The Next 10 Years of Cybersecurity: A Forecast to 2036
A hype-resistant forecast of cybersecurity to 2036: AI on both sides, the death of passwords, post-quantum migration, deepfakes, and the human factor.
Cybersecurity forecasts tend to swing between two errors: breathless "AI changes everything" hype and jaded "nothing ever really changes" cynicism. The truth sits in between. The fundamentals (phishing, patching, identity, the human) barely move, while the tooling and scale on both sides change enormously. This forecast separates the two.
The method: extrapolate the trends that have held (automation of both attack and defense, the slow death of passwords, regulation tightening), name the bottlenecks, and mark bets versus guesses.
This guide contains affiliate links to security tools we recommend, and if you buy through them we may earn a commission at no extra cost to you. Our rankings are editorially independent and based on testing and public audits.
Key predictions
- AI arms both sides. Attackers get cheap, scalable, fluent, personalized social engineering and faster vulnerability discovery. Defenders get faster detection, triage, and response. The edge goes to whoever automates better, and in the near term that is often the attacker, because offense is easier to automate than defense.
- Passwords die slowly. Passkeys and phishing-resistant authentication become the default for anything that matters. The password becomes the legacy fallback rather than the front door.
- The post-quantum migration becomes real, urgent work. "Harvest now, decrypt later" means encrypted data stolen today can be broken when quantum computers mature, so the migration to post-quantum cryptography starts well before the threat is live.
- Deepfakes break identity verification. Voice and video impersonation move fraud beyond email. "I saw and heard them say it" stops being proof.
- Ransomware professionalizes further. It grows less spray-and-pray and more targeted, data-extortion-driven, and increasingly aimed at supply chains and managed-service providers for leverage.
- Privacy regulation tightens globally, and compliance becomes a baseline cost of doing business rather than an afterthought.
- The human stays the weakest link, and the most cost-effective thing you can still do is the boring basics.
Predictions at a glance
| Prediction | Timeframe | Confidence | Why it's likely |
|---|---|---|---|
| AI arms both attackers and defenders | 2026-2028 | High | Offense is easier to automate than defense, so cheap, fluent phishing and voice clones scale first while defenders catch up on triage |
| Passkeys become default; passwords die slowly | 2026-2028 | High | Phishing-resistant auth is already shipping in banks, email, and major platforms; the password becomes the legacy fallback rather than the front door |
| Post-quantum migration becomes urgent work | 2028-2032 | Medium | Standards exist, but rolling them across protocols and certificates is years of engineering, and harvest now, decrypt later forces it to start before the threat is live |
| Deepfake identity fraud goes mainstream | 2028-2032 | Medium | Voice and video impersonation turns business-email-compromise into the "CEO on a video call" attack; "I saw and heard them say it" stops being proof |
| Ransomware professionalizes further | 2026-2028 | High | Crews keep moving from spray-and-pray to targeted, data-extortion-driven attacks aimed at supply chains and managed-service providers for leverage |
| Privacy regulation tightens globally | 2032-2036 | Medium | Brokers and breaches keep feeding targeted attacks, pushing data minimization and removal from niche to baseline cost of doing business |
| The human stays the weakest link | 2032-2036 | High | The same failures (reused passwords, tricked users, unpatched systems) cause most breaches decade after decade, and new tech changes the scale rather than the mechanism |
How to read a security forecast
Two rules. First, separate capability from incentive. Attackers do what is cheap and profitable rather than what is most sophisticated, so the threats that scale are the ones that pay. Second, the fundamentals are durable. The same failures (unpatched systems, reused passwords, tricked humans, exposed secrets) cause most breaches decade after decade. New tech changes the scale and polish of attacks far more than the underlying mechanism.
The near term: 2026-2028
AI-powered attacks scale (high confidence). The first wave is mundane attacks made cheap and flawless rather than sci-fi autonomous hacking. Phishing with no grammar tells, personalized to you from scraped data, voice clones of your boss, and convincing fake support sites at scale (see AI phishing attacks and AI voice cloning scams). The defense is unglamorous and effective: phishing-resistant auth and verification habits that go beyond spotting the typo.
Passkeys cross over (high confidence). Phishing-resistant authentication becomes the default for banks, email, and major platforms. If you are still relying on passwords alone, this is the decade you stop. A password manager plus passkeys and hardware security keys becomes the normal setup rather than the paranoid one.
Defenders automate triage (high confidence). AI does the first pass on alerts, log analysis, and incident triage, handling the volume that drowns analysts rather than replacing them. The teams that adopt this well pull ahead, and the ones that do not stay buried in alerts.
The mid term: 2028-2032
The post-quantum migration turns from paper into a project (medium-high confidence). Standards exist; the work is rolling them out across protocols, certificates, and systems before quantum computers can break today's public-key crypto. "Harvest now, decrypt later" makes long-lived secrets the priority. This is years of unglamorous engineering, and it starts in earnest this window.
