), Glow ($180M), Torq ($140M), Alice ($140M), 7AI ($130M), Zenity ($125M), Noma ($100M), Irregular (~$80M), Sweet ($75M), Oligo ($60M).
Against roughly $20bn of untested 2021–22 paper: Forter at $3bn, Transmit $2.2bn, Orca $1.8bn, Salt $1.4bn, Axonius flat at $2.6bn since 2022, Aqua above $1bn since 2021, Pentera around $1bn since January 2022 — and Snyk marked down from $7.4bn to about $3.7bn, with a sub-$3bn private-equity bid rejected.
Why it is happening. Three pressures point the same way. Buyers are drowning in consoles and want fewer suppliers with more accountability — which is also what NIS2 and DORA reward, because every additional vendor is another oversight obligation. The strategic asset has become the graph: the platforms are buying context, not features — Wiz’s security graph, Armis’s device knowledge base, Astrix’s identity graph, Apiiro’s software graph, XM Cyber’s attack-path twin. And capital concentrated: a firm that can write a $32bn cheque can outspend every independent on distribution.
The hype check. The claim that consolidation improves security is completely unevidenced. Nothing in this library links platform consolidation to lower breach rates, shorter dwell times or faster remediation. What the library does show is the opposite risk: concentration. The CrowdStrike outage, a single automated update agent, cost $5.4–10bn, insured at 10–20%; the WEF cites the October–November 2025 AWS, Azure and Cloudflare outages as non-security proof of the same exposure. Shlomo Kramer, who founded Check Point, Imperva and Cato, puts the technical objection plainly: “True convergence is not achieved by integrating products under a SASE umbrella.” Buying the companies gives a platform a bundle. It does not give it the loop.
Falsifier: evidence that customers consolidated onto a single platform suffer measurably fewer or less severe breaches — the study nobody has run — would turn this from a market trend into a defensive one. Conversely, if the 2026 cohort of independents grows faster than the platforms’ security segments while staying independent, the absorption thesis is weaker than the headline prices suggest.
What to do about it now. Know whose roadmap you are on: when you buy a category leader, model what happens when it is acquired, and negotiate exit and data-portability terms in the first contract rather than the renewal. Keep the graph yours — the one asset a platform cannot sell you is a normalised model of your own estate. For a state, attach conditions to the concentration rather than resisting it: source-code access, local hosting and staff, published end-use vetting, clean exit clauses. And treat concentration as a resilience problem, not a procurement one: the question is not which platform is best, but what your recovery looks like on the day the platform itself is the incident.
What is changing. Europe’s cyber regulation has crossed from rule-making into enforcement, and the political energy has flipped from more requirements to fewer touchpoints. NIS2 and DORA set the obligations; the Cyber Resilience Act sets the product deadlines; the AI Act adds a parallel regime. What is genuinely new in 2026 is that the EU has begun to treat its own fragmentation as the problem.
The evidence.
The CRA timeline is concrete and close. In force 10 December 2024; vulnerability reporting obligations mandatory from 11 September 2026; full applicability with penalties from 11 December 2027. Obligations include placing products on the market free of known vulnerabilities, a minimum five-year support period, reporting of actively exploited vulnerabilities within 24 hours with follow-up in 72, and life-cycle-maintained SBOMs regenerated with each update (Black Duck 2026, p. 26). Its “open source steward” category is a novel regulatory object: an entity that takes documented responsibility for a component’s security without carrying the manufacturer’s penalties.
Certification has under-delivered badly. In seven years the Cybersecurity Act produced one adopted scheme — the EUCC, available to vendors from 27 February 2025 — while cloud, digital identity wallets and 5G remain under development, and the Commission missed its own Article 67 evaluation deadline (EPRS 2026, pp. 3, 5).
The direction of travel is simplification. The November 2025 digital omnibus would create a single entry point through which entities simultaneously fulfil incident-reporting obligations under NIS2, the CER Directive and the GDPR, on one ENISA-hosted platform (p. 4). ProtectEU (April 2025) refocuses the Cybersecurity Act revision on ICT supply chain resilience and explicitly targets “fragmentation of the internal market caused by different approaches at national level”.
