By NHI Mgmt Group Editorial TeamBased on Abnormal AI: “From Operator to Builder: Why Stephen Harrison Joined Abnormal to Shape the Next Generation of Security” (February 25, 2026)

TL;DR: Attackers now chain identity, social engineering, and system access faster than point tools can respond, while AI-native product development is shortening delivery cycles and expanding platform scope, according to Abnormal AI. The governance lesson is that enterprise security needs behavior-aware visibility across identities, not isolated controls that assume predictable attacker paths.


At a glance

What this is: Abnormal AI argues that AI-native product development and attacker behaviour are pushing enterprise defence toward identity-aware behavioural visibility rather than isolated point controls.

Why it matters: IAM, PAM, and NHI teams should care because the same behavioural patterns that expose human accounts also expose machine and delegated identities when controls assume linear, predictable attack paths.


Context

The article is about a governance gap in modern security architecture: attackers and defenders are both moving faster, but many control models still assume stable identity behaviour and predictable response windows. In practice, that assumption breaks once identity, social engineering, and system access are chained together across multiple environments.

Abnormal AI frames its platform and leadership change around this shift, arguing that behavioural AI and AI-native development are changing both how threats unfold and how quickly vendors can respond. For identity programmes, the important question is not whether AI exists in the stack, but whether identity signals are being correlated across human, machine, and delegated access paths.


Key questions

Q: How should security teams handle identity attacks that combine social engineering and system access?

A: Treat them as one chain rather than separate incidents. The key is to correlate the manipulation step, the identity foothold, and the resulting system access in a single workflow so analysts can see how the intrusion developed and respond before later-stage activity spreads across the environment.

Q: Why do point security tools struggle with modern identity-led attacks?

A: Because each tool usually sees only one slice of the attack. When identity compromise, behavioral anomalies, and system access are distributed across different logs and products, the real pattern is lost unless the programme can correlate them into one enterprise view.

Q: How can teams tell whether behavioral detection is actually helping?

A: Teams can tell behavioural detection is helping when it reduces time to triage, improves cross-team coordination, and leads to earlier containment decisions. If it only increases alert volume without changing outcomes, it is adding noise rather than value. The right metric is whether decisions move faster than the attacker does.

Q: What should IAM and security leaders prioritise when platforms expand quickly?

A: Prioritise consistency in identity modelling, telemetry, and response logic. Rapid product expansion is useful only if new capabilities inherit the same governance and detection assumptions as the rest of the stack rather than adding disconnected surface area.


Technical breakdown

Behavioral baselines across identity relationships

Behavioral security models do not rely on a single alert or static rule. They build baselines around who talks to whom, when access normally occurs, and what context makes an action unusual. That approach is particularly relevant when identity activity spans users, service accounts, and delegated workflows, because abuse often looks legitimate at the permission layer while being abnormal in the relationship layer. The article’s core point is that point tools miss attacks when they inspect fragments of activity in isolation rather than the full chain of identity, behavior, and context.

Practical implication: correlate identity activity across accounts, systems, and sessions instead of judging each event in isolation.

AI-native development and security platform scale

AI-native development changes the economics of product delivery by shortening the path from idea to deployment. In security, that matters because platform scope is no longer constrained only by engineering capacity. When a vendor can extend the same behavioural core into adjacent problem areas without re-architecting each time, the platform can expand faster than traditional, manually assembled point solutions. The article presents this as a product-building advantage, but for practitioners the governance question is different: whether fast expansion is matched by consistent control logic, telemetry quality, and lifecycle discipline across the added surface area.

Practical implication: evaluate whether new capabilities inherit the same identity and telemetry model as the rest of the platform.

Why isolated point tools miss chained identity attacks

Attackers do not need to break every control if they can move from identity compromise to social engineering to system access in a sequence that each tool treats separately. That is the failure mode the article highlights. A point solution may be accurate inside its narrow domain and still fail operationally because it cannot see the whole path from initial manipulation to downstream access abuse. The technical lesson is not that individual controls are useless. It is that modern attacks are multi-stage, and defensive visibility has to follow the chain rather than the product category.

Practical implication: map detection and response around attack chains, not around product silos.


Threat narrative

Attacker objective: The attacker objective is to turn a single identity foothold into operational access across multiple enterprise systems before defenders can assemble the full picture.

