Site navigation

Identity Security Falters As Machines Outnumber Humans 82 to 1

Tom Quinn

,

machine identity
“Many organisations still lack full visibility into their identity landscape and struggle to manage expanding workloads across hybrid environments,” said Michael Laudon, Quest Software.

Machine identities are multiplying across enterprise systems faster than security teams can keep up, yet just a fraction of businesses are regularly testing their identity disaster‑recovery plans, according to new research from Quest Software.

The data management firm’s latest State of Identity Threat Detection and Response survey found that more than 75% of organisations are not practising their disaster recovery plans at least every six-months as recommended, while a quarter never practice them at all.

Polling 650 global IT and security leaders, the study found broad agreement that identity has become the primary attack surface, with more than half of respondents saying that non-human identities are now the most difficult to secure.

That’s largely down to the sprawl of machine identities across on-premises, hybrid, and cloud environments, needed to authenticate the expanding universe of servers, apps, containers, and APIs that underpin modern operations.

Quest found that this rapid growth of non-human identities has outpaced visibility and guidance, making it even more difficult for organisations to manage identity security, with an estimated 82:1 ratio of machine identities to human identities.

Given the dramatic spike in AI-focused attacks, such as automated hacking and data poisoning, this increase in advanced machine identities has made security far more complicated, contributing to a 57% jump in identity incidents linked to AI use.

However, despite being at the heart of the problem, most security leaders (79%) believe AI tools can improve ITDR effectiveness, but Quest maintained that too many firms are putting confidence in preventative controls, rather than on response and recovery readiness.


Recommended reading


“Our survey findings make one point abundantly clear: identity security challenges are broad, interconnected, and steadily growing,” said Michael Laudon, chief product and technology officer for Quest Software.

“Many organisations still lack full visibility into their identity landscape and struggle to manage expanding workloads across hybrid environments, and most teams are not validating recovery often enough to ensure rapid restoration after an attack.”

Quest’s findings are the latest evidence that identity management is emerging as a pain point for overworked security teams, with a recent report from Nametag warning about a surge in AI agent identities with access and autonomy over tools and apps at levels similar to some human employees.

Likewise, research from CyberArk in January found that only 1% of organisations have fully adopted Just‑in‑Time (JiT) privileged access for their AI identities, with more than half of firms uncovering new unmanaged privileged accounts every week.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data