There’s barely any part of the IT landscape that is untouched by artificial intelligence (AI) – and cybersecurity is arguably the most affected of all.
Cybercriminals are typically a step or two ahead of those opposing them, and AI has given them to tools to launch new and more deadly attacks faster and more efficiently than ever.
Fortunately, AI also allows for better and more preemptive protection, but the adversary has probably still got the upper hand.
In this new reality, cybersecurity tactics are pivoting from just defending against attacks to resilient systems that are able to recover quickly when – not if – they are breached.
AI innovation is moving at an unprecedented rate, and geopolitical tensions show no signs of easing.
Research analyst Forrester identifies these factors as two primary forces reshaping the threat landscape, placing additional strain on CISOs who are already stretched thin managing increasingly complex security programs.
Anthropic’s Claude Mythos Preview and Project Glasswing are early signals of how radically areas such as vulnerability discovery, remediation, and exploitation are about to change.
Simultaneously, the escalating US-Iran conflict has already translated into real world impact, driving a spike in disruptive cyberattacks; from the Stryker incident to Iranian-linked actors targeting PLCs across US critical infrastructure.
AI has been a consistent thread running through the last three editions of Forrester’s top threats report. Just three years ago, in 2023, when LLMs and ChatGPT first went mainstream, data was identified as the target for AI-driven attacks. By 2024, AI had been weaponized to enable narrative attacks via disinformation and deepfakes, with concerns rising over AI responses due to prompt engineering, injection attacks, or the increased risk of sensitive data spillage.
In 2024, risks associated with AI in the supply chain risk emerged, something that is still a real threat today. This is driven by adoption of open‑source models and frameworks such as those found in Hugging Face and GitHub.
Meanwhile deepfakes are maturing and evading detection. By last year, deepfakes had become easier to produce and were once again a major threat – along with tech exuberance over GenAI and the rise of GenAI-driven extortion.
Forrester’s Top Cybersecurity Threats In 2026 outlines the most critical risks organisations need to plan for.
This year’s report is based on trends and observations from the market at large and the threat landscape. We expect enterprises to experience one or more of the following in 2026:
- Near autonomous attacks from a nation-state. Easy access to AI models enables nation‑state threat actors to automate and scale more sophisticated exploitation at unprecedented speed. Recent cases, such as Anthropic’s report on the China-linked actor using Claude code to conduct a cyber-espionage campaign and, the disclosure by Google’s Threat Intelligence group about cases of attackers misusing Gemini highlight this trend. Hence, defenders must prepare to defend against autonomous attacks and adopt agentic security capabilities anchored in trust, cost, and utility.
- Concerns over agent threats. Personal agents “claw” their way into enterprises via browser hooks and inbox access, turning into shadow operators that access data and perform actions at machine speed outside of governance and visibility, leaving CISOs accountable for increased exposure with limited control. Security leaders must inventory agents, enable policies, actions, and tests while governing use through dedicated vendor platforms.
- Non-negotiable AI software supply chain. Building on its 2024 inclusion as a threat category, agentic AI turns things such as tools, models, skills into a sprawling and fast‑changing supply chain risk. Organizations must adopt a dedicated AI supply chain playbook that enables aspects such as inventorying all AI components, requiring AI‑BOM transparency, applying supply‑chain controls, and enforcing least‑agency for agents.
- Provenance and IAM risks of AI agents. AI agents force a shift from legacy IAM to agent‑specific identity, provenance, and access controls, with standards maturing rapidly and accelerating the adoption of commercial solutions. Organisations must control and govern internal, inbound, and outbound AI agent identities, access, and their activities by implementing agent‑specific IAM. For inbound agents, inspect inbound API requests and check provenance to manage access to MCP servers and tools; for more complex scenarios, use externalized AI agent authorisation tools.
- Digital sovereignty spans regions and tech stacks. Pushes for digital sovereignty can backfire and introduce nascent and fragmented tech stacks. This leaves security leaders vulnerable, especially in regulatory demands. Treat sovereignty-driven providers as a supply chain risk by performing stress tests, evaluating compensating controls, and mandating CISO sign‑off.
Gartner also points to AI as the most pressing threats that companies must counter, with attackers hold a significant advantage to successfully exploit weaknesses in targeted organisations.
These include deepfakes, AI application compromise, prompt injection, and software supply chains.
The Gartner 2026-2027 ThreatScape

Credit: Source: Gartner (June 2026)
The Gartner ThreatScape categorises the threats into six distinct areas along two axes (see the table: Gartner Threatscape).
