Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Identity Security. Show all posts

AI Agents Expose Growing Identity Security Gaps in Enterprise Environments

 

In the face of the rapid adoption of artificial intelligence agents, enterprise security is faced with an increased challenge, as organizations struggle to maintain an increasing number of non-human identities gaining access to sensitive information and critical systems. In an increasingly automated world, security experts warn that each new AI agent introduces another trusted identity into the organization. 

The use of machine identities increases an organization's attack surface without proper oversight, making it harder for security teams to maintain a complete inventory of privileged accounts and monitor their interactions with critical business systems if they are not monitored properly. As opposed to human users, AI agents, service accounts, OAuth applications, and workload identities do not follow traditional employee lifecycles. 

There are many advantages to generating them automatically, inheriting permissions, interacting across multiple systems, and often remaining active long after the applications that generated them cease to exist. In the opinion of security experts, this emerging ecosystem is leading to weaknesses in identity governance that many organizations have yet to address. According to the Non-Human Identity Management Group, machine identities outnumber human users by up to 50 to 1 in many enterprise environments. 

Some of these technologies exist only temporarily, while others continue to operate without any clear ownership for years, making it difficult to determine who created them, what resources they are allowed access to, and whether they are still necessary for security teams to monitor. During a cyber campaign conducted in 2025, threat actor UNC6395 exploited a trusted OAuth token associated with Salesloft's Drift chat integration, demonstrating the risk. 

Instead of exploiting a software vulnerability, the attackers exploited an already trustworthy machine identity in order to access AWS credentials, Snowflake tokens, and other sensitive data across Salesforce environments. The incident demonstrated how compromised machine identities can become gateways to broader enterprise cyberattacks. Security professionals emphasize that artificial intelligence itself is not creating new cybersecurity problems but rather accelerating existing ones. 

With organizations deploying AI-powered agents to automate business processes, the number of privileged identities is continuing to increase, increasing the attack surface if governance processes do not keep pace. Additionally, experts maintain that AI agents are not simply software tools but should be regarded as a distinct class of digital identity instead. 

With AI systems increasingly accessing enterprise applications, making decisions, and executing workflows independently, organizations must provide each AI agent with a unique identity, clear permissions, and full accountability in order to ensure that its actions can be monitored and audited.  

The Netwrix Data and Identity Security Report 2026 reported that organizations with significant increases in the number of identities experienced a 43% breach rate over the previous year, compared to 11% among organizations with no significant changes in their identity landscape due to artificial intelligence. There is no doubt that visibility alone is not sufficient to address the concerns of many affected organizations, as they already invested in identity governance and monitoring. 

There is also a growing concern regarding agent sprawl, in which organizations deploy artificial intelligence assistants and autonomous agents rapidly without establishing governance frameworks. As the number of machine identities within an organization increases, cybersecurity experts warn that this can cause duplicate AI agents, inconsistent permissions, and increased operational, security, and compliance risks.  

As well as stressing the importance of identifying machine identities, the report stresses the imperative of continuous identity governance which tracks ownership, permissions, lifecycles, and access rights throughout the lifespan of every AI agent and non-human identity. The accumulative nature of trusted identities can increase the likelihood that unauthorized access and misuse can occur without ongoing governance. The following four key questions should be answered continuously by organizations for every identity in their environment: What identities exist? 

Who owns them? What can they access? When should they be retired? Unless clear ownership and lifecycle management are in place, AI-driven identities may silently accumulate excessive privileges and provide an opportunity for attackers. Experts also recommend that AI agents be subject to the Zero Trust security principles. 

The same way that human users require continuous verification and least privilege access, AI agents should be given only the appropriate permissions to accomplish their duties. Keeping detailed audit logs and implementing lifecycle controls (including the capability of quickly eradicating or retiring unnecessary agents) can reduce security risks over the long term. 

A growing number of industries are adopting artificial intelligence, which requires cybersecurity strategies to evolve beyond traditional user-focused identity management strategies. It has been recommended that organizations establish stronger governance for non-human identities, identify an owner for each AI agent, and periodically review their permissions. 

A lack of such controls could result in trusted AI-powered identities becoming one of the most overlooked attack vectors in today's enterprise environments, according to experts.

Why AI Agents Are Challenging Identity Security


The wide adoption of AI agents is forcing organizations to rethink identity security as enterprises contend with an expanding population of non-human identities that increasingly outnumber employee accounts. While identity and access management programs have traditionally focused on managing people throughout their employment lifecycle, autonomous software identities are exposing governance gaps that many organizations are still struggling to address.

