<?xml version="1.0" encoding="UTF-8"?>        <rss version="2.0"
             xmlns:atom="http://www.w3.org/2005/Atom"
             xmlns:dc="http://purl.org/dc/elements/1.1/"
             xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
             xmlns:admin="http://webns.net/mvcb/"
             xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
             xmlns:content="http://purl.org/rss/1.0/modules/content/">
        <channel>
            <title>
									General NHI, AI &amp; IAM Discussions - NHIMG Forum				            </title>
            <link>https://nhimg.org/community/non-human-identity-management-general-discussions/</link>
            <description>NHIMG Discussion Board</description>
            <language>en-US</language>
            <lastBuildDate>Tue, 09 Jun 2026 19:09:26 +0000</lastBuildDate>
            <generator>wpForo</generator>
            <ttl>60</ttl>
							                    <item>
                        <title>Women in IT in 2026: where the talent gap and culture gap still collide</title>
                        <link>https://nhimg.org/community/non-human-identity-management-general-discussions/women-in-it-in-2026-where-the-talent-gap-and-culture-gap-still-collide/</link>
                        <pubDate>Mon, 08 Jun 2026 16:46:35 +0000</pubDate>
                        <description><![CDATA[TL;DR: Women remain underrepresented in IT even as demand surges, with Gartner citing 31% female representation in IT roles and the U.S. Bureau of Labor Statistics projecting 667,600 new com...]]></description>
                        <content:encoded><![CDATA[<blockquote>
<p><strong>TL;DR:</strong> Women remain underrepresented in IT even as demand surges, with Gartner citing 31% female representation in IT roles and the U.S. Bureau of Labor Statistics projecting 667,600 new computer and IT jobs through 2030. The opportunity is real, but access to it still depends on culture, support, and sustained skill-building.</p>
</blockquote>
<p><em>NHIMG editorial — based on content published by StrongDM: How to Thrive as a Woman in IT: A Comprehensive Guide in 2026</em></p>
<p><strong>By the numbers:</strong></p>
<ul>
<li>According to Gartner, only <a href="https://www.strongdm.com/blog/guide-for-women-to-thrive-in-information-technology?utm_source=nhimg&amp;utm_medium=NHIForum">31% of IT employees are women</a>.</li>
<li>The U.S. Bureau of Labor Statistics says computer and information technology jobs are expected to grow by 13 percent from 2020 to 2030, adding <a href="https://www.strongdm.com/blog/guide-for-women-to-thrive-in-information-technology?utm_source=nhimg&amp;utm_medium=NHIForum">667,600 new jobs</a>.</li>
</ul>
<h2>Questions worth separating out</h2>
<p><strong>Q: How can organisations improve representation of women in IT teams?</strong></p>
<p><strong>A:</strong> Organisations improve representation by fixing both entry and retention.</p>
<p><strong>Q: Why does workplace culture matter so much in technical careers?</strong></p>
<p><strong>A:</strong> Workplace culture shapes whether people stay long enough to build depth.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-is-the-best-way-to-bring-more-women-into-cybersecurity/?utm_source=nhimg&amp;utm_medium=NHIForum">What is the best way to bring more women into cybersecurity?</a></strong></p>
<p><strong>A:</strong> The most effective approach is to treat cybersecurity as a broad career family rather than a single narrow path.</p>
<h2>Practitioner guidance</h2>
<ul>
<li><strong>Audit hiring and promotion pathways for hidden exclusion</strong> Review job descriptions, interview loops, <a href="https://nhimg.org/top-10-non-human-identity-issues?utm_source=nhimg&amp;utm_medium=NHIForum">promotion criteria</a>, and referral patterns for signals that narrow the candidate pool or advantage one profile repeatedly.</li>
<li><strong>Strengthen workplace reporting and response mechanisms</strong> Make harassment and discrimination reporting usable, confidential, and fast to act on so technical staff do not have to choose between safety and career progression.</li>
<li><strong>Create multiple entry routes into security work</strong> Offer internships, rotational roles, apprenticeships, and adjacent-role transitions so support, analysis, and operations staff can move into IAM and security careers.</li>
</ul>
<h2>What's in the full article</h2>
<p>StrongDM's full blog covers the practical career guidance this post intentionally leaves at the strategy level:</p>
<ul>
<li>Role-by-role examples of IT careers women can pursue, from support to architecture and security</li>
<li>Named training and education resources for building technical skills and confidence</li>
