2026 Threat Landscape Reality Check: Turning Threat Intelligence Into Analytic Advantage

SANS Digital Forensics and Incident Response
SANS Digital Forensics and Incident ResponseMay 22, 2026

Why It Matters

Understanding the identity‑centric threat shift enables businesses to redesign defenses around credential security, reducing breach risk as attackers exploit legitimate access in a geopolitically charged environment.

Key Takeaways

  • Identity-based attacks now dominate threat landscape, surpassing malware.
  • CTI must shift focus from indicators to credential abuse detection.
  • AI tools augment but cannot replace human analyst judgment.
  • Live, unscripted formats foster authentic community learning and insight.
  • Geopolitical conflicts increasingly intertwine with cyber operations globally.

Summary

The SANS "Threat Analysis Rundown" live stream highlighted a pivotal shift in 2026: identity‑based intrusions have become the primary attack vector, eclipsing traditional malware. Host Sean O'Connor, joined by veterans Rebecca Brown and John Doyle, referenced recent reports—CrowdStrike, Unit 42, Microsoft—showing 80‑90% of detections now involve credential misuse. Key insights included the rise of credential theft and information‑stealing as defenders harden perimeter defenses, pushing adversaries toward legitimate logins. The panel stressed that AI can streamline data collection but cannot substitute human judgment, warning against over‑reliance on automated summaries. Community evolution was also noted, with the STAR series moving from scripted webcasts to authentic, unscripted live discussions. Notable moments featured Katie Nichols reflecting on past over‑complication of threat intel and John Doyle emphasizing how defensive actions unintentionally create new attack surfaces. Rebecca highlighted the pandemic‑driven remote‑work boom as a catalyst for identity exploitation, while participants underscored the growing overlap of geopolitical conflict and cyber operations. Implications are clear: CTI teams must prioritize credential‑focused detection, integrate AI as an assistive tool, and maintain skilled analysts to interpret nuanced threats. Organizations that adapt to the “identity is the new perimeter” paradigm will better safeguard assets amid an increasingly politicized cyber landscape.

Original Description

This introductory episode of STAR welcomes new host Sean O’Connor, with former host Katie Nickels joining for a special handoff conversation. Together with guests Rebekah Brown and John Doyle, they will examine insights from recent 2026 threat reports and what those findings reveal about today’s evolving cyber landscape.
The conversation will also explore what these shifts mean for modern intelligence teams and how building a strong foundation in intelligence work, combined with a clear understanding of how attackers operate, helps organizations turn threat information into smarter security decisions and stronger defenses.
Join us for a focused look at how to turn 2026 threat reporting into meaningful analytic advantage.

Comments

Want to join the conversation?

Loading comments...