Intelligent CISO Issue 100 | Page 51

S P E C I A L R E P O R T
Adam Dimopoulos, CISO at Entrust, argued that while AIdriven attacks, software supply chain risks and emerging cryptographic threats all present significant challenges, identity remains the common thread linking them.
“ The next generation of cyber-resilience will be shaped by a convergence of risks, from AI-driven attacks and software supply chain exposure to emerging cryptographic threats. But what consistently determines the real-world impact for these risks is often identity.”
The key to resilience is building trust into a digital workforce to behave securely. their people alone. It will be defined by how well they secure the AI agents now acting alongside them.”
As organisations deploy increasing numbers of autonomous systems, she believes security teams face fundamental questions they currently struggle to answer.
“ What agents exist and where are they running? What can they access? What actions can they take? Who is accountable for them?”
Without that visibility, organisations cannot hope to govern AI safely.
He warned that identity sprawl is already a significant challenge and will accelerate as organisations deploy increasing numbers of AI agents and other non-human identities.
“ Getting a handle on all your identities, whether human, non-human, or agentic will be foundational.”
Traditional authentication methods also need to evolve.
“ Passwords still sit at the centre of too many environments,” Dimopoulos said, arguing that phishing-resistant authentication, passkeys and continuous verification should become standard practice.
John Podboy, CISO at Semperis, believes organisations have underestimated how quickly AI is changing identity management.
“ AI is changing the way businesses operate and cybersecurity has to adapt just as fast.”
Many organisations grant AI agents broad permissions so they can perform useful work but fail to revisit those privileges afterwards.
“ The risk is that AI is being placed too close to sensitive identity infrastructure with little preparation for the potential consequences.”
If compromised, those agents could gain privileged access to critical identity platforms.
“ With access to these Tier-0 systems, attackers have the keys to the kingdom.”
Rather than treating AI agents as extensions of human users, Podboy believes organisations must recognise them as an entirely new category of identity.
“ It’ s important that organisations treat agents explicitly as non-human identities( NHIs) in the identity fabric.”
Mandy Andress, CISO at Elastic, reached a similar conclusion.
“ The next generation of cyber-resilience won’ t be defined by how well organisations secure
“ The priority for CISOs is clear: establish continuous visibility before pursuing autonomous security.”
Martin Kraemer, CISO Advisor at KnowBe4, believes this transformation extends beyond technology.
“ The key to resilience is building trust into a digital workforce to behave securely.”
As employees increasingly supervise teams of AI agents rather than carrying out tasks themselves, governance models based solely on human oversight will become less effective.
“ Organisations must find holistic governance and risk management solutions to reap the benefits of AI and maintain trust with their workforce.”
Visibility becomes the foundation of resilience
Identity is only one part of a broader challenge.
Throughout the discussion, contributors argued that resilience depends on understanding technology environments as they change, not simply documenting them periodically.
Richard Ford, CTO at Integrity360, believes visibility should become every CISO’ s first investment.
“ You cannot protect assets you don’ t know exist, whether that’ s cloud services, machine identities, AI agents, third-party integrations or legacy systems.”
As businesses expand across cloud platforms and interconnected services, resilience can no longer depend on periodic assessments.
“ The result is an environment where exposure changes continuously.”
Instead, Ford argued, resilience itself must become‘ a continuous discipline’.
Justin Henkel also placed visibility at the heart of resilience planning.
WWW. INTELLIGENTCISO. COM 51