Site navigation

Are Enterprises Losing Control of Machine Access?

Tom Quinn

,

identity security
Less than a third of cybersecurity leaders say they have full visibility into non‑human identities, leaving firms exposed to undetected breaches.

Non-Human Identities (NHIs), from service accounts and infrastructure daemons to AI agents, are now deeply embedded in modern enterprises, frequently operating with privileged access, according to new research from Keeper Security.

Polling more than 100 cybersecurity executives, the identity security platform found that nearly half (46%) say their organisation’s AI tools can access critical systems and data, but 76% admit those identities aren’t properly governed under privileged‑access controls.

For those organisations, visibility remains the main roadblock, with just 28% reporting full visibility into NHIs across cloud, on-premises and SaaS environments, and more than half (53%) identifying a lack of oversight of AI, automation and machine access as their top risk.

Without centralised visibility, Keeper said that security teams cannot enforce least-privilege access or monitor how these identities are being used, resulting in the kind of excessive privileges and unmanaged access easily abused by malicious actors.

The findings also highlight critical gaps in governance and operations. Many organisations are working with a patchwork of NHIs across multiple tools and teams, resulting in inconsistent policies and fragmented ownership, an approach that makes it difficult to maintain control over system-level access.

Only a quarter (26%) of firms report using automated detection and response to monitor NHI activity, with the majority relying on manual processes not designed to scale in environments increasingly driven by automation and system-to-system interaction. 

As a result, more than 40% of respondents have experienced a security incident involving non-human identities or credentials in the past year, while 32% are unsure whether such an incident has occurred, a detection gap leaving organisations effectively blind to potentially major breaches.


Recommended reading


Keeper argues that, as enterprises continue to embrace automation and interconnected systems, securing NHIs is now an essential component to maintaining control over critical systems and data. 

The firm said modern Privileged Access Management (PAM) protocols are required to address this challenge by providing centralised visibility, enforcing least-privilege access and enabling continuous monitoring across both human and non-human identities.

“AI and automation are expanding how systems interact and access an organisation’s data,” said Darren Guccione, CEO and co-founder at Keeper Security. 

“That shift introduces new complexity around identity, and requires a unified approach to visibility and control across both human and non-human access.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data