The changing cyber landscape: 5 operator priorities
Insights from conversations at the 2026 Billington CyberSecurity Summit
Artificial intelligence (AI) is accelerating how quickly vulnerabilities can be discovered and exploited. Identity attacks are moving beyond passwords and traditional authentication. AI systems themselves are creating new attack surfaces. Across it all, organizations are balancing greater automation with the need for human judgment, resilience and trust.
Those challenges shaped conversations at the 17th Annual Billington CyberSecurity Summit, which brought together more than 3,500 leaders from government, industry and academia Sept. 8–10 in Washington, D.C. Leidos experts participated in discussions spanning AI, identity security, cyber deterrence and the future of cyber operations.
Here are five takeaways for organizations navigating what comes next:
#1 AI is compressing the cyber timeline
AI isn't simply changing what attackers and defenders can do. It's changing how quickly they can do it.
During a discussion on balancing innovation and risk, Leidos Intelligence’s Chief AI Officer Dr. Dan Taninecz Miller and fellow panelists explored how AI is accelerating both cyber threats and defensive capabilities.
For operators, that can mean having minutes or hours rather than days to understand an emerging threat and determine how to respond. It also increases the importance of faster intelligence sharing, vulnerability disclosure and collaboration between government and industry.
But greater speed doesn't eliminate the need for human expertise. As agentic AI moves from recommending actions toward taking them, organizations need clear boundaries around what can be automated and where human judgment should remain central.
The takeaway: The goal isn't automation for its own sake. It's combining machine speed with the context and judgment needed to act responsibly.
#2 Securing AI requires protecting more than the model
As AI becomes embedded across operations, organizations also have to consider how the technology itself can be targeted.
During a panel on securing machine learning against adversarial threats, Leidos Parcata™ Program Manager Nicholas Vidovich joined a discussion about risks across models, training data and AI infrastructure.
AI systems don't remain static. New data, retraining and fine-tuning can change how models behave, making security validation an ongoing process rather than a one-time checkpoint.
The AI supply chain adds another layer. Third-party models, open-source frameworks, pretrained weights and external datasets can introduce risk before an AI capability reaches an operational environment.
At the same time, AI can strengthen cyber operations. Leidos Parcata™ applies AI to continuously discover, validate and remediate software vulnerabilities.
The takeaway: AI security has to evolve alongside AI itself — from the data and models organizations use to the systems and supply chains surrounding them.
#3 Identity security has moved beyond the login
Strong authentication remains important, but today's identity attack surface extends far beyond passwords.
Attackers are increasingly targeting session tokens, browser credentials and authentication cookies, allowing them to operate as seemingly legitimate users after authentication. Leidos Vice President of Defensive Cyber and Resilient Networks Josh Salmanson joined a discussion examining these weaknesses alongside privilege escalation and attacker movement across complex enterprise environments.
Protecting the login is no longer enough. Organizations also need visibility into what an identity does after authentication.
Once an attacker is using a stolen but valid identity or session, traditional security tools may see activity that appears legitimate. Behavioral monitoring can help identify deviations such as unusual login locations, simultaneous session use or access to systems an account has never touched before.
The takeaway: Modern identity security needs to extend beyond authentication, continuously evaluating access, behavior and privilege.
#4 Cyber strategy is bigger than offense versus defense
Cyber strategy increasingly requires organizations to think beyond a simple choice between defending systems and disrupting adversaries.
During Billington CyberSecurity 2026, Leidos Senior Director of Cyber Growth, Products and Solutions Sharothi Pikar moderated a discussion about balancing defense, resilience, offensive capabilities and deterrence.
The conversation explored the evolving relationship between government and industry, including the authorities, risks and safeguards that must be considered as the cyber operating environment changes.
There is no static balance. As technologies, threats and operational conditions evolve, cyber strategies have to evolve with them.
The takeaway: Defense, resilience, disruption and deterrence aren't competing approaches. They are parts of a broader strategy that must adapt to the operating environment.
#5 The future of cyber will depend on people as much as technology
Technology may be changing quickly, but cyber advantage still depends on the people operating it.
In a fireside conversation on the future of cyber warfare, Intelligence Sector President Jason O'Connor and the Hon. Katie Sutton discussed integrating cyber across warfighting domains and the evolution toward a cyber force built around greater specialization and agility.
That workforce will operate in an environment increasingly shaped by AI, automation and strategic competition. The challenge isn't simply developing new technical capabilities. It's developing people who can apply them, make decisions under compressed timelines and adapt as technologies and adversaries evolve.
The takeaway: Technology can accelerate cyber operations, but people determine how that technology is applied.
Preparing for what comes next
Across these conversations, one theme cuts across AI, identity, deterrence and the cyber workforce: speed without adaptability isn't enough.
Organizations will need to secure emerging technologies while finding new ways to use them, rethink defenses as adversaries change tactics and prepare people to make decisions in increasingly complex environments.
The technology will keep changing. So will the threat.
Cyber operations will have to change with them.
Key takeaways:
- AI is shortening the time defenders have to assess threats and respond
- Securing AI, identities and critical operations requires continuous validation and human judgment
- Leidos leaders highlighted the need to develop cyber workforces alongside faster, more capable tools