Unlike human users, machine identities, including AI agents, service accounts, workload identities, OAuth applications, and API credentials, are created to authenticate systems, automate processes, and enable communication between applications. As organizations embrace cloud computing, automation, and generative AI, these identities are being created at a pace that often exceeds traditional governance processes.

Human identities typically follow a predictable lifecycle. Employees are onboarded, assigned appropriate access, promoted or transferred to new roles, and eventually offboarded when they leave an organization. These lifecycle events form the foundation of identity governance, allowing security teams to periodically review permissions and revoke unnecessary access.

Machine identities operate differently. They may be generated automatically when new cloud workloads are deployed, inherit permissions from existing applications, communicate across multiple enterprise platforms, or exist only briefly before being replaced. Others remain active long after the application, automation workflow, or development project that created them has been retired. Without continuous oversight, organizations can lose visibility into who owns these identities, why they still exist, and what sensitive resources they are capable of accessing.

The scale of this challenge continues to grow. According to the Non-Human Identity Management Group, machine identities can outnumber human users by as much as 50 to one across many enterprise environments. While these identities are essential for modern business operations, security teams frequently struggle to maintain accurate inventories or establish clear ownership for every credential operating within their environments.

The security implications became evident during the UNC6395 campaign in 2025, when attackers reportedly obtained an OAuth token associated with Salesloft's Drift chat integration and leveraged the trusted credential to move across Salesforce environments used by hundreds of organizations. Rather than exploiting a software vulnerability, the attackers abused an identity that had already been authorized within enterprise systems. Investigations found that the compromised access enabled attackers to obtain additional secrets, including AWS credentials and Snowflake tokens, demonstrating how a single trusted machine identity can provide a pathway to multiple connected environments.

AI agents are not creating an entirely new category of identity risk, but they are accelerating an existing challenge. Modern AI systems increasingly perform tasks autonomously, interact with multiple business applications, retrieve sensitive information, and execute workflows without continuous human involvement. As these agents operate across cloud services, they introduce additional trusted identities, inherit permissions from existing accounts, and expand the number of credentials that organizations must secure.

This rapid growth creates a governance challenge that extends beyond simple visibility. Security teams may know that identities exist, but effective identity security also requires understanding who owns each identity, what permissions it has been granted, what sensitive data it can reach, and when that identity should no longer exist. Without continuous lifecycle management, dormant or forgotten machine identities can quietly expand an organization's attack surface.

Findings published in the 2026 Data and Identity Security Report illustrate the scale of the problem. Organizations that reported AI exponentially increasing the number of identities within their environments experienced a 43% breach rate over the previous year, compared with 11% among organizations where AI had not substantially expanded their identity footprint. Notably, many organizations affected by breaches also reported implementing stronger governance practices, suggesting that visibility alone is insufficient if identity ownership, permissions, and access reviews are not continuously maintained.

As enterprises continue integrating AI into daily operations, identity security is becoming less about managing employee accounts and more about governing a rapidly expanding ecosystem of trusted non-human identities. Maintaining comprehensive identity inventories, enforcing least-privilege access, continuously reviewing permissions, and assigning clear ownership to every human and machine identity will be essential to reducing risk. As AI agents become more autonomous, the identities organizations overlook may prove just as valuable to attackers as those they actively monitor.

Why Cloud Outages Turn Identity Systems into a Critical Business Risk

 

Recent large-scale cloud outages have become increasingly visible. Incidents involving major providers like AWS, Azure, and Cloudflare have disrupted vast portions of the internet, knocking critical websites and services offline. Because so many digital platforms are interconnected, these failures often cascade, stopping applications and workflows that organizations depend on daily.

For everyday users, the impact usually feels like a temporary annoyance—difficulty ordering food, streaming shows, or accessing online tools. For enterprises, the consequences are far more damaging. If an airline’s reservation platform goes down, every minute of downtime can mean lost bookings, revenue leakage, reputational harm, and operational chaos.

These events make it clear that cloud failures go well beyond compute and networking issues. One of the most vulnerable—and business-critical—areas affected is identity. When authentication or authorization systems fail, the problem is no longer simple downtime; it becomes a fundamental operational and security crisis.

Cloud Infrastructure as a Shared Failure Point

Cloud providers are not identity platforms themselves, but modern identity architectures rely heavily on cloud-hosted infrastructure and shared services. Even if an identity provider remains technically operational, disruptions elsewhere in the stack can break identity flows entirely.
  • Organizations commonly depend on the cloud for essential identity components such as:
  • Databases storing directory and user attribute information
  • Policy and authorization data stores
  • Load balancers, control planes, and DNS services
Because these elements are shared, a failure in any one of them can completely block authentication or authorization—even when the identity service appears healthy. This creates a concealed single point of failure that many teams only become aware of during an outage.

