In its January 2026 research report, Innovation Insight: Automated Security Control Assessment, Gartner discusses why misconfigured security controls remain one of the most persistent drivers of breaches and why automation is now required to address the problem at scale.
Gartner finds that most organizations struggle with:
At the same time, attackers are using AI to increase the speed and scale of attacks, putting even more pressure on defenders to reduce exposure created by control gaps and misconfigurations.
Gartner defines Automated Security Control Assessment (ASCA) as a technology that:
ASCA automates the process of mapping attacker techniques to an organization’s actual defensive capabilities and industry best practices, enabling more efficient remediation and reducing manual effort and human error.
Gartner discusses three primary ASCA functions:
Gartner also notes that while automation is essential, organizations should be cautious with full auto-remediation for business-critical systems. Many remediation actions will continue to require human oversight to avoid operational disruption.
According to Gartner, organizations adopting ASCA can:
Gartner predicts that by 2030, organizations that successfully operationalize ASCA technologies will experience a 25% reduction in cybersecurity incidents.
Gartner estimates that fewer than 10% of organizations have adopted ASCA to automate control assessment and optimization across multiple cybersecurity product categories and providers, with most still relying on manual processes. However, by 2029, 70% of exposure management platforms providers will contain ASCA features or integrate with ASCA providers, up from 20% today.
In the report, Gartner recognizes Reach Security as a Representative Provider in the ASCA market. In our opinion, Reach delivers Automated Security Control Assessment by continuously analyzing tool configurations across identity, endpoint security, email security, firewall, SASE and other security and IT tools. Using read-only API-based integrations and cybersecurity domain-specific AI models, Reach:
Gartner, Inc. Innovation Insight: Automated Security Control Assessment. Evgeny Mirolyubov. 10 January 2026.
GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved.
Gartner does not endorse any vendor, product or service depicted in our research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.
Unlock the full power of your security stack with a free tool rationalization assessment.
Request a Demo
Read-only API key for a security tool of your choice
Create your account and setup the integration
Get results across licensing, control mapping, risk exposure, and posture