By NHI Mgmt Group Editorial TeamBased on Abnormal AI: “How 4 Cybersecurity Companies Protect Against Cloud Vulnerabilities” (June 26, 2026)

TL;DR: Security leaders from Wiz, Rubrik, Noname, and Abnormal discuss the threats targeting their own companies, how they prioritise defensive tools, and why automation is becoming more important amid the cybersecurity skills shortage, according to Abnormal AI. The resource is best read as a signal that operational pressure is driving security teams toward automation and tighter prioritisation, not as a product story.


At a glance

What this is: This on-demand webinar looks at how security leaders at Wiz, Rubrik, Noname, and Abnormal are thinking about the threats they face, the tools they prioritise, and the role of automation.

Why it matters: It matters because identity and security teams are being forced to decide which controls to automate first when threat volume, staffing constraints, and tool sprawl all compete for attention.


Context

This on-demand webinar is about operational pressure in cyber defence, not a product feature tour. The central question is how security leaders decide what to protect first when threat volume keeps rising and teams cannot manually keep pace.

The identity governance angle is indirect but real: when defenders turn to automation under staffing pressure, they are making decisions about control coverage, response speed, and prioritisation across human IAM, NHI governance, and emerging autonomous workflows. That makes this a programme design topic, not just a tooling discussion.


Key questions

Q: How should security teams decide which defence workflows to automate first?

A: Start with repetitive, well-bounded workflows that have clear inputs, clear outputs, and low exception rates. Preserve human review for privileged decisions, unusual cases, and actions that would be hard to explain after the fact. The test is not whether a task can be automated, but whether automation improves consistency without weakening accountability.

Q: Why does automation become more important when security teams are short-staffed?

A: Because staffing pressure exposes the limits of manual governance. If a team cannot review, triage, and respond quickly enough, controls decay in practice even if they exist on paper. Automation helps preserve coverage, but only when the underlying process is stable, measurable, and understood well enough to delegate safely.

Q: What are the signs that a large security stack is becoming too hard to govern effectively?

A: Warning signs include delayed patching, inconsistent visibility across products, and administrators struggling to configure controls consistently across the environment. Another signal is when critical issues are discovered only after an incident rather than through routine monitoring. If teams need to work around blind spots just to maintain coverage, governance has likely outgrown the operating model.

Q: What do identity teams get wrong about automation in access governance?

A: They often treat automation as a substitute for governance rather than a way to make governance scalable. Automation still depends on clear policy, accurate entitlement data, and accountable reviewers. If those inputs are weak, faster workflows only amplify bad decisions.


Background and context

Why automation becomes a defence control, not just an efficiency play

Automation in security operations is no longer mainly about saving analyst time. In a threat environment where attacks evolve continuously, the practical question is which repetitive decisions can be safely delegated to systems without reducing governance quality. For identity teams, that means separating low-risk orchestration from high-risk access decisions. The more a programme depends on manual triage, the more its coverage depends on scarce people rather than policy design.

Practical implication: define which detection, response, and access workflows can be automated without weakening approval, review, or audit requirements.

Tool prioritisation under skills shortage

A security team cannot operationalise every control at the same depth when people are limited. Prioritisation becomes an architecture decision, because the controls that survive staffing pressure are the ones built for repeatability, observability, and low-friction enforcement. In identity programmes, that usually favours controls with clear lifecycle hooks, clear ownership, and measurable outcomes. Without that discipline, teams accumulate tools faster than they can govern them.

Practical implication: rank controls by operational repeatability and governance value, not by how many features a platform exposes.

Emerging threats force faster governance loops

When bad actors change tactics quickly, static defence models age badly. Security leaders then need faster feedback loops between threat intelligence, policy updates, and operational response. That matters for identity because access decisions and privileged workflows increasingly sit inside fast-moving control planes. The programme challenge is to avoid a mismatch between the speed of attack adaptation and the speed of internal governance change.