The mid-sized-state position is on the record. NÚKIB told the Commission it wants “shorter, policy-relevant output and clearer prioritisation, including advance notice of strategic decisions”, and criticised certification delays as undermining trust (p. 9) — the same complaint as the December 2024 Council conclusions and the March 2025 Warsaw Call, which ask for a “more risk-based, leaner, transparent and faster” approach. The European Court of Auditors separately found ENISA and CERT-EU under-resourced and lacking practical guidance on “how” rather than “what”, while the Committee of the Regions warned that overlaps between CSA certification, the Medical Device Regulation and the AI Act “may lead to fragmentation and ‘regulatory shopping’”.
Jurisdictions are diverging at the same time. EU AI Act high-risk obligations bite from 2 August 2026; China’s amended Cybersecurity Law took effect 1 January 2026 with expanded extraterritorial reach; and the EU, US and Chinese AI governance frameworks are “fundamentally incompatible” (Kurtz and Krawiecka 2026).
Why it is happening. The obligations outgrew the institutions. ENISA’s mandate was written in 2019 for a world without NIS2, the CRA, the Cyber Solidarity Act or the Skills Academy, and a small national agency cannot absorb an expanding regulatory surface on a flat budget. The binding constraint in Europe is no longer requirement stringency; it is reporting burden and certification latency.
Who is building for it. Almost nobody, directly — and that is the finding. Not one of the 52 company dossiers behind this series is a pure-play governance, compliance-automation or cyber-insurance business. Regulation appears instead as a distribution channel.
Waterfall Security — the purest case · its hardware-enforced unidirectional gateways are exempt from over 35% of NERC CIP requirements and 21 of 26 US nuclear perimeter rules; France’s ANSSI requires hardware-enforced one-way flow for the most critical systems; it is referenced by IEC 62443-3-3 and ENISA, and is now watching NIS2 enforcement.
CyberArk — privileged access is “demanded by regulators and cyber insurers, which gives the market a compliance floor” · it enters large accounts through audit findings. Coro sells NIS2 into the SME base through a PwC Italy partnership (2026). Irregular and Alice are keyed to the AI Act and the Digital Services Act respectively.
The certification arms race is the visible form of it — FedRAMP Moderate for Axonius (April 2025) and Checkmarx (July 2026), FedRAMP High for Cellebrite’s Guardian, Oligo routed through Palantir’s FedStart toward FedRAMP High and DoD Impact Level 5, Sweet and Upwind in process. Certification is not a control; it is a market-access licence, and every vendor treats it as one.
Insurance shows up as an investor, not a product — Munich Re Ventures in Sweet’s $75M Series B, American Express Ventures in Zafran, and Guardz, built on a “secure and insure” thesis, which has since repositioned to agentic security operations.
The hype check. There is no evidence in this library that more regulation produces more security. The Court of Auditors found the guidance gap is in the “how”; one certification scheme has been adopted in seven years; and nobody has published a study showing NIS2-regulated entities outperforming comparable unregulated peers on incident outcomes. Regulation is best understood as a forcing function for budgets and deadlines — real and useful — not as a demonstrated control. Industry is split on whether voluntariness survives: Orgalim warns NIS2 and the CRA make certification de facto mandatory; BusinessEurope wants schemes “specific, voluntary, industry-relevant, and affordable”.
Falsifier: ENISA or a national agency publishing incident-outcome data showing regulated entities measurably outperforming unregulated peers would promote this from a deadline to a control. The consolidation claim fails if the single entry point slips or the omnibus is diluted into another parallel channel.
What to do about it now. Treat 11 September 2026 as the organising deadline for the SME base — 99% of EU businesses, of whom 57% say a serious cyber incident could likely bankrupt them — and deliver it through managed service providers rather than direct obligation. Make the governance status of dependencies a procurement criterion now that “open source steward” exists as a legal category. Build the reporting once, against the omnibus template, rather than three times. And push, as NÚKIB has, for the leaner mandate: a small agency’s scarcest resource is attention, and every additional scheme spends it.
