Cybersecurity trends 2026
Trusted Advisor for IT & Telecommunications Sourcing
From optional to mandatory: what shifted in IT security in 2026
Six developments that force procurement decisions in 2026
For a long time cybersecurity was a question of prioritisation. In 2026 it is, in key areas, a question of legal compliance. The German NIS2 implementation act applies without a transition period, AI is shifting attack dynamics, and the security architecture has to carry both at once.
In a nutshell:
- NIS2 is binding: in force since 6 December 2025, no transition period, around 29,500 affected entities and personal liability for management.
- AI becomes an actor: attacks increasingly run autonomously, and a company’s own AI systems become an attack surface themselves.
- Post-quantum begins: the German BSI sets a timeframe through 2031, and the crypto inventory is the first step.
- Zero Trust becomes operational: the jump from concept paper to enforced daily operations decides the benefit.
- The stack consolidates: point solutions give way to SASE and SSE platforms, driven by operational effort.
- Resilience beats prevention: the question is no longer only whether an attack is stopped, but how quickly operations continue.
The solution: examine each of these points for the concrete procurement or architecture decision behind it. SAVECALL evaluates platforms and carriers vendor-neutrally and plans the setup that fits your infrastructure.
What this article covers: the six developments in detail, each with the question of what follows operationally. The core question: which of these already apply to your company as binding obligations, and which are still lead time?
The threat situation in Germany is well documented in numbers. The BSI registers an average of 119 new vulnerabilities per day, and Bitkom put the annual total damage from cyberattacks at around 289 billion euros in its 2025 economic protection study. More interesting than the figures is the shift behind them: what was still a recommendation in 2023 is now, on several points, a legal obligation or a technical necessity with a deadline attached.
1. NIS2 applies, the obligation is here
The German NIS2 implementation act came into force on 6 December 2025, with no transition period for the technical and organisational measures. The registration deadline with the BSI expired on 6 March 2026. Around 29,500 entities across 18 sectors are affected, compared with roughly 4,500 previously under BSI supervision.
What is new is above all that this is binding for mid-sized companies. As a rule of thumb: from 50 employees or 10 million euros in annual revenue in a regulated sector. Fines reach up to 10 million euros or 2 percent of global annual revenue, and management is personally liable. Reporting deadlines are tight: 24 hours for an early warning, 72 hours for an initial report, one month for the final report.
What follows from this: two of the ten core measures under the revised BSI act directly affect network procurement, namely supply chain security and contingency planning. Anyone buying connectivity is also buying compliance evidence, or failing to. Even so, according to the Cyber Security Report 2026, around half of the companies surveyed underestimate their own regulatory exposure.
2. AI becomes an actor, not just a tool
The decisive change of the past twelve months is not that attackers use AI. They did that before. What is new is that AI systems carry out attack steps themselves. On 22 June 2026 the BSI published a cybersecurity warning on the impact of AI development on the threat situation, rated criticality 2 of 4. Its core message: AI lowers the effort, time and entry barriers for offensive capabilities. From published patches, patch diffing can reveal within minutes to hours what an exploit needs to look like.
The practical consequence for vulnerability management: CVSS base scores alone are no longer sufficient as a basis for prioritisation, because AI can chain several individually uncritical vulnerabilities into one attack path. The BSI recommends adding environment-dependent risk, for example via the CVSS 4.0 environmental metric and complete inventory lists.
The second half of the problem is a company’s own AI usage. An agent that automates campaign analysis needs access to the CRM, the mail platform, customer data and external APIs. Each of those is a potential entry point, and prompt injection turns it into a realistic path: a manipulated email with hidden instructions can make an agent forward confidential content. This is exactly where Shadow AI governance via SASE comes in.
3. Post-quantum: the crypto inventory becomes mandatory
In the 2026 edition of its technical guideline TR-02102-1, the BSI stated for the first time that companies should no longer rely on classical asymmetric encryption alone, and set a timeframe through 2031. The NIST standards have been available since August 2024: FIPS 203 for key encapsulation, FIPS 204 and FIPS 205 for signatures. For the transition phase the BSI recommends hybrid methods that run classical and quantum-safe algorithms in parallel.
The time pressure does not come from quantum computers themselves but from the lead time. A crypto migration in a grown infrastructure is a multi-year undertaking, and the risk is already running: with harvest now, decrypt later, encrypted traffic is captured today and decrypted later. That matters for data with a long confidentiality period, regardless of when capable quantum computers become available.
The first step is unspectacular and therefore often skipped: a complete inventory of all cryptographic dependencies. TLS certificates, VPN tunnels, embedded SSH keys, applications with their own cryptography. Without this inventory there is no way to prioritise, and without prioritisation the migration becomes arbitrary. For network services, the question of a PQC roadmap therefore belongs in every provider evaluation from now on.
4. Zero Trust becomes operational rather than conceptual
Zero Trust is largely accepted as a principle, and Gartner surveys show a broad majority of companies with a started or partially implemented strategy. The interesting gap sits between started and enforced. A Zero Trust concept that grants exceptions for legacy systems in three places is, in effect, a perimeter model with extra overhead.
Operational means: continuous identity verification instead of location-based trust, least privilege including for privileged accounts, and consistent policy enforcement regardless of whether access comes from headquarters, a home office or a mobile device. This is exactly where isolated implementations fail: maintaining a separate rule set per access path produces inconsistencies that become a problem during an incident.
