AI & Cybersecurity

AI Reshapes the Cybersecurity Attack-Defense Landscape: 2026 Security CEO Outlook

Based on the CRN CEO Outlook 2026, analyze global security vendor CEOs' assessments of AI's impact on both attack and defense, and provide recommendations for enterprise responses.

AI Reshapes the Cybersecurity Offense-Defense Landscape: Security CEOs’ Outlook for 2026

Introduction

Against the backdrop of AI technologies accelerating their penetration into enterprise operations, cybersecurity now stands at a watershed. In the *CEO Outlook 2026* report published by CRN, CEOs from several world-leading cybersecurity vendors—including Abnormal AI, Cloudflare, Cynomi, Darktrace, Fortinet, Proofpoint, Sophos, and SentinelOne—unanimously concur that AI will strengthen both attack and defense in 2026. Attackers will leverage generative AI and intelligent agents to execute social engineering attacks with higher precision and at greater scale, while defenders will use AI to drive security operations center (SOC) automation in response to security staffing shortages and alert fatigue. This article draws on these CEOs’ observations to dissect the risks, challenges, and opportunities AI poses for enterprise security, and sets out a practical response framework.

Event Overview

  • Time: Late 2025 (outlook for 2026)
  • Data source: The CRN *CEO Outlook 2026* report
  • Participants: Abnormal AI CEO Evan Reiser, Cloudflare CEO Matthew Prince, Cynomi CEO David Primor, Darktrace CEO Jill Popelka, Fortinet CEO Ken Xie, Proofpoint CEO Sumit Dhawan, Sophos CEO Joe Levy, SentinelOne CEO Tomer Weingarten, and other leaders of world-leading security vendors
  • Core consensus: AI is the great “dual force” in the cybersecurity market in 2026—both an engine for the next round of attack escalation and a catalyst forcing security operations to transform.

The report shows that the surveyed CEOs generally believe AI-driven attacks are no longer conceptual demonstrations but have entered practical use. Evan Reiser, for instance, notes that attackers are using AI to automatically identify targets and write phishing emails with near-perfect grammar and wording; as a result, traditional employee training built around “detecting suspicious grammar” will fail. At the same time, generative AI (GenAI) and early-stage Agentic AI are seeping into enterprise applications, creating new blind spots for data security and identity management.

Technology and Risk Analysis

AI-Powered Attack Techniques: From “Manual Phishing” to “Automated Phishing Seasons”

According to the CEOs’ observations, the main ways in which attackers will exploit AI in 2026 include:1. Automated reconnaissance: AI can automatically collect target information across social platforms, email gateways, and public data sources to build highly accurate personal profiles. 2. Realistic social engineering: Generative AI can remove grammatical errors and cultural differences from phishing emails, and can even mimic tone and voice in real time, bypassing traditional security-training defenses. 3. Deepfake proliferation: AI-generated voice and video hijacking is expanding from celebrity fraud to vishing on corporate internal networks and CEO fraud. 4. Nascent autonomous attacks: Sophos CEO Joe Levy stressed that the biggest change is not fundamentally new attack techniques but the exponential growth in attack speed and scale. “AI-driven attack toolkits can launch more than 10,000 variant attacks at once, and manual response is already completely unable to keep up.”

Evan Reiser, CEO of Abnormal AI, also warned that 2026 will see the first “almost fully autonomous” attack campaigns—from initial intrusion to data theft, all orchestrated by AI agents—and traditional security products based on signature libraries and rules will face enormous pressure to fail.

AI-Powered Defense: Security Operations’ “Co-pilots” and “Agents”

Security vendors are upgrading AI from an assistive tool into an autonomous response unit:

  • AI co-pilot embedded in security workflows: Fortinet CEO Ken Xie said its GenAI assistant FortiAI has been embedded into FortiAnalyzer, FortiManager, and FortiSIEM, delivering threat analysis, alert triage, and response actions to SecOps personnel in a conversational manner.
  • Autonomous investigation and response: Darktrace CEO Jill Popelka emphasized that AI can conduct incident investigation, prioritization, and containment at “machine speed,” thereby filling the gap left by understaffed security teams.
  • Security architecture for AI infrastructure: Fortinet, together with partners such as Nvidia and Arista, also launched the “Secure AI Data Center” solution, embedding security policies directly into AI training and inference clusters to prevent data theft and poisoning targeting “AI factories.”

