Gartner tells London CISOs AI agents, quantum clocks and deepfakes are now operating problems

Day 2 of the Security & Risk Management Summit puts seven named threats on the board, a three-wave post-quantum plan, and a survey showing 41 percent of security chiefs already saw a deepfake on an employee audio call

Gartner analysts spent Wednesday telling security chiefs that the next few years will not wait for tidy roadmaps. Day 2 of the firm’s Security & Risk Management Summit here put AI agent sprawl, quantum-ready crypto and a 2030 skills crunch on the same agenda.

The meeting runs Sept. 22-24. Gartner’s Day 2 note flagged three sessions: Marty Resnick on seven forces that can knock an organization off course, Thomas Lintemuth on post-quantum cryptography in three waves, and Peter Firstbrook on what cyber work looks like in 2030.

Resnick, a vice president analyst, framed the landscape through what Gartner calls Tapestry, or TPESTRE: technology, politics, economics, social factors, trust, regulatory and environmental forces. He listed seven emerging threats CISOs have to treat as live, not theoretical. AI agent sprawl. Sovereignty fragmentation. The human cost of agentic AI in cybersecurity. The great employment divergence. Customer interactions in the age of agents. Unexplainable AI stalling security rollouts. The circular IT supply chain attack vector.

Two forecasts sat under that list. Gartner predicts that by 2028, ungoverned AI agent abuse will drive 25 percent of enterprise breaches and will force zero-trust governance plus agent-specific kill switches. It also predicts that by 2028, 30 percent of multinational organizations will have to restructure their AI architecture to meet multipolar national sovereignty rules, lifting operating costs 20 percent.

Resnick’s staffing line was blunt. “Organizations that enable their employees to grow with the adoption of AI will see greater growth and innovation than those that choose to eliminate staff today with the expectation that AI will be a reliable replacement.”

That is the executive problem in one sentence. Cut headcount on a bet. Or train people through the same tools that are chewing the perimeter.

Lintemuth, also a vice president analyst, took the crypto clock. “Quantum computers pose a significant threat to cybersecurity primarily because they can break many of the cryptographic algorithms currently used to secure the digital world.”

Another: “Gartner predicts that a sufficiently powerful quantum computer could arrive by the end of the decade. It is not so much a matter of if, but when.”

He split the work into three waves. Wave 1: strengthen symmetric encryption and migrate to post-quantum key exchange. Wave 2: upgrade private PKI and the hardware security modules under it, and watch public PKI. Wave 3: migrate digital signatures, starting with long-lived use cases, and budget for possible hardware swaps.

“Post quantum cryptography (PCQ) will come at us in three waves. Security leaders need to be prepared and have a plan to address the waves as they hit.”

And this, which matters even if Q-day slips: “Migration to post-quantum cryptography will happen regardless of if quantum computing becomes a real threat or not.”

Developers sitting on TLS, signing keys, HSMs and firmware that will still be in the field in 2030 already know what that sentence costs. Inventory first. Then the waves.

Firstbrook, a distinguished vice president analyst, ran the keynote on skills, AI and the stack through 2030. “CIOs must define a clear ‘north star’ for IT, establishing a high-level vision for the organization’s future. This vision involves selecting archetypes to guide direction, determining the pace of transformation, and deciding whether to pursue an AI-first approach or proceed cautiously.”

The stack, he said, has to move from AI-readiness to agent-readiness and then democratization-readiness. “By 2030, cybersecurity expertise must be embedded into ad hoc agile development processes.”

Headcount does not shrink just because tools get faster. “Cybersecurity headcount needs to increase despite productivity gains. The increased complexity, expanded threat landscape, and regulatory scrutiny associated with AI require a larger, augmented cybersecurity workforce.”

Ownership split: “CISOs must become active enablers of business-led innovation; however, responsibility for GenAI security must also reside with the business.”

Gartner also kept a Tuesday survey on the Day 2 board. In a March-May 2026 poll of 297 senior cybersecurity leaders, 41 percent of CISOs reported at least one social engineering incident involving a deepfake on an employee audio call in the prior 12 months. Thirty-six percent reported one on a video call. Seventy-nine percent saw at least one email phishing, spear-phishing or business email compromise case. Fifty-eight percent reported vishing or smishing.

“Attackers can combine phishing, business email compromise, synthetic media, and aggregated personal context across multiple channels,” said Craig Porter, a director analyst at Gartner. “Most attacks will continue to rely on users, stolen credentials, weak recovery processes, and familiar technical methods. CISOs must use the same discipline used to assess identity and access risks to combat AI-driven social engineering threats.”

For boards and builders, the Day 2 packet is a punch list, not a slogan. Name who owns each agent. Put a kill switch on it. Start the crypto waves before the hardware queue gets ugly. Do not treat AI as a license to thin the security bench. And treat voice and video the way email was treated after BEC became ordinary.

The summit continues Thursday. Media contact listed on the release is Laurence Goasduff at Gartner.

Subscribe
Notify of
0 Comments
Oldest
Newest Most Voted
0
Would love your thoughts, please comment.x
()
x