SecureWorld News

Every Tech Trend Is Now a Cyber Trend, McKinsey Report Suggests

Written by Cam Sivesind | Sun | Sep 27, 2026 | 2:04 PM Z
McKinsey's sixth annual Technology Trends Outlook, published September 15th and authored by Michael Chui, Roger Roberts, and Tanguy Catlin, opens with a line that should get the attention of every security leader: the technology story of 2026 has moved off the screen and into the physical world. Power grids, custom chips, robots, satellites, autonomous labs—every one of them is a new surface to defend.

The 143-page report groups its 14 trends into three buckets: the AI revolution, compute and connectivity frontiers, and cutting-edge engineering. Cybersecurity gets its own chapter (renamed this year from "digital trust and cybersecurity" to "cybersecurity and trustworthy systems"). But read the report end to end and a different picture emerges. Security isn't one trend among 14; it is the connective tissue running through all of them, and in several places it is the constraint that determines whether the other trends deliver value at all.

Here's where the tentacles reach, starting with the four AI trends McKinsey says are driving the revolution.

The headline number: the defense window is gone

Of the five cross-cutting themes McKinsey flags as "new and notable," one is purely about security: the cyber defense window has compressed.

For decades, the gap between vulnerability disclosure and weaponized exploit gave defenders days or weeks to patch. McKinsey says AI has eliminated that buffer. Citing the Zero Day Clock, the report states that more than three-quarters of all vulnerabilities are now classified as zero-day, meaning an exploit exists by the time the flaw is publicly disclosed.

The report backs that up with IBM's 2026 X-Force Threat Intelligence Index: exploitation of public-facing applications rose 44% in a single year, fueling a 49% increase in active ransomware and extortion groups.

More telling is the shift in attack shape. McKinsey points to a sanctioned XBOW test in which an autonomous agent chained dozens of separate exploitation steps to escalate a single low-severity flaw into complete unauthorized file access. Individual vulnerability scans aren't built to catch that kind of path. The report's conclusion is counterintuitive and worth sitting with: defenders may soon face not a visibility problem but a noise problem. The bottleneck shifts from detecting threats to separating real ones from the flood.

McKinsey also cites Anthropic's handling of Claude Mythos Preview, which identified thousands of potential flaws and was released only to a gated group of defenders through Project Glasswing, and Z.ai's open-weight GLM-5.2, which independent benchmarks found competitive on vulnerability detection. The report's point is that the same capability cuts both ways, and increasingly it isn't confined to a handful of frontier labs.

AI trend #1: agentic software development

Adoption score: 3 (Piloting) · Equity investment: ~$5B in 2025, $61B+ in H1 2026

This is one of two brand new trends in this year's report, and its numbers are staggering. Investment jumped from roughly $5 billion in 2025 to more than $61 billion in the first half of 2026, though nearly all of that is the $60 billion SpaceX acquisition of Cursor (announced, pending close). Job postings more than tripled year over year.

McKinsey estimates agentic development could unlock almost $1 trillion in value. The report is equally clear about the downside. In 30% of companies, productivity fell after teams adopted agentic tools. One study found AI increased coding activity by 180% while shipped releases rose only 30%. And in a line that should alarm AppSec teams, the report warns that AI is producing code faster than human systems can review, test, and deploy it securely, "filling enterprise systems with brittle code."

Developers themselves aren't convinced. Citing Stack Overflow's 2025 survey, McKinsey notes that 46% of developers actively distrust AI tools' accuracy and only 3% highly trust their output.

"The real shift in software engineering is not that agents write code faster," said Martin Harrysson, McKinsey senior partner. "To capture the value from these tools, the software development life cycle operating model has to shift, including moving toward smaller, highly leveraged teams that supervise agents through execution."

The cyber tentacles

  • Unreviewed code at scale – When agents run overnight and across weekends, as McKinsey describes, human review becomes the chokepoint. Security testing has to move to the same asynchronous cadence or get skipped.

  • Agents as privileged actors – McKinsey calls for a "multilayered control architecture" covering access control, isolation, monitoring, human oversight, containment, and recovery. It also lists "harness and guardrail systems" as a core underlying technology. That is a security architecture, whether or not the engineering org calls it one.

  • The CI/CD talent gap – CI/CD skills show a talent-to-demand ratio of just 0.1x, the sharpest shortage McKinsey measured in this trend. The pipeline where security checks live is exactly where qualified people are scarcest.

