Budget for Preventive Security

Gartner: Five Priorities for CISOs Through the End of 2026

CISO, Gartner, Gartner CISO, CISO priorities, Gartner CISO priorities 2026, five priorities for CISOs in 2026
Facebook
X
LinkedIn
Reddit
WhatsApp

Gartner is urging security leaders to take five key steps in the fourth quarter of 2026. Among other recommendations, the research firm advises CISOs to treat AI agents as insider risks and launch post-quantum cryptography pilot projects.

Market research firm Gartner has identified five measures that Chief Information Security Officers (CISOs) should address in the fourth quarter of 2026. Christopher Mixter, VP Analyst at Gartner, points to AI-powered cyberattacks, ongoing debates over AI security, and emerging risks posed by quantum computing as the key drivers behind the recommendations.

Ad

Strengthen Accountability for AI Security

According to Gartner, securing AI infrastructure and the interaction between models and the systems they run on is more important than securing the model itself. CISOs are becoming the primary authority for AI security within organizations and should drive both internal governance and practical implementation.

Treat AI Agents as Insider Risks

In a Gartner survey of 297 security leaders conducted in the second quarter of 2026, 54 percent said they had no defined approach for limiting AI agents’ access or relied on predefined human access permissions. Gartner recommends managing autonomous multi-agent systems based on the actions they are authorized to perform rather than their level of intelligence. So-called Guardian Agents are intended to monitor agentic workflows and limit potential damage.

Recognition Is Not Enough for Identity Verification

With deepfakes now widespread, CISOs should redesign processes so that recognizing a voice or face is no longer sufficient to authorize decisions or actions. To protect online presence and brand identity, Gartner recommends combining deepfake detection with contextual signals, additional authentication steps, and content provenance checks.

Ad

Allocate Budget to Preventive Security

AI is reducing both the time and expertise attackers need to exploit vulnerabilities. In a survey of more than 300 risk leaders conducted in the second quarter of 2026, 76 percent of CISOs ranked AI-powered vulnerability discovery among their top 10 emerging risks.

“Detection and response capabilities are no longer sufficient. Organizations should prioritize preemptive cybersecurity capabilities such as automated moving target defense, advanced obfuscation, deception and predictive threat intelligence, to gain a measurable advantage over attackers.”

Luis Castillo, Senior Director Analyst at Gartner

Launch Post-Quantum Cryptography Pilots

Gartner predicts that organizations that fail to launch post-quantum cryptography (PQC) pilot projects by 2027 will face costs at least 200 percent higher for a full migration. Among the CISOs surveyed, 51 percent have not yet begun any PQC activities. Gartner identifies two key threats: attackers harvesting encrypted data for later decryption, known as “Harvest Now, Decrypt Later,” and harvesting data for the future forgery of digital signatures, known as “Harvest Now, Forge Later.”

(Editorial Team)

Ad

Artikel zu diesem Thema

Weitere Artikel