Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

AI-speed attacks and NHI risk: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: AI can now generate working zero-day exploits in minutes and lower the cost of advanced attacks to near zero, according to Expel's RSAC 2026 analysis, while agentic AI can speed lateral movement, credential harvesting, and exfiltration beyond human response loops. The practical inflection point is not just faster malware, but a governance gap where identity, detection, and data controls must operate at machine speed.

NHIMG editorial — based on content published by Expel: a SmartBrief interview of CSO Greg Notch at RSAC 2026 on AI-speed attacks and agentic AI risk

By the numbers:

Questions worth separating out

Q: How should security teams reduce the damage from AI-assisted attacks that move in minutes?

A: They should treat access containment as the primary response objective.

Q: Why do non-human identities become a bigger risk in AI-speed attacks?

A: Because NHIs often provide the shortest route from discovery to real access.

Q: What breaks when detection relies on static rules during AI-driven intrusion?

A: Static rules miss attacks that are generated, adapted, or recombined in real time.

Practitioner guidance

  • Shorten the exploit-to-containment window Create response playbooks that assume AI-assisted exploitation may happen within minutes, then pre-stage isolation, revocation, and escalation steps for internet-facing assets and privileged identities.
  • Inventory and constrain non-human identities Build a complete inventory of service accounts, API keys, tokens, and OAuth grants, then map each to ownership, business purpose, and minimum access.
  • Invest in environment-specific detection engineering Tune detections to your own identity and network patterns so AI-generated attacks do not blend into generic baseline noise.

What's in the full article

Expel's full analysis covers the operational detail this post intentionally leaves for the source:

  • How Expel recommends tuning detection engineering for AI-generated attack patterns in real environments
  • The practical distinctions between MDR and managed SIEM for teams facing AI-speed threats
  • Why identity and data governance are treated as the first containment layer for non-human identities
  • What Expel sees as the main gaps in current security operations when AI compresses attack timelines

👉 Read Expel's analysis of AI-speed attacks, agentic AI, and identity risk →

AI-speed attacks and NHI risk: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

AI-speed compromise has turned exposure management into a real-time identity problem. The central shift in this article is not that exploits exist, but that their creation and use can now be compressed into a timeframe that outpaces manual defence. That changes the governance burden on IAM, PAM, and NHI teams because access and remediation are no longer separate workflows. Practitioners should treat exploitability, identity reach, and response speed as one control surface.

A question worth separating out:

Q: Who is accountable when privileged access compromises AI infrastructure?

A: Accountability should sit with the team that owns the privilege path, not only the team that owns the workload. In practice, that means infrastructure, platform, IAM, and application teams need shared ownership for elevated access, secrets, and session logging. Without that, review becomes fragmented and no one can explain how access was granted or retained.

👉 Read our full editorial: AI-speed attacks are collapsing patch windows and identity controls



   
ReplyQuote
Share: