Disclaimer: All views presented here, in this newsletter, are either sourced from internet and AI (using LLMs) search or are either my own.
Author or the newsletter are not liable for any actions taken by any individual or any organization / business / entity. The information provided is for information, education and awareness purposes only and is not specific to any business and or situation.
All cited statistics, incidents, and regulatory developments are sourced from publicly available materials and referenced accordingly. Readers are encouraged to verify all information against primary sources prior to making strategic or operational decisions. This publication does not constitute legal, regulatory, or professional security advice.
Hi Friends, Hope you are doing well.
Welcome back. Q2 2026 insights coming a bit late (apologies), here it is.
If Q1 was a quarter industry consolidated, Q2 had to show its receipts.
Themes we've been tracking as warnings, became case files.
Vulnerability exploitation overtook stolen credentials as the #1 breach vector for 1st time in 19 years per Verizon DBIR reporting.
AI-driven CVE discovery surged 36% in a single quarter — and NIST's NVD admitted it can no longer keep up.
FBI and Google dismantled a phishing empire linked to $1.9 billion in losses.
US water utilities were specifically targeted.
DHS network coordinating security for the FIFA World Cup across 16 US cities was breached mid-operation.
M&A machine ran hot with $4.18 billion Accenture mega-deals and a relentless pace of 26–38 deals per month.
Ransomware groups industrialized their operations at unprecedented scale, with ShinyHunters alone accountable for 14 of 37 "mega-breaches" tracked between January and May.
Regulatory pressure intensified on both sides of the Atlantic.
And AI moved from a tool used by defenders into a weapon wielded autonomously by attackers.
And if you read ST #86 — Cybersecurity: Before & After Mythos, you already know that AI-assisted vulnerability discovery story that broke in Q1 fundamentally reshaped the threat calculus this quarter.
Its downstream effects i.e., CVE volume surge, NIST database overload, compressed exploit window, are a thread through what follows below.
This edition covers key IT, OT/ICS, AI Cybersecurity insights from Q2 2026:
✍️ Cybersecurity M&As, fundings, and Start-ups.
‼️ Cyber Incidents, Ransomware Attacks & Data Breaches.
📘 Notable Updates — Guidance, Standards & Regulations.
📘 Artificial Intelligence (AI) Guidance & Regulations.
↪️ How CISO's role evolved in Q2 2026.
↪️ References used.
Each section includes expert analysis grounded in Q2 data, rather speculation, to give you actionable intelligence, and not just headlines. Hop on to the section that interests you more.
In case you missed previous quarterly editions, you can find them here:
But before we begin, do me a favor and make sure you "Subscribe" to let me know that you care and keep me motivated to publish more. Thanks!
Ready? Let's dig in.
Yours truly.
— Yousuf.
♻️ If you know someone in your professional circle who will benefit from these resources, I'd really appreciate if you'd forward it to them. Thanks 🌟
Together with (Sponsor):
Yes, that Arnold Schwarzenegger.
He has a newsletter on beehiiv. So do Codie Sanchez, Jay Shetty, David Begnaud, Colin & Samir, and Joanna Stern.
They could publish just about anywhere. They chose beehiiv to build a direct connection with the people who want to hear from them most. And you can do the same, whether you’re world-famous or just at the start of your plan for world domination.
Free Workup - still have time to register:
I am running a free workshop coming Tuesday and the following topic: “AI in OT (already on plant floor). Who approved it? AI Readiness Assessment”. To see details and register click → here.
A certificate of attendance will be awarded for those who attend and participate during the workshop.
One of you is also going to win a free training as part of the following announcement.
Securing Things Academy - Prelaunch
I am also announcing a pre-launch of Securing Things Academy!
I am looking for at-least 15 to a max. of 25 founding members who’ll be interested in joining first cohort of IT/OT Cybersecurity Transformation course focused on Securing Things for Your Digital Factory!
Those who have registered for the waitlist will have preference. I am going to restrict it to 25 people only. The goal is to transform 2 things:
Learners / one of you to be transformation your knowledge
Transform IT/OT Cybersecurity Program for your (if you are an asset owner) or your client’s environment (if you are consultant or system integrator).
IT & OT CySEAT (Cyber Security Education and Transformation) course is designed for IT + OT cybersecurity practitioners.
Join waitlist → here.
Cybersecurity Fundings, Start-ups and M&As
Funding Overview
Crunchbase's H1 2026 analysis confirmed that cybersecurity startups raised $10.6 billion in the first half of 2026. (Crunchbase News)
Q1 2026: ~$6.2B (record quarter)
Q2 2026: ~$4.4B across the quarter, down from Q1's peak, but historically strong
Eight rounds exceeded $100M in Q2. Investor conviction in the sector remains intact.
