Infrastructure Portfolio Management Has Quietly Become a Security Discipline
For a long time, infrastructure portfolio management and network security lived in adjacent but separate lanes. One team decided what to build, modernize, or retire. Another team decided how to protect it. That separation is no longer accurate, and pretending otherwise is becoming one of the more expensive mistakes an enterprise can make.
The shift is not theoretical. Enterprise organizations are now navigating a world where cyber incidents cause physical shutdowns and physical breaches create digital vulnerabilities, largely because cloud dependent systems have become the operational backbone of the business while AI is being used as a tool by both defenders and attackers. A badge reader tied to a cloud identity platform, an IoT sensor feeding an analytics pipeline, a building network sharing infrastructure with business-critical applications, none of these decisions were originally security decisions. They were infrastructure decisions. Today they are both, simultaneously, and that is exactly why infrastructure portfolio management can no longer be evaluated purely on delivery timelines and cost efficiency.
When Visibility Becomes the First Security Problem
Every conversation about modern network security eventually runs into the same wall, and it is not a lack of tools. It is a lack of visibility into what actually exists across the portfolio. Many enterprises enter 2026 with incomplete visibility into their own network assets and telemetry, as environments sprawl across cloud, SaaS, edge, and short-lived workloads, leaving traditional configuration databases and legacy monitoring tools unable to keep up.
This is where infrastructure portfolio management and security genuinely become one function. You cannot secure an asset you do not know exists, and you cannot sequence a modernization program correctly if you do not know what depends on what. A data centre exit, a virtualization consolidation, or a cloud migration all carry hidden risk when the underlying asset inventory is incomplete, and that risk shows up as a security incident just as often as it shows up as a delivery delay.
Agentic AI Has Changed Who Is Doing the Attacking, and Who Is Doing the Defending
If there is one theme running through nearly every credible 2026 security report, it is that AI has stopped being a future consideration and become an active participant on both sides of the fight. Cyber defence in 2026 has reached a critical inflection point, with organizations confronting increasingly advanced threats and evolving technologies, and Gartner forecasting global spending on information security to grow to 240 billion dollars in 2026, a 12.5 percent increase from 2025, largely to counter AI enhanced attacks and cloud risk.
The attacker side of this is not abstract either. As large language models, agentic AI tools, browser automation frameworks, and proxy networks mature, attackers are able to generate more adaptive, context aware, and human like attack traffic at scale, marking a shift from simple scripted automation to industrialized attack operations. At the same time, defenders are not standing still. Thirty six percent of organizations now prioritize AI investment as their top cyber budget item in 2026, while overall security spending is forecast to grow toward 377 billion dollars by 2028.
For infrastructure portfolio leaders, this changes the calculus around automation. It is no longer purely a cost or speed decision. Automating incident response, remediation, and change management across the network is becoming table stakes, and the direction of travel is aggressive. Tier 1 and Tier 2 infrastructure operations are expected to move toward no human in the loop, with agentic AI systems autonomously handling incident response, remediation, change management, and software updates across networks and security infrastructure, leaving human involvement for policy exceptions and high risk decisions, according to ONUG co-founder Nick Lippis. That is a significant shift in how infrastructure teams need to think about governance guardrails, because the humans are being pulled further back from routine execution and closer to policy design.
Zero Trust and SASE Are No Longer Point Solutions, They Are Portfolio Architecture
For years, zero trust and secure access service edge, better known as SASE, were treated as security initiatives bolted onto an existing infrastructure roadmap. That framing has stopped making sense. One of the defining cybersecurity trends heading into 2026 is the convergence of data security, identity, and network security under zero trust principles, with SIEM evolving into a shared intelligence layer across the organization rather than remaining a standalone SOC tool.
The market numbers back this up. The global SASE market is valued at approximately 19.19 billion dollars in 2026 and is projected to reach 68.06 billion dollars by 2032, growing at a 28.8 percent compound annual rate, with large enterprises accounting for close to 59 percent of current market share. Procurement behaviour is shifting just as fast. Security and networking teams are expected to budget less for discrete branch hardware and more for recurring spend on SASE, SSE, and WAF, reinforcing that the network edge is now delivered as a service rather than a rack of physical gear, according to Dell'Oro analyst Mauricio Sanchez.
For a portfolio manager, this is not a security team's procurement decision anymore. It is an infrastructure architecture decision that determines how every future data centre exit, cloud adoption, or branch consolidation gets designed from day one.
Third Party Risk Is Now a Portfolio Management Problem
No enterprise infrastructure portfolio exists in isolation, and the data on third party risk makes that painfully clear. Seventy one percent of organizations experienced a material third party security incident in 2025. Third party involvement in breaches doubled year over year in 2025, reaching 30 percent of all incidents, with system intrusion accounting for 81 percent of those third-party attacks, according to the Verizon 2025 Data Breach Investigations Report.
This matters directly for infrastructure portfolio management because every vendor, integration, and managed service provider touching the portfolio is effectively part of its attack surface. Over 20 percent of newly exploited vulnerabilities in 2025 targeted network infrastructure specifically, a figure projected to exceed 30 percent in 2026 as unmanaged assets become preferred footholds for lateral movement. Vendor consolidation, long treated as a cost and coordination decision, is increasingly also a risk reduction decision.
Governance Is the Layer That Holds All of This Together
None of the above works without governance sitting underneath it as the connective layer, not as paperwork bolted on afterward. Strong governance starts at the top, with boards and executive teams taking clear ownership of cybersecurity, aligning risk appetite with business goals, and ensuring policies are enforced consistently through cross functional collaboration between security, legal, compliance, and operations. Alongside governance, secure infrastructure and network design increasingly means adopting zero trust principles, segmenting critical systems, and securing hybrid connectivity across cloud, on premises, and edge assets so that no single point becomes a weak link.
This is the real argument for treating infrastructure portfolio management and network security as one discipline rather than two. The portfolio manager who sequences a data centre exit, an EOL tech refresh, or a cloud migration is making security decisions whether that is explicit or not. The question is whether those decisions are made deliberately, with visibility and governance behind them, or discovered later, usually during an incident.
Where Galaxy Fits Into This Picture
Galaxy Office Automation has spent close to four decades working inside exactly this intersection, where infrastructure delivery and security cannot be separated. Its work across data centre architecture and modernization, enterprise networking, cybersecurity and zero trust, hybrid cloud, and managed services is built around the same principle this blog has been making the case for, that portfolio decisions and security decisions have to be designed together, not sequenced one after the other. Backed by strong OEM partnerships including Dell, VMware, CrowdStrike, and Check Point, along with PAN India delivery, Galaxy supports enterprise infrastructure portfolios through the full lifecycle, from planning and migration through the ongoing operational period that follows, which is often where the real risk and cost of a portfolio actually plays out.
For infrastructure leaders managing complex, distributed portfolios where visibility, vendor risk, and zero trust adoption are converging into a single set of decisions, this is precisely where an experienced execution partner earns its place. If any of the pressures covered in this piece, incomplete asset visibility, agentic AI reshaping both threats and defences, SASE and zero trust becoming architecture rather than add ons, or third party risk sitting inside the portfolio itself, sound familiar, it may be worth a conversation.
Learn more about Galaxy Office Automation's infrastructure and security capabilities at www.goapl.com, or reach out directly to explore how these capabilities could apply to your environment.
