by | Jun 22, 2026

Reflections from the Gartner Security & Risk Management Summit 2026

By Donna Estrin

Last week, I had the opportunity to attend the Gartner Security & Risk Management Summit in National Harbor, Maryland. I joined thousands of cybersecurity leaders, practitioners, analysts, and technology providers for three days of discussions about the future of security, risk, and resilience. This is my favorite cybersecurity conference as the quality of people attending and the content is excellent, everything from the keynote sessions to conversations in the hallway.  

I’ve attended this event many times over the years, but what stood out to me at this year’s Gartner Summit was how much the conversation has evolved. While security leaders are still focused on defending against increasingly sophisticated threats, the discussions were less about technology for technology’s sake and more about how organizations can navigate change, manage uncertainty, and create business value through security. 

Three themes in particular resonated with me throughout the event: artificial intelligence, human behavior, and organizational resilience. 

Theme 1: AI: From Hype to Practical Governance 

Not surprisingly, AI dominated many of the keynote sessions, analyst presentations, and hotel lobby conversations. What I found refreshing, however, was that the discussion wasn’t centered on hype. Instead, Gartner analysts and security leaders focused on practical questions: 

  • How do we govern AI responsibly? 
  • How do we secure AI systems? 
  • How do we leverage AI to improve security operations? 
  • How do we balance innovation with risk?

There was a clear recognition that AI is changing both sides of the cybersecurity equation. Defenders are increasingly using AI to accelerate detection, investigation, and response, while attackers are finding new ways to use AI to scale phishing campaigns, social engineering attacks, and reconnaissance activities. 

The takeaway that stuck with me was that organizations don’t need to have all the answers today, but they do need a strategy. Security leaders who are waiting for the technology to mature before taking action may find themselves behind the curve. 

Theme 2: Human Behavior and Building Security Cultures 

One of my favorite sessions focused on security culture and behavior. For years, many organizations have treated security awareness training as a compliance exercise. What I heard repeatedly at the summit was that this approach is no longer enough. 

Several Gartner analysts emphasized that employees are often placed in situations where business pressures, competing priorities, and workflow friction make secure behavior difficult. Instead of simply telling people to be more security conscious, organizations should focus on making secure choices easier and more intuitive. 

That perspective resonated with me because it reflects a reality most security professionals experience every day. Technology controls are critical, but people remain one of the most important variables in any security program. The organizations that will be most successful are likely those that build a genuine security culture rather than relying solely on annual training modules and policy reminders. 

Theme 3: Organizational Resilience: Preparing for Disruption  

Another recurring theme was resilience. For years, security teams have focused heavily on prevention. While prevention remains important, there was broad acknowledgment throughout the conference that organizations must also be prepared for the reality that incidents will occur. 

The conversation has shifted from “How do we stop every attack?” to “How quickly can we detect, respond, recover, and continue operating?” I found this particularly relevant given today’s threat landscape. Whether the challenge is ransomware, supply chain compromise, insider threats, or emerging AI-driven attacks, resilience has become a critical business capability rather than simply a security objective. 

The most mature organizations are measuring success not only by the number of attacks blocked, but also by their ability to maintain operations during disruption. 

Cybersecurity’s Expanding Role: Why Security Leaders Are Becoming Business Leaders 

Perhaps the biggest takeaway I left with was that cybersecurity continues to move closer to the center of business strategy. Across many sessions, speakers emphasized that CISOs are increasingly expected to be business leaders, not just technology leaders. Security decisions are now intertwined with digital transformation initiatives, AI adoption strategies, regulatory requirements, customer trust, and organizational growth. 

The most effective security leaders are learning how to communicate risk in business terms, align security investments with organizational objectives, and demonstrate measurable outcomes. That shift was evident throughout the conference and reflects how much the role of security has evolved over the past decade. 

Overall, the Gartner Security & Risk Management Summit reinforced the idea that cybersecurity is no longer just about protecting systems. It’s about enabling organizations to innovate confidently, adapt to change, and build resilience in an increasingly unpredictable world. 

For me, the event served as a valuable reminder that while technologies will continue to evolve, the most successful security programs will be those that effectively balance people, processes, and technology while staying aligned with business goals. 

I’m already looking forward to seeing how these conversations evolve over the next year.