What is changing. Nothing, yet, in the threat data — and that is the point. The standards exist, the deadlines are set, and the work is long. Post-quantum belongs in a trends report not because anything happened in 2025–26 but because the migration has a start date already in the past for anyone holding long-lived secrets.
The evidence.
The standards are published: FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA), with a FALCON-derived signature scheme intended later (NIST 2024, pp. 8–9).
The arithmetic is the whole argument. “Historically, the journey from algorithm standardization to full integration into information systems can take 10 to 20 years“ (p. 8), against National Security Memorandum 10’s 2035 target. The transition table deprecates 112-bit-security classical public-key algorithms after 2030 and disallows all quantum-vulnerable public-key schemes after 2035.
The threat model is present-tense. NIST names “harvest now, decrypt later” explicitly: adversaries “collect encrypted data now with the goal of decrypting it once quantum technology matures”. For health records, diplomatic traffic, source code and intelligence product, the exposure began the day the data was created.
Executive expectation runs far ahead of the science. 37% of WEF respondents expect quantum technologies to affect cybersecurity within twelve months; the report’s own forecast is “a selective but material threat to cryptography” by 2030, and it names the real exposure — legacy encryption in embedded and industrial systems that cannot easily migrate.
Why it is happening. Cryptographic migration is an inventory problem wearing a mathematics costume. Most organisations cannot answer the first question — what cryptography is in use, in which protocol, library, appliance and PKI — and NIST is explicit that the transition covers network protocol standards, software libraries, cryptographic hardware and PKI, and is “unprecedented in scale”.
Who is building for it. Nobody here. Not one of the 52 Israeli companies in this series’ dossiers is a post-quantum or cryptography vendor, and not one contains a single PQC round, valuation or acquisition. The nearest adjacencies are CyberArk’s Venafi, bought for $1.54bn in 2024 for certificate and code-signing key management, and Thales’s CipherTrust stack sitting beside Imperva — and neither makes a post-quantum or crypto-agility claim. Read that as a market signal: the ecosystem that named and owned seven categories in fifteen years — the commercial firewall, privileged access, the web application firewall, agentless cloud security, the enterprise browser, non-human identity, AI-agent governance — has not bet on this one. Israel’s cryptographic tradition is deep, from Shamir at the Weizmann Institute to the Tel Aviv and Technion side-channel school, but its commercial expression has been implementation security, not algorithm migration.
The hype check. No cryptographically relevant quantum computer exists, and NIST IR 8547 remains an initial public draft as of September 2026 — cite it as NIST’s expected approach plus NSM-10, not as settled law. The 37%-within-twelve-months figure is sentiment, and it is exactly the kind of number that sells appliances. Anyone selling a “quantum-safe” box is selling crypto-agility, which is worth buying for reasons that have nothing to do with quantum computing. And the Israeli side-channel school supplies the warning that migration alone is insufficient: Genkin, Shamir and Tromer extracted RSA keys from the sound of a laptop and ECDSA keys from mobile devices with improvised equipment, concluding that air gaps, Faraday cages and power filters do not eliminate leakage and that the fix is algorithmic. A post-quantum algorithm implemented carelessly fails the way its predecessor did.
Falsifier: a credible demonstration of a cryptographically relevant quantum computer, or NIST relaxing the 2030 deprecation date in the final publication. Either would move this trend several places — in opposite directions.
What to do about it now. Start with a cryptographic inventory and a data-classification exercise, not a procurement. Rank data by confidentiality lifetime, because harvest-now-decrypt-later only threatens secrets that must survive past 2035. Identify the embedded and OT estate that cannot be migrated later and plan its replacement cycle now — where the WEF locates the greatest systemic exposure and NIST offers no timeline relief. And write crypto-agility into procurement for everything bought from today.
Read as one object, the twelve resolve into four patterns and one uncomfortable arithmetic.
Speed. In every trend where defenders are losing, the defender’s clock is human and the attacker’s is not. Disclosure to weaponisation is hours; disclosure to remediation is 43 days and rising. A credential is minted in seconds and reviewed in quarters. An intrusion runs at multiple operations per second while an escalation path runs at the speed of a change advisory board. The binding metric of the era is latency, not coverage — and nearly every control that works in 2026 works by removing a human from a loop that does not need judgement, so the humans are free for the loops that do.