Deepfake identity fraud goes mainstream (medium-high confidence). Voice and video impersonation become a standard tool for business-email-compromise-style fraud, the "CEO on a video call authorizing a wire" attack. Verification shifts from "does it look and sound real" to out-of-band confirmation and cryptographic identity (see deepfake detection). Trust in raw audio and video erodes.
Supply-chain and identity become the main battlegrounds (high confidence). Attackers keep moving up the leverage chain, compromising one vendor, software dependency, or identity provider to reach thousands of targets. Defense centers on zero-trust, identity hygiene, and dependency scrutiny rather than perimeter walls.
Privacy and data-removal become consumer-normal (medium confidence). As data brokers and breaches keep feeding targeted attacks, data removal services and identity-theft protection move from niche to mainstream, and regulation pushes companies toward data minimization.
The long term: 2032-2036
Plausible: authentication is mostly passwordless and phishing-resistant; post-quantum crypto is widely deployed; AI is a standard layer in every security team's stack and every attacker's toolkit; identity (human and machine) is the central security problem; and verification of "is this real, is this who they claim" is a routine, cryptographic step rather than a judgment call. Security is more automated, more identity-centric, and, because attackers automate too, not obviously "safer."
Genuinely uncertain: whether AI net-favors attackers or defenders over the full decade; how disruptive quantum actually becomes and when; and whether regulation meaningfully raises the baseline or just adds paperwork. Treat confident claims here skeptically.
What will not happen
- AI won't make security a solved problem. It raises the floor and the ceiling on both sides; the contest continues.
- The human won't stop being the weakest link. Most breaches will still trace back to a tricked person, a reused credential, or an unpatched system rather than exotic exploits.
- Passwords won't vanish completely. They will linger for years as legacy fallbacks; the win is making them no longer the primary defense.
- You won't be safe by buying one product. Security stays a practice, and basics done consistently beat any single tool.
The bets, with falsifiers
A forecast is only honest if it says what would prove it wrong. Each bet below comes with a falsifier, the concrete outcome that would show the prediction failed, and a date to check it. If the falsifier happens, the bet was wrong, and you should trust the rest of this page less.
| Bet | Falsifier (what proves it wrong) | Check by |
|---|---|---|
| AI tilts the early edge to attackers | AI-assisted intrusion rates fall as defenders automate faster than offense | 2028 |
| Passkeys become the default primary auth | Major banks, email, and platforms still enroll new users into passwords first | 2028 |
| Post-quantum migration becomes real engineering work | No major protocol or certificate ecosystem ships post-quantum crypto and harvest-now-decrypt-later stays purely theoretical | 2030 |
| Deepfake identity fraud goes mainstream | Voice and video impersonation stays rare in routine fraud reports rather than staged demos | 2030 |
| Ransomware professionalizes into targeted extortion | Crews revert to broad file-encryption spray-and-pray and the data-extortion share falls | 2028 |
| Privacy regulation tightens with enforcement teeth | Data-minimization rules stay unenforced and data-removal stays a niche service | 2034 |
| The human stays the weakest link | Most major breaches trace to novel technical exploits rather than phished credentials, reused passwords, or unpatched systems | 2034 |
Read the middle column first. If none of those falsifiers land by their dates, the forecast held. If several do, the trends bent in a way this page did not anticipate, and that is the useful kind of wrong: it tells you the shape of the threat changed.
What it means for you
The durable move is the same as it's always been, just more urgent: do the boring basics, consistently. A real password manager with unique passwords everywhere, phishing-resistant hardware keys on your critical accounts, a reputable VPN on untrusted networks, current antivirus/EDR, and a healthy skepticism toward anything urgent, including a familiar voice or face asking you to act fast. Those defeat the overwhelming majority of attacks, AI-powered or not.
And update your mental model for the deepfake era: verify out-of-band. If "your CEO" calls asking for a wire, hang up and call back on a known number. The next decade's attacks are more convincing, and the defense is a habit rather than a gadget.
Related flagships: the foundations behind all of this (the Security Canon) and how to actually skill up (Best Cybersecurity Certifications & Courses).
The mechanics of the AI arms race
The phrase "AI arms both sides" hides a real asymmetry worth spelling out, because it explains why the early advantage tilts toward attackers. Offense is a search problem with cheap, forgiving feedback. An attacker sends a thousand messages and needs one to land. A generated phishing lure that reads fluently, references a real project, and arrives at a plausible moment costs almost nothing to produce at scale, and every failed attempt is free. Defense is a classification problem with expensive, unforgiving feedback. A defender has to be right on nearly every message, every login, and every alert, and a single miss can be the breach. Automating a task where you only need to succeed occasionally is easier than automating a task where you must almost never fail.