<li>Advice from multiple contributors on handling workplace bias, growth, and career progression</li>
<li>Examples of how to choose a role that fits different learning styles and work preferences</li>
</ul>
<p>&#x1f449; <strong><a href="https://www.strongdm.com/blog/guide-for-women-to-thrive-in-information-technology?utm_source=nhimg&amp;utm_medium=NHIForum">Read StrongDM's guide to women thriving in IT careers →</a></strong></p>
<p><em>Women in IT in 2026: where the talent gap and culture gap still collide?</em></p>
<blockquote>
<p><strong>Explore further</strong></p>
<p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a>  |  <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p>
</blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/non-human-identity-management-general-discussions/">General NHI, AI &amp; IAM Discussions</category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/non-human-identity-management-general-discussions/women-in-it-in-2026-where-the-talent-gap-and-culture-gap-still-collide/</guid>
                    </item>
				                    <item>
                        <title>AI governance gaps are widening as policy outpaces controls</title>
                        <link>https://nhimg.org/community/non-human-identity-management-general-discussions/ai-governance-gaps-are-widening-as-policy-outpaces-controls/</link>
                        <pubDate>Mon, 08 Jun 2026 16:20:30 +0000</pubDate>
                        <description><![CDATA[TL;DR: The White House’s AI Action Plan pushes faster AI adoption, infrastructure build-out, and secure-by-design expectations, but the article argues that governance will increasingly fall ...]]></description>
                        <content:encoded><![CDATA[<blockquote>
<p><strong>TL;DR:</strong> The White House’s AI Action Plan pushes faster AI adoption, infrastructure build-out, and secure-by-design expectations, but the article argues that governance will increasingly fall to industry as federal guardrails loosen and questions about training data, bias, and sensitive-data use remain unresolved, according to Cyera. The practical issue is not ambition but whether organisations can prove their AI data, model, and agent controls are trustworthy enough to absorb the policy shift.</p>
</blockquote>
<p><em>NHIMG editorial — based on content published by Cyera: It’s Up to Industry to Regulate AI: The White House’s AI Action Plan is long on ambition, but short on guardrails</em></p>
<p><strong>By the numbers:</strong></p>
<ul>
<li>The Plan cuts federal science funding by <a href="https://www.cyera.com/blog/its-up-to-industry-to-regulate-ai-the-white-houses-ai-action-plan-is-long-on-ambition-but-short-on-guardrails?utm_source=nhimg&amp;utm_medium=NHIForum">34 percent, including math and physics</a> at $289 million, engineering at $127 million, computer science at $85 million, and technology at $18 million.</li>
</ul>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-organisations-govern-access-to-data-used-by-ai-systems/?utm_source=nhimg&amp;utm_medium=NHIForum">How should organisations govern AI systems that can access sensitive training data?</a></strong></p>
<p><strong>A:</strong> Organisations should treat sensitive training data as a governed input, not a loose repository.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/why-do-ai-agents-create-new-access-risk-for-enterprises/?utm_source=nhimg&amp;utm_medium=NHIForum">Why do AI applications and agents create new access risks for IAM teams?</a></strong></p>
<p><strong>A:</strong> AI applications and agents can request data, call tools, and move information across systems faster than traditional review cycles were designed to track.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-do-security-teams-get-wrong-about-secure-by-design-ai-governance/?utm_source=nhimg&amp;utm_medium=NHIForum">What do security teams get wrong about secure-by-design AI governance?</a></strong></p>
<p><strong>A:</strong> They often treat secure-by-design as a policy label instead of an enforceable operating model.</p>
<h2>Practitioner guidance</h2>
<ul>
<li><strong>Inventory AI-connected identities and data paths</strong> Map every <a href="https://nhimg.org/complete-guide-to-the-2026-owasp-top-10-risks-for-agentic-applications?utm_source=nhimg&amp;utm_medium=NHIForum">AI application, agent, service account</a>, and API key that can touch training, retrieval, or output workflows.</li>
<li><strong>Gate sensitive data before model ingestion</strong> Require classification and <a href="https://nhimg.org/top-10-non-human-identity-issues?utm_source=nhimg&amp;utm_medium=NHIForum">policy checks at the point</a> where training data, fine-tuning data, or retrieval content enters the AI pipeline.</li>
