TL;DR: Demand driven by human, machine, and agentic AI identity risk helped CyberArk report third-quarter 2025 net new ARR of $68 million, total ARR of $1.341 billion, and subscription ARR of $1.158 billion, according to CyberArk, while the numbers reinforce that identity security is moving from point controls to platform governance across the full identity lifecycle.
At a glance
What this is: CyberArk’s Q3 2025 results show strong recurring revenue growth alongside management’s view that identity security demand is shifting toward governance for human, machine, and agentic AI identities.
Why it matters: For IAM, PAM, and NHI teams, this matters because the commercial centre of gravity is moving toward platform-wide identity governance rather than isolated point controls.
By the numbers:
- CyberArk reported third-quarter 2025 net new ARR of $68 million.
- Total ARR grew 45 percent year over year to reach $1.341 billion.
- Subscription ARR grew 57 percent year over year to reach $1.158 billion.
- CyberArk reported $342.8 million in total revenue for the third quarter of 2025.
Context
Identity security now spans human users, machine identities, and AI agents that can act with delegated privilege. That changes the governance problem from protecting a single control plane to managing access across the full identity lifecycle, where issuance, use, review, and revocation all matter at once.
CyberArk’s third-quarter results are best read as a signal of that shift rather than as a standalone earnings story. The article links demand growth to privilege risk, machine identity scale, and the emerging need to secure agentic AI, which is increasingly how identity programmes are being judged in practice.
Key questions
Q: What do organisations get wrong when they treat human, machine, and AI identities the same?
A: They apply one policy model to identities with very different lifecycles, behaviours, and evidence requirements. Human users, service accounts, and AI identities should not share the same review cadence or control assumptions. When they do, governance becomes broad but shallow, and the most risky access paths are usually the least visible.
Q: Why do machine identities complicate identity governance more than human accounts?
A: Machine identities act continuously, at scale, and with delegated authority, so they cannot rely on manual review cycles or human pauses. They often outnumber human users and can trigger downstream systems automatically. That makes runtime enforcement, ownership, and revocation timing much more important than in traditional user IAM.
Q: What signals show that identity controls are not keeping up with agentic AI?
A: Look for tool calls that are hard to attribute, access that expands across multiple services in one session, and approvals that do not explain the eventual action chain. Those patterns show that static entitlements are no longer capturing runtime reality. A mature programme should be able to reconstruct the execution path from identity evidence.
Q: What does platform consolidation in identity security mean for practitioners?
A: It means buyers should expect broader coverage demands, tighter integration questions, and stronger evidence that a platform can govern both access state and runtime behaviour. Consolidation usually shifts evaluation away from single-feature comparison toward operating model fit. Teams should validate whether their current stack can still support cross-domain identity governance end to end.
Technical breakdown
Why identity security is becoming a lifecycle problem
Identity security breaks down when controls are built around isolated credentials rather than the full path from provisioning to offboarding. Human users, service identities, certificates, tokens, and AI agents all create different governance pressures, but they now share one operational reality: privilege must be issued, constrained, monitored, and retired as a lifecycle event. That pushes teams beyond static access lists and toward governance of who or what can act, for how long, and under what oversight. In practice, this is where PAM, IGA, and NHI controls start to converge.
Practical implication: Practitioners should align access governance, credential lifecycle, and privileged controls across all identity types instead of managing them as separate programmes.
Machine identity scale changes the control model
Machine identities are not just a larger version of human IAM. They are often created at speed, distributed across pipelines and workloads, and tied to secrets, certificates, or tokens that can persist far longer than the workload itself. That makes inventory, ownership, rotation, and revocation harder than traditional account management. The operational challenge is not simply that machine identities exist in volume, but that they can outlive the systems, teams, or integrations that created them. Governance therefore has to cover discovery, classification, and expiry as first-class controls.
Practical implication: Security teams need to treat machine identities as governed assets with ownership and expiry, not as infrastructure by-products.
Agentic AI raises the question of delegated privilege
An AI agent can be given access, but once it can choose actions at runtime, identity governance has to account for delegated behaviour rather than a fixed script. That is different from ordinary automation because the access decision is no longer tightly bound to a predictable workflow. The governance issue becomes whether privilege was granted for a bounded task, whether tool use is constrained, and whether the system can be audited after the fact. This is where the assumption of stable, reviewable access starts to weaken.
Practical implication: Teams should evaluate whether existing identity controls can describe and constrain runtime-decision systems before those systems are allowed broad access.
Threat narrative
Attacker objective: The objective is to turn identity privilege into a reusable path for broader access and control across enterprise systems.
- Entry begins when a human, machine, or AI identity is granted access that exceeds the task it actually needs, creating an exposed privilege surface.
- Escalation follows when that access is reused across systems, tools, or workflows without tight lifecycle controls or timely revocation.
- Impact occurs when the overextended identity becomes a path to broader resource access, data exposure, or operational abuse.
Breaches seen in the wild
- Sisense breach 2024: A credential in Sisense's GitLab reportedly opened S3 buckets of customer tokens, passwords and certificates; CISA urged a full reset.
