Cybersecurity Research: AI Security, Cloud, Identity, XDR & Cyber Resilience

For years, cybersecurity was built around a fairly simple assumption: people use software, software runs inside a network, and security teams defend the boundary around both.

That model no longer describes the environment companies are trying to protect.

Employees work across SaaS platforms and personal devices. Applications communicate through APIs. Cloud workloads appear and disappear automatically. Contractors connect from outside traditional corporate networks. Machines authenticate to other machines. Industrial equipment is remotely accessible. Third-party software enters production through complex dependency chains.

And now AI agents can be given credentials, access enterprise data, call tools and take actions without a person clicking every button.

The result is a different kind of cybersecurity problem.

The question is no longer simply “How do we keep attackers outside?”

It is:

What exists in our environment?
What can be exploited?
Who-or what-is allowed to act?
How quickly can an attacker move?
How quickly can we contain them?
And can the business continue operating when prevention fails?

DataM Intelligence's Cybersecurity research follows this changing attack surface across artificial intelligence, cloud infrastructure, endpoints, identities, applications, software supply chains, operational technology, cryptography and cyber resilience.

Cybersecurity in 2026 Is Becoming a Race Against Attack Speed

The economic scale of cybersecurity continues to expand.

DataM Intelligence estimates that the global Cybersecurity Market reached US$262.22 billion in 2025 and could reach US$549.80 billion by 2033, representing a CAGR of 10% during 2026–2033.

But the more interesting change is not simply higher security spending.

It is speed.

Attackers are using automation and AI to accelerate reconnaissance, social engineering, vulnerability exploitation and other parts of the attack chain. Defenders are responding with increasingly automated detection, investigation and remediation.

Verizon's 2026 Data Breach Investigations Report provides a particularly important signal: exploitation of vulnerabilities accounted for 31% of breach entry points and overtook stolen credentials as the leading initial access route for the first time.

That changes where security budgets may move.

Finding vulnerabilities is no longer enough.

Organizations increasingly need to understand which exposures can actually become attack paths and which should be fixed first.

Every Breach Is a Chain. The Market Is Moving Toward Breaking It Earlier.

Cybersecurity products are often organized into dozens of categories.

Attackers do not think in product categories.

They look for a path.

A cloud misconfiguration exposes an application. An unpatched vulnerability creates an entry point. A compromised identity opens another system. Excessive permissions allow lateral movement. Endpoint execution provides persistence. A third-party connection creates another route. Eventually the attacker reaches valuable data, operational systems, or business processes.

Thinking about that chain creates a more useful way to understand where cybersecurity markets are developing.

First: Know What Is Exposed

Security teams cannot defend assets they do not know exist.

That sounds elementary, but modern enterprises can contain:

cloud workloads,
SaaS applications,
APIs,
containers,
endpoints,
servers,
internet-facing services,
employee identities,
service accounts,
machine identities,
AI agents,
industrial assets,
and third-party connections.

Some are temporary.

Some were created without the security team's involvement.

Some may already be obsolete but still publicly accessible.

This is why attack surface management and exposure management are becoming strategically important.

The security objective is moving beyond building an inventory.

Teams increasingly need to understand:

Which asset is internet-facing?

Which vulnerability exists on it?

Is an exploit available?

What identity can reach it?

What data sit behind it?

What compensating controls already exist?

What would happen if it were compromised?

That context turns a vulnerability list into a risk decision.

Exposure Management Is Replacing the “Patch Everything” Mindset

Most large environments contain more vulnerabilities than security teams can remediate immediately.

Treating every vulnerability as equally urgent creates an impossible operating model.

Exposure management instead asks whether a weakness belongs to a realistic path toward something valuable.

That is particularly relevant after Verizon's 2026 DBIR found vulnerability exploitation overtaking stolen credentials as the leading breach entry point.

Expect increasing demand around:

attack surface management,
continuous threat exposure management,
vulnerability prioritization,
breach and attack simulation,
threat intelligence,
automated remediation,
and risk-based patching.

For DataM, this is an important research expansion opportunity because the live Cybersecurity cluster currently gives much greater visibility to traditional categories such as cloud security, encryption and identity than to the emerging exposure-management layer.