European picture: Axeleo Capital's Q2 2026 Cybersecurity Index (July 9) confirmed European startups raised €185M across 27 deals. A 38% drop from Q2 2025's €294M. Early-stage rounds dominated at 59% of transactions, with 6 exits.
Notable deal: Tsuga (France) raised €32M Series A backed by DST Global, Singular, and General Catalyst. Despite the Q2 dip, Dealroom's tracker shows European cybersecurity on pace for a record $1.81B annual high in 2026. (Axeleo Q2 2026)
Top Q2 Global Funding Rounds:
Company | Round | Amount | Why It Matters |
|---|---|---|---|
Cyera | Series E | $600M at $12B valuation | Largest Q2 round; AI-native data security at scale |
NinjaOne | Series C extension | $400M+ at $12.3B | Endpoint management at enterprise scale |
Dream | Growth round | $260M at $3B | AI for government & CNI cyber defense |
Gartner projects global information security spending at $244.2 billion in 2026, up 13.3% year-on-year. (Gartner, February 2026)
Cybersecurity M&A Activity
Monthly deal counts tracked by SecurityWeek:
Month | Deals Announced |
|---|---|
April 2026 | 33 |
May 2026 | 26 |
June 2026 | 37 ↑ |
Q2 Total | ~96 |
By mid-June, SecurityWeek had catalogued 190 cybersecurity deals year-to-date — including 20 in identity security alone.
The pace eased from Q1's record highs but recovered sharply in June. Buyers who paused for deeper diligence in April and May returned to close. The harder, more deliberate deals — those requiring more than simple bolt-on logic — are now working through.
Quarter's gold Transaction: Accenture + Dragos + runZero + NetRise
On June 18, Accenture announced it would acquire a majority stake in Dragos (OT threat detection, valued at ~$3.25B), 100% of runZero (attack surface intelligence), and 100% of NetRise (firmware and software supply chain visibility). Combined deal value: ~$4.175 billion.
The three companies together generate ~$208M ARR as of June 2026 — up 53% year-on-year. Accenture estimates the broader OT cybersecurity software market at $27B today, growing to ~$59B by 2031 at 16% CAGR. Closing expected August–September 2026.
Other Notable Q2 Transactions:
Acquirer | Target | Value | Segment |
|---|---|---|---|
1Password | Apono | $250–300M | JIT access for humans, machines & AI agents (SecurityWeek) |
SailPoint | Entro Security | ~$200M | Non-human identity & secrets security (SecurityWeek) |
Akamai | LayerX | ~$205M | Browser & AI agent activity control |
Aikido Security | Root | $70–100M | Agentic vulnerability remediation |
Airbus | Quarkslab | Undisclosed | Sovereign cyber / AI reverse-engineering defense |
Rubrik | Strata | Undisclosed | Identity continuity during incidents |
Cisco | WideField Security | Undisclosed | Identity threat detection for Splunk Agentic SOC |
Cyera | Ryft | Undisclosed | Data lake security automation |
Check Point | Deepchecks | $10–20M | AI model evaluation |
Terra Quantum | Axiom Intelligence Acquisition | ~$3.5B valuation | Quantum security (SPAC exit) |
Executive Summary by Market Segment
Rank | Segment | M&A Activity | Growth Funding | Seed Activity | Overall Momentum |
|---|---|---|---|---|---|
1 | Identity Security | Very High | Very High | High | ★★★★★ |
2 | AI / LLM Security | High | High | High | ★★★★★ |
3 | Data Security | High | High | Moderate | ★★★★★ |
4 | Application Security | Moderate | High | Moderate | ★★★★☆ |
5 | GRC / Cyber Risk | Moderate | Moderate | High | ★★★★☆ |
6 | Detection & Response | Moderate | Moderate | Low | ★★★☆☆ |
7 | Security Services | Moderate | Moderate | Low | ★★★☆☆ |
8 | Browser / Agent Security | High | Moderate | Low | ★★★☆☆ |
9 | Quantum Security | Low | Moderate | Low | ★★★☆☆ |
10 | OT/ICS Security | Low | Low | Low | ★★★☆☆ |
The pattern across all three months is consistent: buyers want identity governance, AI-agent security, OT visibility, and data security. Platform plays are beating point solutions.
MCF Corporate Finance's Q2 sector analysis notes the key implication is "not simply higher cyber risk, but a shift towards integrated, platform-led security solutions... isolated point solutions risk losing relevance unless they remain clearly differentiated or mission-critical." (MCF Corporate Finance, June 2026)
Q2 2026 - Cyber Incidents, Ransomware Attacks & Data breaches
Vulnerability Landscape: A Structural Break
Before individual incidents, the infrastructure story matters.