New Risk Surfaces Introduced by AI

The CEOs also pointed out that the rapid application of AI is creating three major new risks:1. AI data leakage in SaaS environments: Employees input sensitive data into public GenAI tools, creating a "shadow data" phenomenon. 2. Blurring identity and access boundaries: AI agents, as non-human identities, have permissions for file access, email operations, and more, yet often remain outside traditional IAM governance. 3. Model and supply chain attacks: Attacks targeting large model weights, prompt injection, and third-party AI components will increase significantly over the next 12–18 months.

Enterprise Impact Analysis

Operational Risk: Security Teams Have Hit a Staffing Bottleneck

In 2026, security teams will face the dilemma that "AI can always hit the ball faster than humans can catch it." Alert volume is expected to grow by an order of magnitude, while the number and energy of security analysts remain limited. Darktrace CEO Jill Popelka noted that if security operations do not adopt AI, enterprises will be forced to struggle in an "ocean of untriaged alerts," ultimately allowing critical incidents to be drowned out.

Financial Risk: Security Budgets Shift from "Buying Tools" to "Buying Outcomes"

CEOs predict that as AI takes over day-to-day security operations, enterprise procurement logic will change: what is purchased will no longer be individual detection tools, but security outcomes such as "fewer disruptions and faster containment." Partners that cannot demonstrate that their services use AI to enhance customers' security resilience will lose ground in budget battles.

Compliance and Governance Risk: AI Governance Rises to the Board Level

Jill Popelka emphasized in an interview: "As AI begins to act with greater autonomy, cybersecurity is no longer a purely technical issue, but a governance issue at the business and board level." Enterprises will need to comply with increasingly stringent AI regulations worldwide (such as the EU AI Act) and establish auditable AI usage registers, data flow diagrams, and risk tolerance boundaries. Organizations that fail to do so will face regulatory penalties and denial of insurance coverage.

Brand and Data Risk: Deepfakes and AI-Generated "Perfect Phishing"

Even employees trained to recognize phishing emails will be almost unable to detect AI-generated attacks based on outdated criteria such as "spelling errors" or "unusual tone." Abnormal AI CEO Evan Reiser pointed out that by 2026, phishing will become "indiscriminate fraud," where the likelihood of being tricked depends on employees' cognitive blind spots rather than their vigilance. A single successful deepfake audio fraud could cause losses in the tens of millions and inflict irreparable reputational damage.

Industry Trend Observations

Long-Term Trend 1: From "AI Empowering Security" to "Security Empowering AI"Cynomi CEO David Primor pointed out that AI is elevating MSPs/MSSPs from "providing compliance templates" to "providing strategic consulting." By using AI tools, service providers cut report generation and basic assessment time by more than 50%, freeing up manpower for customer business insights and security architecture design. This trend shows that AI is not eliminating security practitioners; rather, it is releasing human effort from low-level repetitive tasks.

Long-term Trend 2: The Rise of Agentic Security Architecture

SentinelOne CEO Tomer Weingarten said that in 2026, "AI will become the ultimate multiplier for the partner ecosystem." More and more security vendors will develop "Security Agents" capable of autonomously executing remediation actions. Through APIs, these agents can interact with EDR, SIEM, and email gateways to automatically contain threats after human approval. This means enterprise security operations will evolve from "humans finding threats" to "machines driving out threats."

Long-term Trend 3: AI-Native Security Infrastructure Becomes a Must-Have

Fortinet and Cloudflare have both independently launched "AI security data platforms" or "AI security suites." Cloudflare CEO Matthew Prince believes that organizations are adopting AI faster than their operational management capabilities can keep up, so they need a security control plane that spans data, identity, and applications. This signals that security vendors are trying to seize the "AI gateway" position—future security controls will extend from protecting a company's existing IT to protecting the AI factories it is about to build.

