Sie haben bei der Identitätshygiene alles richtig gemacht. Und wurden 4-mal häufiger kompromittiert
Aug 14, 2026
Unsere Befragung von 2.317 Sicherheits- und IT-Verantwortlichen zeigt: Organisationen, die bei KI vorangehen, sind bei den Grundlagen weiter. Trotzdem meldeten sie eine Breach-Rate von 43 %. Das Problem ist nicht die Sorgfalt. Es ist die Latenz.
Introduction
For most of my career, I've believed what most security practitioners believe: get the fundamentals right and you'll be in a good position. Keep systems patched, apply least privilege, review access, know what's in your environment. I came up in endpoint management, so patching in particular shaped how I think about security hygiene. But a finding in our 2026 Data and Identity Security Report forced me to question an assumption I didn't know I was making.
The statistic that surprised me
An organization's identity footprint is no longer just employee accounts. It now includes AI agents, copilots, and automated integrations, each provisioned as its own identity with its own access to systems and data.
In our survey, organizations where AI has significantly expanded that footprint reported a 43% breach rate over the past twelve months. Organizations where it hasn't reported 11%. That’s nearly a 4x gap.
The easy explanation would be that the fast movers skipped the fundamentals. The data shows the opposite. Across the 2,317 security and IT leaders surveyed for the 2026 Netwrix Data and Identity Security Report, the organizations leaning hardest into AI are, on average, ahead of their peers on the practices that have anchored identity security for a decade:
- Continuous data inventory: 46% lack one, vs. 60% of slower adopters
- Non-human identity governance: 25% rate theirs as weak, vs. 44% of slower adopters
- Shadow AI visibility: 13% report blind spots, vs. 25% of slower adopters
Source: 2026 Netwrix Data and Identity Security Report, a survey of 2,317 security and IT leaders.
They invested in the playbook. They got breached anyway.
Isn't good identity hygiene the gold-standard for security, regardless of whether the identities are human or AI agents? I've always believed so. So why didn't doing the right things improve their odds?
Pressure-testing the finding
Before accepting any conclusion, I pressure-tested it everywhere I could. At RSA this year, I lost count of the vendors drawing a hard line around AI governance as its own category, and I was skeptical. My instinct was that it was a sales category, not a technical one, a new label built to justify a new budget line.
Then I asked one of our senior solutions engineers whether AI agents really required a different approach on the ground. She said yes, but not because the underlying identity problem had changed, but because of velocity and volume. Customers tell me the same thing: AI-related access needs move faster than their processes can absorb them.
That consistency changed my thinking. The vendors weren't wrong that something had changed. They were wrong about what. This isn't a new category of problem requiring a new discipline. It's the old problem arriving at a new speed and scale. The fundamentals are not wrong, they are simply insufficient because they were built for a rate of change that no longer applies.
The human clock inside every fundamental
Take patching, one of the most mature disciplines in all of security. Even the emergency path runs through people: an engineer identifies the issue, builds a fix, tests it, gets it approved, deploys it. Appropriately so. But the fastest that process can ever run is at the speed of the people in it, and the model works because it assumes the environment holds reasonably still between inspections.
Identity governance runs on the same clock. Joiners, movers, and leavers. Point-in-time inventories. Periodic access reviews. All of it assumes an identity surface that grows about as fast as headcount.
AI identities don't grow at the pace of hiring. They grow at the pace of deployment. Part of the 4x gap is simple math: More identities mean more attack surface, but that's precisely why cadence is the variable that matters. A surface expanding at deployment speed can only be kept safe by governance operating at deployment speed.
In practice: a mid-sized company runs quarterly access reviews, a documented onboarding checklist, and an annual audit. Meanwhile, a product team spins up an AI coding assistant Monday, connects it to the repo and ticketing system by Tuesday, and grants it broader access than intended by Wednesday, because broad access was the fastest way to get it working. That identity is touching real systems three days into a review cycle built to run every ninety. Nothing about the checklist was wrong. It describes a world where access requests wait for a human to create them. That world is ending.
