Basalt Cyber Consulting is now Basalt — On The Frontier Cyber Consulting Read the 2026 Threat Report
2026 Threat Report

On the frontier of cyber security.

How AI-augmented attackers are reshaping identity attacks, code supply chains, and the economics of detection — drawn from Basalt engagements across four markets.

Three shifts to plan for in 2026

1. Identity is the new perimeter — and it’s AI-tested.

Phishing kits with LLM-driven voice, real-time MFA fatigue orchestration, and OAuth abuse have collapsed the gap between “credential stolen” and “tenant compromised”. ITDR coverage is no longer optional.

2. AI features are shipping faster than AI red teams.

Most LLM features in production today were never adversarially tested. Prompt injection chained with tool use is the new RCE — and it routes around the WAF.

3. Detection engineering has compounding returns.

Static rules are now decisively outpaced. Programs that invest in behavioural detection see MTTD fall by an order of magnitude within two quarters.

Reach Out