That asymmetry shapes the near-term reality. The first wave of AI-assisted attacks is ordinary techniques made cheaper, faster, and more polished rather than autonomous machines discovering novel exploits: phishing without the grammar tells that used to give it away, voice that sounds like a specific person, reconnaissance that reads a target's public footprint in seconds, and code that helps a mid-skill operator move faster. On the defensive side, the wins are real but quieter: triaging the flood of alerts, summarizing incidents, drafting detection logic, and surfacing the signal analysts would otherwise miss under volume. The teams that fold these into their workflow pull ahead of the ones that stay buried, and over the full decade the gap between capable and uneven defenders may matter more than any single tool.
The durable defensive lesson is that AI raises the polish of attacks far more than it changes their mechanism. The message is more convincing, the pretext better researched, the timing sharper. The underlying move is still a person being persuaded to click, approve, or pay. That is why the defenses that work against ordinary phishing, phishing-resistant authentication and out-of-band verification of anything urgent, keep working against the AI-assisted version. They defend against the mechanism, and the mechanism is what stays constant.
What the post-quantum migration actually involves
"Post-quantum migration" sounds like flipping a switch, and the reason it is years of work is worth understanding. Today's public-key cryptography, the math that protects web traffic, signs software, and secures key exchange, rests on problems that a large quantum computer could solve. Standards bodies have selected replacement algorithms designed to resist that, so the algorithms exist. The hard part is everything downstream of the algorithm.
Cryptography is embedded in a deep stack: protocols, libraries, certificates, hardware modules, embedded devices, and long-lived systems that nobody wants to touch. Rolling a new algorithm through all of that means updating protocol implementations, reissuing certificates, testing interoperability between old and new systems, and finding the places where a hardcoded assumption about key sizes or algorithms will break. Some of it lives in devices with long service lives and slow update cycles. An inventory of where cryptography is used, often incomplete in large organizations, is itself a significant project before any migration can start.
The urgency comes from a strategy called "harvest now, decrypt later." An attacker does not need a quantum computer today to benefit from one tomorrow. They can steal encrypted data now and store it until the capability matures, then decrypt it retroactively. Any secret with a long shelf life, medical records, state secrets, intellectual property, anything that still matters in a decade, is exposed the moment it is exfiltrated, even if the decryption comes years later. That is why the migration has to begin well before quantum computers are a live threat, prioritizing long-lived secrets first. The realistic timeline is gradual and uneven, and it starts in earnest this decade for organizations that hold data worth stealing on a long horizon.
Signals that tell you which way it is going
A forecast is more useful when you can check it against reality as it unfolds. These are the concrete signals worth tracking, each tied to a prediction above.
Passkey adoption at the platforms you use. When your bank, your email provider, and your workplace make passkeys the default enrollment path rather than an advanced option, the password's demotion is happening. The tell is defaults, since a feature buried in settings changes little and a default changes everything.
Deepfakes appearing in routine fraud rather than staged demos. The mid-term prediction is that voice and video impersonation become standard tools in ordinary business fraud. The signal is when finance teams start reporting convincing voice or video requests, and when "verify out-of-band" becomes a written policy rather than advice.
Ransomware crews shifting to pure extortion. The move from encrypting files to stealing and threatening to leak data, and up the supply chain toward vendors and service providers, is a sign the professionalization prediction is holding. Watch whether incidents center on data theft leverage rather than file encryption.
Regulators pushing data minimization. The long-term privacy prediction shows up as rules that penalize holding data you do not need, and as data-removal moving from niche service to mainstream expectation. The signal is enforcement with teeth rather than paperwork.
The breach post-mortems staying boring. The most durable prediction, that the human stays the weakest link, is confirmed every time a major incident traces back to a phished credential, a reused password, or an unpatched system rather than an exotic exploit. If post-mortems keep reading the same way they always have, the fundamentals are still deciding outcomes.
Common misconceptions about the forecast
"AI will make security a solved problem." It raises the floor and the ceiling on both sides at once. Defenders get faster, attackers get cheaper, and the contest continues at a higher tempo. No tool ends the game.
"Quantum computers will break encryption next year, so today's crypto is already useless." The threat is real and worth preparing for, and it is also not imminent for most systems. The rational response is to start migrating long-lived secrets now because of harvest-now-decrypt-later, while treating breathless "encryption is dead tomorrow" claims with skepticism.
"Passwords will disappear." They will linger for years as legacy fallbacks in older systems and edge cases. The realistic win is making them no longer the primary defense, short of eliminating them entirely.
"Buying the right product will keep me safe." Security stays a practice. The basics done consistently, unique credentials, phishing-resistant authentication, patching, and skepticism toward urgency, beat any single purchase. A product helps only inside a habit.
