Turning “Hype” Into an Opportunity in Information Security
Hype Can Be a Threat or an Opportunity
In the keynote address at the 2025 Gartner Security & Risk Management Summit, experts focused on how technological “hype”—particularly in the field of Artificial Intelligence—can be transformed into an opportunity to improve an organization’s security posture. They noted how enthusiasm for technologies like AI can drive the development of innovative solutions in the security market. On the other hand, hype can also lead to hasty decisions and a sense of pressure following new technological threats; therefore, the excitement surrounding AI requires a cautious approach. While hype can lead to unnecessary investments in unproven technology, experts highlighted how it can be utilized to enhance organizational information security programs. The attention drawn by hype should be leveraged to promote grounded upgrades that ensure relevant and robust defense capabilities.
Managing Hype and Associated Risks: Balancing Hype with Real Risks
When dealing with security risks and hype, it is crucial not to be drawn into panic caused by excitement over unproven solutions. Experts stressed the need for clearly defined goals and information security metrics while maintaining transparency with executive leadership. Utilizing Protection Level Agreements (PLAs) and Outcome-Driven Metrics (ODMs) can assist in planning investments accurately and deliberately. Researchers recommend transparency in discussions with management regarding required protection levels and addressing needs through a fact-based approach. For example, if there is a need to increase the percentage of critical systems covered in the event of a cyberattack, the costs and implications must be presented clearly.
AI Technologies and Their Security: AI Risks and the Need for Technological Literacy
The presentation highlighted the need to understand how AI is being utilized and emphasized the importance of “technological education” for information security teams. Experts recommended training for the judicious use of AI technologies while establishing clear guidelines for recommended use versus use cases that should be avoided. Additionally, it was noted that AI tools are currently used to automate processes such as threat hunting and improving remediation workflows; however, security policies must be diligently updated to prevent new technology-related risks.
Recommendations from IPV Security Information Security Experts:
* Train teams for responsible use of new technologies: Ensure that teams leading the security domain understand the impact of tools like AI on the organization’s information security.
* Define clear metrics for risk assessment: Use Outcome-Driven Metrics (ODMs) to understand existing risk levels and manage technology investments responsibly.
* Maintain transparency with management: Share desired security levels transparently with executive leadership. This transparency helps avoid rapid decisions based on hype or fear, and prevents investment in technologies that have not yet proven effective or reliable.
Conclusion
The hype surrounding new technologies, and AI in particular, presents both challenges and advantages. By properly managing expectations and investing in proven technologies, an organization can upgrade its security capabilities while maintaining stability and long-term performance.
For further information: https://www.darkreading.com/application-security/gartner-security-teams-hype-opportunity
**