AI is now discovering vulnerabilities at machine speed. As covered in depth in ST #86 — Cybersecurity: Before & After Mythos, the announcement of Claude Mythos Preview (April 7, 2026) confirmed that frontier AI can autonomously discover thousands of high-severity zero-days — including 17-year-old and 27-year-old flaws that survived millions of automated tests — and write working exploits without human direction.
The Q2 downstream effects were measurable:
Beazley Security Labs tracked more than 20,700 new software vulnerabilities in Q2 2026. A 36% increase from Q1, following 18.5% growth in Q1 itself. Of those, ~5,600 were classified high-risk, 44 were confirmed actively exploited (CISA KEV), and Beazley issued 21 advisories for the most severe — a 40% increase over Q1. (Beazley Q2 2026 Quarterly Threat Report)
Kaspersky's vulnerability research traced the surge directly to AI-assisted discovery tools proliferating across the security research ecosystem. (Kaspersky Securelist Q2 2026)
On April 15, 2026, NIST announced a fundamental change to the National Vulnerability Database (NVD). The CVE submission volume has grown 263% since 2020. The NVD's enrichment model.
The CVSS scores, product metadata, and CWE classifications that industry patch-prioritization workflows are built on — can no longer scale to keep up. NIST moved to a risk-based triage model, enriching only CVEs on the CISA KEV list, those affecting federal government software, and those under Executive Order 14028.
Around 29,000 backlogged CVEs published before March 1, 2026 have been reclassified as "Not Scheduled" — no committed enrichment timeline.
If your patch prioritization process relies on NVD CVSS scores, you now have a systematic blind spot. Threat-intelligence-driven prioritization, using actual exploitation telemetry, replaces NVD-metadata-driven patch queues as the operational standard. (Black Duck Blog) | (Proofpoint)
Verizon DBIR 2026: The Quarter's Data Frame
Verizon's 2026 Data Breach Investigations Report — 19th edition, 31,000+ incidents, 22,000+ confirmed breaches, 145 countries. (Verizon DBIR 2026)
For the first time in 19 years, vulnerability exploitation (31%) overtook stolen credentials (13%) as the #1 initial access vector.
Read alongside the Beazley CVE data and the NIST NVD shift above, and the pattern is coherent: attackers are exploiting unpatched systems faster, and defenders are losing their tooling to keep up with the volume.
Other key findings:
Median time-to-patch: 32 → 43 days (+34%) (Tenable)
Supply chain in 48% of all breaches up 60% YoY (Help Net Security)
Shadow AI (unapproved AI tool use) tripled to 45% (Help Net Security)
Human element still in 62% of breaches
Mobile social engineering: +40%
Median ransomware payment: $139,875 — 69% of victims refused to pay (SpyCloud)
73% of ransomware victims had a prior infostealer infection — half within 95 days of the attack
That last finding is the most operationally important of the quarter. Infostealer infections are ransomware early-warning signals, not background noise. Treat them with the urgency of an active intrusion.
Ransomware: Plateauing Counts, Rising Concentration
The trackers don't agree with each other on exact counts, which is itself useful context, for how messy ransomware statistics really are.
Brandefense CTI tracked 2,509 confirmed ransomware victims across 91 distinct groups in Q2 2026. 17.5% increase from Q1. June alone produced 919 victim posts, the highest single month in their tracking window. (Brandefense Q2)
BlackFog recorded 2,027 undisclosed attacks. 40% increase year-on-year from Q2 2025. Publicly disclosed attacks reached 306, up 16%. (BlackFog Q2 2026)
The gap between disclosed and actual attacks is large. It is getting larger.
Top ransomware groups in Q2 2026:
Group | Q2 Victims | Trend |
|---|---|---|
The Gentlemen | 300 | 🔴 New #1. Up from 18 victims in Q4 2025. +30.6% QoQ |
Qilin | ~293 | 🟡 Still prolific, declining month-on-month |
DragonForce | 143 (H1) | 🟠 Consistent — energy & manufacturing focus |
Deadlock | 75 (June only) | 🔴 Re-emerged after 11 months' silence — blockchain C2 + kernel-level EDR evasion |
Settra | 22 (June debut) | 🆕 New entrant — most new-group victims of any Q2 actor |
(ReliaQuest) | (Emsisoft)
Black Kite tracked 7,551 publicly disclosed ransomware victims in the 12-month window ending March 2026. 24.9% increase year-on-year. Active groups reached 146 by June 2026, more than double the 61 tracked in 2023. (Black Kite 2026)
US absorbed roughly 49% of all global victims. Professional, Scientific & Technical Services was the #1 sector for the fifth straight quarter.
