According to a recent study, machine identities now outnumber human users by 109 to 1.
AI is playing a major role in intensifying this problem by adding a rapidly growing population of digital identities that require access to organisational systems and data.
The situation is clearly causing widespread concern. New findings from the IDC White Paper, Resilience Operations: The Discipline that Makes Readiness Provable, reveal that 90% of respondents believe their identity management capabilities need improvement to address the risks posed by agentic AI.
Digging deeper, almost 59% said their approach needs significant improvement or a complete overhaul, while only 27% reported having dynamic role-based access controls that support AI and analytics.
In other words, AI is increasing identity risk faster than many organisations can adapt their controls.
An Old Problem with New Urgency
Let’s be clear, identity weaknesses have been a major security headache since the earliest days of networked IT. They can also have consequences far beyond any initial compromise, with Verizon’s 2026 Data Breach Investigations Report finding that credential abuse featured somewhere in 39% of breaches, even when it was not the attacker’s first route into an organisation. Its pervasive, playing a key role in many attack paths.
What’s different today compared to even a few years ago is the sheer complexity of the security challenge, where anything from an acquisition to a cloud migration project can mean organisations have to manage multiple identity environments.
Historically, identity controls were largely designed around employees with defined roles and relatively predictable access requirements. Add AI agents or Agentic AI to the mix, and these often require access to several other systems to complete a task. They also use permissions at machine speed, making it much harder to define the access an agent genuinely needs and maintain clear accountability for it over time.
Imagine an organisation deploying an AI agent to monitor backup and recovery outcomes, for example. Its remit sounds pretty straightforward: identify a failed backup and alert the right team. Yet, to do that, the agent may need to draw information from the backup platform before using the organisation’s service desk to alert the relevant engineers.
The challenge is that this access can quickly extend beyond the agent’s original role. Every additional connection increases the number of permissions that need to be understood and controlled. If the agent is given broader access than its task requires, or its permissions remain in place after the underlying process changes, its identity could become a valuable route into connected systems.
If that wasn’t problematic enough, AI and automation tools can also help threat actors to identify exposed credentials and exploit weak identity controls at greater speed. CrowdStrike’s 2026 Global Threat Report found that the average eCrime breakout time fell to just 29 minutes in 2025, with the fastest observed breakout occurring in only 27 seconds. This rapidly shrinking window makes it harder for security teams to contain an attack before a compromised privileged identity is used to move through connected systems.
Identity Resilience
So, what needs to change to improve identity resilience? Existing identity systems, such as Active Directory and Entra ID, verify users and systems before granting access to business applications and data. If an identity system has been compromised, an organisation may be unable to tell whether a restored account or permission remains safe.
Restoring applications or data has limited value until the people and systems that need them can authenticate safely. Attackers may also retain access if malicious changes to accounts or permissions are carried into the restored environment. This is why recovery teams need a known-good version of their identity environment.
That challenge is reflected in the IDC research findings, where only 24.7% of respondents said they had documented and tested their Active Directory and Entra ID recovery capabilities.
Recovery teams need to know which functions the business must restore first following a cyberattack. That decision affects which identity systems and access rights must be recovered as a priority.
Defining what represents the ‘minimum viable company’ (MVC) can help establish the lowest level of operational capability the organisation needs to maintain. The problem is, IDC found that 57.7% of respondents had not fully defined their MVC, and without that clarity, teams may have to make recovery-priority decisions during an incident, when time and certainty are both limited.
Addressing these issues requires a clearer focus on maintaining and restoring trusted access following a cyberattack. This form of resilience begins with a clear view of the identities operating across an environment and the access each one holds. AI agents and Agentic AI should have defined purposes, with permissions limited to what that purpose requires – put simply, guardrails.
Identity recovery plans also need to be documented and tested, so teams can restore a known-good environment with confidence. Responsibility cannot rest with a single operational function; IT and security teams need to work together on identity resilience, particularly given that 98.4% of IDC respondents reported a need for closer collaboration and 49.7% called for major improvements.
These requirements are becoming more closely integrated as Resilience Operations (ResOps), an emerging operational discipline that brings together security, identity, business and recovery teams around a common objective. This is to maintain business operations and accelerate safe clean recovery despite disruption.
As IDC explains, “ResOps will mature from an emerging discipline into a mainstream enterprise capability over the next three to five years. Organisations that build the governance structures, technical capabilities, and testing disciplines now, before the next major incident, will be better positioned to absorb disruption, protect their customers, and sustain competitive operations in an increasingly hostile threat environment.”
Mark Molyneux is Field CTO – Northern Europe at Commvault
Image: Resource Database
Source: Cyber Security Intelligence