Netwrix 1Secure ofrece visibilidad unificada de datos e identidad - gratis durante 14 días con acceso completo.Comience una prueba gratuita

Centro de recursosBlog
Hicieron todo bien en higiene de identidades. Sufrieron 4 veces más brechas

Hicieron todo bien en higiene de identidades. Sufrieron 4 veces más brechas

Aug 14, 2026

Nuestra encuesta a 2.317 líderes de seguridad y TI reveló que las organizaciones que lideran en IA van por delante en los fundamentos. Aun así, reportaron una tasa de brechas del 43%. El problema no es el rigor. Es la latencia.

Introduction

For most of my career, I've believed what most security practitioners believe: get the fundamentals right and you'll be in a good position. Keep systems patched, apply least privilege, review access, know what's in your environment. I came up in endpoint management, so patching in particular shaped how I think about security hygiene. But a finding in our 2026 Data and Identity Security Report forced me to question an assumption I didn't know I was making.

The statistic that surprised me

An organization's identity footprint is no longer just employee accounts. It now includes AI agents, copilots, and automated integrations, each provisioned as its own identity with its own access to systems and data.

In our survey, organizations where AI has significantly expanded that footprint reported a 43% breach rate over the past twelve months. Organizations where it hasn't reported 11%. That’s nearly a 4x gap.

The easy explanation would be that the fast movers skipped the fundamentals. The data shows the opposite. Across the 2,317 security and IT leaders surveyed for the 2026 Netwrix Data and Identity Security Report, the organizations leaning hardest into AI are, on average, ahead of their peers on the practices that have anchored identity security for a decade:

  • Continuous data inventory: 46% lack one, vs. 60% of slower adopters
  • Non-human identity governance: 25% rate theirs as weak, vs. 44% of slower adopters
  • Shadow AI visibility: 13% report blind spots, vs. 25% of slower adopters

Source: 2026 Netwrix Data and Identity Security Report, a survey of 2,317 security and IT leaders.

They invested in the playbook. They got breached anyway.

Isn't good identity hygiene the gold-standard for security, regardless of whether the identities are human or AI agents? I've always believed so. So why didn't doing the right things improve their odds?

Pressure-testing the finding

Before accepting any conclusion, I pressure-tested it everywhere I could. At RSA this year, I lost count of the vendors drawing a hard line around AI governance as its own category, and I was skeptical. My instinct was that it was a sales category, not a technical one, a new label built to justify a new budget line.

Then I asked one of our senior solutions engineers whether AI agents really required a different approach on the ground. She said yes, but not because the underlying identity problem had changed, but because of velocity and volume. Customers tell me the same thing: AI-related access needs move faster than their processes can absorb them.

That consistency changed my thinking. The vendors weren't wrong that something had changed. They were wrong about what. This isn't a new category of problem requiring a new discipline. It's the old problem arriving at a new speed and scale. The fundamentals are not wrong, they are simply insufficient because they were built for a rate of change that no longer applies.

The human clock inside every fundamental

Take patching, one of the most mature disciplines in all of security. Even the emergency path runs through people: an engineer identifies the issue, builds a fix, tests it, gets it approved, deploys it. Appropriately so. But the fastest that process can ever run is at the speed of the people in it, and the model works because it assumes the environment holds reasonably still between inspections.

Identity governance runs on the same clock.  Joiners, movers, and leavers. Point-in-time inventories. Periodic access reviews. All of it assumes an identity surface that grows about as fast as headcount.

AI identities don't grow at the pace of hiring. They grow at the pace of deployment. Part of the 4x gap is simple math: More identities mean more attack surface, but that's precisely why cadence is the variable that matters. A surface expanding at deployment speed can only be kept safe by governance operating at deployment speed.

In practice: a mid-sized company runs quarterly access reviews, a documented onboarding checklist, and an annual audit. Meanwhile, a product team spins up an AI coding assistant Monday, connects it to the repo and ticketing system by Tuesday, and grants it broader access than intended by Wednesday, because broad access was the fastest way to get it working. That identity is touching real systems three days into a review cycle built to run every ninety. Nothing about the checklist was wrong. It describes a world where access requests wait for a human to create them. That world is ending.

How to tell which side of the gap you're on

An audit won't tell you, because audits check that a control exists and that it ran. Existence was never the issue, as the breached organizations in our data were ahead of their peers. But “ahead of peers” is not the same as “at pace with the environment,” and only 11% of organizations have fully operationalized governance as enforced, continuous, and proactive across identities, permissions, and the data AI can reach. Our focus needs to shift from whether controls exist to how long they take to work. Consider these questions:

How long does a new non-human identity exist before your governance process knows about it? Agents, service accounts, and integrations deserve privileged-account scrutiny starting the day they appear, not the quarter after.

How current is your picture of what identities can reach? Continuous, not reconstructed at review time from last quarter's inventory.

How long does access outlive its need? Three in four organizations we surveyed can't immediately revoke standing access. Breach rates climb another 14 points where over provisioning is tolerated and another seven where standing privileged access is the norm.

If your honest answers are measured in weeks and quarters, hygiene isn't your problem. Latency is. Least privilege and just-in-time access remain the clearest ROI in security based on our research, but they've moved from merely sufficient to absolutely necessary.

Bringing identity and data security together at machine speed

Why isn’t the solution to this problem just faster identity governance?

Every latency question has data on the other end of it. An ungoverned AI agent isn't risky in the abstract; it's risky because of the sensitive data it can reach. Identity security and data security used to be separate programs with separate tools. In an environment where every new identity exists to consume data, they've converged into a single challenge: you can't answer "what can this identity reach" without knowing where the sensitive data is, and you can't answer "who can reach this data" without governing every identity, human and non-human.

That convergence is the thinking behind the Netwrix 1Secure platform: both sides of that question, answered continuously, off the human clock. You always know where sensitive data lives and which identities can reach it. Governance follows identities at creation, so an AI agent gets privileged-account scrutiny the day it appears, scoped to the data it touches. And access moves at provisioning speed. Access is granted when it's needed and revoked the moment it isn't.

So when deploying AI, ask more than whether your team is doing the fundamentals. Ask whether your fundamentals operate at the speed your identity surface is really growing. The fundamentals didn't stop working. They were designed for human speed, and the environments they protect now run at machine speed.

If you want to know how far apart those two clocks have drifted in your environment, that's exactly what we can show you. See how Netwrix 1Secure governs identities and data continuously, then start a free trial against your own environment or launch the in-browser demo to see it work first.

Compartir en

Aprende más

Acerca del autor

Foto de tyler reese

Tyler Reese

VP de Gestión de Producto, CISSP

Con más de dos décadas en la industria de la seguridad de software, Tyler Reese conoce íntimamente los desafíos de identidad y seguridad que evolucionan rápidamente a los que se enfrentan las empresas hoy en día. Actualmente, se desempeña como director de producto para el portafolio de Netwrix Identity and Access Management, donde sus responsabilidades incluyen evaluar tendencias del mercado, establecer la dirección de la línea de productos IAM y, finalmente, satisfacer las necesidades de los usuarios finales. Su experiencia profesional abarca desde la consultoría de IAM para empresas Fortune 500 hasta trabajar como arquitecto empresarial de una gran compañía de venta directa al consumidor. Actualmente posee la certificación CISSP.