Cyber Regret at the Gartner Security & Risk Management Summit: From Risk Dysfunction to Risk Agency

The Gartner Security and Risk Management Summit is running this week at National Harbor in Washington, DC, and the theme is "Smarter, Faster, Stronger... Together." Almost every session points in one direction, which is speed. The opening keynote called the next eighteen months a compressed decision cycle where the cost of waiting keeps rising. The Day 1 sessions covered how to secure AI agents before they act on their own, how to scale AI in cybersecurity while proving a return, and where security skills and tools will be by 2030. The message to the CISOs in the room is simple. Move faster, especially on AI.

One session says the opposite, and it is the one to watch. Gartner has a name for it now, cyber regret. The research describes a reckoning building in boardrooms over the cybersecurity money spent in recent years. The numbers are blunt. Seventy-one percent of directors want to take on more technology risk to grow the business, but nearly forty percent have low confidence in their current cybersecurity investments, and the share of directors with high confidence has dropped from twenty-five percent in 2024 to fourteen percent today. Boards are not asking security to spend less. They want to bet more on technology, and they no longer trust that the security function will help them win.

The Pattern Behind the Regret

The problem is not that companies spent too little or hired the wrong people. It is how the spending happened. Cybersecurity budgets grew one crisis at a time. A breach made the news, or a new threat appeared, and the company bought a tool to handle it. Then the next threat arrived, and the company bought another tool. After years of this, most organizations are left with a large bill and a pile of point solutions that were never designed to work together. The regret comes from the high spend and the sprawl of tools to keep running, with no clear picture to show for it.

Governance, risk, and compliance (GRC) grew the same way, only earlier. Legacy GRC was driven by regulation. A new rule landed, and the company bought a tool to comply. Another rule landed, and it bought another. The result was the same, a stack of disconnected, aging systems that satisfy auditors but do not add up to much else. When a company then relies on that legacy, disjointed GRC technology to answer its enterprise risk management questions, it meets the same disappointment the board now feels about cybersecurity.

None of this is new, and it does not need a new label. It is the same disconnection that integrated risk management was created to address. John A. Wheeler identified the pattern in 2016, when he led the Gartner research that defined the integrated risk management category, and it has only grown more expensive since. The IRM Navigator Curve, developed by Wheelhouse Advisors, gives the condition a name. It is risk dysfunction, the bottom of a climb that ends in risk agency, the point where an organization can finally act on risk instead of only documenting it. Cyber regret is what risk dysfunction feels like once the bill grows large enough for the board to notice. The tools change and the crisis that triggers the next purchase changes, but the dysfunction holds, because reactive buying produces disconnected systems, and disconnected systems cannot answer the question leadership actually has, which is whether all of this spending is helping the business grow.

Why the Tools Cannot Answer the Question

The IRM Navigator Model explains why. It lays out risk management as four connected domains. GRC handles rules and compliance. Technology risk management, which includes cybersecurity, handles protecting the company's assets. Operational risk management handles day-to-day processes. Enterprise risk management handles business goals and performance. Each domain is built to answer a different kind of question, and only enterprise risk management is built to answer the one about performance and growth.

That is the heart of the regret. When the board asks whether its technology spending is moving the business forward, it is asking a performance question. GRC cannot answer it, because GRC reports on compliance. Cybersecurity cannot answer it, because cybersecurity reports on protection. So the board funds those two areas heavily, asks them a question they were never designed to handle, and gets back what they are built to produce. It receives compliance reports and security updates, hears nothing about growth, and loses confidence. The tools are doing their jobs. They are simply the wrong tools for this question.

Enterprise risk management is supposed to fill that gap. In most companies it cannot, for two reasons. The first is that it has been built on the same legacy GRC technology and asked to produce the same compliance reports. Recent research from COSO and Crowe found that almost every risk leader believes ERM should be more strategic, while only seven percent say it actually is, and more than half of programs are seen as compliance or assurance functions. The second is that the function is thinly staffed. Gartner's own benchmarking puts the average ERM team at two and a half full-time people, and most of those teams are not yet turning to AI to extend what they can do. So the company stays in risk dysfunction no matter how much it spends, because the one function that could lift it out has been built to behave like all the others, with the smallest staff in the building.

Use AI to Bring It Together, Not to Go Faster

AI is the first tool the risk function has ever had that can pull those disconnected pieces into one place. That is the promise in the last word of the conference theme, together, and it is real. The trouble is the word sitting next to it. Most companies are reaching for faster, and faster is where they go wrong. Point AI at the pile of tools already installed and it speeds up what is there. The compliance reports and security updates arrive sooner and in greater volume, still disconnected from the business. Used that way, AI does not close the gap the board is frustrated by. It widens it, because now the wrong answers come faster than anyone can stop to question them.

The smarter way runs in the opposite order. Integrated risk thinking comes first and fuels the AI, instead of the AI being bolted onto whatever happens to be installed. Connect the four domains, point AI at the connected whole, and it can do what no small team could do by hand. It can read across compliance, protection, operations, and performance at once and tell leadership whether the strategy is holding. For a function Gartner sizes at two and a half people, that is not a nice-to-have. It is the only way a team that small ever produces a picture that big.

Used this way, AI is how a program climbs out of risk dysfunction. The faster path keeps a company stuck near the bottom, doing the same compliance work at higher speed. The smarter path carries it up the IRM Navigator Curve toward Autonomous IRM, the top of the climb, where the program reaches risk agency. At that point risk is built into the business, watched in real time, and acted on rather than just reported. It is also the only place a company can govern the fast-moving AI agents this conference keeps warning about, because machine-speed risk cannot be managed with a quarterly report.

Risk agency does not mean the machines take over. It means people and machines can both act on the same connected view of risk. The risk team finally sees the whole picture and can move on it. The AI watches continuously and acts within the limits the business sets. Human judgment and machine speed work from one view instead of from separate piles of tools. That partnership is the point of the climb, and it is what the conference theme means by together.

What Actually Answers the Board

The board is asking for one thing. It wants a single, connected view of risk that shows whether its technology spending is both protecting the business and helping it grow. No legacy GRC system and no security tool can build that view alone, and neither can AI laid on top of them. It takes integrated risk thinking joined to modern technology that connects the domains and acts on what it finds, with AI used to bring the picture together rather than to speed up the pieces.

The keynote called this a moment to seize, and it is right. The companies that seize it will not be the ones that simply move faster on AI. They will be the ones that connect their risk functions first and then let AI work across the whole. Gartner has put a name on this year's version of the problem, and the problem itself is a decade old. The conference theme even names the way out, as long as companies read it in the right order. Smarter has to come before faster, and together has to come before either. Get that order right, and AI carries a company from risk dysfunction to risk agency, where people and machines act on one shared view of risk. Get it wrong, and it becomes a faster road to the same regret.


Sources

Samantha "Sam" Jones

Samantha “Sam” Jones is the lead research analyst for the IRM Navigator™ series and a core contributor to The RiskTech Journal and The RTJ Bridge. As a digital editorial analyst, she specializes in interpreting vendor strategy, market evolution, and the convergence of technology with enterprise risk practices.

As part of Wheelhouse’s AI-enhanced advisory team, Sam applies advanced analytical tooling and editorial synthesis to help decode the structural changes shaping the risk management landscape.

Previous
Previous

The Fraud Market Is Funding Its Way Toward Autonomous IRM

Next
Next

The Agent Sprawl Problem Is an IRM Problem