Skip to content
Live newsroom 140 readers online
Tuesday, August 25, 2026 Live Sync: Just now
Demystifying Finance, Technology, and Global Markets for the Next Generation.
BreakingAussie capitals ‘will be driverless within a decade’, says robotaxi pioneer
Share Suggestions AVOID INTC Stage 4 (Conv: 1/5 | Size: 10%)

Gartner: Why cyber security must shift to outcomes against AI-led attacks

As frontier artificial intelligence (AI) models become capable of reasoning across increasingly complex environments, the gap between discovering a vulnerability and exploiting it continues to shrink. For security and risk management leaders, this means the race is no longer simply about patching vulnerabilities faster – it is about making better security decisions faster. AI is […]

By deepak · August 11, 2026 · 3 min read

As frontier artificial intelligence (AI) models become capable of reasoning across increasingly complex environments, the gap between discovering a vulnerability and exploiting it continues to shrink. For security and risk management leaders, this means the race is no longer simply about patching vulnerabilities faster – it is about making better security decisions faster.

AI is reshaping cyber security on both sides of the battlefield. Security teams are using AI to improve threat detection, accelerate investigations and automate routine tasks. At the same time, attackers are exploiting increasingly capable AI models to identify weaknesses, chain together vulnerabilities and develop sophisticated attack paths in a fraction of the time previously required.

Historically, organisations benefited from a degree of friction. Discovering vulnerabilities, validating exploit paths and turning theoretical weaknesses into practical compromises required significant expertise, time and resources, giving defenders valuable opportunities to detect, prioritise and respond.

Those assumptions are rapidly disappearing. AI-enabled attackers can rapidly identify combinations of weaknesses, legitimate system behaviours and architectural dependencies that create credible attack paths, dramatically reducing the time between identifying and exploiting vulnerabilities.

Traditional operational metrics remain useful, but they are becoming increasingly poor indicators of cyber performance. An AI-enabled attacker does not care how many vulnerabilities an organisation has patched – they care about how long a vulnerability is available for exploitation and whether the vulnerability presents a viable attack path.

Many vulnerabilities will never require immediate remediation, while others cannot be resolved through patching alone. Attempting to patch everything risks overwhelming already stretched security teams and diverting attention from the issues that genuinely increase organisational exposure. The challenge has shifted from finding more vulnerabilities to understanding which combinations of vulnerabilities actually matter.

The organisations that adapt most successfully to AI-powered cyber threats are those that rethink how they define cyber security success. Rather than measuring effort, they should measure whether security investments are reducing attacker opportunity, improving resilience and limiting business disruption. This represents a significant shift away from activity-based security towards outcome-driven security.

Instead of asking whether a patch has been deployed, security and risk management leaders should ask whether the organisation has meaningfully reduced its exposure to attack. Rather than measuring the size of the vulnerability backlog, they should understand whether attack path analysis is informing remediation priorities and whether the most critical business services are genuinely better protected.

Cyber security is becoming less about eliminating every possible weakness and more about making defensible investments that ensure attackers cannot achieve meaningful business impact.

One consequence of AI-powered attacks is that organisations should expect more disruption. Not every incident will be preventable. Some defensive actions, including accelerated patching or emergency compensating controls, may themselves introduce operational instability.

This makes recovery capability increasingly important. Security and risk management leaders should be investing now in recovery planning, downtime workarounds, incident response exercises and architectural resilience.

Critical business services should have clearly documented recovery plans, while executive teams should regularly rehearse cyber incidents to improve decision-making before a real crisis occurs.  Network segmentation, identity controls and compensating controls should become core resilience capabilities rather than emergency measures deployed only after compromise.  

Ultimately, the question organisations need to answer is no longer simply, “Can we stop every attack?” It is increasingly, “How quickly can we detect, remediate and recover when attackers find a path?”

As AI changes offensive capabilities, cyber security measurement must evolve alongside it. Traditional dashboards built around vulnerability counts, patch volumes and remediation service-level agreements cannot adequately capture organisational resilience against AI-powered attacks.

Security and risk management leaders instead need metrics that demonstrate whether they are reducing attacker opportunity and improving business resilience.

Source: Read the original article on www.computerweekly.com