What Will We Look Like in 5 Years with AI?
This article shares the key security trends observed at the Gartner Summit 2025.

Gartner Summit 2025 was attended by security professionals from around the world and was held on a large scale, with over ▲5,000 participants, ▲around 250 exhibitors, and ▲approximately 360 sessions. A wide range of topics was addressed, including AI that is transforming the global cybersecurity landscape, along with zero trust security, the optimization of security operations, CPS security, and workspace security.
Keynote: Turning Hype into Opportunity
The opening keynote of Gartner Summit 2025, titled "Harness the Hype: Turning Disruption Into Cybersecurity Opportunity", was delivered by Gartner Distinguished VP Analysts Leigh McMullen and Katell Thielemann. The speech emphasized the importance of transforming excitement around emerging technologies into tangible cybersecurity opportunities.

Picture 1. Opening keynote of Gartner Summit 2025 (Source: Gartner)
The two speakers highlighted that, in a security landscape that is growing increasingly complex and unpredictable, Chief Information Security Officers (CISO) must be equipped with the following three capabilities to address both rising expectations around new technologies and growing security demands.
#1. Align cybersecurity with the organization's mission (Be Mission-Aligned)
CISOs must communicate from the perspective of strengthening protection and reducing exposure to attacks. This approach helps them avoid being swept up in the excessive hype surrounding new technologies. A CISO who understands and knows how to leverage hype can safeguard the organization amid change while also driving innovation. Moreover, this approach helps align cybersecurity efforts with the organization's broader business mission.
#2. Always be ready to innovate (Be Innovative-Ready)
CISOs must foster AI literacy across their organization so that entire departments can understand and experiment with AI. They should actively explore and apply real-world AI use cases within the cybersecurity domain to protect business innovation. AI security enhancement measures and risk response frameworks must be established to protect AI assets the organization invests in. AI, cybersecurity, and organizational change are all interconnected, and the ability to bridge these three is a core trait of CISO leadership.
#3. Respond quickly to change (Be Change-Agile)
CISOs must empower their teams to take ownership in solving problems and to act with initiative. When team members take initiative, they can use AI to automate repetitive tasks and focus on developing new technologies. This not only drives growth for the CISO but also for the entire team, cultivating the resilience needed to navigate any kind of change.
In closing, the two speakers encouraged CISOs to always approach emerging technology hype with a learning mindset, turning disruption into opportunity through informed leadership.
How Should We Approach AI, the Driving Force of the Next Decade?
AI has become central to cybersecurity, and the Gartner Summit 2025 featured numerous sessions dedicated to it. Among them, Gartner Distinguished VP Analyst Peter Firstbrook, who led the session "Future-Ready: Security Implications of Emerging GenAI Technologies," emphasized that "the next 10 years will belong to AI, bringing with it both great opportunities and risks."
#1. AI innovation and challenges
In this session, Peter Firstbrook explored the current state and future of AI security from three perspectives: ▲visible AI innovations ▲risks posed by AI ▲and long-term strategies for risk mitigation.
First, the key theme of emerging AI innovation is agentic AI. Agentic AI refers to AI agents specialized in specific domains that are capable of carrying out tasks autonomously. While today's AI assistants operate based on preset rules with limited autonomy, the rapid development of agentic AI is expected to lead to multiple specialized agents working in coordination, ultimately forming a dynamic AI agent ecosystem.
Peter Firstbrook emphasized that in security operations, there will be a need for AI agents specialized in different areas such as threat detection, analysis, and response. For example, a breach analysis agent could handle log analysis and code explanation, while an incident response agent could manage and plan response workflows. An agent optimized for attack surface management would be responsible for identifying, verifying, and reducing the organization's attack surface.
He also addressed the risks associated with AI adoption, in addition to its benefits. He warned of potential issues such as data lost during the use of generative AI, prompt-based attacks by threat actors, and unauthorized data access. He noted that threat actors are also leveraging generative AI, which is leading to more sophisticated phishing campaigns, deepfake attacks, and malware development. Furthermore, a notable example of the risks introduced by agentic AI was the concept of "LLM-as-a-judge." A concept where a large language model evaluates content generated by other LLMs or by humans. This evaluation could be prone to errors, resulting in inaccurate or misleading assessments.
As a solution to AI-related risks, Firstbrook proposed the "AI TRiSM Framework."

