Gartner Metrics Shift Cybersecurity From Patch Counts To AI Attack Paths
Gartner analyst Emily Tan argues that AI-assisted attacks make outcome-driven metrics, recovery planning and attack-path analysis more useful than patch-volume dashboards for cyber leaders.

AI-assisted attack paths are pushing vulnerability management away from patch-count dashboards and toward business-exposure decisions, as Gartner analyst Emily Tan argued in a ComputerWeekly article on outcome-led cybersecurity.
The shift is not that patching no longer matters.
Attackers using frontier AI models can compress the work of finding weaknesses, linking them to system behaviour and turning them into credible attack paths.
That reduces the useful time defenders get from traditional discovery and remediation cycles.
Patch Volume No Longer Measures Exposure
Security teams already use AI to improve threat detection, speed investigations and automate routine work.
Tan wrote in ComputerWeekly that attackers are using increasingly capable AI models to identify weaknesses, chain vulnerabilities and develop attack paths in a fraction of the time previously required.
A backlog metric can therefore mislead executives.
Tan's argument is that an attacker cares less about the number of patched vulnerabilities than about how long a useful weakness remains exploitable and whether it can be chained into a path that affects a critical service.
That distinction changes remediation priorities.
Some vulnerabilities may never need immediate action, while others cannot be removed through a patch alone.
A programme that tries to repair everything can exhaust security teams while leaving the combinations that drive real exposure insufficiently controlled.
Outcome Metrics Put Recovery Into The Decision
Outcome-driven metrics move the question from activity to effect.
Security and risk management leaders should test whether investments reduce attacker opportunity, protect the most critical services and improve resilience when prevention fails.
Recovery becomes part of that same measurement model.
The ComputerWeekly article says critical business services should have documented recovery plans, executive teams should rehearse cyber incidents and segmentation, identity controls and compensating controls should operate as standing resilience capabilities rather than last-minute emergency measures.
Gartner calls this measurement class outcome-driven metrics, or ODMs.
The examples include time to patch high-risk vulnerabilities, speed of compensating-control deployment when no patch is available, whether attack path analysis drives prioritisation, recovery time from complex incidents and how much technology debt still creates exploitable exposure.
The operating target is larger than a new dashboard.
Gartner's definition of AI-First cybersecurity, cited by Tan, puts the 2030 target at about 80% of cybersecurity workflows augmented by AI and AI security platforms supporting self-service across the enterprise.
Gartner also points to peer-comparable data across 25 cyber metrics and plans to examine AI-powered attack strategy at its London Security & Risk Management Summit from 22-24 September 2026.
For boards, the measurable issue is whether cyber spending shortens attacker opportunity and speeds recovery, not whether the vulnerability count looks smaller at the end of the month.




