Identity. Trends 2, 4, 7 and 8 are one question asked in four places: what is this thing, who vouches for it, and what may it do? A machine credential, a package provenance record, an agent’s scoped token and a browser session are four answers to the same problem, and the standards bodies have noticed — OWASP maps its Agentic Top 10 onto the Non-Human Identity Top 10, CycloneDX/AIBOM and the AI Vulnerability Scoring System. Identity, supply chain and agent governance are converging into a single discipline, and whoever builds one registry for all four will be years ahead of whoever buys four products.
Agency. Software that acts on its own is now on both sides of the line and in between: the attacker’s orchestrator, the defender’s triage agent, and the enterprise’s own automation, which is neither. Koch’s three-channel model is the right instrument — adversaries using agents against you, attacks against your agents, and your own agents acting with excessive autonomy — and most public debate collapses all three into the first. Least-Agency is the governing principle: autonomy without a use case is pure attack surface.
Consolidation. Of vendors into platforms, of regulation into single entry points, of infrastructure into three clouds. The same logic — fewer, bigger, more accountable — and the same second-order risk, which the CrowdStrike outage priced at $5.4–10bn from one automated update agent.
And the arithmetic nobody plans for: every one of these trends is more affordable for large organisations than small ones. Small organisations by revenue are twice as likely to report insufficient resilience as large ones; NGOs report 37% insufficient, the public sector 23%, the private sector 11%; confidence in national protection of critical infrastructure runs from 84% in MENA to 13% in Latin America and the Caribbean (WEF 2026). Meanwhile SMEs are 99% of EU businesses, and 57% of those surveyed say a serious cyber issue could likely bankrupt them. The frontier is widening the inequity, not closing it.
Five second-order effects worth planning for now.
The insurance market is becoming the de facto regulator of machine identity. 88% of organisations already report insurers mandating enhanced privilege controls for machine identities — faster than any legislature moved. But insurance cannot carry systemic loss: 10–20% coverage of the CrowdStrike losses, a European market a quarter the size of America’s, explicit accumulation risk, and a research literature that a structured review found consisted of about five relevant papers.
The attribution gap becomes a liability gap. OWASP diagnoses the agent’s missing identity as a security problem. It is also a contract, audit and insurance problem: when an agent acts, nobody has drafted who is responsible. Expect this to be litigated before it is legislated.
Jurisdictional incompatibility arrives in 2026, not later — EU AI Act high-risk obligations from 2 August 2026, China’s extraterritorial Cybersecurity Law from 1 January 2026, and three governance regimes that do not reconcile.
Geopolitics is a permanent input to the risk register. 64% of organisations account for geopolitically motivated attacks, 91% of those above 100,000 employees have changed strategy because of geopolitical volatility, and confidence in national preparedness is falling (31% low, up from 26%).
Measurement itself is a vulnerability. A national picture built on incident counts is dominated by the 80% that is hacktivist DDoS — activity manufactured to be counted. Impact-weighted reporting is a cheap reform with a large effect on where money goes.
A mid-sized European state cannot out-spend this frontier and does not need to. Some of the twelve trends are cheap to act on and high in leverage; others are expensive and low in leverage; and the difference is knowable in advance.
What to fund.
Patch latency, as a published national metric — median hours from KEV listing to mitigation across regulated entities, reported like an epidemiological indicator. The highest-evidence trend in the report, and the one where Europe is measurably losing ground.
A national machine-identity programme, before an agent programme — an authoritative registry, zero standing privilege, just-in-time credentials, SPIFFE/SPIRE workload identity, and a rule that every agent has its own identity. Cheap relative to leverage, and where both the DBIR and Koch’s 6–18 month forecast point.
The CRA deadline as an SME delivery vehicle — couple 11 September 2026 to a standardised, automatable, risk-based audit the insurance market will accept, with partial-scope and multi-year cycles so it does not price out small firms, and state reinsurance considered as a price lever rather than a subsidy.
A national protective DNS and the boring collective controls. Ukraine’s protective DNS cut losses from financial phishing by more than 30% in its first month, with 300+ providers joined. Nothing in this report has a better cost-to-effect ratio.
