The report behind this piece, "The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations," breaks the market into ten distinct segments: identity security, telemetry and data management, human security, endpoint management, human risk intelligence, exposure management, email and domain security, connected device security, AI-native security operations, and cloud security. That segmentation is the first useful signal for anyone writing the budget. Security spending is no longer one line item with one vendor attached to it. Details in this article come from analysis published by The Hacker News.
What is pushing that spend is the growth in things that need protecting. Cloud infrastructure, remote work, automation, and AI agents have all increased the number of identities requiring access, including non-human ones such as service accounts and machine identities.
Key Insight: More identities means more credentials an attacker can use, and credentials bought or phished are considerably cheaper for an adversary than a software exploit.
AI is also changing the attacker side of the equation. Adaptive Security points to AI-powered social engineering making phishing, voice cloning, deepfakes, and impersonation easier to produce and scale. For your finance team, that is the difference between spotting a badly written email and fielding a voice call that sounds like the managing partner approving a payment.
On the defensive side, the constraint is data volume. Security teams generate more telemetry than they can usefully review, and collecting more of it does not automatically produce better visibility.
"The winning security programs in 2026 and beyond aren't the ones ingesting the most data. They're the ones who can route, reshape, and reuse it on demand." - Nicole Beckwith, Senior Director, Security Engineering and Operations, Cribl
CrowdStrike's Kartik Shahani frames cloud as a central target for identity-driven attacks, with adversaries using credentials, misconfigurations, and cloud controls to move through an organization. Threats that cross identity, endpoint, and cloud at once do not map neatly onto a single product category.
That is why the segment-by-segment view matters for your purchasing decisions. A law firm with fifty staff and a hospital running thousands of connected medical devices face different exposure and should not be buying the same stack.
Key Market Segments and the Risks They Address
Identity and access management is the segment that counters the most common attacker pattern in the report's framing: signing in with credentials that already work. ATT&CK calls this Valid Accounts (T1078), and it sidesteps most perimeter controls because nothing is being exploited. The harder problem now is non-human identity, the service accounts, API keys, and AI agents that hold standing access and rarely sit behind MFA or a password reset cycle.
Keeper Security's Darren Guccione frames the operational cost directly: "Managing multiple disconnected tools is itself a security liability." For a security lead, that translates into a mapping exercise. Count how many separate consoles currently grant, rotate, or revoke access across your estate, because each one is a place where an offboarded account can survive.
Endpoint management and EDR/XDR cover the next stage, where an attacker with access moves to other hosts using remote services and admin tooling. Automox CEO Justin Talerico describes the working model as "Patch what's patchable, mitigate what isn't, and govern the endpoint continuously," with visibility spanning Windows, macOS, and Linux. Mixed fleets matter here because Linux servers and developer Macs routinely fall outside policies written for domain-joined Windows machines.
Cloud and SaaS posture management addresses exposed storage, overly broad roles, and misconfigured controls that attackers reach through stolen cloud credentials. CrowdStrike's Kartik Shahani points at the detection timing problem in that layer.
"Traditional CDR capabilities that rely on static risk models and log batch processing... are simply too slow for today's threat landscape."
If cloud detection runs on batched logs, the gap between an attacker assuming a role and your team seeing it is measured in collection intervals, not seconds. That delay is the business risk, since cloud data access does not require the lateral movement steps an on-premises intrusion would.
Perimeter security now extends past the firewall into domain and DNS infrastructure. Red Sift's Rahul Powar puts it as "Every part of the chain, email, domain, DNS, certificate, is a trust decision made in public infrastructure," which is where fraudulent domains and impersonation campaigns are assembled before any phishing email reaches a user. Adaptive Security extends the same problem to voice cloning, deepfakes, and SMS and video impersonation, channels that no email gateway inspects.
Connected device and OT security handles the assets that cannot take an agent at all. Asimily's Shankar Somasundaram sets the bar at enforcement rather than awareness: "Knowing a device is at risk has to end in an enforced control, and it has to hold as the fleet doubles." Scale is the operative word, since device counts grow faster than the headcount reviewing them.
Coverage gaps cluster in predictable places between these segments:
- Session tokens and refresh tokens that survive a password reset, sitting between IAM and endpoint tooling
- SaaS applications adopted by business units and never registered in cloud posture scope
- Devices with no agent, which EDR cannot see and patch management cannot reach
- Exposures with no named owner, the problem Surf AI's Yair Grindlinger summarizes as "Discovery is commoditized. The middle is hard."
- Telemetry that never reaches the detection tool, which is why Cribl treats routing and reshaping of security data as its own discipline
Managed detection and AI-native security operations sit across all of it. SentinelOne's Paolo Cecchi describes the division of labor as AI that "accelerates, supports and suggests, but does not replace human judgment," automating investigation work while analysts decide what happens next.
