Podcast

Root Causes 632: Gartner Risk and Security 2026 Wrap Up

Hosted by
Tim Callan
Tim Callan
Chief Compliance Officer
Original broadcast date
June 22, 2026

We recently attended the Gartner Risk and Security conference for 2026, where we observed a great deal of attention on not only AI but also post quantum cryptography (PQC). Join us as we share the key takeaways.

Podcast Transcript

Tim CallanTim CallanSo, Jason, you and I both recently had the opportunity to attend the Gartner Risk and Security Conference. And we compared notes a little - I think we had a lot of the same impressions, and let's share them with the listeners here.
Jason SorokoJason SorokoTim, two big overarching topics.
Tim CallanTim CallanI would say that AI - it starts with an A. Yes.
Jason SorokoJason SorokoNo surprises there. I think they got the memo from our podcast that AI is the room. And I would go as far as to say that Gartner - in terms of even the way that they're presenting, the way that they plan their presentations, the way that the presentations are done - are AI-generated as well. And it's actually to their benefit.
Tim CallanTim CallanAbsolutely. To the point where I attended the "six security trends for 2026 and beyond" presentation, and all six of the trends were either AI or PQC. I mean, this conference - we all expected it. You and I didn't talk ahead of time.
Jason SorokoJason SorokoI would actually go that far. I would go that far. There was definitely some other security and risk, the title of the conference - there were definitely some other security and risk topics brought up. There was obviously stuff that you and I did not attend that was really focused on CISOs and other audiences, for their operational stuff.
Tim CallanTim CallanBut even then - when I did dip into some of that stuff and some of the material, or talked to some of the folks on the floor - even then, all that material was "how do we apply AI to this topic?" So even if there was a topic that was phishing, it was either AI as a threat that's changing phishing or AI as a tool that you use to help defend yourself against phishing. Like, either AI as a threat or AI as a response was - geez, apart from some of the real pure PQC stuff - I think in pretty much everything. I also think this is fully appropriate. So it was noteworthy to me how comprehensive, how just utterly ubiquitous AI is. Like someone painted the whole thing with an AI paintbrush. To the point where there weren't any gaps. On the other hand - and this is the important point - that was right. That was the correct way for the conference to be, because every single aspect of our security lives, attacking and defending, at this point is transformed by AI.
Jason SorokoJason SorokoAgreed, Tim. Then let's talk about the angle that they took with AI. This was a security conference, a security and risk conference, and they did take a security and risk angle to AI. It wasn't just AI in general, because that topic was even too big for this conference. But I would say this - here is the, if I'm trying to avoid proprietary information and also trying to give people information on this podcast - this is a sense I got, I don't know if I'm right, give me your opinion on this: AI security as a topic is the hottest brand-new thing. And Gartner brought a lot to the conference, obviously - brought a lot - but still not what I would call the real, true, cutting-edge AI security where it's at at this very moment. However - and here's the gigantic however - I don't think they could take it to the nth degree, because I saw a lot of eyes glazing over of security people who were not there yet.
Tim CallanTim CallanI think that's a really good point, Jason. And you're bringing up a nuance that was missing from my coverage
Jason SorokoJason SorokoSo, Tim, let me put it into slightly different language as well, because there's been so much in the news. We're not a news-coverage podcast, but we've got to bring it up. You and I recently brought up Mythos, right, in our podcast. And that was one of the elephants in the room of the conference.
Tim CallanTim CallanNo surprise. Came up all over the place, completely appropriately, as it should have. I mean, we were there - gosh, I'm guessing you might have this better in your head, Jay, but probably within a month of the big Mythos announcement, we were standing at that conference. So it was fresh, fresh, fresh - ink-is-still-drying kind of fresh - and all over the place.
Jason SorokoJason SorokoFable had not been released yet by that point of that conference. Yes, now we've had Fable released and taken away since.
