10 Years in Cybersecurity: What Changed – and What Didn’t 

Ten years is a long time in cybersecurity.

When AMATAS started in 2016, ransomware was already a threat, cloud adoption was accelerating, and organizations were struggling with vulnerabilities, phishing, and increasingly sophisticated attackers.

Fast-forward to 2026 and much of that sounds surprisingly familiar.

But underneath, a lot has changed.

Attackers move faster. IT environments are more distributed. Regulations place greater responsibility on organizations and their leadership. Security teams have more technology at their disposal, but also more infrastructure, identities, data, and alerts to manage. And AI is beginning to change what both attackers and defenders can automate.

This year, AMATAS turns 10.

Rather than simply looking back at where we’ve been, we wanted to look at what those 10 years have taught us about cybersecurity- and what we believe will matter in the decade ahead.

1. The attack surface no longer stands still

Ten years ago, a penetration test could provide a relatively stable snapshot of an organization’s security posture. Today, that snapshot can become outdated remarkably quickly.

Cloud infrastructure changes. Applications are updated. New integrations are introduced. Employees join and leave. Permissions change. New vulnerabilities are disclosed.

An environment tested several months ago may look very different today.

That’s one reason security testing itself is changing. Point-in-time assessments remain important, but organizations increasingly need testing that follows meaningful changes in their environment.

The question is shifting from “When was our last penetration test?” to “What has changed since we last tested?”

2. Finding vulnerabilities is only part of the job

Over the years, penetration testing has become considerably more accessible. Automated scanners can identify large numbers of potential weaknesses, and AI is beginning to accelerate parts of the testing process even further. 

But more findings don’t automatically create better security. 

Organizations still need to understand which vulnerabilities are genuinely exploitable, which present meaningful business risk, what should be fixed first, and whether remediation actually worked. 

This is where human expertise remains critical. 

The goal isn’t to produce the longest vulnerability report. It is to provide the depth and accuracy organizations need to make better security decisions. 

3. Prevention alone isn’t enough

For years, cybersecurity strategies focused heavily on keeping attackers out. That remains important. But experience has repeatedly shown that organizations also need to answer another question: What happens when someone gets in? 

Can suspicious activity be detected? Will the security team recognize the attack? Can they determine what happened? Can they contain it before the impact grows? 

This shift has made detection and response a fundamental part of modern security programs. 

It has also changed how security needs to be tested. Approaches such as Red Teaming and Purple Teaming don’t only ask whether an attacker can compromise an environment. They examine whether defenders can see and respond to realistic attack techniques while they are happening. 

4. More security technology doesn’t necessarily mean more security

The cybersecurity industry has produced an extraordinary number of tools over the past decade. Organizations now have technologies for endpoint protection, identity, cloud security, vulnerability management, detection, threat intelligence, email security, data protection, and almost every other part of the security stack. 

But technology alone has never solved the problem. 

We’ve seen repeatedly that the value of a security tool depends on how it is configured, monitored, integrated, and used by people who understand both the technology and the organization around it. 

Sometimes the challenge isn’t buying another security product. It’s making the existing security ecosystem work as one. 

5. Cybersecurity has become a business issue

One of the biggest changes since 2016 has happened outside the security team. 

Cybersecurity is increasingly discussed at management and board level. Regulations such as GDPR, NIS2 and DORA have contributed to that shift, but regulation isn’t the only reason. Cyber incidents can interrupt operations, affect customers, create financial losses, damage relationships with partners, and require difficult decisions from senior leadership. 

As a result, the conversation is moving beyond: “Are our systems secure?” toward questions such as:  

  • “What cyber risks could materially affect our business?” 
  • “Which risks are we willing to accept?” 
  • “Are we prepared to respond?” 
  • “Can we demonstrate that we’re managing those risks appropriately?”

That’s a much more mature conversation than the one many organizations were having ten years ago. 

6. Compliance and security are connected – but they aren’t the same thing

The regulatory landscape has changed dramatically. 

GDPR, NIS2, DORA and industry-specific requirements have pushed cybersecurity higher on the organizational agenda and established clearer expectations around risk management, incident response, resilience, testing, and governance. 

That’s positive. 

But ten years of security work have reinforced an important lesson: Passing an audit doesn’t necessarily mean an organization is secure. 

Compliance provides structure and accountability. Effective security requires organizations to understand how those requirements translate into their actual environment, risks, people, processes, and technology. 

The strongest security programs use compliance as a baseline – not the finish line. 

7. Cybersecurity is becoming continuous

Many traditional security activities were built around schedules. 

  • Annual penetration tests.
  • Quarterly vulnerability scans.
  • Periodic risk assessments.
  • Annual awareness training.

But attackers don’t operate according to those schedules. 

As environments become more dynamic, security is increasingly moving toward continuous processes: continuous monitoring, recurring testing, ongoing vulnerability management, continuous improvement of detection capabilities, and regular reassessment of risk. 

The direction is clear. 

Security is becoming less about periodically proving that controls exist and more about continuously understanding whether they actually work. 

8. AI is changing the speed of cybersecurity

AI is changing how quickly security work can be performed. 

Tasks that once required significant manual effort can increasingly be accelerated or automated – from analyzing large volumes of security data to identifying vulnerabilities and supporting investigations. 

In offensive security, this development is particularly significant. Agentic systems can move beyond individual automated tasks and execute sequences of actions toward a defined objective. 

For defenders, this creates both opportunities and new risks. Faster testing can help organizations identify weaknesses sooner, but greater autonomy also requires clear boundaries, oversight, and accountability. 

The next challenge will be finding the right balance between machine speed and human control. 

9. The fundamentals haven’t changed as much as we think

Attackers have more sophisticated tools than they did ten years ago. They automate more, move faster, and continuously develop new ways to evade defenses. 

Yet many successful attacks still depend on weaknesses security teams have known about for years. Unpatched vulnerabilities. Weak or stolen credentials. Excessive privileges. Misconfigured systems. Limited visibility. Slow detection. 

The attack may look different in 2026, but the door it entered through may be surprisingly familiar. For organizations, that makes consistent execution just as important as adopting the latest security technology. 

10. Security is ultimately about resilience

Perhaps the biggest lesson from the past decade is that perfect security doesn’t exist. 

Organizations will introduce vulnerabilities. People will make mistakes. Attackers will discover new techniques. Technology will fail. The goal therefore cannot simply be to prevent every possible incident. 

A resilient organization can reduce the likelihood of an attack succeeding, detect malicious activity quickly, respond effectively, recover operations, learn from what happened, and improve. That requires more than technology. 

It requires testing, monitoring, governance, preparation, expertise, and cooperation across the organization. 

What will the next 10 years look like? 

Predicting technology ten years ahead is difficult. But several directions are already visible. 

AI will give attackers and defenders greater automation. Security testing will become more continuous. Detection and response will need to operate faster. Cybersecurity regulation will continue pushing security into executive decision-making. And the boundary between human and autonomous security operations will become increasingly important. 

The tools will change. The fundamental objective won’t. 

Organizations will still need to understand their risks, test their defenses, detect what gets through, respond when something goes wrong, and continuously improve. 

AMATAS has spent the past ten years helping organizations do exactly that. 

We’ve watched the industry change, built new capabilities as those challenges evolved, worked alongside clients during security assessments and real incidents, and learned a great deal along the way. 

As we mark our tenth anniversary, we’re proud of that history. But we’re much more interested in what comes next.

Related Articles

Scroll to Top