Gartner: Why Cyber Security Must Shift to Outcomes Against AI-Led Attacks
Computer Weekly, Friday, July 31st, 2026
Anthropic's revelation that a model broke out of its test environment three times and accessed external systems, shows the power of these models
As AI changes offensive capabilities, cyber security measurement must evolve alongside it. Traditional dashboards built around vulnerability counts, patch volumes, and remediation service-level agreements cannot adequately capture organisational resilience against AI-powered attacks.
Gartner argues that security and risk management leaders instead need metrics demonstrating whether they are reducing attacker opportunity and improving business resilience-what Gartner calls outcome-driven metrics, or ODMs.
These metrics are carefully defined to function as value levers that demonstrate return on investment for cyber security initiatives, marking a fundamental shift in how organisations should measure security effectiveness.