Tim CallanTim CallanYes. Absolutely. And so, Mythos was clearly high on everybody's mind. I think there were two takes on Mythos I heard there. One of them was - gosh, it's the same thing we said: Mythos is going to be a game-changer, both in terms of attackers and also in terms of finding and stamping out vulns. The other take I heard was: don't get complacent that Mythos is going to find all your vulnerabilities. You need to still be vigilant, and you need to be conscious of the fact that there will be other attacks that you didn't get through this method. And I think that was a great point to bring up - because when you look at the coverage around Mythos, it's like "oh, Mythos is going to find all the zero-days." And, I forget who it was, but someone will say "eh, nothing has ever found all the zero-days, I wouldn't count on that" - which I think is a good, valid point for all of us to bear in mind as we're thinking about how Mythos changes the landscape.
Jason SorokoJason Soroko100%. I heard all of it. So I'll give you one more, which is just reading the room - the hallway conversation, the lunchroom conversation, the body language when keynotes were being spoken about. I really think that the acceleration caused by AI - and I'm talking acceleration from multiple dimensions - the acceleration is beyond a large number of people who are attending that conference. I think it's not just the "oh geez, there's a lot of new things for me to learn." It's the "this is all coming so fast, and my budgets aren't going to stretch to all of it." I'm thinking about -
Tim CallanTim CallanSitting at lunch with strangers who are just regular attendees around a big round table and just asking them. This is a thing I do at these conferences - I just say "hey, what did you guys hear? What do you think is cool?" And I just want to listen to how other people are perceiving it. And I'd say there was a general sense. Now, remember - these are people who paid a lot of money to go to a Gartner Security Conference. These are Gartner professionals, quite possibly CISOs, and if not CISOs, at least security professionals, full-time security professionals. And there was a strong sentiment around the table one of the days at lunch, which was: "I can't keep up. I don't know how to possibly take everything that's going on that I need to know and actually know it."
Jason SorokoJason SorokoAnd that's true - to the point where during the big kumbaya, rah-rah-sis-boom-bah keynotes, the high-energy music and the whole thing, people are sinking in their seats, not rising from their seats. And it has to do with what you just said - it's just too much for people right now. And I don't know how to solve that.
Tim CallanTim CallanI mean, to some degree AI can actually help us with that. It's a tool that can help sort and make sense of things. It is one of the tools that will help us navigate that. But again, it's not going to be a panacea for that.
Jason SorokoJason SorokoSo I think it's great that the way that we've brought up AI topics on this podcast - in terms of risk and security and everything else - are right along the lines of the way that Gartner is producing.
Tim CallanTim CallanIt was noteworthy, I think, how well-aligned those two were. And the other one where there was great alignment, that we need to segue to, was PQC. So AI - no surprise. We all expected it to be all over the place, and it was. I will admit - you may not agree, Jason, I'd love your take on this - but I will say that I was absolutely expecting PQC to be a topic. I was not expecting the amount of attention on PQC. If the show was 80% AI, the other 20% was PQC. It was amazing to me how much there was.
Jason SorokoJason SorokoI had the benefit, of course - because the company I work for is a Gartner client, and I know some of the analysts who are very deeply ensconced there. And they had told me, for a short while now, that the amount of work that they're doing with their clients on the topic of PQC has gone up greatly, and therefore what you saw at the conference reflected that. But I will agree with you that I didn't think that such an ultra-niche topic - that you and I cover on this podcast -
Tim CallanTim Callan- was going to be this. I thought there would be one well-attended session where they told us everything we needed to know, and it was going to be a big crowded room. There were probably ten sessions. Like, it was so much PQC, it was amazing. Now, one of the things - for people who don't attend Gartner, who don't understand the inner workings - one of the things they do is they look at how many sign-ups they have for sessions, and they will actually alter the agenda as time goes along to put more time into things that are getting more attention during pre-registration. So I interpret - I don't know this, I'm not a Gartner insider - but I interpret that they perceived a great deal of interest in terms of early sign-ups, and therefore expanded the agenda. That's my belief for what happened.
Jason SorokoJason SorokoTo the point where they did one of the most central PQC talks many multiples of times within the conference. And so, absolutely - so it's both, it's the sign-ups plus also the call volumes amongst the analysts - they make decisions. And so AI and PQC, who knew? AI, absolutely, but as you say, PQC - and the way in which they covered it, I thought, was very thoughtful, in terms of it was very pragmatic for that audience. I like how they presented, because they didn't go into the overwhelming math.