Technologies Reshaping Defense and Attack
AI shows up twice in this report, once as defensive tooling and once as the thing making attacks cheaper to produce. On the attack side, Adaptive Security's framing is specific: phishing, voice cloning, deepfakes, and impersonation across email, voice, SMS, and video are all easier to create and scale. That matters operationally because a cloned voice on a callback line defeats the verification step most finance teams use to confirm a wire request.
Andrew Jones, Co-Founder and CPO at Adaptive Security, puts the consequence plainly: "Traditional awareness programs weren't built for today's threats. Human security must be continuous, personalized, and responsive to real-world risk." The practical read is that a once-a-year training click-through produces no useful signal about which of your staff would actually approve a synthetic video request from a executive.
On the defensive side, AI is being applied inside security operations to automate investigation and connect evidence across alerts. SentinelOne's Paolo Cecchi draws the boundary clearly: "AI accelerates, supports and suggests, but does not replace human judgment." That limitation is the honest part of the pitch. Automated triage reduces the manual effort to assemble an incident timeline, and it still produces conclusions an analyst has to confirm before containment actions get taken against production systems.
Detection quality depends on data quality, which is why telemetry handling appears as its own discipline. Cribl's position is that volume and visibility are different things, and that controlling how data is routed, structured, retained, and reused across tools determines whether any of it is usable.
Speed is the other constraint. CrowdStrike's Kartik Shahani notes that cloud detection and response built on "static risk models and log batch processing" is too slow for current attack timelines. Batch ingestion introduces delay between an attacker using stolen cloud credentials and anyone seeing it, and in that window the attacker is already modifying configurations and cloud controls.
Exposure management is where the report is most candid about what remains unsolved. Surf AI's Yair Grindlinger reduces it to five words: "Discovery is commoditized. The middle is hard." Finding weaknesses is a solved product category. Correlating how individual weaknesses connect, establishing who owns each one, and determining which fix can be applied without breaking a production dependency is still mostly manual work.
Two segments extend that enforcement problem outward. Red Sift's Rahul Powar treats impersonation as infrastructure rather than inbox content, arguing that "every part of the chain — email, domain, DNS, certificate — is a trust decision made in public infrastructure," which means fraudulent domains and DNS abuse sit outside anything your mail gateway inspects. Asimily's Shankar Somasundaram applies the same logic to connected devices, where the test is whether enforcement "holds as the fleet doubles."
Automox frames endpoint work as a split: "Patch what's patchable, mitigate what isn't, and govern the endpoint continuously," across Windows, macOS, and Linux. That phrasing concedes something useful. A meaningful share of exposure in distributed fleets has no patch available, so compensating configuration becomes the operating control rather than a temporary one.
Budget, Compliance and Operational Consequences
Ten market segments means ten procurement cycles, ten renewal dates, and ten sets of contractual terms your legal team has to read. That is the first budget consequence of the picture this report lays out. The spending question is no longer which product to buy, it is how many overlapping contracts your organization can administer without losing track of what each one actually covers.
Telemetry is where that cost compounds quietly. Most security data platforms price on ingest, so your bill grows in step with your cloud estate, not with your risk. Nicole Beckwith, Senior Director of Security Engineering and Operations at Cribl, puts the shift plainly: "The winning security programs in 2026 and beyond aren't the ones ingesting the most data. They're the ones who can route, reshape, and reuse it on demand." If your retention settings are driven by a regulator's evidentiary requirement rather than by detection value, you are paying storage costs for compliance reasons and should account for them that way.
Cyber insurance underwriters have moved from asking whether you have controls to asking you to evidence them. Expect renewal questionnaires to probe areas the report highlights directly:
- Patch cadence and coverage across Windows, macOS, and Linux fleets, which Automox CEO Justin Talerico frames as "patch what's patchable, mitigate what isn't, and govern the endpoint continuously"
- Which identities hold standing privileged access, including service accounts that sit outside your joiner-mover-leaver process
- How quickly you can reconstruct an incident timeline from retained logs
Where you cannot produce that evidence, the practical outcome is a higher premium, a sub-limit, or a coverage exclusion written into the policy you only read after an incident.
Regulatory pressure pulls in the same direction. Organizations inside scope of NIS2 or DORA face incident notification duties and supervisory expectations that land on named executives, and SEC disclosure obligations put materiality judgments on a timeline your board has to be ready to defend. GDPR enforcement continues to treat inadequate access control as a finding in its own right. The reporting consequence is concrete: your board needs numbers it can repeat under questioning, such as identity coverage, mean time to remediate, and third-party concentration, rather than a slide saying controls are in place.
Staffing is the constraint most organizations hit first. The report describes a widening gap between attack speed and the capacity of human teams to investigate, which is why AI-assisted investigation is being applied inside the SOC at all. Paolo Cecchi of SentinelOne sets the boundary: "AI accelerates, supports and suggests, but does not replace human judgment." Running that judgment around the clock means three shifts of trained analysts, and for most mid-market firms the arithmetic favors a managed service over hiring, which is why SentinelOne is deployed and monitored as part of managed environments rather than left for an internal team to staff overnight.
