Join our Newsletter — 33% off our NHI Course

Identity, trust and governance: what IAM teams need to rebuild

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: C1.ai argues that the CIA triad protects data but not the actors now driving most breaches, citing 74% of attacks starting with compromised identities, 79% of detections being malware-free, and 88% of web application breaches involving stolen credentials. Security now depends on identity, trust, and governance as the control plane above the data plane.

Editorial analysis by NHI Mgmt Group, based on content published by C1.ai: “Security Needs a Second Floor”.

By the numbers:

Key questions

Q: How should security teams govern identity as a control plane?

A: Security teams should treat identity as the layer that decides who can act, how far authority travels, and what context makes an action legitimate.

Q: Why do stolen credentials and compromised identities create more risk than classic perimeter failures?

A: Because most modern attacks exploit the actor, not the data store.

Q: What breaks when access review does not cover non-human identities used by AI agents?

A: When access review ignores the NHIs behind AI agents, organisations lose visibility into stale privileges, inherited rights, and abandoned credentials that still allow action.

Practitioner guidance

  • Map your control plane Inventory which actor types you govern today, including humans, service identities, workloads, and AI agents, then identify where access decisions are still being made with data-centric controls only.
  • Trace delegated authority end to end Document how authority moves from a human sponsor to workloads, APIs, and any agentic sub-processes so you can see where inherited trust expands beyond intended scope.
  • Move access decisions to issuance time Use machine-readable policy and continuous authorisation where actors can act, delegate, or expire faster than quarterly review cycles can capture.

Bottom line: The article reframes modern security as an actor-governance problem, not only a data-protection problem.

What's in the full article

C1.ai's full blog covers the argument and evidence this post intentionally leaves in summary form:

  • The full control-plane framing that links identity, trust, and governance to Zero Trust and policy-as-code
  • The infrastructure-era comparison table showing how security responsibility moved from physical servers to agentic systems
  • The article's discussion of delegation chains, sub-agents, and machine-speed authority in AI environments
  • The market and standards references that support the case for a second-floor security model

👉 Read C1.ai's analysis of identity, trust and governance as security's second floor →

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 2 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 20909
 

Identity, trust, and governance are not additive controls to CIA, they are the layer that decides whether CIA can still be meaningful in modern environments. The article is right to reject the idea that data properties alone can govern actor behaviour. Once the environment includes workloads, service identities, and autonomous systems, the decisive risk is no longer just data exposure but uncontrolled authority. Practitioners should treat the control plane as the primary governance problem, not a sidecar to protection.

A question worth separating out:

Q: How do IAM, PAM, and NHI governance differ from data security controls?

A: IAM, PAM, and NHI governance answer who or what is allowed to act, under what trust conditions, and with what scope. Data security controls answer how the information is protected once that decision has already been made, so the two layers serve different purposes and must be managed separately.

👉 Read our full editorial: Identity, trust and governance are the second floor of security


This post was modified 2 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.