If your mental model of cyber risk was formed in 2023, it's now a museum piece. The last three years changed who attacks, how they get in, and who holds you accountable afterward. Here's what actually shifted — not the conference-keynote version, the operational one.
Attackers industrialized with AI
The tell-tale broken English of phishing is gone. Generative AI writes flawless, context-aware lures at scale — referencing your real vendors, your real projects, your CFO's actual writing style scraped from LinkedIn. Voice cloning turned the "urgent call from the CEO" from a movie plot into a Tuesday. The cost of running a convincing campaign collapsed, which means businesses that were once too small to bother with are now perfectly profitable targets.
Identity replaced malware as the front door
Attackers log in more than they break in. Stolen credentials, session-token theft, and MFA-fatigue prompts — bombarding a user with push notifications until they tap approve — now open more doors than exploits do. The defensive center of gravity moved accordingly: from the firewall to the identity system. If your MFA rollout stalled at "most people," that gap is the whole game. (More on this in our identity piece.)
Ransomware stopped being about encryption
The playbook flipped to exfiltration-first: steal the data quietly, then extort on the threat of publication — sometimes without encrypting anything at all. That broke the old comfort of "we have backups, so we're fine." Backups still matter enormously, but they no longer end the conversation when the leverage is your customer list on a leak site.
Insurers stopped taking your word for it
In 2023, a cyber policy renewal was a form. In 2026, it's an audit — MFA attestations, EDR coverage, tested backups, incident response plans, and increasingly your AI usage policy. Controls you can't evidence are controls you don't have, as far as the premium is concerned. We built a whole practice around renewal readiness because this shift caught so many companies flat-footed.
Compliance rolled downhill
Enterprise customers now push security requirements down their supply chain. A 40-person services firm gets a 200-question security review because its Fortune 500 client demands it of every vendor. Security posture became a sales document — a theme big enough that we wrote about it separately.
What this means operationally
The 2026 baseline for a growing company: phishing-resistant MFA on every account, endpoint detection with someone actually watching it, tested — not assumed — backups, an incident plan with names in it, and evidence for all of the above that survives an underwriter's review. That's not an enterprise wish list anymore; it's the table stakes your insurer and your biggest customer already assume. Our managed security practice exists to run exactly that baseline — and a 30-minute conversation will tell you which pieces you're missing.
