I get a version of the same question at every keynote. What should I be worried about that I'm not already worried about?

Executives ask this because they are drowning in tactical concerns. Ransomware. Cloud misconfiguration. Insider risk. Vendor breaches. And they can feel that something larger is being missed. They are right. The next decade will not be defined by the incidents on today's dashboards. It will be defined by three technologies that are quietly changing what sensitive means.

1. Quantum. The confidentiality horizon collapses.

The most-covered of the three is quantum. Even so, its implications are still under-appreciated in most boardrooms. The conversation fixates on the day a working machine appears, which lets executives file it as a future problem.

The actual change is more radical. Quantum eliminates a foundational assumption that security programs have relied on for thirty years. The assumption that today's ciphertext will be safe indefinitely if the algorithm is strong enough. Under quantum, that assumption inverts. Every RSA-encrypted or elliptic-curve-encrypted blob you produce today has a decryption date. Unknown. Real. Somewhere in the next decade or two.

This is why harvest-now-decrypt-later is not a marketing frame. It is the actual threat model. Adversaries do not need working quantum today to benefit from it tomorrow. They need patience and storage. Both are cheap.

The category shift is this. Confidentiality is no longer a property of the algorithm. It is a property of the algorithm times the shelf life of the data. Once you see that, your data classification schema starts to look wrong. "Confidential" and "highly confidential" mean nothing without a time horizon. Every long-lived data class needs to be reevaluated through this lens. Medical records. IP. PII. Financial contracts. All of it.

2. Agentic AI. The identity and provenance perimeter dissolves.

The second technology is the one moving fastest inside enterprises right now. And the one where governance is furthest behind.

For the entire history of enterprise security, identity has been anchored to humans and to the systems humans operate. Users authenticate. Services get service accounts. Machine identities are enumerated and rotated. The whole scaffolding of least-privilege access, audit logging, and incident forensics assumes a bounded set of authenticating principals, each of whom can, in principle, be interviewed after the fact.

Agents break that assumption. A single agent instance may spin up hundreds of ephemeral sub-agents in an afternoon. Each requesting credentials. Each calling external tools. Each generating outputs consumed by other agents. In the last eighteen months, the number of entities acting on behalf of your organization has quietly become uncountable in many enterprises. Provenance. Who did this. On whose authority. With what input. Often unreconstructable after the fact.

This is the second category shift. The boundary of the organization is no longer the set of humans and systems on the org chart. It is the fluid, expanding set of autonomous processes acting under organizational authority. Every one of those processes is a potential source of harm. A potential vector for compromise. A potential subject of a regulatory inquiry your team cannot answer.

The security programs that will handle this well are the ones that treat agents as first-class identity subjects. With attestation. With scoped credentials. With immutable audit trails. With kill switches. Almost no one is there yet. Most are still discovering how many agents are already running inside their walls.

3. Biometric and genetic data. The non-rotatable perimeter.

The third technology is the least discussed. In the long arc, the most consequential.

Cybersecurity has always operated on the implicit assumption that any given secret can, in extremis, be rotated. Passwords change. Certificates rotate. Tokens expire. Even Social Security numbers, awkwardly, can be reissued. The response playbook to a breach ends with "and we rotated the affected credentials." That assumption is a load-bearing wall of the entire discipline.

Biometric and genetic data breaks that assumption completely. You cannot rotate a fingerprint. You cannot rotate a face. You cannot rotate a retina. You absolutely cannot rotate a genome. Not for the person the genome belongs to. Not for that person's biological relatives, whose genomes now leak information about them too.

In the last five years, the volume of biometric and genetic data collected, stored, and shared across consumer platforms, healthcare providers, employer wellness programs, and third-party analytics firms has grown by orders of magnitude. Very little of it is protected to the standard the underlying sensitivity requires. The security industry has not yet fully internalized the shift.

The category shift here is stark. We are, for the first time, generating sensitive data whose sensitivity outlasts the person it describes. A breach of genetic data in 2028 is a breach for the great-grandchildren of the affected individuals. The traditional cybersecurity vocabulary of "impact," "remediation," and "resolution" simply does not apply.

What connects the three

These technologies look unrelated on the surface. Quantum is math. Agentic AI is systems. Biometric and genetic data is policy. But they share a single deeper pattern that ought to structure how we prepare for all three.

Each one changes the temporal footprint of harm. Quantum makes today's data breachable a decade from now. Agentic AI makes the perpetrator of a harm impossible to identify after the fact. Biometric and genetic data makes the harm from a single breach permanent. In all three cases, the classic security instinct (contain the incident, remediate the damage, move on) is inadequate. There is no moving on from a genetic data breach. There is no remediation of a harvested archive. There is no root cause of an autonomous agent's cascading actions.

The security leaders who matter most in the next decade will not be the ones who managed incidents most efficiently. They will be the ones who saw these category shifts early enough to change what their organizations built. And stored. In the first place.

A personal note on why this matters

I do a lot of work with survivors of cyber-trafficking. People trapped in scam compounds across Southeast Asia, forced under threat of violence to run fraud operations for the profit of criminal syndicates. The technology in those operations is not exotic. Off-the-shelf messaging platforms. Cryptocurrency rails. Deepfake video. Increasingly, agentic AI to scale the outreach. Every one of these tools was built for something else, by people who could not have imagined the downstream harm.

That pattern is not an exception. Technology harm is almost always downstream of technology change. It almost always lands first on the people with the least power to protect themselves. True of quantum. The people whose medical records are being harvested today rarely know it. True of agentic AI. The first casualties of unaccountable autonomous systems are almost never the C-suites deploying them. True of biometric data. The populations most surveilled are the ones with the least legal recourse.

If there is one reason to work in cybersecurity right now, beyond the intellectual pleasure of the work, beyond the compensation, beyond the sheer interest of the moment, it is this. Cybersecurity is one of the very few fields where the practitioner's day-to-day work directly reduces human suffering. The token rotation you enforce. The algorithm you migrate. The audit log you preserve. The biometric database you decline to build. These are not abstractions. They are the difference between a life protected and a life exposed.


The next generation of cybersecurity leaders will be judged on what they anticipated. The three technologies I've named are not the whole story. They never are. But they are the axes along which the meaning of "sensitive" is being rewritten. Get them right and you will have contributed something durable to the field. Get them wrong and the incidents of 2035 will trace back, with clarity, to the choices we made in 2026.

The optimism I hold is this. The people who see this most clearly are, in my experience, also the people who care most. That is not a coincidence. The work draws them because the work matters.

Lekshmy Sankar, PhD