Cybersecurity Trends: McKinsey’s 2026 Insights on AI’s Impact and New Vulnerabilities

4

Every Tech Trend Is Now a Cyber Trend, McKinsey's 2026 Report Warns

AI has collapsed the defense window for cybersecurity teams — and the entire technology landscape is now an attack surface.

McKinsey's sixth annual Technology Trends Outlook, published September 15, 2026, delivers a sobering message for security leaders: cybersecurity is no longer a single trend to manage but the connective tissue running through every major technological shift of the decade. From autonomous labs to power grids and custom chips, the physical world has become the new digital frontier — and every inch of it needs defending.

The 143-page report, authored by Michael Chui, Roger Roberts, and Tanguy Catlin, identifies 14 technology trends grouped into three categories: the AI revolution, compute and connectivity frontiers, and cutting-edge engineering. But read it end to end and one conclusion is unavoidable. Security doesn't sit alongside the other 13 trends. In several cases it is the constraint that determines whether those trends deliver value at all.


The Defense Window Has Vanished

The report's most alarming finding is buried in its cross-cutting themes section: the cyber defense window is gone. For decades, defenders had days or even weeks between a vulnerability disclosure and a working exploit. McKinsey says AI has eliminated that buffer entirely.

Citing the Zero Day Clock, the report states that more than three-quarters of all vulnerabilities are now classified as zero-day — meaning an exploit exists by the time the flaw becomes public knowledge. IBM's 2026 X-Force Threat Intelligence Index reinforces that finding, showing exploitation of public-facing applications rose 44% in a single year, fueling a 49% increase in active ransomware and extortion groups.

The shift in attack shape is equally significant. McKinsey points to a sanctioned XBOW test in which an autonomous agent chained dozens of separate exploitation steps to escalate a single low-severity flaw into complete unauthorized file access. Traditional vulnerability scans are not built to catch that kind of chained-path attack — a gap that demands a fundamental rethink of how organizations approach technology risk management across the enterprise.

"As the time between vulnerability identification and exploitation vanishes," said Marc Sorel, McKinsey partner, "bug bounty programs, fraud-analytics-quality incident response, and forward-deployed, engineer-led delivery of just-in-time cybersecurity solutions for enterprise agentic deployments all become more important for providers and customers."

The counterintuitive conclusion McKinsey draws is worth sitting with: defenders may soon face not a visibility problem but a noise problem. The bottleneck shifts from detecting threats to separating real ones from a flood of automated signals. Organizations that fail to invest in signal-filtering and automated triage capabilities risk drowning their security teams in alerts — while the threats that matter slip through undetected.

Why Speed Now Defines the Security Posture

The compression of the defense window has a compounding effect that goes beyond individual vulnerabilities. When exploits arrive faster than patch cycles can respond, the entire model of reactive security collapses. Continuous runtime inspection, automated remediation pipelines, and real-time threat intelligence sharing are no longer optional enhancements — they are baseline requirements. Security teams that still operate on weekly or monthly patch schedules are, in practice, operating with no patch cycle at all.


Four AI-specific trends in the report carry direct security consequences — and each one introduces new vulnerabilities that most organizations are not yet equipped to handle.

Agentic Software Development

Agentic software development is the most financially dramatic of the new trends. Investment jumped from roughly $5 billion in 2025 to more than $61 billion in the first half of 2026. McKinsey estimates agentic development could unlock almost $1 trillion in value. The downside is stark: in 30% of companies productivity fell after teams adopted agentic tools, and the report warns AI is producing code faster than human systems can review, test, and deploy it securely — "filling enterprise systems with brittle code."

CI/CD skills show a talent-to-demand ratio of just 0.1x, the sharpest shortage McKinsey measured. The pipeline where security checks live is exactly where qualified people are scarcest — a structural vulnerability that no tooling investment alone can resolve.

"The real shift in software engineering is not that agents write code faster," said Martin Harrysson, McKinsey senior partner. "To capture the value from these tools, the software development life cycle operating model has to shift, including moving toward smaller, highly leveraged teams that supervise agents through execution."

For security leaders, this means that embedding security review into the new engineering operating model is not a process improvement — it is a prerequisite for capturing any of the promised productivity gains without catastrophic downstream exposure.

Agentic AI and the Identity Crisis

Agentic AI is scaling fast but unevenly. McKinsey finds 89% of organizations regularly use AI yet only 37% attribute any positive EBIT impact to it. Agents are adding cost faster than value: a single agentic workflow can consume five to 30 times more tokens than a standard chatbot query, and 93% of surveyed organizations report exceeding their AI budgets.

More troubling for security teams is the identity problem. Agents spawning nonhuman identities — API keys, service accounts, and machine credentials — now vastly outnumber human ones. Palo Alto Networks data cited in the report puts that ratio at roughly 100 to 1 in many organizations. Without a formal nonhuman identity governance framework, the attack surface expands silently with every new agent deployment.

"Today's challenge is operationalizing judgment," said Oana Cheta, McKinsey partner. "The defining question of the agentic era is not how autonomous agents can become but how much autonomy the enterprise can safely absorb."

