Shifts in attacks are altering how and what security is being purchased
It’s understandable that an IT decision maker might be resistant to dire warnings coming from a sales rep regarding an impending cyberattack on their infrastructure. That’s less a matter of “crying wolf” and more a matter of “Yeah, we’ve heard that many times before.”
Nonetheless, a cavalier approach to cybersecurity often leads to tragic consequences. There’s no denying that AI-enabled attackers are smarter and faster than ever, while AI applications, cloud services, SaaS sprawl and remote workers and their devices are introducing new exposures at speeds and distances that traditional security approaches weren’t always expected to handle. So, it’s also completely understandable that security leaders are responding to the new realities of dynamic risk with changes to how they source security solutions, what they buy and where their priorities lie.
Indeed, many organizations are currently reviewing and rethinking their security stacks and the vendors that provide them. According to one survey of cybersecurity decision makers by technology marketing company The Hoffman Agency, three in five respondents are looking either for a new provider or to switch a provider in the coming year. The top reason cited by those preparing to switch was “the need to respond to threats,” cited by 55 percent of respondents and compounded by the 38 percent that said it was “the need to secure AI systems.” As the Hoffman Agency noted, both responses were chosen at a higher rate than the need to reduce costs or cope with talent shortages.

Also worth noting, while 31 percent of organizations said they are looking to change providers because their current provider isn’t good enough, dissatisfaction was the least popular driver for new cybersecurity purchases. This tends to suggest that a provider often may get little indication when a customer is about the churn, emphasizing the importance of proactive customer service and quality control.
When asked to consider the attributes that have the biggest impact on the selection of a vendor, the top answers included “value for the money” and “simple and easy to integrate,” both named by nine out of 10 respondents, followed by evidence of delivering for similar business (87 percent) and flexible in adjusting to needs (84 percent).
In terms of investment moving forward, the survey revealed some significant shifts in priorities. Of course, “AI security,” which only 8 percent invested in last year, was the top area of intended purchase for the coming 12 months, cited by 30 percent of respondents. Likewise, data security posture management took a leap in importance, while network security and email security, and to a lesser degree endpoint security, went from top priorities to the bottom of the list. Certainly, some of the dip in those key areas of protection is due to assumptions that prior investments have taken care of those threat vectors. Even so, partners and providers cannot assume that a high-demand or low-demand service last year will have the same demand during the next 12 months.

Any shift in security product selection moving forward will be commensurate with the shifts in how bad guys are now attacking corporate resources. A traditional approach to dealing with emerging threats has been to deploy another point tool, argued Jeannine Edwards, senior director, Cynet Community, in the company’s Global AI Security Readiness Report. “This leads to more noise, alert fatigue, tooling customization and fragmented defense,” she continued. “Today’s attacks are paths, not points.”
Modern attacks, as Cynet executives pointed out, are now comprised of coordinated chains of strikes, engineered to find the path of least resistance across an ever-expanding attack surface. And identity has become the most prevalent path for attacker success, research suggests.
During the past year, identity weaknesses played a material role in 90 percent of the security breaches investigated by Unit 42, the research arm of Palo Alto Networks.”In our caseload, identity shaped intrusions end to end. It served as the way in, the path to privilege escalation and the mechanism for lateral movement using valid access,” said Unit 42 in its most recent Global Incident Response Report.
As organizations move deeper into SaaS, cloud and hybrid environments, the network perimeter matters less, argued the report. Identity – or the linkage between users, machines, services and data – has become the practical perimeter.
“In many cases, threat actors don’t need a sophisticated exploit chain. They log in with stolen credentials, hijacked sessions or mis-scoped privileges,” said Unit 42 researchers.
These types of “authenticated accesses” let adversaries move faster, blend into normal activity and expand their area of impact with fewer obstacles.
“This trend is accelerating as machine identities, embedded AI applications and fragmented identity estates expand the number of access paths attackers can exploit,” the report continued.
Unit 42 case data shows that 65 percent of initial access is driven by identity-based techniques.
This new reality has not gone unnoticed. Identity security was repeatedly cited among the top three security priorities among both the MSSPs and in-house IT teams surveyed by Cynet.