An evaluation-and-assurance niche. There is no European public equivalent of DARPA’s AIxCC or the Five Eyes’ CAGE challenges, and a Masaryk University researcher co-authored NATO’s reference architecture for autonomous cyber-defence agents. A national range that doubles as a gym for defensive agents — and publishes assurance results with measured false-negative rates — is a category nobody owns.
Crypto inventory and data classification, as the first and cheapest phase of post-quantum migration.
What to ignore. Quantum panic-buying — buy crypto-agility, not quantum-safe appliances, and do the inventory first. “Autonomous SOC” claims that report tickets closed and not false negatives; ask for the second number, and treat its absence as the answer. Agentification without a use case: Least-Agency is a procurement question, not a philosophy. Incident-count league tables, which reward the adversary generating countable noise. And sovereignty theatre — a foreign vendor’s “sovereign edition” is still dependency; the conditions are the substance.
For CISOs, five metrics replace fifty dashboards: median hours from KEV listing to mitigation on internet-facing assets; percentage of machine identities with a named owner and an expiry; percentage of agents with their own scoped identity and a signed-intent policy; percentage of components inventoried by binary composition rather than manifest; and tested recovery time for the three systems whose loss would stop the business.
For founders, the unnamed categories are visible in the gaps of this report: agent identity and delegation provenance; exposure validation for OT and embedded estates that cannot be patched; provenance for the extension and MCP distribution layer, where 73% of installation guidance has no integrity check; extortion-decision support and disclosure-risk quantification, which nothing in the 52 dossiers sells; audit automation cheap enough for an SME and credible enough for an insurer; and independent evaluation of defensive agents. Israel’s system names a category and owns it for a decade. Each of these is currently a problem statement with no incumbent.
For investors, three disciplines the 2021 cohort taught the hard way: ask for ARR before paying for momentum — roughly $20bn of Israeli paper from 2021–22 has never been retested; model every exit at normal multiples rather than at the outlier prices of 2026; and read a “trend” as a market signal until someone shows you incident data. The largest rounds in this cycle cluster on identity, supply chain and agent security, which is, for once, where the evidence also clusters.
Five moves in the next twelve months.
Publish a national patch-latency indicator for regulated entities, with KEV-style exploit-aware prioritisation for the internet-facing estate, and make it the headline number in the annual report instead of the incident count.
Stand up a machine-identity programme inside the national agency: a reference architecture (registry, zero standing privilege, JIT credentials, SPIFFE/SPIRE), a model policy for agent identity, and a requirement that regulated entities inventory non-human identities before the CRA deadline.
Ship an SME package against 11 September 2026 — a standardised risk-based audit, delivered through managed service providers, priced for a fifty-person firm, and negotiated in advance with insurers so that passing it lowers a premium.
Build the range as a gym — a national cyber range that trains and certifies defensive agents, publishes evaluation methodology with false-negative rates, and runs an open challenge: the European AIxCC nobody has built.
Start the cryptographic inventory, prioritising long-confidentiality data and the embedded and OT estate that cannot migrate later, against the 2030 deprecation and 2035 disallowance dates.
The honest summary of 2025–26 is less dramatic than the marketing and more demanding than the reassurance. Attackers did not acquire new kinds of capability; they acquired speed, scale and reach, and pointed them at a surface that had quietly stopped being human. Defenders did not lose; they fell behind on one specific clock, and the evidence says exactly which one — 38% to 26%, 32 days to 43.
That is good news, in a way that is easy to miss. A field whose central problem is latency is a field where the fixes are known and the arguments are about execution. The organisations that do well over the next two years will not be the ones that bought the most convincing narrative about artificial intelligence. They will be the ones that can answer three questions in under an hour: what is exposed, who and what may act on it, and how fast can we take the exposure away.
For a state of ten million people, none of that requires a frontier lab. It requires a registry, a published metric, an audit an insurer will accept, and a range where defensive agents are tested rather than advertised. The most valuable thing a mid-sized state can do at this frontier is not to predict it, but to measure it honestly and act on the measurement — because the clearest finding across 171 documents is that the people losing ground are the ones who never knew which number to watch.