中文

Gartner Security Summit: Under AI Impact, CISO's Top Priority Is to 'Stay Calm'

At the Gartner Security & Risk Management Summit, multiple analysts reminded CISOs that, in the face of threats from new AI models such as Anthropic Claude Mythos and OpenAI Daybreak, they should return to security fundamentals, avoid being misled by hype, and be wary of AI investments eroding budgets and talent reserves.

2026-06-0411views
Gartner Security Summit: Under AI Impact, CISO's Top Priority Is to 'Stay Calm'

National Harbor, Maryland News— At the Gartner Security & Risk Management Summit held here this week, multiple experts pointed out that in the age of artificial intelligence, one of the most important responsibilities of a Chief Information Security Officer (CISO) is to remain calm and carefully assess their organization's risk exposure.

"Don't panic," said Katell Thielemann, VP Analyst at Gartner, during a Tuesday presentation on the impact of AI on the security of cyber-physical systems such as industrial control equipment. "Yes, things are changing quickly," Thielemann said, "but there are always some low-hanging fruit" that CISOs can tackle, such as disconnecting critical equipment from the internet and monitoring remote access to the remaining infrastructure.

Recently, two powerful new AI models—Anthropic's Claude Mythos and OpenAI's Daybreak—were unveiled, finding software vulnerabilities much faster than previous tools, unsettling cybersecurity leaders who are now seeking help to address related risks. Technology vendors and consultancies have quickly responded to this demand, but sometimes offer advice and products that are unnecessary or even counterproductive. At the Gartner conference, experts urged CISOs and other security executives to focus on fundamentals rather than chasing hype.

"What change did Mythos or Daybreak bring? It's speed and volume," said Dennis Xu, VP Analyst at Gartner, during a Tuesday session. Attackers "are coming at us at a faster pace, and over the next 12 months, the volume of attacks will rise significantly."

Nevertheless, Xu said CISOs should keep two things in mind: "don't panic" and "keep communicating." "You need to communicate with the executive team and the board that we are now facing a different set of rules," he said, adding that security executives should not shy away from using the new threat landscape as an opportunity to secure larger budgets.

But Xu also noted that despite the increase in attack speed and volume, enterprises' defense priorities should remain largely unchanged, with a continued focus on managing asset exposure and prioritizing patches for the most critical systems.

During the presentation, Xu asked the audience how many had identified their business's "minimum viable operations"—the core systems and processes the enterprise relies on to function. When few hands were raised, Xu said enterprises should prioritize this task. "I don't want you to spend six months doing it, but it's something I would definitely do," he said. "Even if for no other reason, it serves as a common language to agree on what's important, and then stakeholders can begin prioritizing cyber resilience decisions at critical points."

AI Hype vs. Reality

In multiple sessions during the conference, Gartner analysts noted that business leaders must clearly recognize the actual effectiveness of their AI usage and the impact the technology has and has not yet had.

AI companies like OpenAI and Anthropic are pushing enterprises to purchase expensive subscription tools, promising these tools will completely revolutionize complex and time-consuming business processes. But this narrative often clashes with reality, as enterprises find that AI tools consume large amounts of tokens without producing significant results.

Security leaders "feel overlooked and under-resourced," said Bart Willemsen, VP Analyst at Gartner, "because our budgets are actually flowing to—pardon my French—generative AI platforms that were once nearly free, then charged per user per month, and now charge per token."

"Are we wasting budget on things that humans could do better?" Willemsen asked. "I firmly believe that's the case."

He added that enterprises should be cautious about replacing experienced employees with AI models, because if AI tools prove flawed, it will be difficult to bring those employees back or find new ones to replace them. "For those who think 'AI lets me do more with fewer people,' I tell you, once you lay them off, don't expect to get them back."

Valuing Human Skills

Another session similarly warned of the dangers of neglecting talent development in the AI era.

"We are facing immense pressure from executives and boards to demonstrate the value of AI investments," said Alex Michaels, Director Analyst at Gartner. "Years of hype have intensified this urgency. However, AI ambitions are colliding with a talent pool not yet ready for rapid, large-scale AI adoption."

Michaels made these remarks in the context of Security Operations Centers (SOCs). Business leaders have been eager to automate SOCs with AI, but Michaels believes the field requires continued investment in human skills. However, as AI takes on more SOC tasks, Michaels warned that the incentive to maintain critical skills training for human employees will diminish, potentially endangering institutional knowledge. "Even if we successfully achieve large-scale AI automation," Michaels said, "we risk eroding the potential of the next generation of SOC talent."

A Realistic Look at AI and Industrial Control Systems

Thielemann's session focused on cyber-physical systems. She said critical infrastructure operators should focus on foundational cyber hygiene, such as network segmentation and access control, rather than worrying about destructive AI cyberattacks that may not materialize for years.

"We know AI is knocking on the door," she said. "Time will tell, but we haven't yet seen that nightmare scenario happen."

Anthropic has invited some equipment vendors and critical infrastructure operators to participate in its Claude Mythos preview program "Project Glasswing," but Thielemann noted that so far, no industrial control system manufacturer has disclosed its participation. "If specific vendors in the cyber-physical systems space are involved with Mythos, they haven't said so," she said. "We haven't seen any statements from companies like Siemens, Rockwell, or Honeywell."

"Until we see more information," she added, "please don't buy into the narrative that 'Mythos enters manufacturing and we're all doomed'—I've seen quite a bit of that rhetoric."