Industry contribution

2026 National Security Predictions

digital map

As borders become irrelevant through remotely-launched attacks, the geopolitical landscape is rapidly growing in complexity and changing how countries define national security. This trend is expected to intensify in 2026 as harmful actors launch attacks with global ramifications, testing the organizational and governmental resilience. Developing capabilities to anticipate and adapt to evolving threats can help mitigate risks and stay ahead of threat actors.

Accelerating technological advancements, heightened geopolitical tension and the integration of cybersecurity and physical threats may force a redefinition of national security, requiring dedicated responses from both private and public sectors. By examining key developments for 2026, organizations can better predict national security threats and implement necessary protections for their people and assets.** **

Mobile devices: Cyber’s newest frontline

Everyone depends on mobile devices for personal connectivity and professional responsibilities, making these devices valuable data mines. Threat actors recognize this, targeting mobile devices to push political, strategic and financial objectives. These attacks are already happening, and as adversaries hone their skills, the threats will become more prevalent in 2026.

Mobile malware attacks, often targeting high-profile executives and government officials, allow threat actors to exfiltrate sensitive information, monitor communications and track movements, posing clear national security threats. Mobile devices present significant opportunities for these actors, and until governments and organizations prioritize mobile security, critical assets and national security interests remain at risk.

Disinformation/misinformation: Truth under attack

Disinformation and misinformation campaigns effectively harm brand, reputation and enterprise value of targeted organizations, individuals and government officials by spreading false information, deliberately or unknowingly. Adversaries enhance these attacks with manipulated content and deepfakes to create seemingly authentic sources.

These attacks threaten national security by influencing public opinion, eroding trust and destabilizing institutions and individuals. Due artificial intelligence (“AI”) commoditization and social media prevalence, this tactic will likely rise in 2026, as identifying altered content becomes increasingly difficult.

For those targeted by a disinformation or misinformation campaign, effective risk mitigation requires an initial assessment followed by continuous monitoring, root cause analysis and identification of impact and attribution.

Corporate security: Holistic executive threat protection

High-profile incidents at public events and in corporate locations in 2025 highlighted potential gaps in security programs and the blending of physical and digital threats, expected to continue in 2026. Opposition groups can use publicly-available information about high-profile individuals (speaking events, venues, dates) and organizations (addresses, email, phone numbers) to launch physical attacks and digital targeting through doxing, online harassment and phishing.

Corporate security and executive threat protection carry national security implications because attacks on influential individuals and critical industries can sow widespread discord, stall supply chains and disrupt the infrastructure that ensures a nation’s security. Mitigating these risks requires aligning physical and cyber protections instead of developing siloed threat plans.

Artificial intelligence: Machines shaping global power

The benefits of AI are undeniable, but without proper oversight, AI can create significant national security risks. In 2026, it is expected that AI will remain critical for organizations integrating and leveraging advancing capabilities and regulators determining governance strategies.

As organizations rush to adopt AI, employees often overlook proper implementation. Without appropriate protections, sensitive information and system access remain exploitable, including by nation-states with global agendas.

While the White House AI Action Plan intends to remove innovation-encumbering regulation, organizations must recognize persistent national security threats in the AI industry will remain, e.g., exposure of sensitive data, access by nation-states to confidential information and compromised proprietary datasets, requiring dedicated risk mitigation strategies1.

A multidisciplinary approach to AI risks will allow innovation, while prioritizing security and anticipating threats.

Quantum computing: Preparing for “harvest now, decrypt later”

Similar to AI, advances in quantum computing offer significant benefits but also pose risks. Current encryption standards were not created to contend with quantum computing, a risk to prepare for in 2026 and beyond.

Although quantum computing may seem distant, organizations not moving beyond traditional encryption may already face “harvest now, decrypt later” attacks, where threat actors capture encrypted data today to unlock it once quantum technology allows. This strategy allows adversaries to possess sensitive information, reveal confidential messages and exploit virtual private networks, potentially impacting national security by furthering strategic political and military objectives.

Geopolitical tension and the dissolving of digital borders

In September 2025, the U.S. Secret Service discovered and dismantled a massive network of electronic devices in New York City2. This network could have been used in various malicious ways to advance geopolitical agendas, including disabling cell towers, intercepting or eavesdropping communications, cloning devices and launching denial of service attacks. The national security concerns are endless.

While the Secret Service ultimately thwarted this threat, similar geopolitical focused attacks are anticipated in 2026. Reliance on critical infrastructure and the today’s interconnected world mean threats with global implications will persist, especially since threat actors can establish networks in target areas, lay dormant while traveling elsewhere and conduct operations covertly and remotely when ready.

Economic interests and regulation: Meeting market demands

Many national security-related executive orders and regulations were issued in 2025, including Executive Order 14161, to protect the U.S. from foreign terrorists and other threats3. Despite a perceived increase in regulatory oversight, many organizations take a “wait and see” approach due to minimal enforcement and absent government guidance. However, the current U.S. presidential administration will likely focus more on these rules in 2026 through active enforcement, driving compliance efforts.

Organizations should not wait for the hammer to drop and be left flat-footed when regulators come knocking. Taking action now will help protect national security interests. Even without immediate full compliance, demonstrating progress in implementing risk mitigation measures can position organizations more favorably with regulators.

Threat intelligence: Moving from noise to action

With unprecedented access to information, organizations struggle to determine meaningful data from noise. This is especially true regarding threat intelligence; information overload can hide dire threats, an issue expected to remain throughout 2026. Without proper threat identification, nation-states and adversaries can launch successful cyber attacks, weakening national security by targeting critical infrastructure and stealing proprietary information.

Overcoming information overload requires focusing on the most impactful risks and developing intelligence-led defensive strategies that marry geopolitical and cyber intelligence. This shift allows genuine threats to be addressed decisively, protecting national security.

These predictions emphasize an ongoing theme. With shifting geopolitical alliances and new policy developments, national security will dominate the 2026 landscape. Organizations that anticipate threats and meet upcoming regulatory obligations will protect critical assets and strengthen national security interests.

  1. https://www.whitehouse.gov/wp-content/uploads/2025/07/Americas-AI-Action-Plan.pdf ↩︎
  2. https://www.secretservice.gov/newsroom/releases/2025/09/us-secret-service-dismantles-imminent-telecommunications-threat-new-york. ↩︎
  3. https://public-inspection.federalregister.gov/2025-02009.pdf. ↩︎
Photograph of Anthony J. Ferrante

Written by

Anthony J. Ferrante

Global Head of the Cybersecurity practice, FTI Consulting

Mr. Ferrante is an expert in data security, compliance, privacy, national security and cybersecurity readiness, prevention, incident response, remediation, recovery and complex investigation services. Mr. Ferrante has more than 25 years of top-level cybersecurity experience, prov…