<li><strong>Apply least privilege to AI tool use</strong> Limit every AI-connected identity to the <a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum#key-challenges-and-risks">smallest set of tools</a>, prompts, datasets, and export paths needed for its task.</li>
</ul>
<h2>What's in the full article</h2>
<p>Cyera's full analysis covers the operational detail this post intentionally leaves for the source:</p>
<ul>
<li>The article’s specific commentary on the White House AI Action Plan and the policy trade-offs it introduces for enterprises.</li>
<li>Cyera's description of how its AI-native platform discovers and classifies sensitive data in AI training sets and AI applications.</li>
<li>The article’s examples of bias, training-data curation, and the governance challenge of defining objective truth in practice.</li>
<li>The source article’s closing guidance on how organisations should think about secure AI adoption at scale.</li>
</ul>
<p>&#x1f449; <strong><a href="https://www.cyera.com/blog/its-up-to-industry-to-regulate-ai-the-white-houses-ai-action-plan-is-long-on-ambition-but-short-on-guardrails?utm_source=nhimg&amp;utm_medium=NHIForum">Read Cyera’s analysis of the White House AI Action Plan and AI governance →</a></strong></p>
<p><em>AI governance gaps are widening as policy outpaces controls?</em></p>
<blockquote>
<p><strong>Explore further</strong></p>
<p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a>  |  <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p>
</blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/non-human-identity-management-general-discussions/">General NHI, AI &amp; IAM Discussions</category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/non-human-identity-management-general-discussions/ai-governance-gaps-are-widening-as-policy-outpaces-controls/</guid>
                    </item>
				                    <item>
                        <title>AI agent governance is lagging engineering teams’ rapid shift</title>
                        <link>https://nhimg.org/community/non-human-identity-management-general-discussions/ai-agent-governance-is-lagging-engineering-teams-rapid-shift/</link>
                        <pubDate>Sun, 07 Jun 2026 21:01:42 +0000</pubDate>
                        <description><![CDATA[TL;DR: Engineering leaders at Enterprise Ready Conference 2025 described AI as moving junior engineers, product managers, and interns into much more capable roles while exposing non-determin...]]></description>
                        <content:encoded><![CDATA[<blockquote>
<p><strong>TL;DR:</strong> Engineering leaders at Enterprise Ready Conference 2025 described AI as moving junior engineers, product managers, and interns into much more capable roles while exposing non-deterministic output, customer-facing risk, and human oversight gaps, according to WorkOS. The governance lesson is that identity, accountability, and guardrails now matter as much as speed when AI enters delivery paths.</p>
</blockquote>
<p><em>NHIMG editorial — based on content published by WorkOS: CTO panel on how AI is transforming engineering teams</em></p>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-security-teams-govern-ai-generated-code-in-production-environments/?utm_source=nhimg&amp;utm_medium=NHIForum">How should security teams govern AI tools that help write and review code?</a></strong></p>
<p><strong>A:</strong> Treat AI-assisted development as an identity and control problem, not only an engineering productivity issue.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/why-do-ai-assisted-engineering-workflows-complicate-identity-governance/?utm_source=nhimg&amp;utm_medium=NHIForum">Why do AI-assisted engineering workflows complicate identity governance?</a></strong></p>
<p><strong>A:</strong> Because they extend access beyond a single human user into tools that can read context, draft changes, and shape operational decisions.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-do-teams-get-wrong-about-ai-generated-documentation-and-code-review/?utm_source=nhimg&amp;utm_medium=NHIForum">What do teams get wrong about AI-generated documentation and code review?</a></strong></p>
<p><strong>A:</strong> They often assume documentation or review output is proof of oversight.</p>
<h2>Practitioner guidance</h2>
<ul>
<li><strong>Classify every AI-enabled workflow by actor type</strong> Separate human-assisted tooling from non-human identity use cases and from systems that make independent runtime decisions.</li>
<li><strong>Preserve independent review for production-impacting changes</strong> Do not allow the same AI layer to generate and effectively validate the same change without independent human challenge.</li>
