All 2026 Conference Sessions

Gartner Security & Risk Management Summit 2026 dove deep into key topics for security & risk management around the latest AI, cybersecurity strategy and innovation, risk management, business engagement, and cloud and data security areas.

Session Takeaways

Dive into some of the key takeaways you may have missed from the Gartner Security & Risk Management Summit 2026.

The Real Cost of Cybersecurity

Speakers: 

  • Christopher Mixter, VP Analyst, Gartner 

Key takeaways

  • The cybersecurity budget doesn’t represent the real cost of protecting an organization. The real cost of cybersecurity is the all-in cost of delivering protection: technology, labor and the business friction that results from controls.

  • Knowing the real cost of cybersecurity supports an outcome-driven approach because it gives business leaders transparency into the tradeoffs between protection, spend and business enablement.

  • Outcome-driven metrics must be the starting point for measuring the real cost of cybersecurity. They measure control performance, offer a forward-looking view of exposure, can be influenced by investment and allow benchmarking across organizations and governments.

  • The real cost of cybersecurity isn’t just a way to justify budgets or new resources; it’s a tool to engage executives in active conversation about the value of cybersecurity, how much they want to invest and how much risk they are willing to accept.

  • Effective CISOs and CIOs use the real cost of cybersecurity to negotiate protection level agreements with their executives, increasing transparency of value for cost, clarity of accountability and defensibility in the event of an adverse cybersecurity event.


Outlook for AI & Cybersecurity

Speakers: 

  • Leigh McMullen, Distinguished VP Analyst and Gartner Fellow 

Key takeaways

  • AI has become both the engine of cybersecurity transformation and the accelerant of risk. 87% of leaders identify AI vulnerabilities as the fastest growing and most urgent cybersecurity risk.

  • Unlike previous technology waves, AI timelines are compressed. It’s important to operate in three lanes: act for what’s known now, plan for the next few quarters, and monitor the uncertain horizon. Today’s environment requires thinking in sprints, not program years.

  • Most technologies cybersecurity teams have to secure are deterministic, but AI isn’t. Part of its value comes from unpredictability, making it behave more like humans with all of the challenges of anticipating, shaping and responding to unexpected events.

  • Threat actors and rogue states won’t be limited by regulation, driving damaging AI to evolve without boundaries. Organizations must invest in defensive and offensive technologies as quickly and as broadly as threat actors do.

  • Most vendors are racing toward the vision of an AI security platform, but AI security is still too broad for any single platform to go deep enough. Focus the next 12-18 months on AI usage control and AI application security as the most proven way to secure AI applications and agents.

AI-Enhanced SOC: Bridging the Gap to Advanced Automation

Speakers: 

  • Craig Lawson, VP Analyst, Gartner

Key takeaways

  • Gartner predicts 25% of common SOC tasks will become 50% more cost-efficient due to automation enhancements and hyperscaling strategies by 2027.

  • Bridging the gap to advanced automation in the SOC can only be achieved by progressing through the different stages of AI adoption at a pace the organization can sustain.

  • Determine what can be automated today and strategize about what is coming to enable automation and augmentation in the future. The SOC team can then handle greater workloads through the use of AI and automation.

  • Outcomes are only defensible when supported by metrics that demonstrate improvements in the activities the team is doing today. Without doing so, security operations automation initiatives can never be objectively measured.

  • Continuously validate the outputs of automation and AI tools and use metrics consistently to ensure accuracy and reliability. Rely on existing metrics, rather than inventing new ones.

Top Cybersecurity Trends

Speakers: 

  • Richard Addiscott, VP Analyst, Gartner

Key takeaways

  • Amid regulatory volatility and geopolitical, technological and organizational forces, CISOs must rethink how they approach cyber risk management, resilience and resource allocation by assessing each trend to determine whether to embrace, monitor or deprioritize.

  • Postquantum computing moves into action plans: As quantum computing renders today’s cryptography unsafe by 2030, CISOs must inventory all crypto assets and establish a center of excellence to accelerate crypto‑agile readiness.

  • Agentic AI demands cybersecurity oversight: Identify both sanctioned and unsanctioned AI agents, then enforce robust controls for each based on access and agency.

  • Global regulatory volatility drives cyber resilience efforts: Treat compliance as a strategic advantage, not a checklist to drive cyber resilience.

  • GenAI breaks traditional cybersecurity awareness tactics: Stop relying on general awareness and focus on adaptive training that provides visibility into individual employee behaviors.

How to Increase Board Confidence in Cybersecurity

Speakers: 

  • Kristin Moyer, Distinguished VP Analyst, Gartner

Key takeaways

  • Ninety percent of non-executive board directors lack confidence in cybersecurity value.

  • The key to increase board confidence is to become a sense maker. Sense maker CIOs and CISOs have managed to earn their boards’ trust on “just right” levels of protection and cost.

