Join our Newsletter — 33% off our NHI Course

Agentic AI in cybersecurity: are your IAM controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Traditional cybersecurity still reacts after incidents, but agentic AI can observe, plan and execute responses in real time, a shift Twine Security says is needed as 3,158 U.S. data compromises and UK enterprise breach rates keep pressure on defenders. The model changes the speed and governance assumptions behind IAM, access review and remediation.

Editorial analysis by NHI Mgmt Group, based on content published by Twine Security: “From Reactive to Proactive Cybersecurity”.

By the numbers:

  • In 2024 alone, U.S. organizations reported 3,158 data compromises.
  • Across the UK, nearly half of medium-to-large enterprises were hit in the last 12 months.
  • Breaches take an average of 258 days to identify.

Key questions

Q: What breaks when AI actions are not bound to a human approver?

A: Without a verifiable human approval step, high-consequence AI actions become difficult to attribute, contest, or reconstruct after the fact.

Q: Why do agentic AI systems change IAM risk?

A: They change risk because they can move from observation to execution.

Q: How do teams know whether autonomous remediation is actually improving security?

A: Look for verified closure, not just more tickets closed.

Practitioner guidance

  • Define autonomous action boundaries List the specific security actions an AI system may execute without human approval, then separate them from actions that still require operator review or delegated escalation.
  • Rework access review timing Move high-risk entitlement checks closer to issuance and runtime monitoring so privileges are constrained before an autonomous system can use them.
  • Classify agentic systems as actors Treat any system that observes, reasons, plans, and executes security actions as an identity-bearing actor with defined decision rights and audit scope.

Bottom line: Agentic AI changes cybersecurity because it can act, not just advise, which forces IAM teams to govern runtime authority instead of only reviewing outcomes.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21364
 

Agentic AI creates an assumption collapse in identity governance: access review was designed for privileges that persist long enough to be observed, certified, and revoked. That assumption fails when a security actor can decide and execute within the same runtime window. The implication is that governance has to move from after-the-fact certification to runtime authorization boundaries.

A few things that frame the scale:

  • Gartner predicts that by 2028, 33% of enterprise software applications will include agentic AI, up from less than 1% in 2024, and that 15% of day-to-day work decisions will be made autonomously.

A question worth separating out:

Q: Should organisations keep agentic security tools separate from human approval workflows?

A: Yes, when the tool can actually execute actions. Advisory workflows can share human review paths, but autonomous remediation needs explicit scope limits, separate approval logic for high-risk actions, and a clear record of what the system was allowed to change.

👉 Read our full editorial: Agentic AI shifts cybersecurity from reactive defense to proactive action


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.