Then AI Changes Both Sides of the Fight

Artificial intelligence is creating one of the largest structural changes in cybersecurity since cloud computing.

It is doing two things at once.

Attackers can use AI to accelerate malicious activity.

Defenders can use AI to analyze security data and automate decisions at a scale human analysts cannot match.

The World Economic Forum's Global Cybersecurity Outlook 2026 found that 87% of respondents viewed AI-related vulnerabilities as the fastest-growing cyber risk during 2025. The share of organizations assessing the security of their AI tools also increased from 37% in 2025 to 64% in 2026.

DataM's own market intelligence shows how quickly the commercial ecosystem is developing.

The Artificial Intelligence in Security Market reached US$29.8 billion in 2025 and is projected to reach US$171.13 billion by 2035, expanding at a 19.1% CAGR.

DataM separately estimates the Generative AI Cybersecurity Market at US$9.42 billion in 2025, potentially reaching US$211.92 billion by 2033.

Those reports should be flagship assets on this cluster.

Security Operations Are Moving From Alerting to Investigation

Traditional security systems generate alerts.

The problem is that large organizations can generate enormous volumes of them.

Someone still needs to determine:

Is this real?

What happened before the alert?

Which user or machine is involved?

What systems were touched?

Is the activity continuing?

What should be isolated?

That investigative burden is where AI can create practical value.

AI-assisted security systems are increasingly being used to:

summarize incidents,
correlate telemetry,
investigate suspicious activity,
prioritize vulnerabilities,
identify unusual behavior,
assist threat hunting,
and recommend remediation.

DataM's AI in Security research describes the market moving from basic anomaly detection toward automated vulnerability remediation, exposure management, GenAI protection, and increasingly autonomous response.

The economic value is not simply “using AI.”

It is reducing the time between signal and action.

Agentic AI Creates an Entirely New Security Principal

Generative AI initially created a data-security problem.

Employees could paste sensitive information into public models. Organizations worried about model outputs, data leakage, and shadow AI.

Agentic AI creates something deeper.

An AI agent can potentially:

read files,
access databases,
call APIs,
send messages,
write code,
change records,
purchase services,
or operate other enterprise tools.

That means the agent itself becomes an identity that needs security controls.

NIST launched its AI Agent Standards Initiative in February 2026 to support secure and interoperable agent adoption. Its work specifically includes AI-agent security, authentication, identity infrastructure, and secure agent interactions.

NIST's subsequent review of industry responses found broad agreement that agents introduce novel security risks and that existing cybersecurity practices will need to be adapted for secure agent deployment.

The New Question: What Is This Agent Allowed to Do?

An enterprise may know that an employee works in finance and should have access to specific systems.

How should it treat an autonomous finance agent?

The company needs to understand:

Who created the agent?

Which human or business function owns it?

Which model does it use?

What tools can it call?

Which information can it retrieve?

Can it create transactions?

Can it delegate work to another agent?

How long do its credentials remain valid?

What happens when its behavior deviates from policy?

NIST's work on software and AI-agent identity explicitly highlights identification and authorization controls as a prerequisite for safely giving agents access to enterprise data, applications and tools.

This creates an important new cybersecurity market around non-human identity.

Identity security now has to protect more than employees and customers.

It increasingly encompasses:

service accounts,
workloads,
APIs,
bots,
machines,
software agents,
and autonomous AI systems.

Identity Is Becoming the Enterprise Security Perimeter

Traditional security architecture often assumed that users inside a trusted network deserved a certain level of trust.

Cloud computing, remote work, SaaS and API-driven applications made that assumption increasingly difficult to maintain.

Agentic AI pushes it further.

Organizations need to decide continuously whether an identity should be allowed to perform a particular action.

That increases the strategic importance of:

identity and access management,
privileged access management,
continuous authentication,
identity threat detection,
machine identity,
digital identity verification,
and zero-trust architecture.

DataM already has strong research assets across Digital Identity Solutions, Identity Verification and Authentication and Mobile Identity Management, all of which are present on the existing Cybersecurity cluster.

The next content step should connect those markets explicitly to machine identities and AI-agent authorization.

Endpoints Are Becoming the Evidence Layer for Modern Attacks

An endpoint is no longer simply a laptop requiring antivirus.

