Insights | Integrity360

Gartner Security and Risk Management summit: Five priorities for cybersecurity leaders

Written by Richard Ford | 3 October 2026, 08:00:00 Z

AI featured throughout Gartner’s Security and Risk Management Summit, but its implications reached far beyond the introduction of new tools. Discussions examined how organisations govern access, prioritise exposures, engineer detection and prove their ability to recover from disruption.

Across three days, Integrity360’s CTO Richard Ford and Director of Product Management Brian Martin attended sessions spanning security operations, product strategy, identity and resilience. Their complementary perspectives revealed five priorities for organisations seeking to adopt AI securely and strengthen their wider cybersecurity capabilities.

The common requirement was evidence: evidence that controls work, that decisions are informed and that investment delivers a meaningful improvement.

1. Make AI adoption accountable for results

AI investment needs a clearly defined purpose. A use case such as improving investigation quality or reducing repetitive triage gives an organisation something concrete to test and measure.

The summit discussions favoured shorter learning cycles, allowing teams to deliver a bounded capability, assess its performance and revise the approach. This is especially useful where technology and requirements are developing quickly.

Choosing the implementation also requires judgement. Conventional automation may be sufficient for a predictable task, while custom AI development needs the ownership and engineering capacity to support it over time.

Accountability extends beyond deployment. Teams need to understand how performance will be monitored, who can approve changes and what conditions should trigger a review or withdrawal of the capability.

2. Treat Identity as a foundation of AI security

AI security depends on knowing what is acting, what it can access and what it is authorised to do.

Agents, workloads, service accounts and other non-human identities require discovery, ownership and lifecycle management. The permissions they receive should reflect their intended purpose, with monitoring for activity that falls outside it.

Agentic systems add a further requirement: control over goals and actions. An agent may have access to an application without needing permission to perform every available operation. Organisations need to define those boundaries and identify where human approval is necessary.

Multiagent workflows require particular attention because separate permissions can combine in unexpected ways. Oversight must cover the complete process, including interactions between agents and tools.

For human identities, the discussions on deepfakes reinforced the value of independent verification. Sensitive processes should remain protected even when an impersonation appears convincing.

 

 

3. Connect exposure management with remediation

Discovering more weaknesses does not automatically improve security. Organisations need to identify the exposures that matter most and coordinate an effective response.

Continuous Threat Exposure Management (CTEM) supports this through discovery, prioritisation, validation and mobilisation, within an agreed scope. Business context helps establish which findings deserve attention, considering reachability, exploitability, criticality and existing controls.

Mobilisation is where many programmes encounter difficulty. A finding needs an owner who can act, a practical remediation route and agreement on when the work will happen.

Verification then establishes whether the response reduced exposure. Without this connection between evidence and delivery, teams can accumulate findings while leaving important attack opportunities unresolved.

Exposure information should also inform security operations, helping analysts and automated systems understand the significance of activity on affected assets.

 

 

4. Engineer security operations before expanding autonomy

The summit’s SOC discussions consistently returned to the quality of data and detections. AI agents need reliable telemetry, accurate identity and asset information, and enough context to assess business impact.

Detection engineering provides an essential foundation. Detections should be developed against relevant threat scenarios, reviewed, tested and maintained as environments change.

AI can support research, development and investigation, but greater response authority needs to be earned through evidence. Teams must understand the conditions under which automation performs reliably and where human judgement is required.

This also changes how people contribute. Analysts can spend less time collecting information and more time resolving ambiguity, coordinating incidents and validating consequential decisions. That benefit depends on manageable workloads and recommendations that can be meaningfully assessed.

5. Demonstrate resilience in business terms

Recovery plans and service commitments need to be supported by testing. Organisations should understand whether critical services can be restored within agreed timescales and what dependencies could prevent that.

Exercises expose practical weaknesses in playbooks, recovery procedures and decision-making. Their results provide a basis for improvement and a clearer account of the disruption the business may face.

Operational technology adds safety and production considerations. Security teams need to work with engineering colleagues so that interventions reduce exposure without creating unacceptable operational consequences.

For managed services, the same emphasis on evidence applies. Boards need to understand how protection supports continuity and reduces risk, while technical teams need visibility of detection performance, response quality and remaining limitations.

Turning the summit’s insights into a practical plan

These priorities are closely connected. Identity controls determine what systems can do, exposure management guides attention, and reliable telemetry supports investigation. Tested resilience then establishes how the organisation will respond when disruption occurs.

A practical starting point is to select one important business service or AI use case and examine those dependencies together:

    • Identify the owner, supporting systems, data and identities.
    • Assess the exposures and potential consequences.
    • Define access, monitoring and approval requirements.
    • Test detection, response and recovery arrangements.
    • Measure the improvement and use the findings to guide further work.

This gives security leaders a manageable way to connect technical changes with business value. It also creates a repeatable process that can adapt as AI capabilities and organisational priorities evolve.

For Integrity360, the summit reinforced the importance of bringing identity security, exposure management, security operations and incident readiness together. Organisations benefit when these disciplines share context and work towards outcomes that can be demonstrated.

Speak to Integrity360 about connecting these capabilities to support secure AI adoption and stronger cyber resilience.

 

 

Explore the Full Series

Day One: Building the Foundations for Secure AI Adoption
AI investment, non-human identities, deepfake impersonation and tested recovery.

Day Two: Turning AI Visibility and Exposure Findings Into Action
CTEM mobilisation, secure development, SOC data quality and post-quantum preparation.

Day Three: Engineering Security for AI and Continuous Change
Detection engineering, agent permissions, operational resilience and MDR outcomes.

 

 

FAQs

What were the main themes in these Gartner Summit reflections?

The main themes were accountable AI adoption, identity governance, exposure-led prioritisation, engineered security operations and tested resilience. Reliable evidence and clear ownership connected the discussions.

What should organisations prioritise before expanding AI use?

Establish visibility of AI systems, assign owners and understand their data access and permissions. Define the intended outcome, apply proportionate controls and test performance before expanding authority.

How can security leaders demonstrate business value?

Connect security improvements to relevant outcomes, such as reduced exposure, better investigation quality or validated recovery times. Support those claims with technical evidence and explain any remaining dependencies or limitations.