AI trend #2: agentic AI

Adoption score: 3 (Piloting) · Equity investment: $9.9B in 2025 · Job postings: +952%

McKinsey's research finds 89% of organizations regularly use AI, yet only 37% attribute any positive EBIT (Earnings Before Interest and Taxes) impact to it. Agents are adding cost faster than value: a single agentic workflow can consume five to 30 times more tokens than a standard chatbot query, and 93% of surveyed organizations report exceeding their AI budgets.

The report is unusually direct that agentic AI "requires new frameworks for cybersecurity." As agents become read/write operators inside enterprise databases, they spawn nonhuman identities (API keys, service accounts, machine credentials) that now vastly outnumber human ones. Elsewhere, the report cites Palo Alto Networks data putting that ratio at roughly 100 to 1 in many organizations. McKinsey's framing: companies are treating agents as a new class of identity and access risk, not just another software tool.

"Today's challenge is operationalizing judgment," said Oana Cheta, McKinsey partner. "The defining question of the agentic era is not how autonomous agents can become but how much autonomy the enterprise can safely absorb."

The cyber tentacles

  • Integration is the attack surface – McKinsey highlights the Model Context Protocol and machine-readable interfaces as the fix for connecting agents to legacy ERP and CRM systems. Each connector is also a new trust boundary.

  • Agents are leaving the data center – The report notes the OpenClaw surge, when users reportedly bought up Mac minis to run open-source agents locally. For security teams, that reads as shadow AI with desktop-level permissions.

  • Agentic commerce needs cryptographic trust – With McKinsey projecting up to $5 trillion in agent-orchestrated retail revenue by 2030, payment rails are adapting. Google's Agent Payments Protocol lets purchases be cryptographically verified against what the user authorized. Expect fraud teams to become agent-authorization teams.

  • Orchestration is scarce – Orchestration skills show a 0.2x talent-to-demand ratio. The layer that coordinates agents, and therefore governs what they can touch, is the hardest to staff.

AI trend #3: AI for scientific discovery and engineering

Adoption score: 2 (Experimentation) · Equity investment: $7.9B in 2025, $12.5B in H1 2026

The third new trend is the least obviously "cyber," which is exactly why it deserves attention. McKinsey describes AI shifting from prediction tools to closed-loop systems in which models generate hypotheses, robots run experiments, and orchestration software feeds results back into the model. Examples range from Berkeley Lab's A-Lab to Ginkgo Bioworks giving GPT-5 access to a Boston cloud lab, which after six experimental cycles cut cell-free protein synthesis costs by 40%.

"Scientific AI is no longer just about computational prediction," said Alex Devereson, McKinsey senior partner. "It is about tightening the feedback loop between generative models and physical labs."

The cyber tentacles

  • The crown jewels are data – McKinsey calls scientific data "a strategic asset," and the most valuable IP in pharma and materials is increasingly the training data and model weights, not just the molecule. That makes R&D environments prime targets for espionage.

  • Shared data, shared risk – The report describes consortium data pooling, population-scale biobanks in Iceland, the UK, and the U.S., and federated learning initiatives like Eli Lilly's. Every one expands the number of parties that must be trusted with sensitive genomic and health data.

  • Remote labs are cyber-physical systems – When scientists "rent" lab functionality through platforms like Emerald Cloud Lab, an orchestration compromise isn't just a data breach. It can mean tampered experiments or corrupted results that propagate into drug pipelines.

AI trend #4: AI infrastructure and model architectures

Adoption score: 4 (Scaling in progress) · Equity investment: $145B in 2025, ~$384B in H1 2026

This is where the money is. AI infrastructure was the most searched trend in 2025, and at its current pace full-year 2026 investment would reach roughly $769 billion. McKinsey projects data center capex could approach $7 trillion worldwide by 2030, and U.S. power demand tied to AI infrastructure rising from about 30 gigawatts in 2025 to more than 90 by 2030, roughly California's current demand.

"As AI capability advances, the scaling constraint moves into the physical stack," said Pankaj Sachdeva, McKinsey senior partner. "For leaders, AI scale is now an infrastructure and resilience agenda."

McKinsey includes a development explicitly labeled "cyber-resilient AI architectures," calling for AI-native controls such as prompt-injection guardrails, tool-use authorization for autonomous agents, and verification of multistep reasoning before execution. It also notes renewed interest in "neurosymbolic" AI for high-stakes domains including cybersecurity, where explainability matters.

The cyber tentacles

  • Critical infrastructure convergence – When data centers become 14% of U.S. power demand by 2030 (up from 3% in 2022), the AI build-out and grid security become the same conversation. McKinsey reports more than 2,500 gigawatts of energy projects stalled in grid queues and transformer lead times exceeding two years.