- Differentiating threats based on the quality and volume of information (threat signal) available.
- Assessing threats based on organisational capabilities to manage them, and whether the threat actors hold an advantage.
“The introduction of security initiatives by frontier AI companies creates significant noise to an already noisy threat landscape,” says John Watts, vice-president analyst at Gartner. “Cybersecurity leaders must be able to find the threat signal in all the noise in order to respond to shifts in the threat landscape.”
Watts explains how CISOs can tackle these four critical threats:
AI application compromise
AI application compromise is in the critical threat section as attackers target the growing number of production-ready public-facing and internal enterprise AI tools. The attack surface has grown to include custom-built agents, third-party integrations, and employee-only applications often exposing sensitive data or credentials when controls are weak.
“Cybersecurity teams need to expand their programmes beyond traditional software protections by mapping new attack surfaces introduced by GenAI models or agentic tools,” says Watts. “Using Gartner’s trust and risk in security management (TRiSM) framework allows cybersecurity teams to know where to embed AI-specific threat mitigations directly into the AI application development process.”
Securing an AI application does not always mean starting from scratch. There are many AI security startups that offer broader and deeper capabilities as organisations mature and need more security around their use of AI. To address this threat, CISOs should apply secure development life cycle and threat modeling best practices to AI applications. They should also strengthen data security by improving data classification, adopt purpose-based access control (PBAC), and implement runtime monitoring.
Identity impersonation using deepfakes
The advent of GenAI has dramatically increased the volume, fidelity and accessibility of deepfake creation across voice, video and images, both as pre-recorded artifacts or generated in realtime. This has expanded the opportunity for attackers to impersonate identities across a range of attack surfaces. Deepfakes can be used to attack biometric authentication processes, can be combined with social engineering in realtime attacks on employees, and can be used to subvert recruitment processes.
“Attacker use of deepfakes continues to advance and is now commonplace to make fraud and phishing scams difficult to detect,” says Watts. “There is no one cybersecurity control that will protect you. Instead, organisations should use a combination of strengthening business processes, improving awareness, and deploying available deepfake detection technologies where possible.”
As a result, cybersecurity teams must look beyond deepfake detection and strengthen controls to protect the integrity of realtime communications, as well as biometric authentication and verification processes by considering the following:
- Build a robust mitigation strategy by recognising that deepfake detection alone is not sufficient to detect and prevent deepfake identity impersonation attacks. Instead, focus on layers of controls that will vary by use case.
- Protect biometric identity verification by focusing on presentation and injection attack detection in addition to contextual signals.
- Secure online meetings by implementing conditional access policies to enforce strong authentication for call participants and analysis of call metadata.
Software supply chain threats
“The evolution of GenAI offerings will only accelerate the trend of software supply chain attacks through vulnerabilities in open source software,” says Watts. “Organisations must work towards trusted component registries, hardening their CI/CD pipelines, and building strong operational anomaly detection and response capabilities.”
Cybersecurity teams should build comprehensive inventories of software assets while integrating strong controls at every stage of development. These measures help defend against emerging threats that target both traditional applications and modern AI-powered pipelines. With this in mind, CISOs should:
- Require SBOMs (and AIBOMs) from all vendors; assess every component for risk using tools with up-to-date threat intelligence before deployment.
- Use curated repositories for third-party code, container images and AI models; enforce branch protection on code repositories.
- Sign artifacts during builds; implement least-privilege access controls on build systems; continuously monitor runtime activity by agentic tools.
Prompt injection
Prompt injection is a cybersecurity threat targeting AI systems, especially those using large language models (LLMs). Attackers manipulate prompts to alter the model’s behaviour, causing it to leak sensitive information, perform unauthorised actions, or bypass controls. As organisations increasingly adopt GenAI, the risk of prompt injection expands, making it a critical issue for cybersecurity teams.
To effectively counter prompt injection threats, cybersecurity teams should implement a layered mitigation strategy. This involves AI security testing to proactively identify vulnerabilities, establishing strong system prompts to guide AI behaviour, and deploying AI runtime guardrails that monitor for and block suspicious activity. Key actions for CISOs include:
- Implement input validation and sanitisation to filter out potentially malicious prompts.
- Establish monitoring and alerting for abnormal AI behaviour that may indicate successful prompt injection.
- Integrate prompt injection testing into the AI system development lifecycle.
- Leverage the outcomes of the testing to improve runtime controls.
