As part of an online miniseries, Mick Leach, Field CISO and Patricia Titus. Field CISO at Abnormal AI discusses their industry predictions for 2026.
Can you tell me a bit about yourself, your job role and how long you have been at the company?
Leach: My name is Mick Leach and I am a Field CISO at Abnormal AI, where I currently lead a cross-functional team of cyber security professionals performing cloud security architecture, security engineering and security operations.
I’ve been with Abnormal for about four and a half years but I previously held the role of Head of Security Operations.
Titus: I am a Field Chief Information Security Officer at Abnormal AI, where I advise customers on resilience, risk management and the future of AI-driven security.
I joined the Abnormal AI team in April this year and have over 25 years of experience in leading security organisations across public and private sectors, including financial services, technology and government.
I’m really passionate about advancing women in cybersecurity, so I mentor future leaders and serve on the Executive Board of the Girl Scouts of the Commonwealth of Virginia and the Board of Advisors for the Executive Women’s Forum.
What are some of the key trends and predictions you think we will see in the security industry in 2026?
Leach: By 2026, we’re going to stop pretending we can spot deepfakes. The technology will become too good for the old tricks such as asking them to turn their head and looking for visual glitches.
Once it’s no longer possible to trust your eyes or ears, we’re going to be left with something much older and much simpler: trust based on shared secrets.
Next year security against advanced deepfakes will rely on reintroducing techniques that we haven’t used since the 90s and before.
This will consist of pre-agreed passphrases between senior leaders, callback rules for financial approvals and second-factor identity checks that happen over separate channels.
No, it’s not flashy or high-tech, in fact it’s almost embarrassingly basic. But that’s the point. When the attacker’s tool is clever, the defence has to be boring.
Deepfakes won’t be defeated by detection but by procedures that AI simply can’t fake.
Titus: The rise of AI agents interacting with each other and with humans, will create a highly attractive and potent new attack surface for prompt injection and advanced social engineering.
As employees increasingly use trusted internal AI agents for drafting and managing emails, attackers will use their own AI agents to jailbreak and manipulate communications and insert themselves into discussions.
This agent vs. agent battle will exploit the high level of trust employees place in their seemingly secure corporate AI environment, leading to an increase in people unknowingly giving up “crown jewels” like bank routing information or granting unfettered access through credential harvesting.
Security awareness training programs need to evolve with these shifting attacker tactics and educate employees on each agent’s specific use case and what normal behaviour of that agent is supposed to look like, so that employees can recognise and report when an agent’s actions deviate from the established guardrails.
What is one piece of advice you would give organisations and professionals as they head into 2026?
Leach: Next year will be the breaking point for traditional security awareness training.
The old doctrine, check the sender, look for spelling mistakes, beware urgent language, will finally be recognised as outdated.
By 2026, attacks won’t start with a suspicious link, they’ll start with a conversation on WhatsApp, Instagram and LinkedIn.
The attacker’s goal won’t be to fool your logic but to play with your emotions through curiosity, fear, helpfulness and trust.
If they can shift your emotional state, they can shift your behaviour. As a result, security awareness training will have to teach something entirely different.
That being how to notice when someone is trying to influence your emotional response, how to slow down when that happens and how to verify the request through a different communication channel before acting.
With identity as the new perimeter, the easiest way to break it is to talk a human into opening the door themselves.
Titus: Traditional red flags of social engineering – such as bad grammar, suspicious links and awkward phrasing -are becoming obsolete due to AI’s ability to craft highly realistic messages.
Pivoting from these typical tell-tale signs, attackers will leverage AI to adopt an offensive behavioural analytics approach, training AI agents to incorporate cultural norms, courier preferences and communication habits of targets to make social engineering attacks virtually indistinguishable from legitimate messages.
This becomes even more concerning when you consider that 51% of security teams currently lack visibility into abnormal communication patterns, according to Abnormal’s Misdirected Email Prevention Survey.
In 2026, organisations will need to move beyond simply educating employees about threats and focus more on AI-native analysis of telemetry data – like sender reputation, geolocation and communication patterns – before a malicious email ever reaches an inbox.

