- Joined
- Jan 20, 2026
- Messages
- 345
- Reaction score
- 2,483
The perimeter is broken, the algorithms are uncontrollable, attacks are scaled... What to do?

Information security directors will have to change jobs faster due to AI. Gartner believes that new tools already help attackers scaling actions, and protective teams need to use the same technology to automate, analyze and respond.
At Gartner Security & Risk Management Summit, analyst Lee McMullen identified three tasks for the CISO: put access control in order, assess cybersecurity through business resilience to incidents and give commands a safe way to check AI on real targets.
The first block is related to IAM, Identity Management and Access. Previously, such systems mainly worked with people: the employee was issued an account, assigned a role, changed the rights when moving to another department and denied access after dismissal. Clouds, DevOps and automation have already complicated this scheme. AI agents have added even more machine identifiers: service accounts, workloads, bots, scripts and autonomous processes.
Old access rules are poorly suited for an environment where actions are performed not only by people. An AI agent can get a task, access the tool, take data from multiple systems and perform an operation on behalf of the user or service. If the company does not know which machine accounts already exist, who own and what rights have, the risk grows rapidly.
Gartner predicts that by 2028, 25% of the hacks will pass through the surfaces of the attack associated with AI agents. Reasons: Weak control of machine identifiers and lack of access rules that take into account the context. The problem arises not because of the very fact of using the agent, but because of unnecessary rights, poor accounting and weak control of actions.
Investment in AI can speed up the update of IAM. Companies will still have to connect automatic processes, service accounts, external partners, client systems and internal AI assistants. The more accurately the company gives out the rights to machine entities, the easier it is to launch new integrations without unnecessary risk.
The second block concerns the assessment of cybersecurity. Analysts suggest less reliant on the idea of a complete prevention of attacks and look more at the sustainability of the business. Incidents have already become common risk for companies, so not only defense measures before the attack are important, but also the ability to limit damage, maintain critical processes and quickly restore work.
This approach is easier to verify. The company can determine in advance which systems cannot be stopped for a long time, what is easy to predict, where the damage will become critical and how long the recovery will take. These parameters can be practiced on exercises, measured after tests, and improved with IT, business units and management.
The third unit is related to experiments within the security services. Teams often perceive new AI projects as an additional burden. At the same time, many improvements are already born in daily work: specialists connect different tools, automate checks, finalize response scenarios, prepare test environments and simplify the analysis of incidents.
AI can speed up such work. With its help, you can quickly collect the test environment, prepare an attack scenario, create a draft of the detection rules, describe the recovery or sketch the automation. The main thing is that the experiment solves a specific problem: it reduces the number of manual actions, accelerated the investigation, helped to issue rules or reduce the burden on analysts.
By 2028, organizations that will effectively implement AI in safety monitoring centers will reduce the number of manual-treated incidents by 30%. The role of the analyst will shift from a constant manual response to automated control, checking solutions and working with complex cases.
To do this, managers need to take time to test new approaches, and not expect that the team will deal with them after the main work. The result should be measured at once: how many manual operations have disappeared, how much the incident is understood, how the recovery time has changed and what rules or scenarios can be reused.
The practical conclusion for the CISO is reduced to three actions: to restore order in the access of people and machines, to determine in advance the permissible consequences of attacks and to integrate AI into real security processes where the result can be measured.

Information security directors will have to change jobs faster due to AI. Gartner believes that new tools already help attackers scaling actions, and protective teams need to use the same technology to automate, analyze and respond.
At Gartner Security & Risk Management Summit, analyst Lee McMullen identified three tasks for the CISO: put access control in order, assess cybersecurity through business resilience to incidents and give commands a safe way to check AI on real targets.
The first block is related to IAM, Identity Management and Access. Previously, such systems mainly worked with people: the employee was issued an account, assigned a role, changed the rights when moving to another department and denied access after dismissal. Clouds, DevOps and automation have already complicated this scheme. AI agents have added even more machine identifiers: service accounts, workloads, bots, scripts and autonomous processes.
Old access rules are poorly suited for an environment where actions are performed not only by people. An AI agent can get a task, access the tool, take data from multiple systems and perform an operation on behalf of the user or service. If the company does not know which machine accounts already exist, who own and what rights have, the risk grows rapidly.
Gartner predicts that by 2028, 25% of the hacks will pass through the surfaces of the attack associated with AI agents. Reasons: Weak control of machine identifiers and lack of access rules that take into account the context. The problem arises not because of the very fact of using the agent, but because of unnecessary rights, poor accounting and weak control of actions.
Investment in AI can speed up the update of IAM. Companies will still have to connect automatic processes, service accounts, external partners, client systems and internal AI assistants. The more accurately the company gives out the rights to machine entities, the easier it is to launch new integrations without unnecessary risk.
The second block concerns the assessment of cybersecurity. Analysts suggest less reliant on the idea of a complete prevention of attacks and look more at the sustainability of the business. Incidents have already become common risk for companies, so not only defense measures before the attack are important, but also the ability to limit damage, maintain critical processes and quickly restore work.
This approach is easier to verify. The company can determine in advance which systems cannot be stopped for a long time, what is easy to predict, where the damage will become critical and how long the recovery will take. These parameters can be practiced on exercises, measured after tests, and improved with IT, business units and management.
The third unit is related to experiments within the security services. Teams often perceive new AI projects as an additional burden. At the same time, many improvements are already born in daily work: specialists connect different tools, automate checks, finalize response scenarios, prepare test environments and simplify the analysis of incidents.
AI can speed up such work. With its help, you can quickly collect the test environment, prepare an attack scenario, create a draft of the detection rules, describe the recovery or sketch the automation. The main thing is that the experiment solves a specific problem: it reduces the number of manual actions, accelerated the investigation, helped to issue rules or reduce the burden on analysts.
By 2028, organizations that will effectively implement AI in safety monitoring centers will reduce the number of manual-treated incidents by 30%. The role of the analyst will shift from a constant manual response to automated control, checking solutions and working with complex cases.
To do this, managers need to take time to test new approaches, and not expect that the team will deal with them after the main work. The result should be measured at once: how many manual operations have disappeared, how much the incident is understood, how the recovery time has changed and what rules or scenarios can be reused.
The practical conclusion for the CISO is reduced to three actions: to restore order in the access of people and machines, to determine in advance the permissible consequences of attacks and to integrate AI into real security processes where the result can be measured.