It may be the place where identity misuse, ransomware, browser compromise, malicious scripts, remote-access tools and lateral movement become visible.

That is why endpoint security is shifting toward deeper detection and response.

DataM Intelligence estimates that the global Endpoint Security Market reached US$40.30 billion in 2025 and could reach US$119.04 billion by 2035. XDR is identified as the fastest-growing solution category in the current research.

The security architecture is evolving through several layers.

EDR provides detailed endpoint detection and investigation.

XDR attempts to connect endpoint information with telemetry from identities, email, networks, cloud workloads and other security domains.

MDR adds managed expertise and response services where organizations do not want to operate every part of detection internally.

The commercial shift is from buying more alerts toward buying better investigation and faster containment.

That is why Endpoint Security should be added near the top of the cluster rather than remaining absent from the current live report library.

Cloud Security Is Moving From Configuration Checks to Runtime Context

Cloud environments introduced a different security challenge.

Infrastructure can be created through code.

Workloads scale automatically.

Development teams can deploy resources without waiting for central IT.

Applications communicate through APIs.

Permissions can become highly complex.

The early cloud-security market focused heavily on identifying configuration problems.

That remains necessary.

But buyers increasingly need to connect configuration with identity, vulnerability, workload and data context.

This is driving the convergence of areas such as:

CSPM,
cloud workload protection,
cloud IAM,
container security,
application security,
data security posture,
and CNAPP.

DataM currently has a Cloud Security Market report on the Cybersecurity cluster and also maintains dedicated Cloud Security Posture Management research that is not currently included in the live cluster list.

CSPM should be added.

But the page should also explain that cloud security is moving beyond simply finding misconfigured storage buckets.

The larger objective is understanding which combinations of misconfiguration, vulnerability, identity and data create exploitable cloud paths.

Software Is a Supply Chain Before It Becomes an Application

Modern software is assembled.

Developers may combine proprietary code with:

open-source libraries,
third-party packages,
cloud services,
APIs,
containers,
development tools,
and increasingly AI-generated code.

A vulnerability several layers down that chain can eventually affect thousands of organizations.

That is why software supply-chain security has become a distinct cyber market.

CISA continues to maintain guidance around Software Bills of Materials and lists its 2025 Minimum Elements for an SBOM as the current U.S. minimum-elements resource. SBOMs provide structured transparency into the components present in software.

For enterprise buyers, however, an SBOM is only useful if someone can act on it.

The real value chain is:

Know the component → identify the vulnerability → determine whether the product is affected → prioritize remediation → verify the update.

That creates opportunities around:

SBOM management,
software composition analysis,
application security,
DevSecOps,
open-source security,
vulnerability intelligence,
VEX,
third-party risk,
and secure software development.

DataM already has Application Security and Supply Chain Cyber Security research on the live cluster.

Those reports should sit together inside a visible Application & Software Supply Chain Security pathway.

Cyber-Enabled Fraud Is Becoming a Board-Level Security Problem

Not every cyberattack is designed to encrypt infrastructure or steal a database.

Some attackers simply want someone to send money.

The World Economic Forum's 2026 survey found a notable difference in executive priorities: cyber-enabled fraud and phishing became the top concern among CEOs, while ransomware remained the leading concern for CISOs.

That divergence matters.

Cybersecurity strategy has to protect both infrastructure and business transactions.

AI-generated phishing, impersonation, deepfakes and social engineering can exploit employees, customers and payment workflows even when traditional network defenses remain intact.

This increases the value of:

fraud analytics,
identity verification,
behavioral intelligence,
transaction monitoring,
email security,
deepfake detection,
and adaptive authentication.

DataM already has Fraud Detection and Prevention, Healthcare Fraud Detection and Identity Verification research inside its cybersecurity portfolio.

The cluster should connect them through a Digital Trust & Fraud pathway rather than leaving them as isolated report titles.

OT Cybersecurity Is Where Digital Risk Becomes Physical Risk

Cybersecurity takes on a different meaning inside a factory, power network, pipeline, hospital or other operational environment.

An enterprise IT incident may interrupt email or compromise records.

An operational-technology incident can affect machinery, electricity, production, physical processes or safety.

Industry 4.0, remote maintenance, industrial cloud systems and connected devices are increasing communication between IT and OT.

That connectivity creates operational value.

