AI, Regulations, and Ransomware: The State of Cybersecurity in 2026

Cyber experts explain how the threat landscape has changed, and what's still to come.

Key Takeaways

  • New regulations, AI, and ransomware attacks are key factors shaping cybersecurity in 2026.
  • Experts Michelle Faylo and Adam Darrah spoke exclusively to Tech.co about their assessment of 2026’s cybersecurity landscape so far, and gave advice for small businesses today.

In 2026, technology is advancing rapidly, and the cybersecurity landscape is shifting in response. In some sense, we are safer than we once were. And in another, threats are beginning to take on new shapes.

This doesn’t only mean AI, either. A wealth of new state-level regulations at the beginning of the year has created a more complex environment to navigate. And, despite newer threats emerging, experts are still quick to point out the danger of ransomware attacks.

I spoke to cyber experts Adam Darrah, Vice President of Intelligence at ZeroFox, and Michelle Faylo, US Cyber and Technology Leader at Lockton Companies, to get their perspectives on the current state of cybersecurity at this point in 2026.

A Changing Regulatory Environment for 2026

January 2026 saw the introduction of several state-level cybersecurity regulations. Fresh into the new year on January 1st, Indiana, Kentucky, and Rhode Island became the newest states with comprehensive privacy laws.

Likewise, California tightened data breach reporting deadlines on the same day and introduced new requirements for automated decision-making technology, risk assessments, and cybersecurity audits. The world also awaits the EU AI act, which comes into full effect in early August.

 

About Tech.co Video Thumbnail Showing Lead Writer Conor Cawley Smiling Next to Tech.co LogoThis just in! View
the top business tech deals for 2026 👨‍💻
See the list button

New regulations are a positive response to the changing threat landscape, but it also means businesses should be aware of any compliance changes and adjust their processes accordingly.

“Practically, this is pushing businesses to formalize AI governance policies, conduct documented risk assessments, and tighten breach notification procedures, and it’s increasingly a factor in cyber insurance applications, since carriers want to see that clients have a handle on this patchwork rather than treating compliance as an afterthought,” says Michelle Faylo, US Cyber and Technology Leader at Lockton Companies.

AI is Making Attacks Faster, But is Also Keeping Businesses Safer

AI within cybersecurity is a “two-sided story,” Faylo says. As a defensive tool to protect businesses, AI has shown promise. “Security teams are deploying AI for faster anomaly detection, automated response, and predictive threat modeling.”

However, this has meant AI governance “is becoming a security issue in its own right,” Faylo continues. “Organizations need to treat their own AI systems and AI agents as a new class of digital identity within its own attack surface… From an insurance standpoint, carriers are starting to ask how organizations are securing and governing their own AI tools, not just how they’re defending against AI enabled attacks.”

On the other hand, AI has significantly increased the scalability and speed that criminals can mount an attack. Attacks have become “more intelligent and adaptive rather than opportunistic,” Faylo says. Ultimately, AI is helping both businesses and criminals alike.

Adam Darrah, Vice President of Intelligence at ZeroFox, explains a similar development as AI has become more of an offensive tool within cyberattacks. “AI is changing how cyber operations are built and delivered, increasing the speed and sophistication of attacks,” he says.

In particular, “threat actors can automate the discovery, weaponization, and delivery process at a scale we haven’t seen before. Accessible GenAI tools are also lowering the barrier to entry for attacks, making it easier to generate targeted phishing lures and convincing synthetic media for impersonation and social engineering.

“AI is making established threat actor techniques faster, more adaptive, and more scalable,” Darrah says.

Ransomware Attacks Remain a Critical Small Business Threat

Yes, AI is concerning, and but both Faylo and Darrah pointed out the danger tried-and-tested ransomware attacks still pose to today’s businesses.

Faylo says “ransomware remains the costliest category once it hits,” and pointed out the specific dangers for small businesses, because of “the vast majority of small business breaches involving a ransomware component.”

Similarly, Darrah says: “Ransomware-as-a-service and other criminal marketplaces are also lowering the barrier to entry for attackers while allowing more established groups to operate faster and at a larger scale. 

“Organizations should expect these groups to continue adapting quickly. Like startups, they experiment with new techniques, improve their tooling, and pivot to new approaches as their operations are disrupted.”

How Businesses Can Navigate 2026, and Beyond

Navigating today’s landscape can be disorienting, and Darrah acknowledges this. “We are living in strange times where reports of nation-state meddling, ever changing privacy laws, advances in technology such as AI, data extortions, and data breaches are constant.”

His advice for small businesses is to prioritize strategically. Not everything is equally important, and he recalls the earlier advice of a colleague when he says, “if everything is a priority, nothing is a priority.” Somewhat cliche, he adds, but it resonated with him.

In practice, Darrah’s advice is to follow the basics, particularly if you’re tight for security budget. “We live in a world that values new and novel, but cyber criminals exploit the basics of network security hygiene and social engineering awareness.”

Faylo, on the other hand, recommends similar. “For budget-constrained clients, we generally advise them to fix the ‘insurability gaps’ first.’ These are multi-factor authentication, endpoint detection and response, and ensuring you have restorable and tested system backups.

“The common thread is that these are governance and process failures, not just technology gaps, which is why we push clients toward treating cyber resilience as a leadership level priority, not something delegated entirely to IT.”

It’s no surprise that the more of your company exposed to best cybersecurity practice, the stronger your company will be.

Did you find this article helpful? Click on one of the following buttons
We're so happy you liked! Get more delivered to your inbox just like it.

We're sorry this article didn't help you today – we welcome feedback, so if there's any way you feel we could improve our content, please email us at contact@tech.co

Written by:
Nicole is Tech.co's News Editor, reporting on the latest technology news and curating The AI Strat newsletter. After studying English Literature and Creative Writing, they worked on local newspapers and online publications, including Outlander Magazine. Previously, they covered tech products and news at Expert Reviews. Outside of Tech.co, they enjoy sports and video games.
Explore More See all news
Back to top