How to tell which side of the gap you're on
An audit won't tell you, because audits check that a control exists and that it ran. Existence was never the issue, as the breached organizations in our data were ahead of their peers. But “ahead of peers” is not the same as “at pace with the environment,” and only 11% of organizations have fully operationalized governance as enforced, continuous, and proactive across identities, permissions, and the data AI can reach. Our focus needs to shift from whether controls exist to how long they take to work. Consider these questions:
How long does a new non-human identity exist before your governance process knows about it? Agents, service accounts, and integrations deserve privileged-account scrutiny starting the day they appear, not the quarter after.
How current is your picture of what identities can reach? Continuous, not reconstructed at review time from last quarter's inventory.
How long does access outlive its need? Three in four organizations we surveyed can't immediately revoke standing access. Breach rates climb another 14 points where over provisioning is tolerated and another seven where standing privileged access is the norm.
If your honest answers are measured in weeks and quarters, hygiene isn't your problem. Latency is. Least privilege and just-in-time access remain the clearest ROI in security based on our research, but they've moved from merely sufficient to absolutely necessary.
Bringing identity and data security together at machine speed
Why isn’t the solution to this problem just faster identity governance?
Every latency question has data on the other end of it. An ungoverned AI agent isn't risky in the abstract; it's risky because of the sensitive data it can reach. Identity security and data security used to be separate programs with separate tools. In an environment where every new identity exists to consume data, they've converged into a single challenge: you can't answer "what can this identity reach" without knowing where the sensitive data is, and you can't answer "who can reach this data" without governing every identity, human and non-human.
That convergence is the thinking behind the Netwrix 1Secure platform: both sides of that question, answered continuously, off the human clock. You always know where sensitive data lives and which identities can reach it. Governance follows identities at creation, so an AI agent gets privileged-account scrutiny the day it appears, scoped to the data it touches. And access moves at provisioning speed. Access is granted when it's needed and revoked the moment it isn't.
So when deploying AI, ask more than whether your team is doing the fundamentals. Ask whether your fundamentals operate at the speed your identity surface is really growing. The fundamentals didn't stop working. They were designed for human speed, and the environments they protect now run at machine speed.
If you want to know how far apart those two clocks have drifted in your environment, that's exactly what we can show you. See how Netwrix 1Secure governs identities and data continuously, then start a free trial against your own environment or launch the in-browser demo to see it work first.
Teilen auf
Erfahren Sie mehr
Über den Autor
Tyler Reese
VP of Product Management, CISSP
Mit mehr als zwei Jahrzehnten in der Software-Sicherheitsbranche ist Tyler Reese bestens vertraut mit den sich schnell entwickelnden Identitäts- und Sicherheitsherausforderungen, denen Unternehmen heute gegenüberstehen. Derzeit ist er als Produktleiter für das Netwrix Identity and Access Management Portfolio tätig, wo seine Aufgaben die Bewertung von Markttrends, die Festlegung der Richtung für die IAM-Produktlinie und letztendlich die Erfüllung der Bedürfnisse der Endanwender umfassen. Seine berufliche Erfahrung reicht von IAM-Beratung für Fortune-500-Unternehmen bis hin zur Arbeit als Unternehmensarchitekt eines großen Direkt-an-Verbraucher-Unternehmens. Derzeit hält er die CISSP-Zertifizierung.
Erfahren Sie mehr zu diesem Thema
Leistungsstarke erweiterte LDAP-Steuerelemente: Anti-Remediation und unsichtbare Aufklärung in AD
Erstellen Sie AD-Benutzer in Massen und senden Sie deren Anmeldeinformationen per E-Mail mit PowerShell
Wie man Passwörter mit PowerShell erstellt, ändert und testet
So fügen Sie AD-Gruppen hinzu und entfernen Objekte in Gruppen mit PowerShell
Vertrauensstellungen in Active Directory