2026 Data and Identity Security Report
AI is expanding access to data faster than most organizations can govern it. To understand how organizations are adapting, Netwrix Research Lab surveyed 2,317 IT and security professionals representing 1,889 organizations across more than 60 industries worldwide.
The findings reveal a growing gap between AI adoption and AI readiness. Organizations where AI significantly expanded the number of identities requiring access reported breach rates nearly four times higher than those where AI had not materially changed access patterns. The report examines how AI-driven identity expansion, non-human identities, governance maturity, and data visibility are reshaping security risk.
Content in this issue
AI security readiness
AI-driven identity expansion
Non-human identity governance
Sensitive data exposure
Data and identity visibility
AI governance maturity
Incident response readiness
Industry benchmarks
Regional findings
Security maturity tiers
43%
of organizations where AI significantly expanded identities reported a breach in the past 12 months, compared with 11% where AI had not materially changed access patterns.
76%
of organizations do not fully govern or monitor non-human identities.
11%
of organizations report full AI security readiness through continuous enforcement and monitoring.
"Organizations where AI expanded access saw four times the breach rate of those where it didn't, 43% versus 11%. The root cause here is speed. AI adds identities and accesses data faster than human-paced reviews can track them, and attackers can create an impact in seconds. Governance has to run at that speed or it's just theater."
Grady SummersCEO, Netwrix
Is your data security strategy keeping up?
Benchmark your organization across data visibility, access governance, and AI readiness — showing where your perceived posture and actual exposure diverge, and where to act first
Take the assessmentShare on
About the authors
Learn More
About the author
Grady Summers
Chief Executive Officer
Grady Summers brings 20+ years of cybersecurity expertise and a proven track record leading product innovation and transformational growth. He’s held leadership roles at pioneering companies like SailPoint, FireEye, GE, and Mandiant, where he drove SaaS transformation and portfolio expansion. With hands-on experience across global markets and customer-facing roles, Grady pairs boardroom strategy with boots-on-the-ground insight. While he is recognized industry leader in cybersecurity, Grady maintains his connection to nature by spending his spare time planting trees on his Pennsylvania farm. He holds an MBA from Columbia University and a bachelor's degree in computer systems management from Grove City College.
Learn More
About the author
Jeff Warren
Chief Product Officer
Jeff Warren oversees the Netwrix product portfolio, bringing over a decade of experience in security-focused product management and development. Before joining Netwrix, Jeff led product organization at Stealthbits Technologies, where he used his experience as a software engineer to develop innovative, enterprise-scale security solutions. With a hands-on approach and a knack for solving tough security challenges, Jeff is focused on building practical solutions that work. He holds a BS in Information Systems from the University of Delaware.
Learn More
About the author
Huy Kha
Director of Security Research
Huy is the Director of Security Research at Netwrix, leading the security research team and driving improvements across the security product portfolio to help customers improve resilience. He is also a Microsoft MVP in Windows & Devices. With a background in incident response, security operations, and system optimization, he focuses on practical, repeatable approaches that turn complex problems into clear, streamlined processes.
Learn More
About the author
Darryl Baker
Senior Staff Security Researcher
Darryl G. Baker is a Senior Staff Security Researcher at Netwrix and a recognized authority in Identity and Active Directory security. With over a decade of identity systems experience, he has led enterprise security assessments, identity security trainings, and threat emulations focused on Active Directory, Entra ID, and Azure environments. Darryl has delivered highly rated trainings and demos at BlueTeamCon, BSidesCT, The Experts Conference, and Wild Wild West Hackin’ Fest. He’s the architect behind numerous hands on attack emulation labs—leveraging current red team and blue team tools to help defenders master everything from attack path analysis to threat hunting. In his sessions, Darryl blends deep technical insight with real world case studies, empowering blue team professionals to strengthen their identity security posture and defend against evolving adversary techniques.
Learn More
About the author
Farrah Gamboa
Sr. Director of Product Management
Senior Director of Product Management at Netwrix. Farrah is responsible for building and delivering on the roadmap of Netwrix products and solutions related to Data Security and Audit & Compliance. Farrah has over 10 years of experience working with enterprise scale data security solutions, joining Netwrix from Stealthbits Technologies where she served as the Technical Product Manager and QC Manager. Farrah has a BS in Industrial Engineering from Rutgers University.
Learn More
About the author
Joe Dibley
Security Researcher
Security Researcher at Netwrix and member of the Netwrix Security Research Team. Joe is an expert in Active Directory, Windows, and a wide variety of enterprise software platforms and technologies, Joe researches new security risks, complex attack techniques, and associated mitigations and detections.