Resource centerResearch
2026 Data and Identity Security Report

2026 Data and Identity Security Report

AI is expanding access to data faster than most organizations can govern it. To understand how organizations are adapting, Netwrix Research Lab surveyed 2,317 IT and security professionals representing 1,889 organizations across more than 60 industries worldwide.

The findings reveal a growing gap between AI adoption and AI readiness. Organizations where AI significantly expanded the number of identities requiring access reported breach rates nearly four times higher than those where AI had not materially changed access patterns. The report examines how AI-driven identity expansion, non-human identities, governance maturity, and data visibility are reshaping security risk.

Content in this issue

AI security readiness

AI-driven identity expansion

Non-human identity governance

Sensitive data exposure

Data and identity visibility

AI governance maturity

Incident response readiness

Industry benchmarks

Regional findings

Security maturity tiers


43%

of organizations where AI significantly expanded identities reported a breach in the past 12 months, compared with 11% where AI had not materially changed access patterns.

76%

of organizations do not fully govern or monitor non-human identities.

11%

of organizations report full AI security readiness through continuous enforcement and monitoring.


"Organizations where AI expanded access saw four times the breach rate of those where it didn't, 43% versus 11%. The root cause here is speed. AI adds identities and accesses data faster than human-paced reviews can track them, and attackers can create an impact in seconds. Governance has to run at that speed or it's just theater."

Grady Summers

CEO, Netwrix

Is your data security strategy keeping up?

Benchmark your organization across data visibility, access governance, and AI readiness — showing where your perceived posture and actual exposure diverge, and where to act first

Take the assessment

Share on

About the authors

Learn More

About the author

A man in a suit and white shirt smiles for the camera

Grady Summers

Chief Executive Officer

Grady Summers brings 20+ years of cybersecurity expertise and a proven track record leading product innovation and transformational growth. He’s held leadership roles at pioneering companies like SailPoint, FireEye, GE, and Mandiant, where he drove SaaS transformation and portfolio expansion. With hands-on experience across global markets and customer-facing roles, Grady pairs boardroom strategy with boots-on-the-ground insight. While he is recognized industry leader in cybersecurity, Grady maintains his connection to nature by spending his spare time planting trees on his Pennsylvania farm. He holds an MBA from Columbia University and a bachelor's degree in computer systems management from Grove City College.

Learn More

About the author

A man in a blue jacket and plaid shirt smiles for the camera

Jeff Warren

Chief Product Officer

Jeff Warren oversees the Netwrix product portfolio, bringing over a decade of experience in security-focused product management and development. Before joining Netwrix, Jeff led product organization at Stealthbits Technologies, where he used his experience as a software engineer to develop innovative, enterprise-scale security solutions. With a hands-on approach and a knack for solving tough security challenges, Jeff is focused on building practical solutions that work. He holds a BS in Information Systems from the University of Delaware.

Learn More

About the author

Asset Not Found

Huy Kha

Director of Security Research

Huy is the Director of Security Research at Netwrix, leading the security research team and driving improvements across the security product portfolio to help customers improve resilience. He is also a Microsoft MVP in Windows & Devices. With a background in incident response, security operations, and system optimization, he focuses on practical, repeatable approaches that turn complex problems into clear, streamlined processes.

Learn More

About the author

Darryl baker headshot

Darryl Baker

Senior Staff Security Researcher

Darryl G. Baker is a Senior Staff Security Researcher at Netwrix and a recognized authority in Identity and Active Directory security. With over a decade of identity systems experience, he has led enterprise security assessments, identity security trainings, and threat emulations focused on Active Directory, Entra ID, and Azure environments. Darryl has delivered highly rated trainings and demos at BlueTeamCon, BSidesCT, The Experts Conference, and Wild Wild West Hackin’ Fest. He’s the architect behind numerous hands on attack emulation labs—leveraging current red team and blue team tools to help defenders master everything from attack path analysis to threat hunting. In his sessions, Darryl blends deep technical insight with real world case studies, empowering blue team professionals to strengthen their identity security posture and defend against evolving adversary techniques.

Learn More

About the author

Asset Not Found

Farrah Gamboa

Sr. Director of Product Management

Senior Director of Product Management at Netwrix. Farrah is responsible for building and delivering on the roadmap of Netwrix products and solutions related to Data Security and Audit & Compliance. Farrah has over 10 years of experience working with enterprise scale data security solutions, joining Netwrix from Stealthbits Technologies where she served as the Technical Product Manager and QC Manager. Farrah has a BS in Industrial Engineering from Rutgers University.

Learn More

About the author

Asset Not Found

Joe Dibley

Security Researcher

Security Researcher at Netwrix and member of the Netwrix Security Research Team. Joe is an expert in Active Directory, Windows, and a wide variety of enterprise software platforms and technologies, Joe researches new security risks, complex attack techniques, and associated mitigations and detections.