Fahmida Y. Rashid wrote a 20-year retrospective for Dark Reading (May 2026). If you sit on a board or approve security budgets, it's the clearest explanation I've seen in a long time of how we got here.
She covers the whole arc: from antivirus and firewalls, to the cloud and mobile era that moved our data outside the office, and now to the AI moment. She ends with a point from Ross Haleliuk that stayed with me: "Cybersecurity today looks nothing like it did 20 years ago, but cybersecurity also looks exactly the same." Everything about the work has changed. The fundamentals haven't.
Here's what that means as AI becomes the next big shift.
The perimeter is gone
Our data have left through every exit we ever opened: onto laptops and phones, into cloud apps that never made the inventory, out with employees whose logins still worked after they left, and now into chatbots where people paste whatever's on their screen. I wrote about that last one recently: shadow AI, where anyone can accidentally become a data leak.
After a breach, the question is no longer "did they get in." It's "which identities, which systems, which data."
The money followed the problem off the network. Gartner projects 2026 security spending at about $240 billion, with roughly half going to software and only about a tenth to network security (Gartner, 2025).
The basics still decide who gets breached
Fernando Montenegro of The Futurum Group puts it simply in the article: you can have all the network security in the world, but if everyone has domain admin privileges, there is no point.
That's the core of AI-native security. AI-powered defenses are fast, and they catch things a human SOC might miss. But they're only as strong as your foundations. Point AI at an environment with poor identity hygiene and overbroad access, and all it does is speed up your path to the same breach.
Getting the basics right pays off twice
Get identity and access management right, and know where the sensitive data live, and your AI projects get easier and safer, right alongside your defenses. When the groundwork is in place, AI starts to earn its keep. It scales the work and takes the busywork off your team, so they can build instead of firefight.
MCP, the Model Context Protocol that connects AI tools to your business systems, is the clearest example. Point it at an environment where access is already right-sized and your sensitive data are labeled, and a team moves fast and stays safe. Point it at one where they aren't, and a single connector can reach sensitive data the same afternoon you turn it on.
So do the basics first. Know your identities. Verify who can touch what. Document where the sensitive data live. Get that right, and you make AI work for you instead of cleaning up after it.
Your next step
The next wave is real, and it's already here. How prepared you are depends mostly on the work you've already done.
Thank you to Fahmida Rashid for a piece that resonates. It's a good reminder that the fundamentals still carry the weight, and that the teams who get them right have every reason to be confident about what comes next. If you'd like a clear read on who can touch what and where your sensitive data live before your next AI project, talk with ProCircular. We'll help you find out where you are, so you know exactly what to do next.