Actual intelligence needed before AI
In a Security Operations Centre (SOC), incidents rarely arrive neatly labelled. Analysts do not get a single perfect alert saying, “This is the problem. Here is the business impact. Here is the safest response.” What they usually see is something far messier: an unusual login, a file moving where it should not, a strange endpoint, an email that looks almost legitimate, or a user action that could be a simple mistake, or a sign that someone is exploiting pressure, trust, and timing.
This is where AI has become increasingly useful. It can connect signals faster, cut through alert noise, and support threat detection, investigation, and response. Given the pace of modern attacks, no serious security team can afford to ignore it.

Ray Hall
“I do not believe the future of cybersecurity is AI on its own. In a SOC, the better model is AI²: actual intelligence and artificial intelligence. Human judgement comes first. AI strengthens it,” says Ray Hall, SOC manager at DigitalShield.
That is because cybersecurity depends on interpretation. A tool can tell you something unusual has happened, but people still need to work out whether it is a genuine risk, what it means for the business, and how to respond without unnecessary disruption.
The AI conversation has become more urgent as both defenders and attackers adopt it. Hall believes that the pressure is sharper in South Africa because many businesses are modernising with uneven security maturity, stretched IT teams, and complex legacy environments. If the basics are not under control, AI can magnify the risk.
The concern is rarely the AI tool alone. More often, the deeper issue is the data environment behind it. Sensitive information may be spread across systems, access rights may have expanded, classification may be inconsistent, and permissions may no longer match what people need. If that environment is already exposed, AI can accelerate the problem.
But people are still a vital part of the cybersecurity picture.
AI can prioritise alerts, identify patterns and help analysts move faster. But Hall argues that analysts still need to apply judgement, test assumptions, understand business context and decide what happens next. After an incident, people still need to refine detection rules, tighten access controls, review configurations, update awareness training and strengthen response plans.
He says the AI conversation should start with the parts of security that too often receive too little attention. Sensitive data needs to be identified, access rights controlled, over-permissioned accounts reduced, and continuous monitoring maintained. Incident response plans also need testing in advance, with alerts reviewed by people who understand both the technical signal and the business consequence.
The outlook for SA

James Hickman
James Hickman, country manager for South Africa at Amazon Web Services (AWS), warns that South African organisations are probably not keeping the cybersecurity posture up to date as AI adoption accelerates.
“We have never seen a technology more quickly adopted than AI,” he point out.
“South Africa is building the plane while flying it – and AI adoption is outpacing the security posture needed to sustain it.
“The organisations closing this gap fastest are those treating security as a foundation, not a feature. As more businesses adopt AI, cybersecurity and cloud readiness need to become part of the conversation from the start.
“Responsible AI development means building security, transparency, and safety in from day one, not bolting it on afterwards.”
The risks to enterprises and SMEs alike cannot be trivialised. Hickman explains that cybercriminals are using AI to make attacks more sophisticated, convincing and difficult to detect.
“This includes phishing emails, fake voices, deepfakes, and automated scams that can trick people into sharing sensitive and personal information or transferring money.”
Fortunately much of the risk today can be mitigated with existing common security best practices – encrypting data, enforcing least privilege, isolating workloads in VPCs, and automating threat detection and incident response.
For SMEs, a bigger risk is the lack of skills to detect, manage, and prevent cyberthreats. “As a result, the attacks are outpacing the human capacity. It is critical for every SME to ensure their employees have basic digital skills training.”
Keeping the people up to date is vital to maintain customer’s trust, Hickman adds.
“Trust is not just a nice to have,” he says. “Leading organisations are moving beyond ‘trust but verify’ to ‘verify, then trust’. They are implementing multiple layers of validation: checking inputs for malicious content, verifying outputs against known facts and policies, and continuously monitoring for drift or unexpected behaviour.
“SMEs need to also transform the culture, not just the technology. One of the biggest inhibitors is change management. Organisations are structured around complex processes, with employees who manage those processes. Getting individuals to step back and reimagine those processes so they can be automated end-to-end or handled by agents requires intentional cultural transformation through skills training and development.
Ensuring the people are properly trained is more important than ever as attackers are shifting their focus away from networks and systems and towards the people who use them.
According to Cyberlogic, AI-driven social engineering and identity-based attacks have emerged as two of the most significant cyber threats facing businesses in 2026.
While organisations have traditionally focused on securing hardware, software, and infrastructure, the human factor has become a preferred target for cybercriminals looking for easier ways to gain access to sensitive information and systems.

Rowan Swanepoel
“Cybercriminals have realised that breaking through a company’s technology stack is often far more difficult than manipulating a person,” says Rowan Swanepoel, principal cyber security specialist at Cyberlogic.