  • Supply chain as geopolitics – The report details China halting shipments of gallium, dysprosium, terbium, and yttrium to Japan for months in 2026, U.S. deliberation over restricting Chinese open-weight models, and TSMC raising its planned U.S. investment to $265 billion. It also notes ASML is the only company in the world producing the EUV lithography machines needed for chips at 3nm and below. Hardware provenance is now a risk-register item.

  • Open weights, on-prem, and a wider threat pool – Moonshot AI's 2.8-trillion-parameter Kimi K3, which McKinsey reports approaches frontier performance, and the broader rise of open-weight models expand deployment options for enterprises. They also expand the pool of capable models available to adversaries and complicate model-provenance decisions for security teams.

The dedicated chapter: what McKinsey says about cyber itself

Adoption score: 4 (Scaling in progress) · Equity investment: $77.5B in 2025, ~$63B by mid-2026

Cybersecurity and trustworthy systems remains one of the most heavily funded trends, though investment is still below its 2022 level. McKinsey reads the modest patent and research growth as a sign of a mature field in sustained deployment rather than a breakout phase.

The chapter's thesis: security is no longer only about keeping bad actors out; it is about building the trust layer required for agents, distributed cloud, and machine-to-machine interactions to operate verifiably. Enterprises need to know who authorized an action, whether an agent stayed in scope, and how delegation flowed across systems.

The M&A trail McKinsey assembles tells the story on its own:

  • Google/Wiz – integrated cloud and runtime security

  • CrowdStrike/SGNL – real-time access decisions for people, machines, and agents

  • Cisco/Astrix Security – identity oversight for agents and machine credentials

  • Palo Alto Networks/Portkey – AI gateway and runtime protection

  • Cyera/Oasis Security ($1B) – data security unified with nonhuman identity governance

  • Proofpoint/Acuvity – governance over how employees and agents use gen AI, extending to MCP servers

  • Keyfactor/InfoSec Global – cryptographic inventory ahead of "Q-Day"

On quantum cryptography, McKinsey says "harvest now, decrypt later" has moved from speculative research to active enterprise planning, with NIST's finalized post-quantum standards serving as the migration starting point for governments, banks, healthcare, and critical infrastructure.

"As the time between vulnerability identification and exploitation vanishes," said Marc Sorel, McKinsey partner, "bug bounty programs, fraud-analytics-quality incident response, and forward-deployed, engineer-led delivery of just-in-time cybersecurity solutions for enterprise agentic deployments all become more important for providers and customers."

Roger Roberts, McKinsey partner and one of the report's authors, reframes the whole discipline: "Cyber and trust are often framed as defensive disciplines, but they also determine how much value technology can create. That is why trust belongs in the value case, not just the risk register."

One of the report's most useful findings for security leaders is buried in the skills charts. In cybersecurity, the sharpest gaps are in AI skills (0.3x talent-to-demand) and CI/CD (0.1x). The same CI/CD shortage shows up in agentic software development and in AI infrastructure.

Put simply: the people who can secure AI and the people who can secure the pipelines that ship AI-generated code are the two scarcest profiles McKinsey measured. Meanwhile, cyber hiring has stabilized after its postpandemic contraction, with 2025 marking the first year-over-year increase and a more balanced mix across compliance, operations, and commercialization than most other trends.

What this means for security leaders

McKinsey's big-picture warning is that AI "is the most powerful accelerant in recent history," and "its speed is also its biggest obstacle." For CISOs, that translates into five practical priorities:

  • Plan for machine-speed exploitation – Patch cycles measured in weeks are obsolete. Invest in continuous runtime inspection, automated containment, and triage that can filter chained-attack noise.

  • Treat every agent as an identity – Register it, scope it, log its delegations, and revoke it in real time. The 100-to-1 machine-to-human ratio makes this the new center of IAM.

  • Get a seat in the SDLC redesign – If engineering is moving to "smaller, highly leveraged teams that supervise agents," security review has to be designed into that operating model, not bolted on.

  • Extend the threat model to the physical stack – Power, chips, rare earths, and model provenance now belong in board-level risk conversations alongside ransomware.

  • Make the value case, not just the risk case – As Roberts argues, trust determines how much value AI creates. With only 37% of companies seeing EBIT impact from AI, security that enables safe adoption is a business lever.

The report's final framing applies squarely to this community: leaders who understand the patterns behind technological change will shape the future rather than react to it. In 2026, nearly every one of those patterns runs through security.