Practical implication: shorten the cycle between threat insight, policy adjustment, and control validation across identity and security operations.


NHI Mgmt Group analysis

Automation is becoming a governance necessity, not a convenience. When security leaders say they are turning to automation, the underlying issue is not novelty but scale mismatch. Threat volume, staffing constraints, and tool sprawl are forcing programmes to move from manual oversight to policy-driven enforcement. For identity teams, the important question is which decisions can be automated without turning governance into blind trust.

Operational prioritisation now determines control quality. Security teams cannot treat every threat, workflow, and access event as equally urgent. The better programmes will decide where automation supports consistency and where human review remains essential for high-risk access paths. That distinction matters across human IAM, NHI governance, and emerging autonomous systems because the same staffing constraint affects all three.

Control coverage, not tool count, is the real maturity signal. Leaders who focus on the number of deployed tools can miss the more important issue: whether those tools actually reduce response time, improve visibility, and enforce policy reliably. In identity governance, that means measuring whether access, privilege, and workflow decisions are consistently handled at machine speed where appropriate.

Named concept: automation pressure gap. This is the gap between the volume and speed of modern threats and the manual governance capacity of the security team. It shows up when teams know what they should enforce but cannot execute quickly enough to keep pace. Practitioners should treat that gap as a programme design problem, not a staffing footnote.

What this signals

Automation pressure gap: Security teams are now being forced to close the distance between threat speed and human governance capacity. That changes programme design across identity, detection, and response because the limiting factor is often operational throughput, not policy intent.

Security leaders should expect control value to be judged less by feature breadth and more by whether a workflow can be enforced consistently under staff constraints. That makes repeatability, ownership, and measurable coverage the real criteria for deciding what to automate next.


For practitioners

  • Define automation boundaries for high-risk controls Separate routine detection and response tasks from privileged access decisions, approval gates, and exception handling so automation does not erode governance over sensitive actions.
  • Map tool priorities to governance outcomes Assess each tool by the control outcome it enables, such as reduced response time, better visibility, or clearer ownership, rather than by feature volume alone.
  • Shorten policy-to-response cycles Review how quickly threat intelligence becomes policy change, then how quickly that change is enforced in operations across identity and security workflows.
  • Preserve human review where risk is highest Keep human approval for access paths, exception cases, and privileged actions that cannot be safely reduced to a repeatable machine rule.
  • Measure automation by control coverage Track whether automation is actually reducing backlog, inconsistency, and manual handoffs across the workflows it is meant to support.

Key takeaways

  • Security operations are being reshaped by the need to cope with faster threat change and limited human capacity.
  • Automation is becoming a governance choice, not just an efficiency choice, because manual review cannot scale everywhere.
  • The strongest programmes will automate repeatable work while preserving human oversight for privileged and exceptional decisions.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 provides the primary governance reference for this term.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OC-01 — Organisational ContextThe article is about how security leaders set operational priorities under pressure.
GV.RM-01 — Risk Management StrategyPrioritisation under threat pressure is fundamentally a risk-management question.
PR.IR-04 — Incident Response Plan is ExecutedThe article centres on faster response and operational readiness through automation.
Recommendation — Align automation decisions to organisational context and measurable defence outcomes. Use a risk strategy to decide which workflows to automate and which to keep manual. Automate response steps where repeatability improves execution without removing oversight.

Key terms

  • Automation pressure gap: The gap between the speed and volume of security events and the human capacity to govern them manually. It becomes visible when teams know what they need to do but cannot execute fast enough, consistently enough, or with enough coverage to keep pace.
  • Control Coverage: Control coverage is the degree to which security controls actually match the assets, identities, and data flows they are meant to protect. A programme can look mature on paper while still missing blind spots if discovery, classification, and enforcement are not aligned.
  • Governance Feedback Loop: A structured way to collect and use implementation lessons, peer input, and operational criticism to improve identity controls over time. It turns practitioner experience into programme input so that policy, process, and tool configuration stay aligned with real-world use.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org