<li><strong>Map delegated data access for AI tools</strong> Identify which repositories, tickets, logs, and operational systems AI tools can read or influence.</li>
</ul>
<h2>What's in the full article</h2>
<p>WorkOS's full recap covers the operational detail this post intentionally leaves for the source:</p>
<ul>
<li>Panel commentary on how enterprise customers are evaluating AI guardrails for customer-facing deployments</li>
<li>Examples of how engineering leaders are using AI tools to accelerate coding, migrations, and documentation</li>
<li>Details on the forward deployed engineering motion and why it is resurfacing in AI-native products</li>
<li>The panel's full discussion of how teams are thinking about scale, quality, and customer value in AI-heavy environments</li>
</ul>
<p>&#x1f449; <strong><a href="https://workos.com/blog/cto-panel-ai-transforming-engineering-teams?utm_source=nhimg&amp;utm_medium=NHIForum">Read WorkOS's recap of the Enterprise Ready Conference 2025 CTO panel on AI in engineering →</a></strong></p>
<p><em>AI agent governance is lagging engineering teams’ rapid shift?</em></p>
<blockquote>
<p><strong>Explore further</strong></p>
<p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a>  |  <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p>
</blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/non-human-identity-management-general-discussions/">General NHI, AI &amp; IAM Discussions</category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/non-human-identity-management-general-discussions/ai-agent-governance-is-lagging-engineering-teams-rapid-shift/</guid>
                    </item>
				                    <item>
                        <title>AI startup compounding and enterprise identity readiness: what changes?</title>
                        <link>https://nhimg.org/community/non-human-identity-management-general-discussions/ai-startup-compounding-and-enterprise-identity-readiness-what-changes/</link>
                        <pubDate>Sun, 07 Jun 2026 20:22:56 +0000</pubDate>
                        <description><![CDATA[TL;DR: AI adoption is pulling enterprise buying cycles forward so quickly that startups are landing customers in months, not years, according to WorkOS’s conversation with the hosts of Acqui...]]></description>
                        <content:encoded><![CDATA[<blockquote>
<p><strong>TL;DR:</strong> AI adoption is pulling enterprise buying cycles forward so quickly that startups are landing customers in months, not years, according to WorkOS’s conversation with the hosts of Acquired. That acceleration changes the identity baseline: enterprise readiness, access governance, and trust assumptions now have to exist earlier in the product lifecycle.</p>
</blockquote>
<p><em>NHIMG editorial — based on content published by WorkOS: Ben Gilbert and David Rosenthal from Acquired on what makes companies last</em></p>
<p><strong>By the numbers:</strong></p>
<ul>
<li>This year they stopped by the WorkOS booth at re:Invent before interviewing the CEOs of AWS, JP Morgan Payments, Netflix, and Perplexity in a <a href="https://workos.com/blog/acquired-podcast-what-makes-companies-last?utm_source=nhimg&amp;utm_medium=NHIForum">2,000-person auditorium</a>.</li>
</ul>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-teams-evaluate-ai-era-vendors-before-granting-enterprise-access/?utm_source=nhimg&amp;utm_medium=NHIForum">How should teams evaluate AI-era vendors before granting enterprise access?</a></strong></p>
<p><strong>A:</strong> Treat evaluation as an identity assurance exercise, not just a product review.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/why-do-fast-growing-ai-companies-create-new-iam-risk-for-enterprises/?utm_source=nhimg&amp;utm_medium=NHIForum">Why do fast-growing AI companies create new IAM risk for enterprises?</a></strong></p>
<p><strong>A:</strong> Because growth usually outpaces governance.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-breaks-when-ai-adoption-outpaces-governance/?utm_source=nhimg&amp;utm_medium=NHIForum">What breaks when access governance is added after AI adoption has already scaled?</a></strong></p>
<p><strong>A:</strong> Review cycles become reactive instead of preventative.</p>
<h2>Practitioner guidance</h2>
<ul>
<li><strong>Add identity readiness to vendor intake</strong> Require an <a href="https://nhimg.org/52-non-human-identity-breaches?utm_source=nhimg&amp;utm_medium=NHIForum">access model review</a> for any AI-era vendor before production integration.</li>
