Gartner Outlines 5 Moves CISOs Should Make Before 2027

Protect the king.
Emily Hill
Contributing Writer
Chess. White board with chess figures on it. Plan of battle. The white Bishop is under attack.
gedzun - stock.adobe.com

The next set of cybersecurity decisions won’t all come with the same sense of urgency. AI agents and deepfakes are already forcing companies to reconsider access and identity controls, while quantum computing is pushing CISOs to make plans for risks that may still be years away.

New guidance from Gartner puts those issues on the same near-term agenda, outlining five actions for CISOs to take by the end of 2026.

Many of those decisions are already landing on executives’ desks: how much autonomy to give AI agents, what constitutes sufficient proof of identity and how early to prepare for threats that may still be years away. The challenge lies in anticipating where those risks are headed rather than building defenses only after they become immediate problems.

The five priorities span AI safety, autonomous systems, identity verification, preemptive cybersecurity and postquantum cryptography, areas that could require changes not just to security tools, but to how companies govern access, authorize sensitive actions and plan long-term technology investments.

The Five Actions for CISOs

Gartner’s recommendations stretch from risks CISOs are dealing with today to security changes that could take years to carry out. The guidance puts five moves on the near-term agenda:

  • Cement their role in AI safety. CISOs should take the lead on the security controls surrounding AI systems, including the infrastructure and workflows that determine how models interact with company systems.
  • Treat frontier AI deployments as insider risks. Rather than focusing on how advanced an AI model is, security teams should look at what an agent can access and what actions it has permission to take.
  • Move beyond recognition as proof of identity. With deepfakes making voices and appearances easier to replicate, sensitive requests should rely on stronger authentication and other signals instead of recognition alone.
  • Invest in preemptive cybersecurity. As AI lowers the time and expertise needed to find vulnerabilities, Gartner says companies should add capabilities designed to make attacks harder to carry out, rather than relying primarily on detecting and responding to them.
  • Begin testing postquantum cryptography. Preparing for quantum threats will require more than swapping out encryption methods. Gartner says organizations should start pilots now so they can understand what a broader migration will require.

What This Looks Like in Practice

AI agents are creating one of the more immediate challenges. Unlike traditional software, agents can be given permission to access data, use tools and take actions on their own.

But security controls haven’t necessarily caught up.

Gartner found that 54% of organizations either have no defined approach to limiting AI agent access or are using access rules built for humans.

Deepfakes raise a different question: What counts as proof that someone is who they say they are? A familiar face or voice can no longer carry the same weight, especially when someone is requesting access, sensitive information or a financial transaction. That means companies may need stronger authentication and additional checks before approving high-risk actions.

Some of the changes require planning further ahead.

More than half of CISOs surveyed by Gartner have yet to begin work on postquantum cryptography, even though replacing existing encryption could take years. At the same time, AI is making it easier for attackers to find vulnerabilities, adding pressure to stop threats earlier rather than relying primarily on detection and response.

The Wrap

The five priorities operate on very different timelines. AI agents and deepfakes are already testing existing controls, while postquantum cryptography requires companies to prepare for a threat that may be years away.

That leaves CISOs managing risks at both ends of the spectrum: closing gaps that exist today while making decisions now about technologies and security controls they may not need at scale for years. Preparing for what comes next is becoming part of managing what’s already here.

Cybersecurity updates, executive insights, and the stories shaping the enterprise.

Browse past editions of TNCR newsletters. 

Technology news, cybersecurity, & executive insights.

×
You have free article(s) left this month courtesy of the CIO Professional Network.

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Would You Like To Save Articles?

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Thanks for subscribing!

We’re excited to have you on board. Stay tuned for the latest technology news delivered straight to your inbox.

Save My Spot For TNCR LIVE!

Thursday April 18th

9 AM Pacific / 11 PM Central / 12 PM Eastern

Register for Unlimited Access

Already a member?

Digital Monthly

$12.00/ month

Billed Monthly

Digital Annual

$10.00/ month

Billed Annually

Would You Like To Save Books?

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Log In To Access Premium Features

Sign Up For A Free Account

Name
Newsletters