Third-party risk has become a contracting problem as much as a technical one. Nisos extends human risk intelligence to candidates, executives, and third parties, and Red Sift's Rahul Powar notes that "every part of the chain, email, domain, DNS, certificate, is a trust decision made in public infrastructure." Your vendor questionnaire rarely covers any of that. Asimily CEO Shankar Somasundaram adds the scaling point, that an enforced control "has to hold as the fleet doubles." Write the evidence requirements into the contract at renewal, because after a supplier incident your recourse is limited to what the agreement says.
Priorities for Security Programs in 2026
Start with the asset inventory, because everything else in this list depends on it. In the next 30 days, pull a current list of your internet-facing assets and every identity provider in use, including the ones a business unit stood up without telling IT. Name an owner for each line. An inventory nobody owns is a document, not a control.
Then work through the rest of the 0-30 day list:
- Enforce phishing-resistant MFA (hardware keys or platform authenticators) on administrative accounts and all remote access paths. SMS codes do not survive the voice and video impersonation techniques now in circulation.
- Confirm your backups are offline or immutable, and restore one to a clean host. A backup you have never restored is an assumption.
- Find your EDR coverage gaps. They are almost always on servers, build agents, and legacy hosts that nobody wants to reboot.
Good looks like a signed-off list with a named owner per asset class and a restore test with a timestamp on it.
Months one to six are for the work that needs scheduling. Run a tabletop that covers two scenarios: ransomware that reaches your hypervisors, and a compromise at a supplier who holds your data. Invite finance and legal, not just IT, because the decisions that stall an incident are usually about money and disclosure.
Map your controls to the regulation that actually applies to your sector and your customers' locations, rather than to a generic framework checklist. Where two tools do the same job, retire one and redirect the license spend into closing the gaps your detection content cannot see, typically identity logs, SaaS admin audit trails, and connected device traffic. Surf AI's Yair Grindlinger describes the problem as "Discovery is commoditized. The middle is hard." The middle is triage, ownership, and safe remediation, and that is where your effort belongs.
Put security requirements into vendor contracts during this window too. Specify breach notification timelines in hours, the right to review their findings, and a named security contact. Renewal is the only moment you have real negotiating leverage over a supplier's security terms.
The 6-18 month items are the ones that fail if you start them late. Build a segmentation roadmap that begins with your highest-value data stores and your connected device fleets, since Asimily's Shankar Somasundaram sets the bar correctly: "Knowing a device is at risk has to end in an enforced control, and it has to hold as the fleet doubles." Start a cryptographic inventory, listing where TLS certificates, code signing keys, and VPN tunnels live and who issues them, so post-quantum migration becomes a scheduling exercise instead of a discovery project. Red Sift's Rahul Powar frames why this inventory matters beyond the crypto question: "Every part of the chain, email, domain, DNS, certificate, is a trust decision made in public infrastructure."
Finally, decide build-versus-buy on 24/7 monitoring. A three-person team cannot cover nights and weekends without burning out, and attacks do not wait for business hours.
On the identity side, in environments Capstone manages, Adlumin monitors authentication behavior across managed environments and surfaces logins that do not match a user's normal pattern, which is how credential misuse gets caught when nothing is technically being exploited. Automox CEO Justin Talerico summarizes the operating rhythm for the rest: "Patch what's patchable, mitigate what isn't, and govern the endpoint continuously."
What to Act On First
The ten segments in this report did not appear because defenders lost interest in the problem. They appeared because the cost of producing a convincing attack fell. Cloned voices, fraudulent domains, and credentials that already work are cheaper to assemble than they were, and the market grew to cover the ground that opened up.
That changes how you should read a vendor landscape this wide. Each segment describes a real gap, and buying into all ten gives you ten consoles, ten renewal dates, and no guarantee that the path an intruder would actually take is closed. Yair Grindlinger, Co-Founder and CEO at Surf AI, puts the gap between finding and fixing plainly: "Discovery is commoditized. The middle is hard." Your tooling will tell you what is exposed. Whether anyone acts on that is an operational question, not a purchasing one.
The highest-value work sits in two places: how people and services authenticate into your environment, and whether you can get your data back without paying for it. Those two areas cover the methods that recur across almost every segment in the report, including stolen credentials, impersonated sign-ins, and standing access held by service accounts and AI agents that nobody reviews.
Spending there outperforms another product line because it removes the route rather than adding another place to watch it. A new console needs staff, tuning, and an owner before it produces anything. Closing an authentication gap or confirming that a restore actually completes reduces risk the day the work is finished.
If your 2026 budget conversation starts with which segment to fund, reframe it. Ask which route into your organization is currently open, and fund that.