Notable IT-related Ransomware and Data Breaches
The quarter's theme from Fortian's Q2 review is the right frame: "attacks on trust." Supply chain, identity, and third-party compromises, not perimeter breaches. (Fortian Q2 2026)
ShinyHunters ran the most sustained multi-target campaign of the quarter:
📌 Instructure / Canvas LMS (May 2026). ~275 million records claimed. One of the largest education-sector breaches on record. (Malwarebytes)
📌 Oracle PeopleSoft (late May – early June). Exploitation of CVE-2026-35273, a critical unauthenticated RCE zero-day, compromised 100+ organizations, ~68% universities. (Fortian Q2 2026)
📌 One Medical / Amazon (June 8–13). 8.8TB of clinical and demographic data from legacy Iora Health / One Medical Seniors patients claimed. (PKWare)
📌 Aflac (June 2026). Roughly 22.7 million customers, beneficiaries, employees, and agents affected. (Bright Defense)
📌 NAIC (National Association of Insurance Commissioners) (June 2026). ShinyHunters compromised credit rating data from Moody's, S&P, Fitch, KBRA, and Morningstar DBRS. The NAIC suspended investment risk designations. Systemic disruption to US insurance capital markets. This was the quarter's most significant financial-sector impact. (CSIS)
📌 Kodak (June 15). ShinyHunters claimed 2.2 million records. Kodak confirmed unauthorized access to "a limited amount of company data." (Bright Defense)
📌 Klue (June 2026). Competitive intelligence platform breached, exposing enterprise Salesforce instances, including those of cybersecurity firms. (Beazley Q2 Quarterly Threat Report)
📌 Foxconn North America (May 12). Nitrogen ransomware claimed 8TB of schematics and project data tied to Apple, Dell, Google, and Nvidia. (Bright Defense)
📌 DHS Homeland Security Information Network (HSIN) (Breach: late May – early June; Disclosed: July 1). Attackers breached the federal platform used by DHS, FBI, state and local agencies for real-time threat intelligence sharing. HSIN was actively supporting FIFA World Cup 2026 security operations across 16 US cities at the time.
DHS confirmed breach of both HSIN servers and a connected SharePoint environment. Attackers remain unidentified. Senator Mark Warner described the exposed data as "highly sensitive." (TechTimes)
📌 24 billion credential records. A publicly accessible Elasticsearch database holding 8.3TB of stolen credentials was discovered. (RSecurity)
📌 Microsoft June 2026 Patch Tuesday. The largest in the program's history: 200 vulnerabilities patched, including an actively exploited Exchange Server flaw. (RSecurity)
📌 Novo Nordisk (June 16). Unauthorized access to a limited number of internal IT systems. Non-public information copied externally. (Industrial Cyber)
Phishing-as-a-Service: Disruptions, New Entrants, and Takedowns
Q2 produced the most significant coordinated law enforcement action against phishing infrastructure in recent memory. Threat actors adapted within days.
Tycoon2FA:Disrupted in Q1, Rebuilt Quickly, Then Faded Through Q2
On March 4, 2026 (Q1), Europol coordinated the disruption of Tycoon2FA. Dominant MFA-bypass PhaaS platform. 330 domains seized.
At its peak, it accounted for 62% of all phishing attempts blocked by Microsoft, sending emails to 500,000+ organizations monthly, and enabling unauthorized access to ~100,000 organizations globally. (The Hacker News) | (BleepingComputer)
Activity dropped to 25% of pre-disruption levels on March 4–5, then returned to normal within days. (CrowdStrike)
Through Q2, however, the sustained effect was real. By end of June, Tycoon2FA-linked phishing was running at 8% of its H2 2025 baseline. 92% total decline. Its share of CAPTCHA-gated phishing fell from 41% in March to 12% in June. (Microsoft Security Blog, July 23)
The lesson: infrastructure takedowns work better than critics suggest — but only over time, and only when arrests follow.
Kali365: The Replacement Arrived in April
Kali365 appeared in April 2026 and drew an FBI public warning on May 21. It uses device code phishing, abusing Microsoft's OAuth 2.0 Device Authorization flow. No password theft required. No MFA interception. The victim unknowingly authorizes persistent attacker access to their M365 environment.
Subscribers pay $250/month or $2,000/year and receive AI-generated phishing lures, automated campaign templates, real-time victim tracking dashboards, and OAuth token capture. Device code phishing detections surged 37.5x in early 2026 as at least 11 competing kits entered the market. (FBI IC3 PSA) | (BleepingComputer)
FBI defensive recommendations: Block device code authentication flow with Conditional Access policies, audit existing device code usage, and deploy phishing-resistant MFA (hardware security keys).
