Gartner's Five Year-End Actions for CISOs

Gartner's Five Year-End Actions for CISOs

More than half of organisations have no defined way to limit what AI agents can access, or simply give agents the same access as humans. Gartner says chief information security officers (CISOs) should now treat every frontier AI deployment as an insider risk.

The advice is one of five actions Gartner says security leaders should take by the end of 2026. The 54 per cent figure comes from a Gartner survey of 297 cyber security leaders in the second quarter of 2026.

"AI-augmented cyberattacks, AI safety debates and emerging quantum computing risks create persistent uncertainty across the enterprise," said Christopher Mixter, VP Analyst at Gartner.

1. Cement a role in AI safety

Gartner says securing AI infrastructure, and understanding how models interact with the harnesses around them, matters more than the safety of the model itself.

It argues CISOs are becoming the de facto authority on AI safety in the enterprise. That gives them a chance to guide other executives past the hype and drive internal governance.

2. Treat frontier AI as insider risk

An AI system does not need general intelligence to create significant cyber risk, Gartner says. It only needs the ability to affect enterprise operations.

Gartner recommends governing autonomous multi-agent systems by their action privileges rather than model intelligence. Guardian agents should be used to constrain the blast radius of agentic workflows.

3. Stop accepting recognition as proof of identity

Deepfakes are now mainstream, according to Gartner. It says CISOs must redesign processes so that recognising a voice or face is no longer an acceptable basis for authorising a decision or action.

Deepfake detection should be backed by contextual signals, additional authentication and checks on content provenance.

4. Budget for preemptive security

AI is cutting the time and skill attackers need to exploit weaknesses. Gartner also cited a survey of more than 300 enterprise risk leaders. In it, 76 per cent of CISOs ranked AI-driven vulnerability discovery among their top 10 emerging risks.

"Detection and response capabilities are no longer sufficient," said Luis Castillo, Senior Director Analyst at Gartner. He nominated automated moving target defence, advanced obfuscation, deception and predictive threat intelligence as priorities.

5. Pilot post-quantum cryptography

Gartner predicts organisations that do not begin piloting post-quantum cryptography (PQC) by 2027 will face at least 200 per cent higher costs for their full migration.

More than half (51 per cent) of CISOs surveyed have not started any PQC-related activity.

"Quantum threats, including harvest now, decrypt later (HNDL) and harvest now, forge later (HNFL), are capturing executive attention and demanding immediate action," Mixter said.

In Australia, the Australian Signals Directorate's Information Security Manual sets 2030 as the target for ceasing use of traditional asymmetric cryptography.

 

Business Solution

Gartner's Five Year-End Actions for CISOs

More than half of organisations have no defined way to limit what AI agents can access, or simply give agents the same access as humans. Gartner says chief information security officers (CISOs) should now treat every frontier AI deployment as an insider risk.

The advice is one of five actions Gartner says security leaders should take by the end of 2026. The 54 per cent figure comes from a Gartner survey of 297 cyber security leaders in the second quarter of 2026.

"AI-augmented cyberattacks, AI safety debates and emerging quantum computing risks create persistent uncertainty across the enterprise," said Christopher Mixter, VP Analyst at Gartner.

1. Cement a role in AI safety

Gartner says securing AI infrastructure, and understanding how models interact with the harnesses around them, matters more than the safety of the model itself.

It argues CISOs are becoming the de facto authority on AI safety in the enterprise. That gives them a chance to guide other executives past the hype and drive internal governance.

2. Treat frontier AI as insider risk

An AI system does not need general intelligence to create significant cyber risk, Gartner says. It only needs the ability to affect enterprise operations.

Gartner recommends governing autonomous multi-agent systems by their action privileges rather than model intelligence. Guardian agents should be used to constrain the blast radius of agentic workflows.

3. Stop accepting recognition as proof of identity

Deepfakes are now mainstream, according to Gartner. It says CISOs must redesign processes so that recognising a voice or face is no longer an acceptable basis for authorising a decision or action.

Deepfake detection should be backed by contextual signals, additional authentication and checks on content provenance.

4. Budget for preemptive security

AI is cutting the time and skill attackers need to exploit weaknesses. Gartner also cited a survey of more than 300 enterprise risk leaders. In it, 76 per cent of CISOs ranked AI-driven vulnerability discovery among their top 10 emerging risks.

"Detection and response capabilities are no longer sufficient," said Luis Castillo, Senior Director Analyst at Gartner. He nominated automated moving target defence, advanced obfuscation, deception and predictive threat intelligence as priorities.

5. Pilot post-quantum cryptography

Gartner predicts organisations that do not begin piloting post-quantum cryptography (PQC) by 2027 will face at least 200 per cent higher costs for their full migration.

More than half (51 per cent) of CISOs surveyed have not started any PQC-related activity.

"Quantum threats, including harvest now, decrypt later (HNDL) and harvest now, forge later (HNFL), are capturing executive attention and demanding immediate action," Mixter said.

In Australia, the Australian Signals Directorate's Information Security Manual sets 2030 as the target for ceasing use of traditional asymmetric cryptography.

 

Business Solution