It also creates additional attack paths.

DataM Intelligence estimates its Industrial Cybersecurity Market at US$23.12 billion in 2025 and US$52.42 billion by 2035.

DataM also now has newer dedicated research on Operational Technology Security and Industrial Control Systems Security that should be incorporated into the Cybersecurity cluster.

The important buying requirements differ from ordinary enterprise security.

Industrial operators care about:

asset visibility,
network segmentation,
secure remote access,
legacy equipment,
availability,
safety,
industrial protocols,
anomaly detection,
and incident recovery.

A security tool that protects office laptops perfectly may still be inappropriate for a production system that cannot tolerate an unexpected restart.

That difference deserves dedicated editorial treatment.

Post-Quantum Security Has Moved From “Someday” to Migration Planning

Quantum computing does not need to break modern cryptography today to create a current cybersecurity decision.

Some information needs to remain confidential for many years.

Organizations also require substantial time to identify where cryptography exists across applications, hardware, networks, and third-party products.

NIST now explicitly states that organizations should begin applying its finalized post-quantum cryptography standards and start migrating systems to quantum-resistant cryptography. Its first three principal standards-ML-KEM, ML-DSA and SLH-DSA-are available for use.

In June 2026, NIST also finalized guidance on achieving crypto agility, reinforcing the importance of designing systems that can replace cryptographic algorithms more easily as standards and threats change.

This shifts the enterprise conversation.

The immediate question is not:

“When will a cryptographically relevant quantum computer arrive?”

It is:

“Do we know which systems would need to change if today's cryptography became unsafe?”

Cryptographic Inventory Becomes the Starting Point

Organizations need visibility into:

certificates,
public-key algorithms,
VPNs,
TLS implementations,
code signing,
software libraries,
hardware security modules,
embedded devices,
and cryptographic dependencies supplied by third parties.

Only then can they create migration priorities.

DataM's Quantum Cryptography Market research already addresses quantum-safe infrastructure, hybrid cryptographic systems, migration services and crypto-agility platforms.

It should be added immediately to the Cybersecurity cluster alongside Encryption Software.

Regulation Is Becoming Part of Product Architecture

Security regulation used to be something companies often considered after technology had been designed.

That model is becoming increasingly difficult.

The EU Cyber Resilience Act applies cybersecurity obligations directly to products with digital elements.

A particularly immediate deadline arrives on September 11, 2026.

From that date, manufacturers covered by the CRA must report actively exploited vulnerabilities and severe security incidents affecting their products. Early warnings are generally required within 24 hours and full notifications within 72 hours.

The CRA's broader obligations apply later, but the September reporting requirement creates a clear near-term reason for vendors to strengthen vulnerability monitoring, disclosure processes and incident workflows.

Europe's regulatory environment also includes NIS2, which establishes cybersecurity requirements across 18 critical sectors, and DORA, which applies digital-operational-resilience requirements in financial services.

The market consequence is important.

Security becomes part of:

product development,
vendor selection,
software maintenance,
vulnerability disclosure,
third-party management,
incident reporting,
and executive governance.

This benefits security technologies that help companies produce evidence, not merely protection.

Cyber Resilience Is the Market Beyond Prevention

Every cybersecurity architecture eventually confronts an uncomfortable truth.

Some attacks will get through.

A vulnerability may be unknown.

An employee may approve a convincing fraudulent request.

A supplier may be compromised.

A security tool may fail.

An attacker may already be inside.

That is why cybersecurity is increasingly being discussed through resilience rather than prevention alone.

The World Economic Forum's 2026 outlook places cyber resilience alongside AI, geopolitics and supply-chain security as a defining theme of the current landscape.

A resilient organization needs to know:

How quickly can an intrusion be detected?

Can compromised identities be disabled?

Can affected systems be isolated?

Are backups usable?

Can critical services continue?

How fast can operations recover?

Can the company communicate accurately with regulators, customers and partners?

This changes how security return on investment should be measured.

The metric is not simply:

How many attacks did our firewall block?

It is also:

How much business damage occurred when something bypassed the controls?

Cybersecurity Market Signals from DataM Intelligence

DataM has something generic cybersecurity publishers do not: proprietary market intelligence across dozens of adjacent security categories.

The cluster should surface a small number of those signals directly.

