October is recognized within the EU as Cybersecurity Month. This makes it a perfect time to reflect on all that’s changed in the last year, the current state of the field, and a summary of the main takeaways that we should bring away from Cybersecurity Month 2026.

AI – works for you, works for them
AI has continued to develop and to find novel use cases in the cybersecurity field – both on the side of protection and playing the attacker’s role.
Detection and defense
One of the defensive applications of AI is in early detection of ongoing intrusions into your systems. For all their flaws, AI tools excel at establishing out-of-pattern behavior. This means that they can often perform at a superior level to a traditional manned one, detecting issues like stolen identities or illegitimate access.
Cybercrime
Unfortunately, AI tools have found applications in less savory communities as well. At the most basic level, more advanced machine learning algorithms have made finding and exploiting weaknesses in systems significantly easier. Attacks have now been carried out entirely without a human in the loop, a data point that should make us all wary.
It is not currently clear what the cybersecurity environment will look like as automation continues; the ability of AI tools to develop malicious code, identify a target, find a weakness in their security posture and exploit it is concerning, but is balanced by the increased detection ability and reduced response time on the other side of the ledger.
Where does the threat come from?
The other concerns are, of course, that the simple number of attacks has also been increasing over the course of the past years and the gap between government-sponsored and independent cyberattacks is closing – both in terms of demonstrated capability, but also in that it is increasingly being done by some of the same actors.
Cybercrime as a Service have also continued to develop and mature. By developing and selling malware, discovered vulnerabilities and so on, low-skilled actors have been able to purchase advanced malware or phishing kits on the dark web, further spreading the field of possible attackers.
Some things never change
ENISA finds that phishing remains the primary initial intrusion vector, accounting for approx. 60% of cases. Phishing continued to be the primary method for initial intrusion, remaining an effective technique to carry out cyberattacks.
In other words, no matter how the threats develop and take on complexity, the primary vector hasn’t changed for years now; the easiest way for attacks to begin is through simple phishing and taking advantage of momentary human lapses in attention.
Your Data in Your hands – With TECH-ARROW
by Matúš Koronthály
Image generated by Canva