
This article first appeared in Digital Edge, The Edge Malaysia Weekly on January 12, 2026 - January 18, 2026
Artificial intelligence (AI) is changing cybersecurity for both attackers and defenders. Here are some issues we expect chief information security officers (CISOs) to deal with in 2026 and beyond.
1. AI is driving innovation, but at what cost?
AI is fundamentally transforming almost every business, not only by automating tasks but also by changing how decisions are made, how value is created and how companies compete.
Previously, broad technology changes were within the remit of IT teams. The new wave of generative AI (Gen AI) technology, however, is democratising technological changes, putting control into the hands of all teams.
Every department is leveraging AI to enhance efficiency, facilitate better decision-making and deliver more personalised experiences for customers.
However, this brings with it some new risks, including:
Lack of transparency: Many AI models are opaque, making it difficult to interpret how the system arrived at its decision, which can create accountability and compliance challenges.
Privacy and data misuse: AI requires large, often sensitive datasets to be uploaded to cloud-based systems. If teams are not adequately trained on the risks, this could result in the leaking of sensitive personal information or intellectual property, leading to privacy violations or regulatory breaches.
Security vulnerabilities:
● Adversarial attacks: The subtle manipulation of input data to trick models into making incorrect predictions.
● Model inversion and extraction: Model queries enable attackers to reconstruct sensitive training data or to clone the model itself, such as extracting personal faces from facial recognition AI.
● Data poisoning: The manipulation of data to force it to generate incorrect predictions.
● Large language model (LLM) prompt injection: The circumvention of guard rails by embedding hidden instructions in text or websites that cause AI systems to ignore safety rules or leak data.
● Unexpected results: As AI agents interact more, there is a risk of coordination or collusion, swarm attacks and emergent vulnerabilities. These threats are sometimes not covered by traditional cybersecurity frameworks.
● Weak identity and authentication: Agentic AI can enable multiple agents to query one another, making autonomous, reasoned decisions and taking actions to achieve specific goals, often without human intervention. As the use of this technology increases, the security of the agents’ non-human identity (NHI) becomes crucial, as a weakness in the identity of one agent could lead to cascading vulnerability.
There have already been multiple breaches of AI LLMs. Next year will see this increase in both volume and severity as AI accesses more and more sensitive data, and agent-to-agent communication is allowed without considering the identity and security implications.
2. Adversarial use of AI
There have been many cases of disinformation being used to unduly influence people. The power of AI takes this to a new level with services such as OpenAI DALL-E and Sora 2, which make the creation of almost indistinguishable audio, images and videos trivial.
In 2026, deep-fake services will take business email compromise (BEC) and social engineering to a whole new level. The use of AI-generated audio has already been observed in extortion attempts but this year, we expect organisations to face an onslaught of audio- and video-generated content used for BEC, phishing and other targeted attacks.
3. CISOs’ growing role in the boardroom
At the top of CISOs’ concerns over the past three years has been the cybersecurity skills gap. Fortinet has been working to close this gap by helping train one million people in cybersecurity by the end of 2026, and we are well on the way to achieving that goal.
However, Fortinet’s 2025 Cybersecurity Skills Gap Report shows that multiple issues remain: IT leaders stated that the leading causes of breaches were the lack of security awareness (56%) and the lack of IT security skills and training (54%), while 49% of leaders do not think their board members are aware of the risks posed by using AI.
More than ever, the CISO’s place in the boardroom is critical. We need to communicate the benefits of new technologies like AI, along with their associated business risks, as clearly as possible so that the board can determine their appetite for risk.
The good news for CISOs is that cybersecurity is becoming so critical to the board that we are beginning to see CISOs becoming board members themselves, thereby broadening the experience of the board.
4. The next generation of security experts
Gen Z (born between 1997 and 2012) is already well established in the workforce and Gen Alpha (born between 2013 and 2029) will enter the workforce in the next few years.
Because many new workers were raised in the digital age, where information is abundant but attention is limited due to social media, we must adapt our approach to recruitment, training and, ultimately, work.
AI is growing so rapidly that it is replacing many of the entry-level roles that new graduates may typically have cut their teeth on in the past. This means there will no longer be stepping stones to the more senior roles that are still required.
AI fluency will become a baseline skill. For this to happen, it must be woven into every student’s curriculum if we hope to prepare tomorrow’s workforce for an AI-driven world. As today’s entry-level roles evolve or disappear, those who understand how to apply and secure AI will advance fastest.
5. The quantum of solace
Quantum computing is a complex technology, unlike anything CISOs are used to. However, while quantum threats are not an immediate concern, there is a real risk that malicious actors might implement a “harvest now, decrypt later” strategy, underscoring the urgency of preparing for a future in which current cryptographic standards may be rendered obsolete.
More of a recommendation: Don’t wait. Start adding quantum readiness to your procurement process now so that all your purchases today are quantum-ready for the future.
6. The CISO is dead! Long live the chief resilience officer!
The CISO title belies the fact that the role is not purely security-focused. Our daily role is that of enabling business transformation and innovation while doing so in a safe and secure manner. Most of all, though, we have to keep the business running at all times. It is this last point that is sometimes missed, but is one of the most important roles of a CISO.
There have been multiple cases of businesses grinding to a halt in 2025 due to security incidents. It is crucial, therefore, for CISOs to understand the minimum viable business (MVB) required to keep the organisation running and ensure this is available at all costs.
We all must become chief resilience officers.
Attacks on multibillion-dollar multinational organisations are going to continue in 2026, driven by AI simplifying reconnaissance, the continued growth of cybercrime-as-a-service, and further nation state-sanctioned activity.
CISOs need to plan for failure and wrap their arms around building a business continuity plan. This includes helping to define the MVB needed, practical testing of the plan and conducting regular tabletop exercises.
The year 2026 will test every assumption about how we defend, recover and adapt to today’s evolving threat landscape. AI is now both the weapon and the shield, and the line between IT and business risk has disappeared.
For CISOs, the path forward is clear:
Build resilience first. Assume disruption is inevitable and invest in business continuity, segmentation and recovery readiness.
Treat AI as a governed capability, not a shortcut. Use it to enhance detection and response — but protect models, data and access with the same rigour as any other critical system.
Harden identity everywhere. As human and machine agents multiply, non-human identities must be secured and continuously verified.
Strengthen collaboration. Break down silos between security, operations and leadership. Resilience depends on shared understanding and unified response.
Stay informed and adaptive. Threat actors innovate as quickly as technology evolves, which means continuous learning and testing are now core security disciplines.
Success in 2026 will belong to those who can combine technical depth with strategic vision, turning security from a reactive function into a force for resilience, trust and growth.
Carl Windsor is chief information security officer at cybersecurity firm Fortinet
Save by subscribing to us for your print and/or digital copy.
P/S: The Edge is also available on Apple's App Store and Android's Google Play.