Cybersecurity: US$262.22 billion in 2025 → US$549.80 billion by 2033.

Artificial Intelligence in Security: US$29.8 billion in 2025 → US$171.13 billion by 2035.

Endpoint Security: US$40.30 billion in 2025 → US$119.04 billion by 2035.

Generative AI Cybersecurity: US$9.42 billion in 2025 → US$211.92 billion by 2033.

Industrial Cybersecurity: US$23.12 billion in 2025 → US$52.42 billion by 2035.

Do not hide all of these numbers several clicks below the cluster.

Used selectively, proprietary DataM data give the page something worth citing.

Build the Cybersecurity Research Library Around the Attack Surface

The existing page currently shows 16 reports in one continuous catalogue, including Application Security, Big Data Security, Cloud Security, Cybersecurity, Defense Cybersecurity, Digital Identity, Encryption Software, Fraud Detection, Industrial Cybersecurity and Supply Chain Cybersecurity.

That library should be expanded and organized into recognizable security problems.

AI, Generative AI & Agent Security

Feature prominently:

Artificial Intelligence in Security Market
AI in Cybersecurity Market
Generative AI Cybersecurity Market

This collection should track AI-assisted defense, autonomous security operations, LLM security, shadow AI, GenAI data leakage, and emerging AI-agent security.

Exposure, Endpoint & Security Operations

Feature:

Endpoint Security Market
Relevant vulnerability, SOC, and threat-detection research.

Add DataM's SOC as a Service Market as a complementary managed-security asset. Its current research already covers generative AI, SOAR, behavioral analytics, and automated response.

This collection should own:

EDR,
XDR,
MDR,
vulnerability management,
exposure management,
ransomware protection,
threat hunting,
and automated remediation.

Cloud, Network & Zero Trust

Feature:

Cloud Security Market
Cloud Security Posture Management Market
Network Security Market

DataM's newer Network Security research includes SASE, ZTNA, NGFW, DDoS protection, NDR and secure-access architectures.

This should become the page's cloud-to-network control layer.

Identity, Machine Identity & Digital Trust

Feature:

Digital Identity Solutions Market
Identity Verification and Authentication Market
Mobile Identity Management Market

Expand the editorial coverage into non-human identity, privileged access, workload identity, and AI-agent authorization.

Application & Software Supply Chain

Feature:

Application Security Market
Supply Chain Cyber Security Market

Build future coverage around:

SBOM,
software composition analysis,
API security,
DevSecOps,
open-source security,
VEX,
secure-by-design software,
and AI software supply chains.

OT & Critical Infrastructure Security

Feature:

Industrial Cybersecurity Market
Operational Technology Security Market
Industrial Control Systems Security Market
Smart Grid Cybersecurity Market
Medical Device Cybersecurity Solutions Market
Defense Cybersecurity Market

This becomes one of DataM's strongest bridges into Industry 4.0, Energy, Healthcare and Defense research.

Quantum, Encryption & Data Protection

Feature:

Quantum Cryptography Market
Encryption Software Market

Develop the collection around:

post-quantum cryptography,
crypto agility,
cryptographic discovery,
quantum-safe migration,
data protection,
and hybrid cryptography.

Fraud & Digital Trust

Feature:

Fraud Detection and Prevention Market
Healthcare Fraud Detection Market
Identity Verification and Authentication Market

Tie this collection to AI-enabled fraud, impersonation, phishing, transaction monitoring, and adaptive identity verification.

The Questions Cybersecurity Buyers Are Asking in 2026

The market has moved beyond asking whether an organization needs cybersecurity.

More useful questions now include:

Which vulnerabilities form real attack paths?

Can we identify every externally exposed asset?

Which identities have excessive privileges?

How should we authenticate AI agents and software workloads?

Where are employees using unapproved AI tools?

Which AI models can access sensitive enterprise data?

Should an AI security agent be allowed to remediate a system automatically?

How do we correlate endpoint, cloud and identity signals?

Which third-party software components create hidden exposure?

Can we generate and consume useful SBOM data?

Where are quantum-vulnerable algorithms embedded in our systems?

Can our cryptography be changed without redesigning entire applications?

How does IT security connect with OT and physical operations?

How quickly could the organization recover from a destructive incident?