Picture 2. Gartner's AI TRiSM Framework (Source: Gartner)
AI TRiSM stands for Artificial Intelligence Trust, Risk and Security Management. From a security perspective, it is a framework in which the security of existing technologies in use by the organization is addressed first, followed by the security of AI infrastructure. Next, information governance such as data security is implemented, and then AI runtime inspection and AI governance are carried out. Peter Firstbrook stated that because AI-driven attacks can easily outpace human response, it is crucial to adopt a proactive cybersecurity approach that makes it harder for threat actors. He highlighted the importance of AI TRiSM as a foundation for such strategies, particularly in automating attack surface management.
#2. What will using AI look like in 2030?
As discussed, AI brings both benefits and risks. So what will we look like five years from now as users of AI in 2030? Gartner Distinguished VP Analyst Jeremy D'Hoinne explored the future of AI security in his session titled "Future of AI in Cybersecurity: AI Predictions and Roadmap Challenges for 2025–2028."

Picture 3: Jeremy D’Hoinne, Gartner Distinguished VP Analyst (Source: Gartner)
First, Jeremy D’Hoinne noted that expectations are outpacing the actual maturity of AI technology, leading to repeated cycles of hype and cooling-off. He also addressed ongoing discussions about the early arrival of Artificial General Intelligence (AGI), suggesting that it is more likely to emerge sometime after 2040. He repeatedly emphasized the importance of distinguishing between what AI can and cannot do at present, rather than exaggerating its potential.

Picture 4. AI security outlook presented by Gartner (Source: Gartner)
He then presented both optimistic and pessimistic outlooks for AI by 2030. On the optimistic side, he predicted that around 80% of all digital workers will be using generative AI to improve work efficiency. However, he also warned that by 2030, approximately half of all organizations may become overly reliant on generative AI, leading to weakened security capabilities.
Jeremy D'Hoinne stressed that, given the rapid pace of AI development, organizations must shift from traditional three-year roadmaps to flexible, experiment-driven strategies on a six-month cycle. He also emphasized that AI should be defined as an activity rather than an objective. Rather than saying "we are adopting AI," organizations should set specific, measurable goals such as "we are improving detection accuracy with AI." In conclusion, he urged that the true value of AI can only be realized when it is supported by ▲measurable outcomes ▲a willingness to experiment and accept failure ▲and adaptable strategies.
What is the Future of the Next Generation Network Security Platform, SASE?
Secure Access Service Edge (SASE) is a security framework that prioritizes performance and management efficiency in line with modern traffic patterns, while also putting a focus on applying zero trust principles. From a functional standpoint, its components include ▲SD-WAN ▲firewall ▲SWG ▲ZTNA ▲and CASB. SASE is considered one of the most comprehensive concepts among current network security platforms.
So how should organizations approach SASE? In the session titled "Technical Insights: Which SASE Operating Model Is Right for Me?", Gartner VP Analyst Andrew Lerner cited Gartner survey findings, explaining that 70% of companies view security functions as the top priority when it comes to SASE. This was followed by ease of management (51%) and unified policy control (44%), while networking capabilities ranked lower at 19%.
He identified the main reasons enterprises adopt SASE platforms as follows: ▲replacing VPNs ▲reducing management complexity ▲modernizing branch offices ▲establishing zero trust ▲and responding to increasingly distributed networking environments. He also noted that SASE implementation can be approached either through a single-vendor solution or by collaborating with multiple vendors. Typically, large companies that prioritize functionality tend to favor multi-vendor approaches, while smaller businesses that value convenience are more inclined to adopt single-vendor solutions.
Andrew Lerner then outlined the future direction of SASE platforms and emphasized the importance of tailoring adoption strategies based on the specific needs of each organization.
- Platform acceleration: Accelerated trend of integrating individual features into a unified SASE platform
- Expansion of sensitive data detection and control: Highlighted as important as threat intelligence
- AI application: Generative AI assistants, generative AI-based control, expansion of agentic AI adoption
- Expansion of use cases: Universal ZTNA, networking in public places, expansion to LAN and IoT devices
- Integration with adjacent solutions: Expansion to EPP, DSPM, SSPM, and XDR areas
CPS Security is About Protecting Society, Not Just Systems
According to Gartner, a Cyber-Physical System (CPS) is an engineered system that coordinates sensing, computation, control, networking, and analytics functions to interact with the physical world, including humans. In the past, the concept of OT security was commonly based on the Purdue Model, which emphasizes separation from external networks. However, as OT and IT become increasingly interconnected, the complexity of securing these environments has grown significantly.
Gartner VP Analyst Wam Voster explored the present and future of CPS security in his session titled "Outlook for Cyber-Physical Systems Security 2025."