The transition from classical VPN structures to Zero Trust is therefore less a product decision than a matter of operational discipline. What helps is an architecture that knows only one rule set.
5. Consolidation: SASE and SSE instead of point solutions
The driver of stack consolidation is not security but operational effort. Separate systems for secure web gateway, CASB, ZTNA and DLP mean separate rule sets, separate logs and, during an incident, separate support chains. Gartner expects around half of all new SASE deployments to be single-vendor by 2028, compared with roughly 30 percent in 2025.
Technically, inspection thus moves from appliances into a distributed cloud fabric with single-pass inspection at global points of presence. This avoids the latency penalty that arises when traffic has to pass through several separate inspection stages. The path there runs in stages in practice, usually starting with remote access.
The point that regularly gets lost in platform comparisons: SASE only works as well as the underlay. A platform with a first-class policy engine is of little use if site connectivity is the bottleneck. Platform choice and underlay procurement should therefore be evaluated separately and decided together.
6. Resilience instead of pure prevention
The BSI observes that attackers take the path of least resistance and pick the targets with the lowest level of protection. This disproportionately affects small and mid-sized companies. At the same time the BSI warns of a false sense of security: many companies rate themselves well above their actual maturity.
This shifts the metric. No longer only how many attacks were repelled, but how long operations stand still after a successful one. This is also where NIS2 and the new rules of resilience converge: contingency planning is no longer optional but part of the required risk management measures.
In concrete terms: redundant connectivity per site, a tested recovery plan and the ability to stay operational while the actual systems are restored. For the last point, emergency workstations provide an answer that can be arranged contractually in advance instead of being improvised in an emergency.
How SAVECALL supports implementation
Five of the six points end in a procurement decision: which platform, which carrier, which underlay, which SLA. SAVECALL is neither a carrier nor a platform vendor, but evaluates both vendor-neutrally and, with over 80 carrier partners, assembles the setup that fits the existing infrastructure.
- SASE and SSE platform comparison vendor-neutral, including an assessment of the underlay per site
- Security architecture from cyber security and dedicated cloud access through to Zero Trust, modular and combinable
- NIS2-relevant connectivity with highly available internet and documented SLAs
- Emergency workstations as a pre-arranged bridge, available across the DACH region
Conclusion: obligation is the new driver
The technical trends of 2026 are largely continuations. What has changed is their character: NIS2 turns recommendations into obligations with personal liability, the BSI sets a timeframe for post-quantum, and AI shortens response windows. Companies that build these three points into their procurement decisions, rather than parking them alongside as separate security projects, are well positioned for 2026.

Written by
Frank Frommknecht
Key Account Consultant, SAVECALL
Has supported companies for over 20 years in selecting and optimizing their connectivity solutions. His focus: making complex telecommunications understandable from the customer’s perspective and strategically finding the right solution.
Why
Telecom & IT sourcing. Worldwide. Carrier-independent.
Selection & operation of worldwide connectivity & cloud infrastructure. Without vendor risk & unnecessary costs.
- 80+ carriers worldwide
- One point of contact
- One SLA
- One portal: mySAVECALL
- Min. 20% savings
25+
years of experience
40+
Employees
80+
Partner
1400+ Clients
Quellen
- BSI, cybersecurity warning on the impact of AI development on the threat situation, BITS-B no. 2026-262788-1032, 22 June 2026
- BSI, Technical Guideline TR-02102-1, Cryptographic Mechanisms: Recommendations and Key Lengths, 2026 edition
- BSI, The State of IT Security in Germany 2025
- NIST, Post-Quantum Cryptography Standards FIPS 203, 204 and 205, August 2024
- Bitkom, Wirtschaftsschutz (economic protection study) 2025
- German act implementing the NIS2 Directive (NIS2UmsuCG), promulgated in the Federal Law Gazette, December 2025
Frequently asked questions about cybersecurity trends 2026
Six developments shape 2026: the German NIS2 implementation act in force since December 2025, AI acting as an autonomous actor in attacks, the start of post-quantum migration, the operational rollout of Zero Trust, consolidation of the security stack toward SASE and SSE, and the shift from pure prevention to measurable resilience.
Yes. The German NIS2 implementation act has been in force since 6 December 2025, with no transition period for the security measures. The registration deadline with the BSI expired on 6 March 2026. Around 29,500 entities across 18 sectors are affected, and management is personally liable.
Two things at once. Attackers use AI to turn vulnerabilities into usable attack paths far faster. And a company’s own AI systems become targets, for example through prompt injection when an agent has access to CRM, mail and file storage. The German BSI issued a cybersecurity warning on this in June 2026.
Because the lead time is long. In its technical guideline TR-02102-1, the BSI advises against relying on classical asymmetric cryptography alone and sets a timeframe through 2031. The first step is a complete cryptographic inventory, without which no prioritised migration is possible.
The operational burden of separate point solutions is the main driver. Gartner expects around half of all new SASE deployments to be single-vendor by 2028, up from roughly 30 percent in 2025. The underlay remains decisive, though: a SASE platform is only as good as the connectivity beneath it.
SAVECALL evaluates platforms and carriers vendor-neutrally and translates regulatory and technical requirements into a concrete procurement decision. With over 80 carrier partners, the underlay can be combined freely per site instead of being tied to a single provider.


