Machine Identities now Outnumber Human Workers by 109 to One

As AI continues to develop and more businesses embed it into operations, AI agents are quickly becoming the most significant insider threat.

In fact, research suggests that machine identities now outnumber human workers by 109 to one. Its rapid evolution has resulted in rules and regulations being rewritten across every industry as teams look to adapt.

Given 93% of security leaders already identify insider incidents as harder to detect than external cyber threats, organisations must update their security controls to incorporate AI risk or suffer the consequences.

Tailored Security is Essential in an AI Workplace

As AI agents become firmly integrated into business functions, Neil Jenkins, Chief Product Officer, Fastmail, warns: “AI agents have moved the needle on what insider risk looks like. The biggest threat inside an organisation is no longer necessarily a disgruntled employee. It could be someone clicking the wrong link or an AI agent doing exactly what it was told, with consequences nobody intended.

“That makes controlling who, or what, can access sensitive systems more important than ever,” he continues. “Strong authentication is a fundamental part of managing insider risk, but it’s only the first line of defence. Businesses need to apply the principle of least privilege, giving employees access only to what they need and making it easy to flag suspicious activity. Increasingly, that same thinking needs to apply to AI agents.

“Like King Midas, an AI agent can give you exactly what you asked for, but not necessarily in the way you intended. Agents need tightly defined permissions, clear boundaries and appropriate monitoring so that an unexpected route to completing a task doesn’t become a security vulnerability,” Jenkins concludes.

Setting out clear guardrails and managing permissions is key to combating insider threats in an increasingly AI-centric world. However, Bertijn Eldering, Associate Sales Engineer at HackerOne, argues that businesses must go further. He explains that “the insider risk in enterprise AI is rarely about intent and more so about inherited access. An assistant does not simply decide to leak data, it answers the question it was asked using whatever it can access.”

Because these AI systems operate at speed, it can be difficult for businesses to identify whether a threat is human, or AI-driven. “The answer to combating this challenge is practical,” says Eldering. “Give agents their own identities and scope them to a single task. Keep an audit trail you would be willing to defend in an investigation. Treat every change to a tool, model or integration as a change to your exposure, test that continuously rather than at review points, and keep a human in the loop for the judgement calls.”

Solidifying Resilience Through Protected Backups

As insider risk expands beyond human users, access control isn’t the only security consideration. Organisations must look beyond initial defensive measures and identify how critical data can be recovered if those controls fail.

Carlos Sandoval Castro, IBM Worldwide Tape Offering Manager for the LTO Program, argues that “one way to reduce that risk is to ensure that critical backup data cannot be accessed through the network at all.”

He continues: “Tape storage is particularly well suited to this because data stored on offline tape is physically separated from connected infrastructure. Once a tape cartridge has been removed from the drive and securely stored, an insider – whether a compromised account, malicious employee or autonomous system – cannot remotely access, alter, or delete the data. Access requires someone to be physically present and able to retrieve and load the media.

“This physical air gap can therefore provide an important additional layer of protection within a broader cyber resilience strategy,” he adds. “It helps organisations preserve a known-good copy of critical data that remains available for recovery even if production and connected backup environments have been compromised – a must-have when getting back to business-as-usual.”

The importance of secure, isolated backups is echoed by Mark Molyneux, Field CTO at Commvault. With 90% of businesses saying they need to make identity management improvements to address AI-related risks, he argues that “a ResOps model that brings identity, security and recovery together, whilst monitoring for unexpected activity, is essential. Organisations should also maintain a recovery environment isolated from live systems, so that critical data and the backups required to restore it remain protected. Adopting this approach and preparing in advance allows businesses to respond quickly if an incident does occur.”

As AI agents reshape insider risk, businesses must adapt their defences, combining tighter controls and continuous oversight with resilient, isolated backups to ensure critical data remains protected.

Source: Cyber Security Intelligence