TL;DR: Hybrid identity risk now spans Active Directory, cloud, credentials, NHIs and AI agents, creating attack paths that siloed tools miss because they do not map how exposures connect across environments, according to XM Cyber. The core issue is not isolated misconfigurations but linked identity pathways that let attackers move from one weak point to the next.
NHIMG editorial — based on content published by XM Cyber: identity exposure management for hybrid, cloud and AI accounts
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface.
Questions worth separating out
Q: How should security teams reduce risk in hybrid authentication environments?
A: They should treat the remaining password estate as the main control surface, not a temporary leftover.
Q: Why do AI agents make non-human identity governance harder?
A: AI agents make governance harder because they can request tools, act autonomously, and change behaviour across sessions while still relying on machine credentials.
Q: What breaks when identity tools only cover one side of a hybrid environment?
A: Attackers exploit the seam.
Practitioner guidance
- Map identity attack paths across all environments Build a view that links directory access, cloud permissions, cached credentials and workload identities so remediation targets reachable paths rather than isolated findings.
- Inventory unmanaged non-human identities and AI agents Require ownership, purpose, permissions and lifecycle status for every service account, API token, automated workflow and AI-driven identity before granting production access.
- Prioritise credential reuse and cache exposure Find reused passwords, cached credentials on endpoints and tokens stored outside approved secrets management so you can remove the easiest on-ramps first.
What's in the full article
XM Cyber's full analysis covers the operational detail this post intentionally leaves for the source:
- The exposure-mapping workflow used to connect identity findings into validated attack paths across hybrid environments
- The cross-environment detection logic for spotting when Active Directory, cloud and workload identities combine into one route
- The prioritisation model for deciding which identity weaknesses to fix first based on exploitability and business impact
- The practical remediation context for teams responsible for directory, cloud and workload identity changes
👉 Read XM Cyber's analysis of hybrid identity exposure and attack paths →
Identity exposure across hybrid environments: are your controls keeping up?
Explore further
Identity exposure is now a path problem, not a point problem. Security teams still talk about compromised credentials, misconfigurations and unreviewed accounts as separate issues, but attackers only need them to connect. Once identity relationships span Active Directory, cloud, endpoints and workloads, the real risk is the route they form, not the individual exposure. That means the governance unit has shifted from the account to the attack path, and practitioners should treat reachability as the primary identity control objective.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
A question worth separating out:
Q: Who is accountable when an unmanaged AI agent or service account creates exposure?
A: Accountability should sit with the owner of the identity and the team that approved its access, not with security alone. If the identity has no owner, that is a governance failure. Organisations need explicit lifecycle ownership, review and deprovisioning responsibilities for every non-human identity and AI-driven workflow.
👉 Read our full editorial: Identity exposure management for hybrid, cloud and AI accounts