Outsider Enterprise / Operation Ghost Hook: FBI + Google Take Down $1.9B Phishing Empire
In June, the FBI, Google, and Black Lotus Labs dismantled Outsider Enterprise. PhaaS coordinated through Telegram. (SecurityWeek) | (BleepingComputer)
9,000+ fake websites, 1M+ fraudulent URLs
2.5 million phishing SMS messages in two weeks in May alone
3.87 million stolen credit cards
Estimated $1.9 billion in losses across 54+ countries
Platform subscription starting at $88/month
The FBI seized administration servers, phishing domains, a Shopify storefront, and ~$100,000 in crypto. The operation was dubbed Operation Ghost Hook, part of the FBI's broader Operation Riptide.
Two numbers tell the whole story: $88/month subscription. $1.9 billion in losses. That asymmetry explains why AI-assisted PhaaS keeps growing.
OT/ICS and Critical-Infrastructure-Sector Incidents
The OT picture in Q2 leaned heavily geopolitical — and operationally real.
A recurring theme in Industrial Cyber's Q2 coverage: adversaries are visibly shifting from data theft toward operational disruption as the primary objective. The stakes on every advisory below are availability and safety, not just confidentiality.
📌 Iran-linked Handala → Cal Water (June 2026). Handala targeted California Water Service, exposing IT-to-OT pathways in US water infrastructure. (Industrial Cyber)
📌 Black Shadow → US and Middle East (May 29). Gambit researchers linked the Iran-linked Black Shadow group to a destructive campaign targeting US and Middle East organizations. (Industrial Cyber)
📌 Poland Energy Sector Wiper (Incident: December 2025 / CISA Alert: February 2026). Attacker gained access via internet-facing edge devices and deployed wiper malware on RTUs at Polish renewable energy plants and a combined heat-and-power plant. (CISA Alert)
📌 CISA + ATG Systems Advisory (June 4). CISA and international partners urged operators to secure automatic tank gauge systems against ongoing exploitation. (Industrial Cyber)
📌 Phoenix Contact PLCnext vulnerabilities (June 2). Privilege-escalation flaws enabling root access to widely deployed PLCnext controllers. (Industrial Cyber)
📌 US Coast Guard Maritime Cyber Guidance (June 16). Baseline cybersecurity requirements issued for US-flagged vessels, port facilities, and OCS facilities. Maritime now has its own OT cyber rulebook alongside energy, water, and rail. (Industrial Cyber)
📌 ENISA Cyber Europe 2026 (June 10–11). 8th edition of Europe's flagship coordinated incident response exercise. (Industrial Cyber)
AI-related Cyber Incidents and Data Breaches
The most consequential AI-security document of Q2 wasn't a vendor report. It was OWASP.
OWASP GenAI Security Project published v2.01 of its State of Agentic AI Security and Governance on June 11. The 2025 edition catalogued hypothetical threats. The 2026 edition catalogues actual CVEs. (Help Net Security)
📌 LiteLLM Supply Chain Attack (March 2026 — documented through Q2) — Autonomous bot hackerbot-claw exploited a misconfigured GitHub Actions workflow and pushed backdoored versions of LiteLLM (used by CrewAI, DSPy, Microsoft GraphRAG) to PyPI. ~47,000 downloads before removal. No human direction after launch. (TechTimes)
📌 CVE-2026-22708: Cursor Coding Agent. Attackers poisoned the execution environment so allowlisted commands could deliver arbitrary payloads. The allowlist meant to restrict became the attack vehicle. (OWASP v2.01 via Help Net Security)
📌 Prompt injection attacks surged 340% year-on-year, now the fastest-growing attack category globally. (AI Magicx)
Agentic AI security is no longer a governance slide. It has a CVE number.
Updates - Guidance, Standards & Regulations!
US: Trump AI Executive Order (June 2, 2026)
President Trump signed "Promoting Advanced Artificial Intelligence Innovation and Security". Most consequential US AI policy action of the quarter.
Three core components: (A&O Shearman) | (Latham & Watkins)
1. Federal & critical-infrastructure cyber hardening Establishes a voluntary AI Cybersecurity Clearinghouse (Treasury-led) and expands AI-enabled defensive tools to state, local, and critical-infrastructure operators, explicitly naming rural hospitals, community banks, and local utilities.
2. Voluntary frontier-model pre-release framework AI developers may provide 30-day early government access to "covered frontier models" before release. Framework design deadline: August 1, 2026. Explicitly not a mandatory licensing regime.
3. Criminal enforcement directive Attorney General directed to prioritize prosecution of AI-enabled unauthorized computer access and data exfiltration.
EU: AI Act Digital Omnibus: Real Relief, Selectively Applied (May 7, 2026)
Political agreement on the first amendment to the AI Act since June 2024. Not all deadlines moved. (Inside Privacy) | (European Commission)
Obligation | Original Deadline | New Deadline |
|---|---|---|
High-Risk AI Systems (Annex III) | Aug 2, 2026 | Dec 2, 2027 (+16 months) |
Synthetic content transparency marking | Aug 2, 2026 | Dec 2, 2026 (+4 months) |
National AI regulatory sandboxes | Aug 2, 2026 | Aug 2, 2027 (+12 months) |
GPAI model obligations | Aug 2025 | Unchanged |
Prohibited AI practices | Feb 2025 | Unchanged |
If you've been planning to the original timeline, check which specific obligations apply before adjusting any compliance roadmap. The 16-month Annex III deferral is the headline, but several deadlines are unchanged.