Identity as the Universal Gatekeeper

Authentication and authorization are not limited to login screens. They continuously control access for users, applications, APIs, and services. Modern Zero Trust architectures are built on the principle of “never trust, always verify,” and that verification is entirely dependent on identity system availability.

This applies equally to people and machines. Applications authenticate repeatedly, APIs validate every request, and services constantly request tokens to communicate with each other. When identity systems are unavailable, entire digital ecosystems grind to a halt.

As a result, identity-related outages pose a direct threat to business continuity. They warrant the highest level of incident response, supported by proactive monitoring across all dependent systems. Treating identity downtime as a secondary technical issue significantly underestimates its business impact.

Modern authentication goes far beyond checking a username and password—or even a passkey, as passwordless adoption grows. A single login attempt often initiates a sophisticated chain of backend operations.

Typically, identity systems must:
  • Retrieve user attributes from directories or databases
  • Maintain session state
  • Generate access tokens with specific scopes, claims, and attributes
  • Enforce fine-grained authorization through policy engines
Authorization decisions may occur both when tokens are issued and later, when APIs are accessed. In many architectures, APIs must also authenticate themselves before calling downstream services.

Each step relies on underlying infrastructure components such as datastores, policy engines, token services, and external integrations. If any part of this chain fails, access can be completely blocked—impacting users, applications, and critical business processes.

Why High Availability Alone Falls Short

High availability is essential, but on its own it is often insufficient for identity systems. Traditional designs usually rely on regional redundancy, with a primary deployment backed up by a secondary region. When one region fails, traffic shifts to the other.

This strategy offers limited protection when outages affect shared or global services. If multiple regions depend on the same control plane, DNS service, or managed database, a regional failover does little to improve resilience. In such cases, both primary and backup systems can fail simultaneously.

The result is an identity architecture that looks robust in theory but collapses during widespread cloud or platform-level disruptions.

True resilience requires intentional design. For identity systems, this may involve reducing reliance on a single provider or failure domain through multi-cloud deployments or carefully managed on-premises options that remain reachable during cloud degradation.

Planning for partial failure is equally important. Completely denying access during outages causes maximum business disruption. Allowing constrained access—using cached attributes, precomputed authorization decisions, or limited functionality—can significantly reduce operational and reputational damage.

Not all identity data demands identical availability guarantees. Some attributes or authorization sources may tolerate lower resilience, as long as those decisions are made deliberately and aligned with business risk.

Ultimately, identity platforms must be built to fail gracefully. Infrastructure outages are unavoidable; access control should degrade in a controlled, predictable manner rather than collapse entirely.

The Silent Guardians Powering the Frontlines of Cybersecurity

 


There is no doubt that a world increasingly defined by invisible battles and silent warriors has led to a shift from trenches to terminals on which modern warfare is now being waged. As a result, cyberwarfare is no longer a distant, abstract threat; now it is a tangible, relentless struggle with real-world consequences.

Power grids fail, hospitals go dark, and global markets tremble as a result of unseen attacks. It is at this point that a unique breed of defenders stands at the centre of this new conflict: cyber professionals who safeguard the fragile line between digital order and chaos. The official trailer for Semperis Midnight in the War Room, an upcoming documentary about the hidden costs of cyber conflict, has been released, bringing this hidden war to sharp focus. 

Semperis is a provider of AI-powered identity security and cyber resilience. It has an extraordinary lineup of voices – including Chris Inglis, the first U.S. National Cyber Director; General (Ret.) David Petraeus, the former Director of the CIA; Jen Easterly, former Director of the CISA; Marcus Hutchins, one of the WannaCry heroes; and Professor Mary Aiken, a globally recognised cyber psychologist – all of whom are highly respected for their expertise in cybersecurity. 

The film examines the high-stakes battle between attackers, defenders, and reformed hackers who have now taken the risk of exploiting for themselves. As part of this documentary, leading figures from the fields of cybersecurity and national defence gather together in order to present an unprecedented view of the digital battlefield. 

Using their insights into cyber conflicts, Midnight in the War Room explores the increasing threat that cybercrime poses to international relations as well as corporate survival today. A film that sheds light on the crucial role of chief information security officers (CISOs), which consists of who serve as the frontlines of protecting critical infrastructure - from power grids to financial networks - against state-sponsored and criminal cyber threats, is a must-see. 