Understanding how AI is reshaping cybersecurity threats and defenses is now a foundational literacy requirement for CISOs, not a specialist interest.

AI for Scientific Discovery

AI for scientific discovery introduces what may be the least obvious but most serious cyber risk in the report. McKinsey describes closed-loop systems in which models generate hypotheses, robots run physical experiments, and orchestration software feeds results back into the model. When scientists access lab functionality remotely through platforms like Emerald Cloud Lab, an orchestration compromise isn't just a data breach. It can mean tampered experiments or corrupted results that propagate directly into pharmaceutical pipelines — with consequences that extend far beyond the digital environment into physical harm.

This is a category of risk that sits well outside the traditional cybersecurity frame. The integrity of scientific output is now a cybersecurity problem.

AI Infrastructure: Where Physical and Digital Risk Converge

AI infrastructure is where the money concentrates and where physical and digital risk converge most acutely. Equity investment in AI infrastructure reached roughly $384 billion in the first half of 2026 alone. McKinsey projects data center capital expenditure could approach $7 trillion worldwide by 2030, with U.S. power demand tied to AI infrastructure rising from about 30 gigawatts in 2025 to more than 90 by 2030.

When data centers represent 14% of U.S. power demand, AI infrastructure and grid security become the same conversation. Supply chain exposure — from rare earth materials to custom silicon provenance — now sits alongside ransomware on the board agenda. The intersection of IoT and digital transformation makes this physical-digital convergence even more acute, as connected infrastructure multiplies the points of potential failure across energy, logistics, and manufacturing environments.

"As AI capability advances, the scaling constraint moves into the physical stack," said Pankaj Sachdeva, McKinsey senior partner. "For leaders, AI scale is now an infrastructure and resilience agenda."


What Security Leaders Must Do Now

McKinsey's dedicated cybersecurity chapter — renamed this year from "digital trust and cybersecurity" to "cybersecurity and trustworthy systems" — carries an adoption score of 4, meaning scaling is already in progress. Equity investment reached $77.5 billion in 2025. The report's thesis is clear: security is no longer only about keeping bad actors out. It is about building the trust layer required for agents, distributed cloud, and machine-to-machine interactions to operate verifiably.

"Cyber and trust are often framed as defensive disciplines, but they also determine how much value technology can create. That is why trust belongs in the value case, not just the risk register." — Roger Roberts, McKinsey report author

Five Priorities for CISOs in 2026 and Beyond

McKinsey identifies five practical priorities for CISOs navigating this landscape:

  • Eliminate patch cycles measured in weeks. Continuous runtime inspection is now the operational baseline, not an advanced capability.
  • Govern every nonhuman identity. Every agent must be registered, scoped, logged, and revocable in real time. The 100-to-1 ratio of machine to human credentials demands a dedicated identity governance program.
  • Integrate security into the engineering operating model. Security review must be designed into the new agentic development workflow rather than appended after the fact — particularly given the 0.1x CI/CD talent shortage.
  • Elevate physical risk to the board agenda. Power infrastructure, custom chips, rare earth supply chains, and model provenance now belong alongside ransomware in board-level risk conversations.
  • Make the value case alongside the risk case. With only 37% of companies seeing EBIT impact from AI, security that enables safe adoption is a direct business lever — not a cost center.

The Quantum Cryptography Timeline Is Compressing

On quantum cryptography, McKinsey notes that "harvest now, decrypt later" has moved from speculative research to active enterprise planning. NIST's finalized post-quantum standards now serve as the migration starting point for governments, banks, healthcare providers, and critical infrastructure operators. The Keyfactor and InfoSec Global acquisition McKinsey highlights signals that cryptographic inventory is becoming an urgent operational priority ahead of what the industry calls Q-Day.

For organizations that have not yet begun mapping their cryptographic dependencies, the window for orderly migration is narrowing. The NIST Post-Quantum Cryptography project provides the current standardization framework and serves as the definitive starting point for any enterprise migration plan.

Security as a Value Multiplier

The reframing McKinsey offers here is significant and underused. Security leaders who position their function purely as a risk management discipline are leaving a strategic argument on the table. When AI adoption is delivering positive EBIT impact in fewer than four in ten organizations, the ability to accelerate safe adoption — through governed agent deployment, secure development pipelines, and trustworthy system architecture — is a measurable business contribution.

The organizations most likely to close the AI value gap are those where security and technology strategy are built together, not sequenced.

The report's closing framing applies directly to security professionals: leaders who understand the patterns behind technological change will shape the future rather than react to it. In 2026, nearly every one of those patterns runs through security.


How Readers Can Use This Information

  • Security and IT leaders can use McKinsey's five CISO priorities as a board-ready framework for budget justification and organizational redesign heading into 2027 planning cycles.
  • Hiring managers and CISOs should treat McKinsey's talent shortage data — AI security skills at 0.3x and CI/CD at 0.1x talent-to-demand — as a roadmap for recruiting investment and internal upskilling programs.
  • Business executives outside security functions can use Roberts' framing — that trust determines how much value AI creates — to integrate cybersecurity into technology ROI conversations rather than treating it as a separate cost center.
You might also like