This piece unpacks KPMG's list of top CISO considerations for 2026, with non-human identity governance flagged as a critical emerging problem: machine credentials, service accounts, and AI agents now outnumber human identities in most enterprises. That shift demands a fundamentally different lifecycle governance approach than traditional user identity management.
 
It also describes autonomous security agents increasingly embedded in SOC workflows, compliance processes, and identity management, which is shifting the skillset CISOs need on their teams toward agent oversight rather than manual triage alone. Post-quantum cryptography migration is described as now an explicit regulatory program in multiple jurisdictions, with finance and defense facing the most immediate pressure to act.

The report's broader thread is expanding scope: physical-cyber convergence, AI safety, and enterprise resilience are named as considerations that make the other priorities executable in practice. For CISOs, the practical implication is that identity governance, vendor risk, and AI oversight are converging into a single program rather than remaining separate initiatives.