Cybersecurity 2026

USA Trends and Developments Contributed by: Brock Dahl, Beth George, Timothy Howard and Megan Kayo, Freshfields

weakest link in cybersecurity due to a number of fac - tors, such as: • limited cybersecurity awareness; • phishing; • social engineering; • weak password practices; and • insider threats. For example, a prevalent attack has involved threat actors tricking personnel to unlock access to their systems and documents, including by impersonating IT help desk workers and BPO providers and having such personnel disable multi-factor authentication on their accounts. In Addition to Established Security Controls, Organisations Should Implement Greater Security Measures and Leverage More Powerful Tools As noted above, more capable frontier AI models and agents are being used by threat actors to support their cyber-attack campaigns, but these tools can and should also be used by security teams to defend against such attacks. For example, AI agents can be used defensively to autonomously triage alerts, inves - tigate incidents, and even contain threats in real time, drastically reducing response times. Additionally, such tools can be used to: • ensure code is developed securely; • mitigate against vulnerable systems; or • identify vulnerabilities within organisations’ sys - tems so they can be remediated before threat actors find them. To defend against insider risk, such as the North Korea IT worker campaign, organisations should implement a zero-trust model by configuring systems so that no users or devices are trusted by default, regard - less of whether they are inside or outside the network perimeter. Additionally, organisations should ensure their security programs rigorously authenticate every user, including through phishing-resistant multi-fac - tor authentication, validation of the security of every device and granting only the minimum level of access (“least privilege”) required for a specific task.

Additionally, with attack dwell times shrinking to a handful of days, the speed and efficacy of an organi - sation’s incident response will be crucial to minimise damage and, in turn, mitigate regulatory scrutiny and litigation. Accordingly, having robust patch manage - ment procedures, patching early and often, as well as maintaining an incident response plan regularly prac - tised through tabletop exercises, would help combat ever-shortening attacker dwell times. These evolving threats could raise the bar for what regulators consider “reasonable” security. An organi - sation’s reliance on outdated security measures or security measures with known gaps could be viewed as maintaining a security program that is not reason - able. The prevalence of credential theft places a high - er legal expectation on the implementation of robust identity and access management controls, particularly phishing-resistant multi-factor authentication. The fight for cybersecurity has changed. It is faster, more complex, and more deeply intertwined with global conflict than ever before. It is no longer an IT problem to be solved, but a persistent business risk to be managed. The organisations that thrive will be those that understand this new reality and adopt a cul - ture of relentless adaptation, proactive governance, and genuine resilience.

477 CHAMBERS.COM

Powered by