Tim CallanTim CallanThey didn't go into it - they went right into "here's what you guys have got to be thinking about right now." So I think the tone of it was perfect. There was a supposition that you knew what PQC was and why you needed it. I didn't see a single thing that said "I'm going to explain what a quantum computer is," or "I'm going to define Shor's law." I didn't go to that session, I did not see that occur. And I don't think there was one. It was very much a "what you need to do." And I agree with you - I walked in and I wasn't sure if I was going to see some kind of unrealistic, purist kind of approach. And this is some of what we sometimes get in the press, and you and I, in our various consulting on this - here on the channel and in our day jobs - I think are always strongly advocating a pragmatic, risk-based approach. What I recently said to somebody is: if it is cheaper to get breached than to fix the particular thing that might get breached, then you're going to choose to risk the breach. And that's what people are really going to do in the real world. And so giving them coherent advice about how to do that optimally - as opposed to giving them some kind of pure fairy-tale advice that won't actually occur - is the better way to serve those clients. And I felt like we very much saw a common-sense, pragmatic set of advice that - I don't know how much I'm allowed to say, but I'll just say - very closely aligns with what we've been saying on this podcast.
Jason SorokoJason SorokoAnd, Tim, all true - except, once again, I'm going to repeat the same thing I saw with a lot of the AI security talks. I didn't see a lot of "I got my head wrapped around this, thank you very much," and, rising from the seat like "I'm inspired, I've got to get to the office now and get this solved because I know what to do." What I saw was a lot of people whose eyes were not glazing over - they got it, a lot of people were getting it - but -
Tim CallanTim Callan- they just didn't know how in the world they were going to fit it in with the rest of the work. It's not an "eyes glaze over," it's a "deer in the headlights," right? It's an "oh my god, what am I going to do?" Yes. There was a lot of "my god, what are we gonna do" just around that conference in general, I think.
Jason SorokoJason SorokoSo, risk practitioners, the very people who listen to this podcast, Tim, right, people who are in the trenches in one way or the other - man, I think... and this is what I told the Gartner analyst when I had a face-to-face, I said: there's a certain amount of sympathy I do have for people who are in the trench and have an unstretchable budget, because they are facing utterly unprecedented times. And the Gartner conference really highlighted where the unprecedented parts were: AI and PQC. And I think that unless you're some sort of huge bank - you've got to carve out the budget because it's existential to you - for everyone else, they're just being asked to do more with less. And now it's not just more with less, it's way, way more than anybody's ever dealt with in their careers. With less.
Tim CallanTim CallanAbsolutely. And no end to that in sight. This is not a temporary thing. This is not an ebbs-and-flows, peaks-and-valleys thing. This is the new plateau.
Jason SorokoJason SorokoI'm going to leave you with this one thought, Tim. I think you saw this as well. Gartner was not talking about Mythos, and,, any of those class of AI frontier models that are going to be happening in the next little while - of which Fable was... if you're involved with Anthropic's class, you've already got Mythos, you've been dealing with it
Tim CallanTim CallanAnd I'll go a step further. It's an asymmetrical conflict, and it always has been. The blue team has to plug every hole, and the red team only has to find one hole. And so it's really an unfair competition. I think if you sort of up the stakes on capabilities - if you turn everything up to 11 everywhere - I suspect that advantages the red team more than it does the blue team.
Jason SorokoJason SorokoI think for now, it does. And I'll push it one last step, Tim - just because we always like the juicy end of the point. Tim, have we reached a point... I, by the way, wrote a Substack on this very topic a few months ago, called, basically, trying to ask the question of whether or not we're all technical Luddites now in this new age. And so, at the Gartner conference, when I saw people sinking in their seats, it wasn't just "I don't have the budget." I think - and this is my speculation - I think we've hit cognitive load limits for a lot of people.
Tim CallanTim CallanAnd that was, again, the theme that was at lunch - it was "I just... my head is full, I just don't even know how to process everything that's being thrown at me."
Jason SorokoJason SorokoThere it is, Tim. There it is.
Tim CallanTim CallanThank you, Jay.

Stay informed with expert insights

Subscribe to Root Causes for engaging discussions on PKI, digital security, and best practices for protecting your organization's critical assets. Don’t miss an episode!

Listen on Apple PodcastsListen on SpotifyListen on SoundCloud