Gartner UK from the Practitioner’s Seat: Everyone Wants to Be an Orchestrator. Now What?
Be an orchestrator. Don’t buy, build. Automate the low-level tasks so your team can focus on the work that matters.
Those are just a few of the buzzwords that filled the halls at the Gartner Security & Risk Management Summit in London. As a practitioner, I agree with most of them. But buzzwords don’t run a security program. So what does it actually mean to be an orchestrator?
The conductor doesn’t play every instrument
An orchestrator is someone who arranges music for an orchestra, or who carefully organizes a complex plan or event. I like the second meaning best, because that was the story in session after session.
“Don’t buy it, build it.” Build what, exactly? The AI SOC. An AI-driven TPRM process. The dashboard that tracks your KPIs, the system that produces the metrics, and the model behind it.
A conductor doesn’t play every instrument. They decide who plays what, and when. In security, the instruments are AI, agents and APIs. The orchestrator’s job is to point them at processes that are well-defined and low-risk to automate, and to keep people on the decisions that carry real consequences.
I chose the words “low-risk” on purpose. As a risk professional, I have a lower appetite for agentic automation without a human in the loop. Orchestrating doesn’t mean stepping away from the podium.
Recovery time should be modeled, not asserted
One message that stood out to me: “Theoretical RTOs are meaningless.” Two questions from the sessions have stayed with me since:
- “What should my RTO be for my crown jewels if I want to stay at the mean ALE?”
- “Most enterprises don’t have more than six critical value chains, and you likely already have business impact assessments for these.”
To me, this is a real shift. Organizations are no longer only asking how to prevent an attack. They’re asking what happens after one. Recovery time is turning into a financial decision instead of a number someone picked in a BCP workshop: how much downtime can the business absorb before the loss goes past what leadership has said it will tolerate?
Speaker after speaker made the same point. An attack may be inevitable. How much it hurts doesn’t have to be.
Gartner got one wrong, and I’m glad
A few years ago, Gartner predicted that nearly half of cybersecurity leaders would change jobs by 2025, and a quarter would leave the field entirely because of stress. On stage in London, the message was clear: that one didn’t play out the way it was expected to. Cybersecurity is still a calling, not just a job.
What separates the leaders who stay and thrive? In my experience, it’s the ability to tell a story with the data they already have. A board doesn’t remember a heat map. It remembers a clear answer to “what could this cost us, and what are we doing about it?”
What comes next: KPIs for AI, KRIs for the orchestrator
I see a very near future where:
- KPIs are tied to AI productivity: how much work your automation actually takes off your team’s plate, and how well it does it.
- KRIs are owned by the orchestrators: the signals that tell them what’s safe to automate next and what still needs a human.
Cybersecurity is no longer a compliance checklist. AI can work through the checklist now. What changes the game is having systems that can synthesize data across your environment and connect the results to business outcomes.
Where SAFE fits
This is why SAFE is building AI-native. Our goal is a platform that fits your program’s expertise, lets your team become the orchestrators, and automates what can safely be automated. Then we carry the risk analysis, so your security organization can make decisions the way the rest of the business does: with real business and financial data.
If you were in London and these ideas sound familiar, or if you’re working out where orchestration fits in your own program, I’d love to compare notes.