A SecurityWeek feature from September 2026 identifies four evolving cyber threats that security programmes must plan for: artificial intelligence, supply-chain and third-party exposure, quantum computing, and geopolitical conflict. The piece argues that attackers and defenders are both leveraging AI, which accelerates attack stages such as reconnaissance and vulnerability scanning and can produce highly convincing phishing, deepfakes, and synthetic identities.
It cites an example from May 2026 where AI-generated deepfakes were used to impersonate a government official in a Zoom meeting to commit fraud, illustrating the real-world potential of AI-enabled manipulation.
The article emphasises the risk posed by third parties, vendors and unmanaged APIs, noting that backdoors in vendor software can operate inside an organisation’s trusted environment and thus spread across networks. It highlights the Australian Mackay Sugar incident as an example of how a breach can ripple through a supply chain, shutting mills and pausing farm operations.
In the quantum section, the piece warns of the Harvest Now, Decrypt Later problem: although quantum-era breakage of common public-key schemes is not imminent, migration to post-quantum cryptography should begin now, given five to seven years for small firms and longer for large organisations to complete a full replacement across systems and dependencies.
Geopolitics is described as a persistent driver of cyber risk, with nation-state activity targeting energy, transport and critical infrastructure, alongside disinformation and hybrid campaigns. The recommended response calls for resilience as a core, continuously enacted capability—integrating technology, governance, operations and people, with regular crisis exercises, enhanced threat intelligence, and stronger collaboration with external agencies. The piece closes by stressing that no single tool will neutralise these threats; sustained, organisation-wide resilience remains essential.