  • Fewer cybersecurity breaches won’t earn board trust – business alignment will.

  • Being transparent about actual exposure levels and revealing uncomfortable truths builds board confidence.

  • Real cybersecurity leadership means protecting what the organization values, from managing cost and reducing risk, to safeguarding revenue.

Outlook for Human Factors in Cybersecurity: Adapt to Optimise

Speakers: 

  • Mia Yu, Director Analyst, Gartner

Key takeaways

  • The greatest – and most neglected – opportunity to reduce cyber risk in any organization is harnessing the human element.

  • Mounting pressure is driving employees to insecure behavior. Cybersecurity isn’t at the top of their minds and they’re looking for any way to make their lives easier, resulting in 41% intentionally bypassing cybersecurity controls.

  • Burnout quietly shapes the daily reality of cybersecurity teams – how they respond to threats, enable secure design and control implementation. Those that don’t address it risk losing their most valuable assets and make their organizations more vulnerable.

  • Only CISOs carry the triple AI mandate: secure AI, defend against AI-enabled attacks and use AI to do both. Upskilling isn’t optional; it’s the only way to survive this pressure.

  • Employees are humans, not risks. Mindsets must change from treating them as risks and investing in them to become a more valuable part of the cybersecurity program.

Be the first to receive the 2027 conference agenda

Get the latest details around the 2027 conference agenda, speakers, and more straight to your inbox.

By clicking the "Continue" button, you are agreeing to the Gartner Terms of Use and Privacy Policy.

Contact Information

All fields are required.

Look back at 2026 conference sessions

Hundreds of conference sessions were presented each day at the 2026 Gartner Security & Risk Management Summit. While we work to develop this year's agenda, filter to see sessions that align with your role and interests.

Show Filters

Filter Sessions Cancel
Showing 5 Sessions
Clear All
Monday, 16 March, 2026

10:30 AM - 11:15 AM AEDT

Ask the Expert: How to Secure the Cloud — Without Crippling Business Innovation

Esraa ElTahawy, Sr Director Analyst, Gartner
Cloud adoption — SaaS, PaaS and IaaS — continues to grow in the vast majority of enterprises. This Ask the Expert session provides a forum to ask about how to make this adoption as secure as possible without crippling business innovation. You can ask your specific questions about cloud security approaches, techniques and technical controls. ... Show More Show Less

10:30 AM - 11:15 AM AEDT

Ask the Expert: Where to Start Your Journey in CPS Security?

Wayne Hankins, Sr Director Analyst, Gartner
As cyberattacks shift towards manufacturing, production, mission-critical, or national critical infrastructure environments, CISOs are increasingly asked to reach beyond Enterprise IT. They discover a new world of ICS, OT, IoT, and "smart" technologies - a world of cyber-physical systems where their IT-centric playbooks do not work. Join this session to get answers on where and how to start on the journey. ... Show More Show Less

02:00 PM - 02:45 PM AEDT

Ask the Expert: Preparing Cybersecurity for the Post-Quantum Cryptography Era

Mark Horvath, VP Analyst, Gartner
Quantum computers will weaken and break today’s cryptography, which all organizations rely on to secure their data and systems. But when do organizations need to start preparing for this threat, what should they focus on, and how should they ultimately remediate the risks? This session gives cybersecurity leaders an opportunity to ask questions about this emerging threat and how to respond. ... Show More Show Less
Tuesday, 17 March, 2026

11:45 AM - 12:30 PM AEDT

Ask the Expert: How to Overcome Emergent Security Risks When Building AI Applications?

Manjunath Bhat, Distinguished VP Analyst, Gartner
Building AI applications and agents introduces new security risks, such as prompt injection, data exfiltration and excessive agency due to nondeterminism, autonomy and behavior drift. Join this session to learn about preemptive practices, compensating controls and emerging security markets that help mitigate these risks when building AI applications. ... Show More Show Less

01:45 PM - 02:30 PM AEDT

Ask the Expert: How to Secure AI Personal Assistants and Browsers

John Watts, VP Analyst, Gartner
AI-enabled apps are multiplying with minimal visibility, while threat actors are already deploying autonomous, agentic AI capable of planning, adapting and executing attacks — exfiltrating data up to 100 times faster. Join this session to ask your questions about the latest AI-driven threats and what you need to do to stay ahead of intelligent adversaries. ... Show More Show Less

... Show More Show Less
Items per page: 19 of 5 Items
1 of 0 Pages

Sorry, no sessions match your criteria. Please refine your filters to display sessions.

“Quality presentations with incisive and interesting topics. Would recommend to cyber and risk professionals alike.”

Craig Thompson
IT Risk Manager, Hollard

Discover what it’s like to experience Gartner Security & Risk Management Summit.