TL;DR: C1.ai argues that the CIA triad protects data but not the actors now driving most breaches, citing 74% of attacks starting with compromised identities, 79% of detections being malware-free, and 88% of web application breaches involving stolen credentials. Security now depends on identity, trust, and governance as the control plane above the data plane.
Editorial analysis by NHI Mgmt Group, based on content published by C1.ai: “Security Needs a Second Floor”.
By the numbers:
- 74% of attacks start with compromised identities, according to C1.ai.
- 79% of cyberattack detections are malware-free, according to C1.ai.
- 88% of web application breaches involve stolen credentials, according to C1.ai.
Key questions
Q: How should security teams govern identity as a control plane?
A: Security teams should treat identity as the layer that decides who can act, how far authority travels, and what context makes an action legitimate.
A: Because most modern attacks exploit the actor, not the data store.
Q: What breaks when access review does not cover non-human identities used by AI agents?
A: When access review ignores the NHIs behind AI agents, organisations lose visibility into stale privileges, inherited rights, and abandoned credentials that still allow action.
Practitioner guidance
- Map your control plane Inventory which actor types you govern today, including humans, service identities, workloads, and AI agents, then identify where access decisions are still being made with data-centric controls only.
- Trace delegated authority end to end Document how authority moves from a human sponsor to workloads, APIs, and any agentic sub-processes so you can see where inherited trust expands beyond intended scope.
- Move access decisions to issuance time Use machine-readable policy and continuous authorisation where actors can act, delegate, or expire faster than quarterly review cycles can capture.
Bottom line: The article reframes modern security as an actor-governance problem, not only a data-protection problem.
What's in the full article
C1.ai's full blog covers the argument and evidence this post intentionally leaves in summary form:
- The full control-plane framing that links identity, trust, and governance to Zero Trust and policy-as-code
- The infrastructure-era comparison table showing how security responsibility moved from physical servers to agentic systems
- The article's discussion of delegation chains, sub-agents, and machine-speed authority in AI environments
- The market and standards references that support the case for a second-floor security model
👉 Read C1.ai's analysis of identity, trust and governance as security's second floor →
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Identity, trust, and governance are not additive controls to CIA, they are the layer that decides whether CIA can still be meaningful in modern environments. The article is right to reject the idea that data properties alone can govern actor behaviour. Once the environment includes workloads, service identities, and autonomous systems, the decisive risk is no longer just data exposure but uncontrolled authority. Practitioners should treat the control plane as the primary governance problem, not a sidecar to protection.
A question worth separating out:
Q: How do IAM, PAM, and NHI governance differ from data security controls?
A: IAM, PAM, and NHI governance answer who or what is allowed to act, under what trust conditions, and with what scope. Data security controls answer how the information is protected once that decision has already been made, so the two layers serve different purposes and must be managed separately.
👉 Read our full editorial: Identity, trust and governance are the second floor of security