Chasing AI Won’t Save You From Ignoring Endpoint Security
Black Hat 2026 felt different as the Forrester Black Hat attendees shared how the conference buzz centered on AI, agentic workflows, coding assistants, vulnerability discovery, and what some attendees jokingly called the latest phase of the “vulnerability apocalypse.” Those topics deserve attention. They are reshaping how organizations build software, operate security teams, and manage risk.
Yet amid all that discussion, something was missing at Black Hat: traditional endpoint security barely made the agenda.
Whether we’re talking about desktops, mobile devices, browsers, IoT assets, or operational technology (OT), the systems that run businesses received far less attention than in previous years. Even within critical infrastructure discussions, the focus shifted toward threats, vulnerabilities, and AI rather than the foundational protections that make exploitation in OT environments difficult.
Prevention Still Beats Detection
For years, security programs have steadily expanded their detection and response capabilities. Endpoint detection and response (EDR), extended detection and response (XDR), network detection and response (NDR), and a growing collection of other tools help security teams identify malicious behavior after it begins. These investments matter. Organizations need visibility and response capabilities.
But somewhere along the way, many teams started treating detection as the primary control rather than the backup plan. I’ve had numerous client engagements where the question from them is: “Do we need application control when we have EDR?”
When a user, script, or application cannot execute an action, there is nothing for detection systems to find. That distinction matters because:
- If a user cannot launch an unauthorized executable, the attack stops before the EDR alert.
- If a script cannot reach a sensitive system, the investigation never begins.
- If an application cannot communicate with an unauthorized service, the security operations center never sees the incident because the incident never occurs.
Organizations should not be choosing between prevention and detection. They should recognize that prevention reduces the number of situations requiring detection in the first place.
Every Vulnerability Requires a Path
Black Hat featured no shortage of vulnerability discussions. That’s not surprising. Vulnerabilities remain an important source of enterprise risk, but vulnerabilities don’t exist in isolation. Every exploit requires conditions that allow it to succeed.
- Can the attacker reach the target system?
- Can code execute?
- Is physical access required?
- Is network access required?
- Does the user possess privileges that enable exploitation?
These questions often matter more than the vulnerability itself.
Consider operational technology. Recent incidents involving exposed programmable logic controllers (PLCs) have highlighted a recurring issue: The vulnerability is only part of the story. The more important question is why the vulnerable asset was reachable in the first place.
A vulnerable system hidden behind strong segmentation, access controls, and execution restrictions presents a significantly different risk profile than a vulnerable system directly accessible from the internet.
Security leaders cannot patch every vulnerability immediately. They can, however, make exploitation dramatically harder by reducing the paths available to attackers.
AI Makes Endpoint Controls More Important, Not Less
The industry’s focus on AI should strengthen the case for foundational security controls. Instead, many organizations appear to be treating AI as a separate discussion.
It isn’t.
Agentic systems are ultimately taking actions on endpoints, applications, networks, and operational systems. They use the same paths, identities, permissions, and connectivity that humans use. That means they inherit the same risks.
One observation raised during Black Hat discussions stood out to me. The recent examples of agentic taking unexpected actions demonstrated that many of those actions were treated as normal activity by traditional monitoring controls. The systems performed authorized actions using authorized access.
In other words, detection did not always help. Prevention could have.
If an AI agent is explicitly allowed to perform only approved actions, then attempts to execute anything outside those boundaries fail immediately. It doesn’t matter whether the request originates from a human, a script, or an AI agent; the action never occurs because the system was never allowed to perform it.
OT Has No Room for Assumptions
This becomes especially important in operational environments.
The longstanding idea of an OT air gap has largely disappeared. Organizations increasingly connect operational environments to business systems, cloud applications, remote support tools, analytics platforms, and AI initiatives. Those connections create value but also create pathways.
If an AI-driven workflow can traverse from an internet-facing environment into critical operational systems, security leaders must understand exactly which actions are possible along that path. If an attacker discovers the same pathway, the consequences can be even more severe.
The answer is not to reject modernization. The answer is to apply the same principles that security professionals have advocated for decades: least privilege, segmentation, application control, execution restrictions, and tightly managed access between environments.
If You Forget the Fundamentals, You’re Asking For Trouble
Black Hat 2026 showcased where the industry is heading. AI matters. Agentic workflows matter. Secure coding matters. Vulnerability management matters. But none of those investments eliminate the need for foundational endpoint security. In fact, they make it more important.
The organizations that succeed with AI will not be the ones that raced fastest toward the newest capability. They will be the ones that built guardrails first.
Forrester clients interested in this topic should connect with us to discuss via an inquiry or guidance session.