Picture 5. Wam Voster, Gartner VP Analyst
First, Wam Voster noted that the number of ransomware groups increased from about 50 in 2023 to 120 in 2024, with 40 of them launching attacks specifically targeting the manufacturing sector. He explained that nearly half of the attacks aimed at CPS were targeted attacks, where threat actors observed their targets over an extended period before striking.
He pointed out that while many organizations understand the connection between CPS and IT, they still struggle to implement security measures effectively. In CPS security, the biggest issues are ownership and governance. It was noted that departments responsible for CPS assets, like security teams and IT departments, often shift responsibility onto one another. Furthermore, he emphasized that in CPS security, clear accountability is essential, and owning assets also means accepting the associated risks and responsibilities.
Finally, Wam Voster conveyed the message that there are many infrastructures in our society that need protection, and they are interconnected. CPS security is about protecting society, not just systems. And for effective CPS security, he recommended the following measures.
- Reduce the opportunities for threat actors to breach by proactively managing CPS.
- Use the MITRE ATT&CK for ICS framework to understand threat actors' tactics, techniques, and procedures (TTPs).
- Avoid assuming that a CPS security platform will work seamlessly in your corporate environment and select the most appropriate solution through proof of concept (PoC) testing.
- Review references and real-world use cases for AI-based CPS security capabilities to distinguish between exaggerated claims and actual operational value.
- Conduct internal training to raise security awareness and clearly define roles and responsibilities within the organization.
- Develop an incident response plan and continuously test it.
Workspace Security: The Key is Efficiency
Workspace Security is a new security concept introduced by Gartner that focuses on integrating people, processes, and technologies to protect employees working in hybrid environments. Key protection targets include devices, applications, data, credentials, and ID systems.
In the session titled "Strategic Roadmap for Workspace Security 2025," Peter Firstbrook pointed out that many organizations still struggle with breach response because their security infrastructure remains fragmented. While threat actors have already begun enhancing their methods using AI, most defenders are suffering from a lack of personnel and insufficient automation.

Picture 6. Peter Firstbrook, Gartner Distinguished VP Analyst
Looking at the Workspace Security components presented by Gartner, they include ▲Edge security (Internet and email security) ▲endpoint detection & response (EDR) ▲identity access management (IAM) ▲data loss prevention (DLP) ▲user behavior recognition (security behavior and culture) ▲and other services (asset discovery, security configuration assessment, vulnerability detection & response).
However, Peter Firstbrook emphasized that the ultimate goal of Workspace Security is not to have every security tool, but to operate a minimally effective portfolio that is integrated and manageable. He also urged organizations to achieve efficiency through security structures centered on automation, such as Continuous Threat Exposure Management (CTEM).
On this topic, Gartner VP Analyst Chris Silva pointed out in the session "Forget the Hype: 5 Key Things You Should Be Doing to Secure Your Endpoints" that many organizations are chasing the hype around new technologies while neglecting security fundamentals. He then introduced five key elements organizations can implement immediately to strengthen workspace security.
Five key elements:
- EDR: A key security technology that enables real-time attack detection and proactive response
- Application control: Identifying programs running on endpoints and restricting risky behaviors
- Security configuration management: Treating configuration management as a standalone layer of defense
- Patch management: Prioritizing patches based on evidence, especially as medium-severity vulnerabilities are often exploited
- Mindset: Moving from siloed approaches to a connected and integrated perspective
Chris Silva advised that sustainable and efficient security operations can only be achieved when these technical foundations—EDR, application control, security configuration management, and patch management—are paired with a structural shift that integrates security and operations mindsets.
Conclusion: Be Efficient Now, Be Bold for the Future
The key message of Gartner Summit 2025 was "Engage. Innovate. Lead." As new concepts and technologies like AI and zero trust continue to emerge rapidly, the values of collaboration and innovation are drawing sustained attention. This trend was clearly visible throughout the exhibition hall where cybersecurity vendors participated.

Picture 7. Gartner Summit 2025 exhibition hall
However, as discussed in the section on Workspace Security, it is also critically important to enhance the efficiency of currently deployed security solutions to safeguard the present effectively. AhnLab is fully aware of this need and continues to dedicate itself not only to the development of future-oriented technologies such as AI, but also to improving the usability of the solutions and services currently provided to its customers.
We hope that readers will also, as the closing subheading suggests, "be efficient now and be bold for the future" to securely protect your business.