NIS2: Common Incident-Reporting Templates (May 26, 2026)
The NIS2 Cooperation Group adopted standardized templates at its 39th Plenary (Cyprus). Organizations no longer need to file in slightly different formats across member states. Aligns with the Digital Omnibus push toward a single EU entry point for incident reporting. (NIS2-Directive.com)
China: Major Supply Chain Security Regulations (Effective Immediately)
The most significant geopolitical-regulatory development for multinational security and procurement teams this quarter.
On April 7, 2026, China's State Council published and immediately enacted:
Decree No. 834: China's first dedicated Industrial and Supply Chain Security Regulations. Establishes investigation authority, countermeasure powers against foreign actors, and restrictions on supply-chain information gathering in China.
Decree No. 835: Anti-Extraterritorial Jurisdiction Regulations. Enables China to respond to foreign sanctions and export controls affecting Chinese supply chains.
On June 18, the CAC, MIIT, and MPS jointly issued China's first dedicated operational rulebook for Network Data Security Risk Assessment — effective August 20, 2026.
On June 22, MOFCOM issued Investigation Measures implementing Decree 834, also effective immediately.
(National Law Review) | (White & Case) | (Morgan Lewis)
These rules restrict supply-chain information gathering inside China and cross-reference PRC data security, cybersecurity, and national security laws.
If your TPRM or due-diligence processes involve gathering information about Chinese supply chain participants, legal review is not optional.
Post-Quantum Cryptography: Two Deadlines Now in Sight
April 2026 (passed): US federal agencies due to submit PQC transition plans under NSM-10. (PostQuantum.com)
September 21, 2026 (8 weeks away at time of writing): NIST CMVP sunsets all FIPS 140-2 certificates. Only FIPS 140-3-validated modules accepted for new federal procurement.
January 1, 2027: New National Security System acquisitions must comply with NSA CNSA 2.0.
September deadline. Cryptographic inventory must be built now.
Artificial Intelligence (AI) Guidance & Regulations
Q2 2026 is the quarter regulators stopped debating whether to govern agentic AI and started arguing over how fast and how binding.
US and EU are now visibly diverging:
US: Voluntary frameworks, fast procedural deadlines, emphasis on innovation.
EU: Binding obligations, substantive deadlines (deferred, not dropped), emphasis on risk classification.
Multinational teams need both playbooks running in parallel.
Other key Q2 AI-governance data points:
KPMG's 2026 Cybersecurity & Technology Risk Survey found only 24% of organizations have fully integrated AI into their cyber programs — even as AI-powered attacks accelerate. 83% reported an increase in cyberattacks over the past 12 months. (KPMG, June 2026)
Kiteworks 2026: 41–44% of organizations have not implemented basic AI governance controls like human-in-the-loop oversight. 55–63% lack kill switches, purpose binding, or network isolation for AI agents. (BabyBots / Kiteworks analysis)
Industrial Cyber analysis (June 16): AI is quietly dissolving the foundational segmentation assumptions of Purdue Model architecture underlying most OT security programs. The air gap is no longer the default assumption. (Industrial Cyber, June 16)
The gap between AI adoption speed and AI governance maturity is the most significant structural vulnerability entering H2 2026.
For more comprehensive coverage checkout, the following Global AI Regulations Roundups from Securiti:
Together with (Sponsor):
100+ ChatGPT Prompts to Revolutionize Your Day
Supercharge your productivity with HubSpot's comprehensive guide to Chat GPT. This free resource is your fast track to AI mastery:
Industry-Specific Use Cases: 15+ real-world applications across various sectors
Productivity Guide: 21 best practices to 10x your efficiency with AI
Prompt Powerhouse: 100+ ready-to-use prompts for immediate implementation
Challenge Buster: Overcome common AI hurdles with expert strategies
Plus, in-depth sections on email composition, content creation, customer support, and data analysis.
How CISO’s role Evolving in Q2 2026
The Numbers
Splunk / Oxford Economics 2026 CISO Report — 650 global CISOs: (Cisco Newsroom)
Metric | Figure |
|---|---|
CISOs now responsible for AI governance | 96% |
Concerned about personal liability | 78% (up from 56%) |
Now overseeing DevSecOps | 85% |
Responsible for OT/ICS/IoT security | 67% |
Considered quitting due to AI governance burden | ~25% |
Cannot correlate ROI to risk mitigation | 41% |
One in four CISOs considered leaving their role this quarter. Specifically because of AI governance pressure. (Cybersecurity Insiders)
What Q2 Actually Demanded
Q1 surveys showed expanded mandate as abstract, Q2 made it concrete.
