**Karen Stokes Lockhart** (0:02)
AI is everywhere, but what does it mean for your business? Gartner is the world authority on AI, with more than 200,000 client conversations, and more than 6,000 written insights on AI in 2025 alone. Leaders across the C-suite, just like you, are partnering with Gartner to turn AI ambition into impact. Go to gartner.com/ai to learn more.
Welcome to Gartner ThinkCast. I'm Karen Stokes Lockhart. In this episode, we're tackling the cybersecurity trends shaping 2026, a year we're accelerating AI adoption, an increasingly volatile threat landscape, and growing regulatory pressures are pushing security leaders to rethink how they operate and what they prioritize.
To unpack what this means in practice, you'll hear from Gartner experts, Chiara Girardi and Will Candrick, previewing one of their recent webinars.
Together, they'll break down the most impactful trends for 2026, the risks and opportunities they create, and the actions security leaders should take now to stay ahead. Now, here's Chiara and Will.
**Chiara Girardi** (1:16)
Today, Will and I are going to talk about eight key trends. I want you to treat this eight trends as your map on exactly what to keep track of and look out for in 2026
As we look at the landscape, our map is divided into three distinct themes. Normalize AI adoption, transform governance, and secure new frontiers. With that, let's start with our first peak of the day. Normalize AI adoption. Will, to you to walk us through each trend in this session.
**William Candrick** (1:57)
Absolutely, and thank you. Our first trend is GenAI breaks traditional cybersecurity awareness tactics. This occurs for a few reasons. First, security awareness is failing. In fact, 60 percent of data breaches involve a non-malicious human element. We can train people, we can test them, but clearly, we are not making a sufficient impact. Second, to be successful, we need to shift from awareness and training to managing fundamental employee behavior change. This requires a total rethink. Third, AI drives deep fake attacks, including vishing, smishing, quishing, and of course, traditional email phishing. AI puts social engineering on steroids. Now, if we roll the clock back to 2016, security awareness was all about email-based phishing. But today, human threats have exploded. Attacks now include deep fakes, cookie session theft, brand spoofing, and fake QR codes. These attacks span many channels, such as browsers, job boards, and SMS to name a few. Now, you might think, well, many of these attacks have been around for a while. Why is this a trend in 2026?
Enter GenAI. AI is a force multiplier for threat actors. It accelerates the scale, scope, and likelihood of social engineering attacks. This trend is important today because human behavior is not just a risk. It's also cybersecurity's biggest opportunity. Improving employee habits has an outsized impact on cyber risk. At the same time, AI enables deepfakes and employee use of AI tools accelerates risk even beyond social engineering. For example, 57 percent of employees use consumer GenAI tools. Thirty-three percent expose sensitive data to GenAI, and 36 percent use unapproved GenAI apps on work devices. Yikes.
So how do we address the explosion of AI-related risks? We have three recommendations. First, stop relying on traditional legacy security awareness. Instead, shift to dynamic interventions that engage and nudge employees in the moment based on their actual behavior. Second, run specific deepfake simulation campaigns. Don't just train employees, but rather test and improve their ability to distinguish malicious AI attacks.
And third, plan to adopt a security behavior management platform. This represents an upgrade to next-gen security awareness. Next, let's dive into our second trend. AI-driven SOC solutions destabilize operational norms.
This is a top trend today because CISOs and their teams face incredible uncertainty around planning for a SOC workforce of the future, evaluating risk-benefit trade-offs when integrating AI-driven automation, and adapting skills to maintain long-term operational resilience. We need to ensure the SOC has skills to be successful now and into the future.
Life in the SOC is busy. There's more work to do than time in the day, and burnout in cybersecurity is a very, very real issue. AI is both an opportunity, but also a significant risk, because as more tasks are automated, SOC analysts lose learning opportunities. In essence, what gets automated gets forgotten.
Let's explore this concern. Your SOC today has skills that are at risk of atrophy. At a baseline, we have foundational skills, such as critical thinking, ethical decision-making, troubleshooting, and so on.
Enduring skills that remain even in the AI era, skills such as threat landscape analysis, cross-team communication, and so on. But above that, we need to be very careful. There are critical skills at risk of atrophy, such as threat modeling and investigating positives from AI. It's imperative to ensure we protect these at-risk yet essential skills, even as we promote acceptable skill atrophy. It's okay for teams to lose skills such as basic report writing, simple playbook execution, and so on. Of course, we also have to monitor the horizon for new emerging skills. For example, autonomous agent supervision, security policy automation, and AI-driven threat hunting. This trend is important today because CISOs face crushing pressure from the C-suite and board to showcase value from AI investments. Years of AI hype further accelerates this urgency. Yet, AI ambitions are met by a talent bench that's not prepared for widespread rapid AI adoption. At the same time, AI-driven automation risks eroding vital skills for junior SOC analysts. Even if we are successful implementing AI automation at scale, we risk losing the next generation of SOC talent. So, as a result, SOCs face a catch-22. AI failures lead to ballooning costs and low ROI today, and AI success leads to lost skills tomorrow.
8 more minutes of transcript below
Try it now — copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/1000766595585