- CISA Private-CISA GitHub leak 2026: A CISA contractor's public GitHub repo exposed AWS GovCloud admin keys, Artifactory credentials and plaintext passwords for six months.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Identity security is moving from point control to lifecycle governance. The results are less about one vendor’s quarterly execution than about how the market is redefining the problem. Human access, machine identities, and AI agents now sit inside the same governance conversation because privilege is increasingly distributed across the full identity lifecycle. Practitioners should expect buying decisions to favour platforms that can govern issuance, use, review, and retirement across identity classes.
The new competition is for governance scope, not feature count. When identity risk spans workforce access, workload credentials, and agentic AI behaviour, point products stop being enough on their own. The market is converging around platform narratives that promise end-to-end visibility, but the real test is whether the governance model still works when identities are ephemeral, delegated, or machine-generated. Security teams should re-evaluate whether their current stack can enforce policy across those transitions.
Agentic AI exposes a basic assumption in traditional identity design. Least privilege is easier to define when the identity’s purpose is known at provisioning time. That assumption fails when the actor can decide which tool to use and when to act at runtime. The implication is not simply more access control, but a different governance model for delegated execution.
Identity blast radius is now the most useful way to think about programme risk. A single identity compromise can propagate across human workflows, automated pipelines, and AI-driven actions if access boundaries are porous. That is why boards and security leaders are increasingly drawn to governance stories that connect PAM, NHI, and AI control planes. The practical conclusion is that identity programmes will be judged by how well they constrain blast radius, not by how many accounts they manage.
The AI era is forcing identity security into the language of operational resilience. The article’s acquisition context matters because consolidation usually follows category expansion, not maturity. That suggests buyers will increasingly compare how well a platform supports control consistency, lifecycle enforcement, and auditability across multiple identity types. Practitioners should prepare for more platform-centric evaluation and less tolerance for fragmented governance models.
What this signals
Identity governance is becoming a cross-actor discipline. When human, machine, and agentic identities share the same enterprise resources, the programme boundary shifts from account administration to control consistency. Teams should expect future evaluation criteria to focus on lifecycle enforcement, privilege boundaries, and auditability across all three actor types.
Delegated execution is the pressure point. The hardest governance problem is no longer simply authenticating an identity. It is making sure that an identity, whether human-operated or machine-driven, cannot act outside the scope that was approved when privilege was issued.
For practitioners
- Map governance across all identity classes Inventory where human, machine, and agentic identities are governed today, then identify where access decisions, approvals, reviews, and revocation still sit in separate systems.
- Define ownership for machine identities Assign accountable owners to service accounts, tokens, certificates, and workload identities so that lifecycle actions are not left to platform teams by default.
- Test whether agentic systems can be constrained Review whether any AI-driven workflow can select tools or act on its own privilege without a bounded task definition, logging, and revocation path.
- Reassess privilege boundaries after consolidation news Use the vendor consolidation signal to revisit whether your current stack can still support least privilege, visibility, and auditability across the full identity estate.
- Separate commercial consolidation from control validation Do not treat revenue growth or market expansion as proof of governance maturity. Validate whether the controls actually reduce standing privilege and improve lifecycle enforcement.
Key takeaways
- The article shows that identity security is moving beyond isolated controls and toward lifecycle governance across human, machine, and agentic identities.
- The financial results reinforce that platform demand is now tied to privilege risk, machine identity growth, and the need to govern AI-driven access patterns.
- Practitioners should test whether their current identity stack can still enforce privilege boundaries and revocation consistently across the full identity estate.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | The article centres on privilege expansion across human, machine, and AI identities. |
| NHI-01 — Improper Offboarding | Lifecycle enforcement is a core theme because identities must be retired as business need ends. | |
| Recommendation — Review whether non-human identities hold more privilege than their tasks require and reduce standing access. Tie identity retirement to workload and vendor offboarding so stale accounts and tokens do not linger. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | The article’s emphasis on identity lifecycle and credential governance maps directly to authenticator handling. |
| Recommendation — Apply authenticator lifecycle controls to rotate, revoke, and retire credentials on a governed schedule. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The post is about managing entitlements consistently across identity types. |
| Recommendation — Continuously validate permissions and entitlements so access stays aligned to current business need. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | The breach examples and risk discussion point to credential abuse as a path to broader movement. |
| Recommendation — Map identity exposure to credential access and lateral movement tactics to prioritise detection and containment. | ||
Key terms
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
- Machine Identity: The digital identity of a machine, device, or workload, such as a server, container, or VM, used to authenticate it within a network. Sometimes used interchangeably with NHI, though NHI is the broader category.
- Agentic execution environment: A runtime in which an AI system can choose actions, call tools, and continue a task with limited human intervention. In identity terms, it becomes an access-bearing environment that can amplify whatever credentials and permissions it inherits, so governance must treat it like a privileged workload.
- Lifecycle Governance: Lifecycle governance is the set of controls that cover creation, assignment, review, rotation, and retirement of identities and credentials. For NHIs, it is the difference between a temporary automation asset and a persistent access risk. Strong lifecycle governance keeps ownership and expiry tied to actual business use.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org