It is the work of more than fifty international experts, including cyber journalists, intelligence veterans, and reformed hackers, who provide perspectives which demonstrate the ingenuity and exhaustion that those fighting constant digital attacks have in the face. Even though the biggest threat lies not only with the sophistication of adversaries but with complacency itself, Chris Inglis argues that global resilience is an urgent issue at the moment. 

It has been reported that Semperis' Chief Marketing Officer and Executive Producer, Thomas LeDuc, views the project as one of the first of its kind to capture the courage and pressure experienced by defenders. The film is richly enriched by contributions from Professor Mary Aiken, Heath Adams, Marene Allison, Kirsta Arndt, Grace Cassy and several former chief information security officers, such as Anne Coulombe and Simon Hodgkinson, and it provides a sweeping and deeply human perspective on modern cyber warfare. 

With its powerful narrative, Midnight in the War Room explores the human side of cyberwarfare—a struggle that is rarely acknowledged but is marked by courage, resilience and sacrifice in a way that is rarely depicted. A film about those defending the world's most vital systems is a look at the psychological and emotional toll they endure, in which trust is continually at risk and a moment of complacency can trigger devastating consequences. 

The film explores the psychological and emotional tolls endured by those defending those systems. During his remarks at Semperis, Vice President for Asia Pacific and Japan, Mr Sillars, points out that cyber threats do not recognise any borders, and the Asia Pacific region is at the forefront of this digital conflict as a result of cyber threats. 

During the presentation, he emphasises that the documentary seeks to highlight the common challenges cybersecurity professionals face worldwide, as well as to foster collaboration within critical sectors to build identity-driven resilience. As the Chief Marketing Officer at Semperis and Executive Producer, LeDuc describes the project as one of the most ambitious in cybersecurity history—bringing together top intelligence leaders, chief information security officers, journalists, victims and reformed hackers as part of a rare collaborative narrative.

In the film, Cyber Defenders' lives are portrayed through their own experiences as well as the relentless pressure and unwavering resolve they face every day. Among the prominent experts interviewed for the documentary are Marene Allison, former Chief Information Security Officer of Johnson & Johnson; Grace Cassy, co-founder of CyLon; Heather M. Costa, Director of Technology Resilience at the Mayo Clinic; Simon Hodgkinson, former Chief Information Security Officer of BHP; and David Schwed, former Chief Information Security Officer of Robinhood. 

Among those on the panel are Richard Staunton, Founder of IT-Harvest, BBC Cyber Correspondent Joe Tidy, as well as Jesse McGraw, a former hacktivist who has turned his expertise towards safeguarding the internet, known as Ghost Exodus. As Jen Easterly, former Chief Information Security Officer of the U.S. Department of Homeland Security (CISA), points out, defeating malicious cyberattacks requires more than advanced technology—it demands the human mind's ingenuity and curiosity to overcome them. 

A global collaboration was exemplified through the production of this documentary, which was filmed in North America and Europe by cybersecurity and professional organisations, including the CyberRisk Alliance, Cyber Future Foundation, Institute for Critical Infrastructure Technology, (ISC)2 Eastern Massachusetts Chapter, Michigan Council of Women in Technology, and Women in CyberSecurity (WiCyS) Delaware Valley Chapter. 

As part of these partnerships, private screenings, expert discussions, and public outreach will be conducted in order to increase public awareness and cooperation regarding building digital resilience. By providing an insight into the human narratives that underpin cybersecurity, Midnight in the War Room hopes to give a deeper understanding of the modern battlefield and to inspire a collective awareness in the safeguarding of society's systems. 

There is something special about Midnight in the War Room, both as a wake-up call and as a tribute - a cinematic reflection of those who stand up to the threats people face in today's digital age. The film focuses on cyber conflict and invites governments, organisations, and individuals to recognise the importance of cybersecurity not just as a technical problem, but as a responsibility that people all share. 

In light of the continuous evolution of threats, people need stronger international collaborations, investments in identity security, and the development of psychological resilience among those on the front lines to help combat these threats. Semperis' initiative illustrates the power of storytelling to bridge the gap between awareness and action, transforming technical discourse into a powerful narrative that inspires vigilance, empathy, and unity among the community.

Providing a critical insight into the human aspect behind the machines, Midnight in the War Room reinforces a fundamental truth: that is, cybersecurity is not just about defending data, but also about protecting the people, systems, and values that make modern society what it is today.