<li><strong>Map delegated access before rollout</strong> Document every <a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum">delegated permission</a>, token exchange, and machine-to-machine trust path introduced by the new system.</li>
<li><strong>Shorten entitlement review cycles for fast-moving platforms</strong> Increase <a href="https://nhimg.org/nhi-lifecycle-management-guide?utm_source=nhimg&amp;utm_medium=NHIForum">recertification frequency</a> for platforms that are still changing features, integrations, or ownership structures.</li>
</ul>
<h2>What's in the full article</h2>
<p>WorkOS's full article covers the conversational context and company journey details this post intentionally leaves for the source:</p>
<ul>
<li>How Ben Gilbert and David Rosenthal describe compounding growth and why that framing matters for enterprise adoption decisions.</li>
<li>The specific examples they use from Nvidia, Costco, Google, and other durable companies to explain how category leaders behave.</li>
<li>Why AI companies are reaching enterprise customers earlier than previous generations of startups, and what that means for go-to-market timing.</li>
<li>The broader interview context from AWS re:Invent 2025, including why WorkOS was discussing enterprise readiness in this setting.</li>
</ul>
<p>&#x1f449; <strong><a href="https://workos.com/blog/acquired-podcast-what-makes-companies-last?utm_source=nhimg&amp;utm_medium=NHIForum">Read WorkOS's conversation on AI-era compounding and enterprise readiness →</a></strong></p>
<p><em>AI startup compounding and enterprise identity readiness: what changes?</em></p>
<blockquote>
<p><strong>Explore further</strong></p>
<p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a>  |  <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p>
</blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/non-human-identity-management-general-discussions/">General NHI, AI &amp; IAM Discussions</category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/non-human-identity-management-general-discussions/ai-startup-compounding-and-enterprise-identity-readiness-what-changes/</guid>
                    </item>
				                    <item>
                        <title>Engineering leadership at WorkOS: what it means for IAM teams</title>
                        <link>https://nhimg.org/community/non-human-identity-management-general-discussions/engineering-leadership-at-workos-what-it-means-for-iam-teams/</link>
                        <pubDate>Sun, 07 Jun 2026 20:22:16 +0000</pubDate>
                        <description><![CDATA[TL;DR: Engineering leadership models where managers own product areas end to end, stay close to customers and code, and guide reliability, security, and architecture decisions as companies s...]]></description>
                        <content:encoded><![CDATA[<blockquote>
<p><strong>TL;DR:</strong> Engineering leadership models where managers own product areas end to end, stay close to customers and code, and guide reliability, security, and architecture decisions as companies scale, according to WorkOS. That kind of operating model matters because identity and access programmes increasingly need engineering-led governance, not handoffs.</p>
</blockquote>
<p><em>NHIMG editorial — based on content published by WorkOS: Engineering leadership at WorkOS: Product, people, and impact</em></p>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-security-teams-handle-identity-features-built-inside-product-engineer/?utm_source=nhimg&amp;utm_medium=NHIForum">How should security teams handle identity features built inside product engineering teams?</a></strong></p>
<p><strong>A:</strong> Treat the engineering team as part of the control environment, not as a separate delivery function.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/why-do-developer-experience-and-identity-governance-need-to-be-designed-together/?utm_source=nhimg&amp;utm_medium=NHIForum">Why do developer experience and identity governance need to be designed together?</a></strong></p>
<p><strong>A:</strong> Because developers will choose the fastest workable path, not the most policy-compliant one.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-breaks-when-access-related-decisions-are-made-without-explicit-review-gates/?utm_source=nhimg&amp;utm_medium=NHIForum">What breaks when access-related decisions are made without explicit review gates?</a></strong></p>
<p><strong>A:</strong> The organisation loses the ability to prove who approved what, why the tradeoff was accepted, and how the change will be supported after launch.</p>
<h2>Practitioner guidance</h2>
<ul>
<li><strong>Map identity feature ownership to governance ownership</strong> Identify which engineering leaders own SSO, RBAC, directory sync, secrets handling, and related access surfaces.</li>