Researchers also have noted, in response to accelerating threats, a rebalancing of investment from traditional detection/response solutions that work downstream after an event has occurred to preemptive and predictive threat intelligence that can get ahead of AI-driven attacks. Newer, smarter preemptive security works to identify externally exposed and high-risk assets before an attack, prioritize exposures based on real-world threat activity and disrupt malicious invasions earlier in the attack lifecycle.
According to surveys of cybersecurity professionals performed for Infloblox, nearly half of organizations expect to allocate security tools toward preemptive controls during the next 12 months, expecting an almost even split between preemptive security (49 percent) and traditional detection/response (51 percent) within that same time period.

Compared with the past year, the share of preemptive tools has risen by an average of 12 percent, as 82 percent of respondents report increasing their use of preemptive security tools year over year.
“Organizations are no longer choosing between detection and prevention,” said Infoblox researchers. “They are seeking ways to connect digital risk intelligence, exposure management and foundational controls into a more continuous, proactive approach.”
Crunch Time
In addition to changes in what businesses are buying in reaction to faster, smarter and more dynamic threats, they are adjusting how they purchase, showed The Hoffman Agency surveys. Most notably, the buyer journey has shrunk as the usual process of awareness, longlisting, shortlisting and decision-making is being streamlined in order to make purchasing decisions more quickly, said Florie Lhuillier, head of cybersecurity and senior vice president at The Hoffman Agency.
Looking at the time from when the need for a cybersecurity solution is identified to deciding what vendor can deliver, purchases take seven months, on average. And some outliers are skewing that number up. The majority of respondents (55 percent) said they take less than six months, while just 15 percent take more than a year, on average. An additional 15 percent claim to take less than three months.

Given the complexity of the category, the level and importance of the investment and a buying circle that can include both technology and C-level decision makers, these are fast decisions being made. But buyers clearly are feeling a sense of urgency created by today’s evolving threat landscape. That sense of urgency, and the resultant compressed buying journey, may be pushing more businesses to seek the help of outside technology advisors and consultants to identify and select vendors, The Hoffman Agency surmised. Just 1 percent of buyers surveyed did not employ an outside agency – whether analysts, advisor, MSP or consultant – at some point in the buying process.
According to findings from Cynet, about six of every 10 internal IT teams surveyed plan to involve an MSP when adopting new security tools. That includes 64 percent when it comes to cloud and Saas security and 61 percent in the case of agentic AI.
“The preference for adopting new tools through either a hybrid approach or MSPs is becoming more pronounced, reflecting a strategic shift in how organizations manage their cybersecurity needs,” said Cynet researchers.
This trend is at least partly driven by the fact that MSPs are further along the AI learning curve, with a significant portion of MSPs already integrating AI technologies into their security operations, showed the Cynet data. Indeed, MSPs had higher rates of AI usage (60 percent, on average) compared to in-house teams (44 percent on average) across every AI-related security product listed.
“While running AI security in-house at an SMB will technically be possible in 2026 and beyond, strategically it will be hard to defend,” Cynet researcher argued. “MSPs have the delivery channel, are 13 to 16 percentage points ahead on every AI capability and have the scale which most in-house teams lack.”

The good news for partners and providers is that businesses are not shifting dollars around to deal with an evolving threat landscape; the majority are increasing security budgets. In addition to the 60 percent of organizations that increased their budget in the last 12 months, 67 percent expect to see an increase in the next 12 months, showed The Hoffman Agency figures. Cynet, for its part, found that 78 percent of internal IT teams expect cybersecurity budgets to grow.
Those estimates could even be conservative, considering that 96 percent of security professionals surveyed by Infoblox reported challenges managing threat exposure, driven by rapid expansion in cloud services, SaaS applications, IoT/OT systems and shadow IT. Cloud exposure alone is the top priority for more than half of security teams, reflecting how quickly risk is shifting beyond traditional enterprise boundaries, said the Infoblox study.
Put together, research suggests that many organizations will be reviewing and rethinking their security stacks and the vendors that provide them. Partners and providers that can articulate and understand the challenges presented by today’s dynamic and morphing threat landscape stand the most to gain.