In a compressed window, CISOs were handed:
→ A DBIR showing patch speed is the #1 breach-risk variable and that infostealer infections are a ransomware early-warning signal — meaning identity hygiene and vulnerability management feed the same risk model.
→ A NIST NVD announcement telling the industry that the central database underpinning vulnerability prioritization can no longer keep up — requiring every scanner-dependent patch queue to be rethought from the baseline.
→ An OWASP report converting agentic AI risk from a governance slide into a CVE patching queue with real advisories against tools developers are already running.
→ A federal EO creating an AI cybersecurity clearinghouse that critical-infrastructure CISOs may be expected to engage with.
→ China supply chain regulations that require legal review of TPRM processes involving PRC-based suppliers.
→ A PQC deadline now 8 weeks away.
None of that is abstract "AI governance." It's vulnerability management, regulatory compliance, and incident response preparation — with "AI" as a modifier on each, not a separate department.
The Hitch Partners Global CISO Leadership Report identified the governance gap — the distance between AI adoption speed and AI governance maturity — as the most significant structural vulnerability CISOs are managing into H2 2026. (Hitch Partners 2026)
What Best-Prepared CISOs Did Differently in Q2
Based on field guidance from Splunk, Dragos, KPMG, and Hitch Partners:
Treated infostealer telemetry as a ransomware early-warning program, not just credential hygiene.
Inventoried every AI agent in production: data access, trigger permissions, kill switches, purpose binding.
Mapped OT risk to board language. Not "PLCnext zero-day" but "production shutdown risk at Site X."
Documented AI governance decisions as defensible records, not because regulators asked, but because personal liability exposure made it non-optional.
Started the PQC cryptographic inventory before the September FIPS deadline.
Switched from NVD-metadata-driven to threat-intelligence-driven patch prioritization, using actual exploitation telemetry as the queue signal.
Conclusion - Closing Signal: 2026 Outlook
1. Patch speed is your #1 breach risk. DBIR's vector reversal is the clearest signal in 19 years of data. Vulnerability exploitation beat credentials. Patching speed and exposure management deserve at least the budget that identity got in 2024–2025.
2. The NVD is no longer a complete baseline. NIST said so explicitly. Threat-intelligence-driven prioritization replaces NVD-CVSS-driven patch queues as the operational standard. Build that capability in Q3.
3. OT/ICS security has its biggest buyer yet. $4.175B for Dragos + runZero + NetRise. A $27B market size estimate. Geopolitical threat actors naming specific utilities. "OT security is underfunded" narrative has a limited shelf life.
4. PhaaS is an industrialized economy. $88/month subscription. $1.9 billion in losses. 37.5x increase in device code phishing. Every MFA strategy that doesn't account for session token theft and device code abuse is incomplete.
5. The regulatory map is now genuinely multinational and diverging. US: voluntary, fast process deadlines. EU: binding, deferred substantive deadlines. China: immediate-effect supply chain rules with extraterritorial reach. Security and compliance teams spanning more than one jurisdiction need all three playbooks running simultaneously.
6. Agentic AI security has a CVE number. OWASP's 2026 catalog changed the conversation. Treat coding agents, agent frameworks, and MCP-style integrations the way you treat any internet-facing software.
Stay ahead. Stay secure.
Until next time — keep the lights on (and the attackers out).
Questions or topic requests for Q3 2026? Hit reply.
Some References & Further Reading
Here’s a list of sources used and for further reference reading:
Crunchbase News. Cybersecurity H1 2026 funding.
Axeleo Capital. Cybersecurity Index Q2 2026. July 9, 2026.
Dealroom. European Cybersecurity Funding 2026.
Gartner. Top Cybersecurity Trends 2026. , February 5, 2026.
SecurityWeek. Cybersecurity M&A Roundups: April-June 2026.
Accenture strengthen Critical Infrastructure Defense. June 2026.
SecurityWeek. Accenture Acquires Majority Stake in Dragos.
Industrial Cyber. Accenture expands OT security capabilities.
SecurityWeek. 1Password Acquires Apono.
SecurityWeek. SailPoint to Acquire Entro.
MCF Corporate Finance. Cybersecurity Sector Insights Q2 2026.
Anthropic / Project Glasswing. April 7, 2026.
CSA research, Claude Mythos Autonomous Offensive Threshold.
Software Analyst. Cybersecurity Implications of Claude Mythos.
Wiz. Claude Mythos: AI Finds, Exploits Vulnerabilities Faster.
Beazley Security. Quarterly Threat Report Q2 2026.