Long-term Trend 4: Partner Relationships Shift from "Delivering Services" to "Co-Managing Operations"

  • Evan Reiser said that Abnormal AI's partner ecosystem has grown 40% over the past year, and in 2026 the company will increase its Market Development Fund (MDF) investment. Sophos CEO Joe Levy explained that AI will automate all non-differentiating tasks, so the value of channel partners will no longer lie in reselling and speed of quoting, but in "understanding customer business scenarios, orchestrating AI workflows, and providing ongoing policy optimization." In short, in 2026 channel partners must become co-owners of customers' "AI security posture."- Layer 1 — Usage Standards: Establish a clear “Enterprise AI Acceptable Use Policy,” requiring employees to verify data classification levels before invoking public GenAI; conduct security assessments for AI applications that can access enterprise data.
  • Layer 2 — Identity and Permissions: Treat all AI agents as non-human identities, bring them into the identity governance and administration (IGA) system, enforce least privilege and dynamic access control, and mandate MFA.
  • Layer 3 — Data Flow Map: Map how sensitive data enters, traverses, and exits AI models, and clarify which data must not leave the on-premises environment or private cloud.

Technical Level: Deploy “AI-Augmented Defense” and “AI-Protective Defense”

AI-Augmented Defense (defending with AI): Introduce AI-driven alert triage and automated response tools into the SOC, and train them to adapt to your own network and email environment. It is recommended to prioritize applying AI in the following three scenarios: 1. Automatic quarantine of phishing emails (based on behavior and context rather than static signatures); 2. Identity threat detection (anomalous permission changes and login behavior); 3. Automation of incident response playbooks (e.g., malware isolation and account disabling).

AI-Protective Defense (preventing AI abuse): Deploy deepfake detection, prompt injection protection, and “data leak prevention” plugins for large models. Focus coverage on video conferencing, voice customer service, and internal collaboration platforms.

Management Level: Incorporate AI Risk into the Enterprise Risk Management Framework

  • Have the CISO lead the formation of an “AI Security Committee,” with members including legal, data officers, and business leaders;
  • Conduct quarterly risk assessments of AI applications and track threat intelligence on AI attack trends;
  • Engage external auditors to review AI operational transparency, ensuring compliance with the EU AI Act, China’s MLPS 2.0 (if China operations are involved), and other regulatory requirements.

Supply Chain and Partner Level: Select Vendors with “Aligned AI Security Capabilities”

When evaluating security partners, enterprises should assess whether they have: 1. Threat hunting capabilities based on generative AI; 2. Protection solutions for SaaS and AI agents; 3. Explainable automated incident response records.

As Sophos recommends, partners must be able to explain “which steps are completed by machines and which steps are decided by humans,” to avoid the risk of erroneous operations caused by black-box automation.

SecurityPost Insight

Although each CEO’s statements on AI have their own emphases, a shared signal is clear: 2026 will be a turning point for cybersecurity—shifting from “defense primarily by humans” to “the coexistence of AI-driven defense and AI risk governance.” Attackers are using AI to lower the threshold for launching cybercrime to “virtually zero,” while defenders must use AI to raise security teams’ productivity to “superhuman levels.”For enterprises, the most important thing now is not to debate whether AI matters, but to embrace AI security in an institutionalized manner. There are three action priorities: First, immediately assemble a cross-functional team to inventory all GenAI tools and AI agents currently used in the business and map data flows; Second, upgrade the SOC platform to ensure it has AI-driven alert compression and incident correlation capabilities, rather than continuing to rely on manual rules; Third, incorporate AI security into the annual budget and board reports, because AI risk is no longer just a technology risk, but a business continuity and regulatory compliance risk.

The consensus among CEOs also reminds us that the security industry itself is undergoing an "AI-driven transformation." Security teams that can simultaneously navigate both the "AI-enabled attack surface" and "AI-enabled defense" curves will gain a significant competitive advantage in 2026. SecurityPost will continue to track technological innovation, attack cases, and best practices in the AI security field, providing independent, actionable in-depth references for enterprise security decision-makers.

Evidence route · securitypost

securitypost frames this note through Security Post publishes defensive cybersecurity intelligence for enterprise security leaders, covering thre.... Threat Briefing / Enterprise Security / AI & Cybersecurity explains the local editorial angle: Source links should be opened before the summary is reused. dates, names and status changes still need checking.

Source URL

  1. https://www.crn.com/news/security/2026/10-top-cybersecurity-ceos-on-ai-s-impact-in-2026Primary

Related articles

Back to channel