  1. Entry occurs when attackers begin with identity compromise or social engineering rather than overt malware delivery, giving them a legitimate-looking foothold.
  2. Escalation follows as they chain that foothold into broader system access, adapting in real time to what works across identities and environments.
  3. Impact arrives when fragmented tooling cannot correlate the full sequence quickly enough, allowing the intrusion to spread across enterprise systems before response catches up.
  • MGM Resorts breach 2023: A help desk call gave attackers Okta and Azure admin access at MGM, leading to ransomware, ten days of outages and a $100 million hit.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Behavioral visibility has become the control plane for modern identity defense: When attackers chain identity compromise, social engineering, and system access, isolated tools see too little and too late. The field is moving away from single-control thinking toward enterprise behavior correlation across accounts, sessions, and contexts. Practitioners should treat visibility itself as a governance capability, not just a detection feature.

AI-native development is changing the operational expectations for security platforms: Small teams can now extend products faster, but speed only matters if the platform preserves a consistent identity model underneath the growth. That raises the bar for lifecycle discipline, telemetry integrity, and cross-domain control consistency. The practical test is whether platform expansion increases coherence or simply adds more surface area.

Identity and behavior are now coupled risk variables: The article’s strongest insight is not about AI as a feature, but about identity relationships as the structure of attack and defense. That makes human IAM, NHI governance, and delegated access part of the same analytical frame. Security programmes that still separate those domains will keep missing the connective tissue attackers exploit.

Named concept: identity relationship visibility: This is the ability to model how identities interact across people, systems, and contexts rather than reviewing permissions as standalone entitlements. It matters because abuse often emerges from abnormal relationships, not obviously malicious credentials. Practitioners should think in terms of relationship trust, not just access approval.

The market is rewarding vendors that can reason across behaviour, not just control lists: The article signals a broader shift in enterprise security buying, where product value increasingly comes from correlating identity, context, and response speed. That does not eliminate point tools, but it does change their role in the stack. Security leaders should re-evaluate whether their current portfolio can actually follow a multi-stage attacker path.

What this signals

Identity relationship visibility: Programmes that still treat access events as isolated records will keep missing the chain that turns manipulation into system access. The next stage of maturity is to model trust between identities, not just permissions on resources.

Security leaders should also watch how AI-native development changes the buying criteria for platforms. Faster feature delivery is useful, but only if logging, correlation, and response logic remain coherent as the product surface expands.

The practical consequence is that human IAM, NHI governance, and delegated access can no longer be managed as separate control towers. Attackers already move across those boundaries, so defenders need an operating model that does the same.


For practitioners

  • Instrument identity relationship telemetry Capture how users, service accounts, and delegated workflows relate to one another so unusual access patterns can be detected at the relationship level, not just the event level.
  • Correlate social engineering with access activity Treat phishing, help-desk manipulation, and account abuse as one attack chain in your SOC workflows so the response team does not wait for a later-stage alert to connect them.
  • Review control coverage across chained access paths Check whether your current stack can see from identity compromise through system access without losing context between products, tenants, or log sources.
  • Validate platform expansion against governance consistency When evaluating new security capabilities, verify that the underlying identity model, logging, and response logic remain consistent as the platform grows into adjacent use cases.

Key takeaways

  • Modern enterprise defence is shifting from isolated point controls to behavioural visibility across identity relationships.
  • The article links attacker speed with AI-native product delivery, showing why governance and telemetry coherence matter as platforms expand.
  • Security teams should assess whether their controls can follow a multi-stage identity attack from manipulation to system access.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article centers on identity-led abuse across AI-native security operations.
Recommendation — Map identity-led attack chains to ASI03 and assess where privilege abuse crosses product boundaries.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article’s governance theme is about seeing and controlling access across identities.
Recommendation — Review entitlement visibility across human, machine, and delegated identities under PR.AA-05.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementThe source describes chained identity abuse and movement across systems.
Recommendation — Map chained identity abuse to TA0006 and TA0008 to improve detection coverage across stages.

Key terms

  • Behavior Baseline: A record of normal activity for a non-human identity, including typical consumers, resources, and actions over time. Baselines help security teams detect when an identity is being used in an unusual way and provide the context needed to enforce least privilege safely in dynamic environments.
  • Identity relationship visibility: Identity relationship visibility is the ability to understand how people, services, and delegated workflows connect and influence each other across the enterprise. It shifts detection from isolated entitlements to the network of trust and behaviour that attackers often manipulate first.
  • AI-native development: AI-native development is the practice of building software with AI capabilities and AI-assisted workflows built in from the start. It treats models, prompts, agents, and data access as core design elements, so architecture, testing, governance, and security are shaped around machine-driven behavior, not added later as an afterthought.
  • Chained identity attack: A chained identity attack is an intrusion sequence that moves from manipulation or compromise of one identity into further access, often crossing systems and products before defenders can connect the steps. It is especially difficult to stop when teams treat each stage as a separate problem rather than one continuous path.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org