Those are the questions this research hub should help buyers investigate.

Cybersecurity FAQs

What are the biggest cybersecurity trends in 2026?

Major themes include AI and agentic security, vulnerability exploitation and exposure management, machine identity, XDR and MDR, cloud-native security, software supply-chain security, post-quantum migration, OT cybersecurity, cyber-enabled fraud and increasingly formal cyber-resilience requirements. WEF identifies AI, geopolitical risk, cybercrime, resilience and supply-chain security among the forces reshaping cybersecurity in 2026.

How is AI changing cybersecurity?

AI is helping security teams analyze large volumes of telemetry, prioritize incidents, investigate threats and automate parts of response. At the same time, AI can introduce data leakage, adversarial manipulation, automated attacks and new risks associated with autonomous agents. WEF found 87% of surveyed respondents saw AI-related vulnerabilities as the fastest-growing cyber risk during 2025.

What is agentic AI security?

Agentic AI security focuses on securing AI systems capable of taking autonomous actions. Important areas include agent identity, permissions, tool access, data access, authentication, authorization, auditability, and protection against manipulation. NIST launched a dedicated AI Agent Standards Initiative in February 2026.

Why is vulnerability exploitation receiving more attention?

Verizon's 2026 DBIR found vulnerability exploitation represented 31% of breach entry points and had overtaken stolen credentials as the leading entry route. This increases the importance of exposure management, vulnerability prioritization, and attack-surface visibility.

What is exposure management?

Exposure management is a continuous approach to identifying and prioritizing security weaknesses according to their real-world risk. Instead of treating every vulnerability equally, organizations examine factors such as asset exposure, exploitability, identity paths, business importance and available controls.

What is XDR?

Extended Detection and Response combines security telemetry across several domains-commonly endpoints, identities, networks, cloud environments and applications-to improve detection, investigation and coordinated response.

What is MDR?

Managed Detection and Response provides externally managed security monitoring, threat investigation and response capabilities. It is often used by organizations that need advanced detection and response without building every security-operations capability internally.

Why is machine identity becoming important?

Modern enterprises contain large numbers of service accounts, workloads, APIs and software systems that authenticate without human users. AI agents add another category of non-human identity. NIST is already working specifically on identity and authorization for software and AI agents.

What is software supply-chain security?

Software supply-chain security protects the components, dependencies, development processes and third-party services involved in building and operating software. SBOMs can improve component transparency, while application security, software composition analysis and vulnerability management help organizations act on that information.

What is post-quantum cryptography?

Post-quantum cryptography uses algorithms designed to remain secure against both conventional and future quantum-computing attacks. NIST has finalized three principal PQC standards and says organizations should begin migrating to quantum-resistant cryptography now.

What is crypto agility?

Crypto agility is the ability to replace or update cryptographic algorithms and related components without major disruption to systems. NIST finalized dedicated guidance on strategies and practices for crypto agility in June 2026.

What changes under the EU Cyber Resilience Act in September 2026?

From September 11, 2026, manufacturers covered by the CRA must report actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements. The EU requires an early warning generally within 24 hours and a full notification within 72 hours.

Why is OT cybersecurity different from enterprise IT security?

Operational technology controls physical equipment and processes, so availability and safety can be as important as confidentiality. Industrial environments also contain long-lived equipment and specialized protocols that cannot always tolerate conventional IT security practices. DataM's Industrial Cybersecurity research identifies growing investment around OT protection as connected industrial infrastructure expands.

Why DataM Intelligence for Cybersecurity Research?

Cybersecurity does not evolve as one market.

Cloud security moves differently from industrial cybersecurity. Identity behaves differently from endpoint protection. Quantum-safe security has a different adoption horizon from ransomware defense. AI can simultaneously create a new security technology market and a new category of risk.

DataM Intelligence connects those markets.

Our cybersecurity research helps technology vendors, enterprises, investors, consulting firms and strategic teams evaluate market size, growth, enterprise adoption, emerging technology, competitive positioning, regional opportunities and commercialization priorities across the global security ecosystem.

The value of the Cybersecurity Research Hub should therefore be simple:

Understand how attackers are changing.
Understand how enterprise defenses are changing with them.
Then identify which cybersecurity markets benefit from that shift.