The Future of Cybersecurity Has Already Arrived
07 October
Every year, the cybersecurity industry produces another wave of predictions.
AI will transform attacks. Identity will replace the network perimeter. AI agents will create a new attack surface. Ransomware will become more targeted. Security teams will consolidate their technology.
There is certainly change ahead. But increasingly, many of these “predictions” aren’t predictions at all.
They’re things that are already happening.
The real challenge for organisations isn’t trying to predict what cybersecurity will look like in five years. It’s recognising how quickly today’s threats are evolving, understanding where their own exposure sits and making sure the security controls they already have are actually working.
AI isn’t the future of the attack. It’s already part of it.
AI is already changing the economics of cyber attacks.
Vulnerability research, reconnaissance, social engineering and the analysis of compromised environments can all be accelerated through AI. The important shift isn’t simply that attackers have another tool. It’s that activities that previously required considerable time, expertise and manual effort can increasingly be automated or accelerated.
That changes the equation for defenders.
The window between a vulnerability being discovered and being exploited can become smaller. A vulnerability management programme that relies on periodic scanning and a long list of CVEs isn’t necessarily enough.
Organisations need to understand which vulnerabilities matter in their environment, what they expose and how they could contribute to an attack path.
This is where cybersecurity needs to become more contextual.
The network isn’t dead. Neither is identity.
“Identity is the new perimeter” is a compelling phrase, but cybersecurity isn’t quite that simple.
Identity has become hugely important as organisations move towards cloud services, SaaS applications, remote working and distributed environments. But networks haven’t disappeared.
There are still data centres, branches, manufacturing environments, legacy systems, operational technology, wireless networks and applications that depend on network connectivity.
The perimeter hasn’t simply moved.
It has become more complicated.
Identity, endpoint, network, application and cloud security all form part of the same environment. Treating one as the new perimeter risks creating another security silo rather than solving the underlying problem.
The more useful question is not “Where is our perimeter?”
It is:
“What controls access to what, and can we see when that relationship becomes dangerous?”
AI agents are already creating the next attack surface
The same technology organisations are adopting to improve productivity is creating new security considerations.
AI agents are increasingly being connected to applications, APIs, internal information and business processes. That means they can potentially do much more than generate text.
And where something has access, it has the potential to become an attack path.
Prompt injection is already being investigated and exploited. Excessive permissions, insecure integrations, sensitive data exposure and poorly controlled agent actions are becoming genuine security concerns.
We shouldn’t wait for these to become mainstream headlines before addressing them.
The same principle applies to shadow AI. If employees can introduce powerful AI tools into an organisation faster than security teams can assess them, the attack surface is already changing.
The future attack surface isn’t something we need to wait for. We’re building it now.
Phishing will become more convincing. That doesn’t make people the weakest link.
AI-generated phishing removes some of the obvious warning signs we’ve historically relied upon.
Better writing. Better personalisation. Better context.
But the answer isn’t to expect employees to become increasingly sophisticated at identifying increasingly sophisticated attacks.
Security should assume that eventually, someone will click.
Phishing-resistant authentication, strong identity controls, effective email security and sensible access policies can limit what happens next.
That’s a broader lesson for cybersecurity: good security doesn’t depend on everyone making the right decision, every time.
Ransomware is only part of the story
Ransomware continues to receive significant attention, and rightly so. But building a security strategy around ransomware alone is increasingly narrow.
Threat actors don’t necessarily start an attack knowing exactly how it will end.
They may be looking for credentials, data, privileged access, intellectual property, financial information or a way into another organisation through a trusted relationship.
Ransomware may ultimately be the monetisation stage of a much longer compromise.
That means organisations should spend less time asking:
“Are we protected against ransomware?”
and more time asking:
“If an attacker gets in, what can they reach?”
That question takes us back to attack paths, privilege, segmentation, identity, endpoint controls and monitoring.
Third-party risk stopped being third-party risk a long time ago
The idea that a supplier’s security is somehow separate from your own is becoming increasingly difficult to defend.
Organisations are deeply interconnected with technology providers, managed service providers, software vendors, partners and customers.
If a third party has privileged access to your environment, processes your data or provides a critical service, their security is part of your risk.
This isn’t a new trend.
Organisations have been breached through their partners for years.
The challenge is making sure third-party risk is treated as part of the wider security architecture rather than a compliance exercise completed once a year.
More visibility doesn’t automatically mean better security
Continuous exposure management is increasingly positioned as the next evolution of cybersecurity.
There is genuine value in understanding your exposure continuously. But the industry needs to be careful not to confuse a new category name with a new security capability.
Organisations have been assessing vulnerabilities, testing security controls, monitoring networks and identifying attack paths for years.
The problem isn’t necessarily a lack of information.
It is knowing what matters and doing something about it.
The same applies to firewalls.
Modern firewalls already provide significant security intelligence and visibility. Yet many organisations aren’t necessarily using the full capabilities they’ve already invested in.
Before buying another platform, there is a valuable question to ask:
Are we making full use of what we already have?
Segmentation needs to evolve
Network segmentation still has a role to play, but simply separating networks into VLANs isn’t the answer to every modern security problem.
Modern environments require more granular control over how users, devices, applications and workloads communicate.
Microsegmentation and technologies such as Akamai Guardicore can provide a much more detailed understanding of those relationships.
The question should no longer simply be:
“Have we segmented the network?”
It should be:
“Why does this workload need to communicate with that workload in the first place?”
That shift from broad network boundaries to understanding actual communication and trust relationships is much more meaningful.
Threat hunting will become more accessible
Threat hunting isn’t new either.
What is changing is the ability to do it at scale.
LLMs and AI-assisted security tools can help analysts interrogate large volumes of telemetry, identify relationships and accelerate investigations.
That doesn’t remove the need for experienced security professionals. If anything, it makes their expertise more valuable.
The opportunity is to remove some of the manual work that prevents skilled people from focusing on the threats that genuinely require human judgement.
AI shouldn’t replace the hunter. It should give the hunter better tools.
And no, security teams probably won’t suddenly consolidate everything
Cybersecurity vendors will continue to tell us that organisations need fewer security products.
In reality, security environments are complicated because businesses are complicated.
Different technologies solve different problems. Organisations have different infrastructure, applications, compliance requirements, risk profiles and internal capabilities.
The objective shouldn’t necessarily be fewer products.
It should be less fragmentation.
Better integration. Better visibility. Better processes. Better use of existing technology.
A large security stack that works together can be considerably more effective than a small one that doesn’t.
So what actually changes?
Perhaps the most important shift isn’t a new technology or a new category.
It is the move away from thinking about cybersecurity as a collection of individual controls.
Attackers don’t see an EDR deployment, a firewall, an identity platform and a vulnerability scanner as separate products.
They see an environment.
They look for the weakest point, the easiest route and the relationships between systems.
Defenders need to do the same.
That means understanding how a vulnerability could become an entry point. How an identity could provide privilege. How a compromised endpoint could move laterally. How a supplier could create access. How an AI agent could expose information. How a firewall or VPN could become the route into the environment rather than the barrier keeping an attacker out.
Cybersecurity is becoming less about having the right products and more about understanding how everything connects.
And perhaps that’s the biggest prediction worth making.
The future of cybersecurity won’t be defined by the next acronym, platform or industry buzzword.
It will be defined by how well organisations understand their own environments, how quickly they can identify meaningful exposure and how effectively they can respond when something inevitably gets through.
The future isn’t coming. Much of it is already here. The question is whether we’re ready to deal with it.