As frontier artifical intelligence (AI) models become capable of reasoning across increasingly complex environments, the gap between discovering a vulnerability and exploiting continues to shrink. For security and risk management (SRM) leaders, this means the race is no longer simply about patching vulnerabilities faster. It is about making better security decisions faster.
What is clear is that AI is reshaping cybersecurity on both sides of the battlefield. Security teams are using AI to improve threat detection, accelerate investigations and automate routine tasks. At the same time, attackers are exploiting increasingly capable AI models to identify weaknesses, chain together vulnerabilities and develop sophisticated attack paths in a fraction of the time previously required.
Why traditional vulnerability management is no longer enough
Historically, organisations benefited from a degree of friction. Discovering vulnerabilities, validating exploit paths and turning theoretical weaknesses into practical compromises required significant expertise, time and resources, giving defenders valuable opportunities to detect, prioritise and respond.
Those assumptions are rapidly disappearing. AI-enabled attackers can rapidly identify combinations of weaknesses, legitimate system behaviours and architectural dependencies that create credible attack paths, dramatically reducing the time between identifying and exploiting vulnerabilities.
Traditional operational metrics remain useful, but they are becoming increasingly poor indicators of cyber performance. An AI-enabled attacker does not care how many vulnerabilities an organisation has patched; they care about the length of time a vulnerability is available for exploitation, and whether the vulnerability presents a viable attack path.
Many vulnerabilities will never require immediate remediation, while others cannot be resolved through patching alone. Attempting to patch everything risks overwhelming already stretched security teams and diverting attention from the issues that genuinely increase organisational exposure. The challenge has shifted from finding more vulnerabilities to understanding which combinations of vulnerabilities actually matter.
Optimising for outcomes, not activity
The organisations that adapt most successfully to AI-powered cyber threats are those that rethink how they define cybersecurity success. Rather than measuring effort, they should measure whether security investments are reducing attacker opportunity, improving resilience and limiting business disruption. This represents a significant shift away from activity-based security towards outcome-driven security.
Instead of asking whether a patch has been deployed, SRM leaders should ask whether the organisation has meaningfully reduced its exposure to attack. Rather than measuring the size of the vulnerability backlog, they should understand whether attack path analysis is informing remediation priorities and whether the most critical business services are genuinely better protected. Cybersecurity is becoming less about eliminating every possible weakness and more about making defensible investments that ensure attackers cannot achieve meaningful business impact.
Recovery becomes a competitive advantage
One consequence of AI-powered attacks is that organisations should expect more disruption. Not every incident will be preventable. Some defensive actions, including accelerated patching or emergency compensating controls, may themselves introduce operational instability.
This makes recovery capability increasingly important. Security and risk management leaders should be investing now in recovery planning, downtime workarounds, incident response exercises and architectural resilience.
Critical business services should have clearly documented recovery plans, while executive teams should regularly rehearse cyber incidents to improve decision-making before a real crisis occurs. Network segmentation, identity controls and compensating controls should become core resilience capabilities rather than emergency measures deployed only after compromise. Ultimately, the question organisations need to answer is no longer simply “Can we stop every attack?” It is increasingly, “How quickly can we detect, remediate and recover when attackers find a path?”
Measuring what matters
As AI changes offensive capabilities, cybersecurity measurement must evolve alongside it. Traditional dashboards built around vulnerability counts, patch volumes and remediation service-level agreements cannot adequately capture organisational resilience against AI-powered attacks.
Security and risk management leaders instead need metrics that demonstrate whether they are reducing attacker opportunity and improving business resilience.
Gartner refers to this special class of metrics as “outcome driven metrics” or ODMs. These metrics are carefully defined to function as value levers that demonstrate return on investment for cybersecurity initiatives. This dual role balances informed decision making — ensuring that resources are allocated effectively to enhance security — with the imperative to pursue the organisation’s mission. Examples of these metrics understanding how quickly high-risk vulnerabilities can be patched, how rapidly compensating controls can be deployed when patches are unavailable, whether meaningful attack path analysis is informing prioritisation, how quickly organisations recover from complex incidents, and the extent to which technology debt continues to create exploitable exposure.
When ODMs are used to continuously measure cybersecurity performance, they enable clearer and swifter decision-making at an executive level. These decisions can also be directed and prioritised with greater transparency and control. Further guidance is provided via peer comparable data across 25 cyber metrics benchmarked by Gartner.
AI changes the speed of defence, not its purpose
The changes AI has brought, and will continue to bring, to cybersecurity has a pretty broad scope. Cyber needs to use AI to protect employees, business applications, emerging AI threats, and harness innovation, and at the centre of all this is evolving the capabilities of the team. That being said, the goal of cybersecurity remains consistent: To balance the needs to protect with the needs of running the business.
AI has increased the velocity and volume of the changes and challenges it brings to cybersecurity. By 2030, the cybersecurity function will have to evolve to be AI-First to meet this challenge. By AI-First, we mean that about 80% of cybersecurity workflows will be augmented by AI and the implementation of AI Security platforms to enable a degree of cybersecurity self-service across the enterprise.
Keeping up with this rate of change will require a refocus on outcomes, continuous performance measurements and clear executive decision-making. This will only be achieved through a foundation of the right metrics.
Emily Tan is a director analyst at Gartner
Gartner analysts will further explore how AI-powered cyber-attacks are reshaping vulnerability management, cyber resilience and security strategy at the Gartner Security & Risk Management Summit in London, from 22–24 September 2026.