“As a result, we’re seeing a significant increase in attacks that exploit human behaviour rather than technical vulnerabilities.”
AI is accelerating this trend: while it has become a valuable tool for improving productivity and business efficiency, it is also being used by malicious actors to automate and scale cyberattacks.
Attackers are increasingly using AI to create highly personalised phishing emails and voice phishing, or vishing campaigns. By leveraging information gathered from social media platforms and other publicly available sources, criminals can craft convincing messages that appear legitimate and relevant to their targets.
At the same time, deepfake technology has evolved rapidly, making it increasingly difficult for individuals to distinguish between a real person and an AI-generated voice.
“Deepfake audio has become remarkably convincing,” says Swanepoel. “We are reaching a point where many people don’t realise they are speaking to a machine. That creates significant risks for organisations, particularly where financial approvals, sensitive information, or executive communications are involved.”
Alongside AI-driven social engineering, identity-based attacks are becoming a growing concern. Rather than attempting to breach corporate networks directly, cybercriminals are targeting user identities through stolen credentials, session token theft, and multi-factor authentication (MFA) fatigue attacks.
In many cases, attackers gain access using credentials exposed in previous data breaches or by tricking users into clicking malicious links that capture authentication tokens. Stolen credentials are useful because password reuse is very common. For session token theft, users are often not even aware of anything – and this would even bypass any MFA requirement.
A growing concern within identity-based attacks is the rise of stolen credentials and session token theft. Cybercriminals regularly harvest usernames and passwords from previous data breaches and then use automated tools to test them across multiple platforms, relying on the fact that many users still reuse passwords.
Even more concerning is session token theft, where attackers steal the authentication token that proves a user has already logged in. This can occur when a user clicks on a malicious link, downloads malware, or interacts with a fraudulent website. Once in possession of a valid session token, attackers can often bypass passwords and even multi-factor authentication controls, effectively impersonating the user and gaining direct access to corporate systems, cloud applications, and sensitive business data.
“The modern attacker doesn’t necessarily need to break into your network anymore,” explains Swanepoel. “If they can steal or hijack your identity, they can often gain the same level of access with far less effort and far less chance of being detected.
Swanepoel contends that technology alone is no longer enough to defend against modern cyber threats.
“We need to empower employees to become part of the organisation’s cyber defence strategy. The goal is to transform staff from potential vulnerabilities into a human firewall. Every employee should understand how to recognise phishing attempts, avoid risky online behaviour, and know exactly what to do if they suspect a security incident.”
Security awareness training remains one of the most effective defences against social engineering and identity-based attacks. Training programmes should address common risks such as password reuse, recognising suspicious communications, incident reporting procedures, and adopting a zero-trust mindset where every request is treated with caution until verified.
Businesses are also encouraged to implement password managers that generate and store unique passwords for every account. Many modern password management solutions support multi-factor authentication and passkeys, which offer a more secure, passwordless approach to authentication.
Cyber accidents on the rise
South Africa’s current focus on external attacks by organised cybercriminals masks the fact that 95% of cybersecurity issues globally can be traced back to human error, according to sources that include the World Economic Forum.
Employees leaving Cloud databases unsecured and open to the public, misdirecting emails, losing unencrypted work devices and improperly sharing credentials are just some examples of why Surfshark’s latest quarterly analysis of global data breaches indicates that, to date, about 70 out of 100 South Africans have been affected by data breaches.
Adriaan Venter, CEO of Cube ICT Solutions, points out that, between April 2025 and March 2026, South Africa’s Information Regulator received 3 219 data breach notifications. In the 2024/25 financial year, 2 374 data breach notifications were received. Reported breaches were about 1 700 in 2023.
The Regulator has previously confirmed these leaks are largely-driven by simple human error and avoidable internal system failures, rather than external cyberattacks.
“It’s definitely not all bad news,” says Venter. “The mere fact that we now have an Information Regulator that organisations are required by law to notify of data breaches is very encouraging,” he explains.
More good news is that human error originating within South Africa is infinitely more fixable than the problem of external attacks by cybercriminals.
He says the solution starts with education. Conducting regular, mandatory security awareness training can help educate employees about handling data securely, and the risk of phishing.
Enforcing least privilege access means companies can restrict employee access to only the specific data and systems required for their roles to minimise data accidents.
Meanwhile, enforcing multi-factor authentication (MFA) ensures that, even if an employee mistakenly shares their password, a breach is prevented.