Risk & Insurance. More Vulnerabilities, Same Old Door.
Kaspersky Securelist. Vulnerabilities and Exploits in Q2 2026.
Black Duck Blog. NVD Changes 2026.
Proofpoint. More CVEs, Same Playbook. June 9, 2026.
Verizon 2026 Data Breach Investigations Report. May 2026.
Help Net Security. Verizon 2026 DBIR Findings. May 20, 2026.
Help Net Security. Lessons from Verizon 2026 DBIR. May 2026.
SpyCloud. Top Takeaways from 2026 Verizon DBIR.
Tenable. Key Findings from Verizon DBIR 2026.
Brandefense. Top 5 Ransomware Groups Q2 2026.
BlackFog. Q2 2026 Ransomware Report.
ReliaQuest. Ransomware and Cyber Extortion Q2 2026.
Emsisoft. State of Ransomware in Q2 2026.
Black Kite. 2026 Ransomware Report.
Fortian. Q2 2026 Quarterly Cyber Threat Review.
Fidelis Security. Top Cyber Threats Q2 2026. June 25, 2026.
Malwarebytes. Canvas/Instructure breach.May 2026.
PKWare. 2026 Data Breaches.
CSIS. Significant Cyber Incidents.
RSecurity. June 2026 Cyber Attacks Report.
TechTimes. DHS World Cup Security Network Breached.
Bright Defense. List of Recent Data Breaches 2026.
CISA. Poland Energy Sector Cyber Incident Alert. February, 2026.
Industrial Cyber. US Coast Guard Expanded Cybersecurity Guidance. June 16, 2026.
Industrial Cyber. Novo Nordisk Unauthorized IT Access.
The Hacker News. Europol Takes Down Tycoon2FA. March 2026.
BleepingComputer. Europol Disrupts Tycoon2FA. March 2026.
CrowdStrike. Tycoon2FA Persists After Takedown. March 2026.
Microsoft Security Blog. E-mail Threat Landscape Q2 2026.
FBI IC3. Kali365 Phishing-as-a-Service PSA. May 21, 2026.
BleepingComputer. FBI Warns of Kali365. May 25, 2026.
Cybersecurity Dive. Kali365 FBI Warning. May 26, 2026.
SecurityWeek. FBI and Google Dismantle Outsider Enterprise.
BleepingComputer. FBI Disrupts Outsider Enterprise. June 2026.
Help Net Security. OWASP Prompt Injection AI Failures. 2026.
TechTimes. AI Agent Security CVEs. June 14, 2026.
AI Magicx. Prompt Injection Attacks 2026.
A&O Shearman. Trump Administration AI EO. June 2026.
Latham & Watkins. Trump AI EO Analysis. June 2026.
Morrison Foerster. Trump AI EO. June 5, 2026.
Inside Privacy. EU AI Act Omnibus Update. , 2026.
European Commission. EU AI Act.
NIS2-Directive.com. NIS2 Incident Reporting Templates.
National Law Review. China Newsletter Q2 2026.
White & Case. China Supply Chain Security Regulations 2026.
Morgan Lewis. China Supply Chain Regulations. April 2026.
PostQuantum.com. US PQC Regulatory Framework 2026.
Cisco Newsroom / Splunk. CISO Report. February 24, 2026.
Help Net Security. CISO Liability Risk. February 27, 2026.
Cybersecurity Insiders. AI Governance CISO Liability. 2026.
KPMG. 2026 Cybersecurity & Technology Risk Survey. June 2026.
Hitch Partners. 2026 Global CISO Leadership Report.
BabyBots / Kiteworks. AI Agent Security Governance Gap.
Securing Things Cybersecurity Before & After Mythos [ST #86].
Securing Things Cybersecurity Insights from Q1 2026 [ST #85].
Ways in which I can help?
Whenever you are ready - I can help you with:
A: IT & OT Cybersecurity Advisory/Consulting services for businesses.
B: Security Awareness Training & Phishing Portal - Enroll your staff.
C - Securing Things Academy (STA) - trainings for IT & OT practitioners.
Reach out: info[at]securingthings[dot]com or DM me via LinkedIn.
D - Sponsor ST Newsletter - showcase your brand globally or subscribe.
Reach out: newsletter[at]securingthings[dot]com or DM via LinkedIn.
✉️ Wrapping Up
Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.
Also, if you find this or previous newsletter edition(s) useful and know other people who would too, I'd really appreciate if you'd forward it to them. Thanks a ton.
Thanks for reading - until the next edition!
It’s a Great Day to Start Securing Things for a Smart & Safer Society.
Take care and Best Regards,
Rate the newsletter content
Your feedback and input are invaluable to me as we work together to strengthen our cybersecurity defenses and create a safer and smarter digital society. Thank you for your trust and continued support.





