TL;DR: Emerging technologies such as AI, IoT, cloud, blockchain and quantum computing expand the attack surface while also giving attackers new ways to bypass verification, exploit weak access controls and abuse misconfigurations, according to INTIGRITI. For identity and security teams, the key issue is not innovation itself but whether access, authentication and monitoring keep pace with new runtime risk.
NHIMG editorial — based on content published by INTIGRITI: The cyber threat landscape part 4, emerging technologies and their security implications
By the numbers:
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.
- Only 5.7% of organisations have full visibility into their service accounts.
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface.
Questions worth separating out
Q: How should security teams handle identity risk when legacy infrastructure and AI threats collide?
A: They should treat this as a single governance programme with two time horizons.
Q: Why do AI systems complicate zero trust assumptions?
A: AI systems complicate zero trust because they can act continuously, reuse credentials across sessions, and operate with delegated access that outlives the original request.
Q: What do organisations get wrong about biometric authentication and deepfakes?
A: They often assume a biometric match proves that a live human is present.
Practitioner guidance
- Map new technology to identity controls Create a control matrix for AI, IoT and cloud services that identifies the human and non-human identities in scope, then assign authentication, authorization and audit requirements for each.
- Harden verification for impersonation risk Add step-up checks, out-of-band approval and exception review for executive requests, finance actions and helpdesk resets that could be targeted by deepfake or social engineering attacks.
- Review cloud and IoT access for over-permission Inventory service accounts, device credentials and API tokens connected to cloud and IoT environments, then remove standing privilege and enforce least privilege at the point of use.
What's in the full article
INTIGRITI's full article covers the operational detail this post intentionally leaves for the source:
- Examples of AI-enabled phishing, deepfake impersonation and adaptive malware that expand the attacker toolkit.
- Cloud and IoT control recommendations for patching, segmentation, authentication and misconfiguration monitoring.
- Blockchain threat examples including smart contract flaws, 51% attacks and privacy exposure.
- Long-horizon quantum risk discussion for encryption planning and cryptographic transition readiness.
👉 Read INTIGRITI's analysis of emerging technologies and their security implications →
Emerging technologies and the governance gap security teams are missing?
Explore further
Emerging technology risk is increasingly an identity governance problem. AI, cloud and IoT introduce more machine identities, more delegated access and more opportunities for trust to be assumed rather than verified. When verification and authorization do not scale with the technology footprint, the result is not just broader attack surface but weaker governance over who or what can act. The practitioner conclusion is simple: modern security programmes need identity controls that understand runtime behaviour, not just login events.
A question worth separating out:
Q: How do teams reduce risk from machine identities in cloud environments?
A: Start with inventory, because you cannot govern what you cannot see. Then remove default credentials, shorten token lifetimes, restrict privileges to the task at hand and monitor for unusual use patterns. Machine identities should be treated as production assets with owners, scope limits and lifecycle controls.
👉 Read our full editorial: Emerging technologies widen attack surfaces across AI, cloud and IoT