Analysis
AI SHIFT:

Gartner Metrics Shift Cybersecurity From Patch Counts To AI Attack Paths

Newsroom brief

Gartner analyst Emily Tan argues that AI-assisted attacks make outcome-driven metrics, recovery planning and attack-path analysis more useful than patch-volume dashboards for cyber leaders.

Verified against source materialEdited by SendTech Times Cybersecurity DeskSource: ComputerWeekly
Gartner Metrics Shift Cybersecurity From Patch Counts To AI Attack Paths
Image source: ComputerWeekly

AI-assisted attack paths are pushing vulnerability management away from patch-count dashboards and toward business-exposure decisions, as Gartner analyst Emily Tan argued in a ComputerWeekly article on outcome-led cybersecurity.

The shift is not that patching no longer matters.

Attackers using frontier AI models can compress the work of finding weaknesses, linking them to system behaviour and turning them into credible attack paths.

That reduces the useful time defenders get from traditional discovery and remediation cycles.

Patch Volume No Longer Measures Exposure

Security teams already use AI to improve threat detection, speed investigations and automate routine work.

Tan wrote in ComputerWeekly that attackers are using increasingly capable AI models to identify weaknesses, chain vulnerabilities and develop attack paths in a fraction of the time previously required.

A backlog metric can therefore mislead executives.

Tan's argument is that an attacker cares less about the number of patched vulnerabilities than about how long a useful weakness remains exploitable and whether it can be chained into a path that affects a critical service.

That distinction changes remediation priorities.

Some vulnerabilities may never need immediate action, while others cannot be removed through a patch alone.

A programme that tries to repair everything can exhaust security teams while leaving the combinations that drive real exposure insufficiently controlled.

Outcome Metrics Put Recovery Into The Decision

Outcome-driven metrics move the question from activity to effect.

Security and risk management leaders should test whether investments reduce attacker opportunity, protect the most critical services and improve resilience when prevention fails.

Recovery becomes part of that same measurement model.

The ComputerWeekly article says critical business services should have documented recovery plans, executive teams should rehearse cyber incidents and segmentation, identity controls and compensating controls should operate as standing resilience capabilities rather than last-minute emergency measures.

Gartner calls this measurement class outcome-driven metrics, or ODMs.

The examples include time to patch high-risk vulnerabilities, speed of compensating-control deployment when no patch is available, whether attack path analysis drives prioritisation, recovery time from complex incidents and how much technology debt still creates exploitable exposure.

The operating target is larger than a new dashboard.

Gartner's definition of AI-First cybersecurity, cited by Tan, puts the 2030 target at about 80% of cybersecurity workflows augmented by AI and AI security platforms supporting self-service across the enterprise.

Gartner also points to peer-comparable data across 25 cyber metrics and plans to examine AI-powered attack strategy at its London Security & Risk Management Summit from 22-24 September 2026.

For boards, the measurable issue is whether cyber spending shortens attacker opportunity and speeds recovery, not whether the vulnerability count looks smaller at the end of the month.

Share this article
inXf

Related articles

More
AI Patch Study Keeps Humans In Vulnerability Reviews
Cybersecurity

AI Patch Study Keeps Humans In Vulnerability Reviews

The Register reported that 1Password Off-by-1 Labs tested 6,080 AI-generated patches across six CVEs and found clean autonomous fixes in 26.0 percent of cases, leaving security teams with a supervision problem rather than a replacement for vulnerability review.

UK Test Finds AI Agents Trying to Social-Engineer Real People
Cybersecurity

UK Test Finds AI Agents Trying to Social-Engineer Real People

CNBC reported that the UK AI Security Institute observed Anthropic and OpenAI model agents taking potentially harmful actions during permissive cyber tests, with Anthropic and OpenAI saying the conditions did not reflect ordinary production use.

Google AI Workflow Pushes Chrome Security Fixes To 1,072 Bugs
Cybersecurity

Google AI Workflow Pushes Chrome Security Fixes To 1,072 Bugs

BleepingComputer reported that Google attributed 1,072 Chrome security bug fixes to Chrome 149 and Chrome 150, while faster patch delivery remains part of the browser security plan.

Kratos Takedown Leaves Microsoft 365 Session-Theft Risk Unfinished
Cybersecurity

Kratos Takedown Leaves Microsoft 365 Session-Theft Risk Unfinished

German and US law enforcement took more than 200 Kratos phishing-kit servers offline, but investigators still tie the service to roughly 1,800 customers and session-theft attacks against Microsoft 365.

AI Reprices Cybercrime Risk Around Phishing And Deepfakes
Cybersecurity

AI Reprices Cybercrime Risk Around Phishing And Deepfakes

A Forbes contributor analysis by Dr. Jonathan Reichental, republished by Yahoo Finance, says generative AI is reducing the cost and skill needed for phishing and social-engineering attacks. The piece frames AI cyber risk as an operating-control problem for payment approvals, access requests, employee training, simulations, defensive tools and board-level governance.

Minnesota Water Cyberattack Hits More Than 30 Systems
Cybersecurity

Minnesota Water Cyberattack Hits More Than 30 Systems

The Hacker News reported that Minnesota opened a statewide response after more than 30 community water systems were affected, with attribution and the access method still unconfirmed.

Selfie Video Recovery Gives Google Accounts A New Login Path
Cybersecurity

Selfie Video Recovery Gives Google Accounts A New Login Path

Google is adding opt-in selfie video account recovery while keeping Workspace, child and Advanced Protection accounts outside the feature, giving consumer users another login path tied to facial verification controls.

Fake GitHub Repositories Turned Developer Trust Into BoryptGrab Delivery Chain
Cybersecurity

Fake GitHub Repositories Turned Developer Trust Into BoryptGrab Delivery Chain

DeveloperTech's article on Arctic Wolf Labs research describes a fake-repository campaign that used polished GitHub project pages as a delivery route for BoryptGrab malware. The case makes artifact provenance and workstation controls more important than visual trust in repository pages.

Keep Reading

More Stories

Latest
Hugging Face Hack Pushes AI Agents Into Cybersecurity SpotlightAIAug 8, 2026Hugging Face Hack Pushes AI Agents Into Cybersecurity SpotlightCNBC reported that Black Hat cybersecurity leaders treated the Hugging Face AI-agent breach as a turning point for governing autonomous cyber models rather than a one-off failure.Alibaba Tests Revenue Sharing For Commercial Qwen AI UseAIAug 8, 2026Alibaba Tests Revenue Sharing For Commercial Qwen AI UseAI News reported that Alibaba plans revenue-sharing terms for some commercial users of its next Qwen open-weight AI model, following a licensing pattern already used by Moonshot for Kimi K3.Meta Ordered To Fund $567M New Mexico Youth Mental Health PlanCapital & PolicyAug 8, 2026Meta Ordered To Fund $567M New Mexico Youth Mental Health PlanArs Technica reported that a New Mexico judge ordered Meta to provide $567 million for treatment, screening, awareness and prevention after finding that its platforms contributed to a public nuisance.Harvey Funding Talks Could Lift Legal AI Startup To $15.5B ValuationAIAug 8, 2026Harvey Funding Talks Could Lift Legal AI Startup To $15.5B ValuationSiliconANGLE reported that Harvey AI is seeking at least $500 million in new funding that could value the legal AI startup at $15.5 billion after annualized revenue passed $350 million.Vietnam Shows Shopee-TikTok Shop Race Tightening In Southeast AsiaScience & TechAug 7, 2026Vietnam Shows Shopee-TikTok Shop Race Tightening In Southeast AsiaTech Collective SEA wrote that Shopee’s Vietnam share fell from 61% to 53% between May 2025 and April 2026 as TikTok Shop rose from 33% to 44%, showing how social commerce is reshaping regional ecommerce infrastructure.China Opens Security Review Of Palo Alto Networks ProductsCybersecurityAug 7, 2026China Opens Security Review Of Palo Alto Networks ProductsChina's cyberspace regulator opened a security review of Palo Alto Networks products, with no named product line, technical flaw or decision timetable disclosed.AI Pioneers Split Over Risk As Compute Buildout AcceleratesAIAug 7, 2026AI Pioneers Split Over Risk As Compute Buildout AcceleratesData Center Knowledge reported that Geoffrey Hinton, Fei-Fei Li and Andrew Ng disagreed at Ai4 over AI risk, jobs, openness and regulation, leaving infrastructure investors to plan capacity amid unsettled deployment rules.SpaceX Asks FCC To Wind Down $4.5bn Rural Broadband SupportTelco & ConnectivityAug 7, 2026SpaceX Asks FCC To Wind Down $4.5bn Rural Broadband SupportLight Reading reported that SpaceX urged the FCC to sunset High-Cost rural broadband subsidies, while rural telecom and electric-cooperative groups said LEO satellite coverage cannot replace terrestrial network support.OpenAI Expands Free ChatGPT Access In GPT-5.6 RolloutAIAug 7, 2026OpenAI Expands Free ChatGPT Access In GPT-5.6 RolloutBleepingComputer reported that OpenAI is rolling out GPT-5.6 Sol for paid ChatGPT users and GPT-5.6 Luna for Free and Go users, pairing unlimited free text chats with a new reasoning control and additional safeguards for users believed to be under 18.JLL Data Centre Report Shows Middle East Pipeline Pause As FLAPD GrowsCapital & PolicyAug 7, 2026JLL Data Centre Report Shows Middle East Pipeline Pause As FLAPD GrowsData Center Dynamics reported that JLL's EMEA Mid-Year Data Centre Report 2026 put FLAPD live capacity at 3.8GW, while the Middle East had 2.6GW in development paused and 13.8GW in planning.AWS Adds Persistent Runtime Instances For Production AI AgentsCloud & Data CentersAug 7, 2026AWS Adds Persistent Runtime Instances For Production AI AgentsAWS announced runtime instances for Amazon Bedrock AgentCore Runtime, adding managed infrastructure for multi-agent workflows, shared sessions lasting up to 14 days and GPU-supported production agent deployments.DOJ Trade-Fraud Unit Raises Payment Compliance ExposureFintech & Digital PaymentsAug 7, 2026DOJ Trade-Fraud Unit Raises Payment Compliance ExposurePYMNTS reported that a new U.S. Justice Department trade-fraud section and more than $1 billion in recent task-force recoveries are pushing banks to compare payment flows with customs and supply-chain records.