KPMG’s 2026 cybersecurity report names non-human identities as one of eight load-bearing risks for the year, drawn from interviews with more than 20 KPMG cyber leaders and senior executives at Google, Microsoft, Palo Alto Networks, the AI-and-network-security vendor, and ServiceNow, the workflow automation platform. The argument the cybersecurity report lands hardest for CISOs: AI agents, service accounts, and machine credentials now outnumber human users inside most enterprises, and the identity-governance practices built for humans do not survive that ratio. The other seven considerations cycle around the same problem of scale, from post-quantum cryptography migration to IT/OT hyperconnectivity. - Non-human identities now outnumber humans in most enterprise environments, demanding lifecycle governance for service accounts, AI agents, and machine credentials. - Autonomous security agents are moving into the security operations center (SOC), compliance workflows, and identity management, shifting workforce skills toward agent oversight. - Post-quantum cryptography (PQC) migration is now an explicit regulatory program in multiple jurisdictions; finance and defense face existential pressure to act. - Supply-chain attack surface keeps expanding into AI and IoT, pushing third-party risk management toward continuous monitoring instead of annual review. - The CISO mandate has broadened to cover physical-cyber convergence, AI safety, and board-level resilience reporting. What the KPMG 2026 cybersecurity report puts on the CISO desk The full report, available as a downloadable PDF on the KPMG site, is organized around eight considerations: preparing the cyber workforce for autonomous security; navigating geopolitics, resilience, and compliance; safeguarding AI systems; managing non-human identities; enabling trusted IT/OT hyperconnectivity; transitioning to post-quantum cryptography; protecting the supply chain through detection and response; and broadening the role and influence of the CISO. KPMG pulls together insights from a global panel that includes its own cyber partners plus named senior executives at Google, Microsoft, Palo Alto Networks, and ServiceNow, supplemented by findings