<li><strong>Add explicit architecture review gates for access-related changes</strong> For any change that affects authentication, authorisation, or lifecycle behaviour, require a documented review trail that covers threat assumptions, rollback paths, and operational support.</li>
<li><strong>Test whether developer experience encourages unsafe workarounds</strong> Review integration patterns for hardcoded secrets, bypassed approvals, duplicated access logic, or manual provisioning steps.</li>
</ul>
<h2>What's in the full article</h2>
<p>WorkOS's full article covers the organisational detail this post intentionally leaves for the source:</p>
<ul>
<li>The specific responsibilities WorkOS assigns to engineering managers across product, architecture, and team health</li>
<li>How the company structures weekly decision-making between managers and the CEO</li>
<li>The cultural expectations WorkOS uses to evaluate engineering leaders in a product engineering organisation</li>
<li>How the leadership model is expected to evolve as headcount and AI infrastructure work expand</li>
</ul>
<p>&#x1f449; <strong><a href="https://workos.com/blog/engineering-leadership-at-workos-product-people-and-impact?utm_source=nhimg&amp;utm_medium=NHIForum">Read WorkOS's analysis of engineering leadership in a product engineering model →</a></strong></p>
<p><em>Engineering leadership at WorkOS: what it means for IAM teams?</em></p>
<blockquote>
<p><strong>Explore further</strong></p>
<p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a>  |  <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p>
</blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/non-human-identity-management-general-discussions/">General NHI, AI &amp; IAM Discussions</category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/non-human-identity-management-general-discussions/engineering-leadership-at-workos-what-it-means-for-iam-teams/</guid>
                    </item>
				                    <item>
                        <title>Cybersecurity state of the industry report: what teams should benchmark</title>
                        <link>https://nhimg.org/community/non-human-identity-management-general-discussions/cybersecurity-state-of-the-industry-report-what-teams-should-benchmark/</link>
                        <pubDate>Sun, 07 Jun 2026 20:13:40 +0000</pubDate>
                        <description><![CDATA[TL;DR: Cyber Security Tribe’s 2025 annual state of the industry report compares 350-plus cybersecurity professionals’ responses across people, process, and technology, giving practitioners a...]]></description>
                        <content:encoded><![CDATA[<blockquote>
<p><strong>TL;DR:</strong> Cyber Security Tribe’s 2025 annual state of the industry report compares 350-plus cybersecurity professionals’ responses across people, process, and technology, giving practitioners a benchmark for priorities and maturity shifts from 2024 into 2026. The report is most useful as a programme calibration tool, not a vendor scorecard.</p>
</blockquote>
<p><em>NHIMG editorial — based on content published by Cyera: Cyber Security Tribe's 2025 Annual State of the Industry Report</em></p>
<p><strong>By the numbers:</strong></p>
<ul>
<li>The survey gathered responses from <a href="https://www.cyera.com/reports/cyber-security-tribes-2025-annual-state-of-the-industry-report?utm_source=nhimg&amp;utm_medium=NHIForum">over 350 cybersecurity professionals</a>.</li>
<li>The survey was conducted between <a href="https://www.cyera.com/reports/cyber-security-tribes-2025-annual-state-of-the-industry-report?utm_source=nhimg&amp;utm_medium=NHIForum">December 2024 and January 2025</a>.</li>
</ul>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-teams-use-cybersecurity-benchmark-reports-in-identity-governance-plan/?utm_source=nhimg&amp;utm_medium=NHIForum">How should teams use cybersecurity benchmark reports in identity governance planning?</a></strong></p>
<p><strong>A:</strong> Use them to compare your programme’s operating assumptions with peer priorities, then check whether the gaps are in people, process, or technology.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-does-a-people-process-and-technology-model-miss-in-nhi-governance/?utm_source=nhimg&amp;utm_medium=NHIForum">What does a people, process, and technology model miss in NHI governance?</a></strong></p>
<p><strong>A:</strong> It misses whether the identity subject is actually the same across controls.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/how-can-security-leaders-tell-if-their-identity-programme-is-over-focused-on-too/?utm_source=nhimg&amp;utm_medium=NHIForum">How can security leaders tell if their identity programme is over-focused on tooling?</a></strong></p>