"Deepfakes mean you can trust nothing." The useful conclusion is narrower: raw audio and video stop being proof of identity on their own. The response is a verification step, calling back on a known number, confirming through a separate channel, short of abandoning trust altogether.
What stays the same and what changes
The clearest way to hold the whole forecast in mind is to separate the durable fundamentals from the shifting tooling. The mechanisms barely move. The scale, polish, and speed change enormously.
| Dimension | Stays the same through 2036 | Changes through 2036 |
|---|---|---|
| Attack entry point | Phishing, stolen credentials, unpatched systems | Lures become flawless, personalized, and multi-channel |
| The weak link | The human being persuaded to act | The persuasion gets more convincing and harder to spot |
| Identity | Proving who you are remains the core problem | Passwords give way to passkeys and cryptographic identity |
| Cryptography | The need to keep secrets secret | The algorithms migrate to post-quantum designs |
| Defender workload | Alerts, triage, patching, response | AI absorbs volume and speeds the first pass |
| Winning move | Doing the boring basics consistently | The basics get more urgent as attacks automate |
Read down the left column and you have the reason a hype-resistant forecast is possible at all. The things that decide most outcomes are the things that have decided them for years. Read down the right column and you have the reason complacency is dangerous. The same attacks arrive faster, cleaner, and at greater scale, so the cost of neglecting the fundamentals rises even though the fundamentals themselves do not change.
FAQ
Will AI make cybersecurity better or worse? Both, and which wins depends on who automates better. AI hands attackers cheap, scalable, flawless social engineering and faster vulnerability discovery, while handing defenders faster detection and triage. In the near term offense often gains more because it is easier to automate, and well-resourced defenders close the gap. The fundamentals (patching, identity, the human) still decide most outcomes.
Are passwords going away? Slowly, yes. Passkeys and phishing-resistant authentication are becoming the default for important accounts, and within the decade passwords become the legacy fallback rather than the primary defense. They will not vanish entirely, and relying on a password alone will look as careless as having no lock at all. Use a password manager and adopt passkeys and hardware keys now.
What is the biggest emerging cyber threat? Two stand out: AI-scaled social engineering (perfect phishing, voice and video deepfakes that defeat "it looked real" verification) and supply-chain attacks that compromise one vendor to reach thousands. Both exploit trust as much as technology, which is why out-of-band verification and identity hygiene matter more than any single product.
What is "harvest now, decrypt later"? It is the strategy of stealing encrypted data today and storing it until quantum computers are powerful enough to break today's encryption. It is why the migration to post-quantum cryptography is urgent now for anything with a long secret lifespan, because the data being exfiltrated today could be readable in a decade.
What's the single best thing I can do for my security in the next decade? Adopt phishing-resistant authentication (a password manager plus passkeys and hardware keys) and build the habit of verifying urgent requests out-of-band. Those two cover the largest share of real-world attacks, credential theft and social engineering, far more cost-effectively than any expensive product.
Should a small business worry about quantum computing yet? For most small businesses the immediate priorities stay the same: phishing-resistant authentication, patching, backups, and skepticism toward urgent payment requests. Quantum matters now mainly if you hold secrets that must stay confidential for a decade or more, because those are exposed to harvest-now-decrypt-later. For everyone else the practical step is to prefer vendors and platforms that are already planning their post-quantum migration, and let them carry the heavy engineering.
Will AI replace security analysts? No, it changes what they spend time on. AI handles the volume, the first pass on alerts, log summarization, and routine triage, which frees analysts for judgment, investigation, and the decisions that need context a model does not have. The teams that adopt it well cover more ground with the same people, and the human judgment at the top of the stack stays essential.
How should I think about supply-chain and vendor risk over the next decade? Treat it as one of the main battlegrounds. Attackers keep moving up the leverage chain, compromising a single vendor, dependency, or identity provider to reach many targets at once. The defensive posture is identity hygiene, scrutiny of the dependencies and third-party scripts you load, and an assumption that any vendor with access is part of your attack surface. Zero-trust thinking, verifying rather than assuming trust, applies to vendors as much as to users.
Related guides
Related guides
- Deepfake Detection: How to Spot Synthetic Media
Deepfake video and audio are now weaponized for fraud at scale. How the technology works, what real incidents looked like, and how to verify what you see.
- Cybercrime-as-a-Service Explained: The Criminal Gig Economy
How the cybercrime-as-a-service economy works: RaaS, phishing kits, malware, access brokers, and bulletproof hosting, and why it lowered the skill bar.
- Initial Access Brokers: The Middlemen of Ransomware
Who initial access brokers are, the footholds they sell, how they get in through stealer logs and exposed RDP and VPN, and how they feed ransomware crews.