<p><strong>A:</strong> If reporting tracks product deployment more closely than access ownership, exception closure, and lifecycle review, the programme is likely over-focused on tooling.</p>
<h2>Practitioner guidance</h2>
<ul>
<li><strong>Re-baseline identity governance against all three operating dimensions</strong> Map current controls to <a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum">people, process, and technology</a> and identify where human IAM coverage does not extend cleanly to service accounts, API keys, tokens, and AI-driven access paths.</li>
<li><strong>Separate human and non-human benchmarks in reporting</strong> Track <a href="https://nhimg.org/nhi-lifecycle-management-guide?utm_source=nhimg&amp;utm_medium=NHIForum">visibility, ownership, lifecycle</a>, and exception handling for NHIs separately from human access review metrics so that one group’s maturity does not hide the other’s gaps.</li>
<li><strong>Use the report as a roadmap checkpoint</strong> Compare your current 2025 and 2026 priorities against peer benchmarks to see whether remediation work is still centred on tooling when operating-model change is the real constraint.</li>
</ul>
<h2>What's in the full report</h2>
<p>Cyera's full report covers the survey detail this post intentionally leaves for the source:</p>
<ul>
<li>The year-over-year survey comparisons across people, process, and technology that let you benchmark your own programme.</li>
<li>The expert commentary sections that explain how practitioners are interpreting the 2025 priorities.</li>
<li>The full response breakdown from more than 350 cybersecurity professionals for deeper peer comparison.</li>
<li>The report framing for using the benchmarks as a planning tool through 2026.</li>
</ul>
<p>&#x1f449; <strong><a href="https://www.cyera.com/reports/cyber-security-tribes-2025-annual-state-of-the-industry-report?utm_source=nhimg&amp;utm_medium=NHIForum">Read Cyera's state of the industry report for cybersecurity benchmarks and trends →</a></strong></p>
<p><em>Cybersecurity state of the industry report: what teams should benchmark?</em></p>
<blockquote>
<p><strong>Explore further</strong></p>
<p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a>  |  <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p>
</blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/non-human-identity-management-general-discussions/">General NHI, AI &amp; IAM Discussions</category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/non-human-identity-management-general-discussions/cybersecurity-state-of-the-industry-report-what-teams-should-benchmark/</guid>
                    </item>
				                    <item>
                        <title>Identity security and AI agents: is your defense model ready?</title>
                        <link>https://nhimg.org/community/non-human-identity-management-general-discussions/identity-security-and-ai-agents-is-your-defense-model-ready/</link>
                        <pubDate>Thu, 28 May 2026 11:37:23 +0000</pubDate>
                        <description><![CDATA[TL;DR: Identity now sits in the center of breach paths, with Saviynt citing EY’s view that 90% of breaches involve identity through lateral movement and privilege escalation while AI compres...]]></description>
                        <content:encoded><![CDATA[<blockquote>
<p><strong>TL;DR:</strong> Identity now sits in the center of breach paths, with Saviynt citing EY’s view that 90% of breaches involve identity through lateral movement and privilege escalation while AI compresses time-to-exploit and non-human identities outnumber people. That makes identity governance a core control plane for security, not just a compliance function.</p>
</blockquote>
<p><em>NHIMG editorial — based on content published by Saviynt: EY's Ayan Roy on why identity security is now the foundation of defense in depth</em></p>
<p><strong>By the numbers:</strong></p>
<ul>
<li>Identity is involved in <a href="https://saviynt.com/blog/identity-security-foundation-cyber-defense/?utm_source=nhimg&amp;utm_medium=NHIForum">90% of breaches through lateral movement</a> and privilege escalation, making it the most critical and most overlooked layer of cyber defense.</li>
<li>If a certification campaign only eliminates <a href="https://saviynt.com/blog/identity-security-foundation-cyber-defense/?utm_source=nhimg&amp;utm_medium=NHIForum">2–5% of entitlements</a>, you're doing compliance.</li>
</ul>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-security-teams-govern-non-human-identities-that-have-persistent-acces/?utm_source=nhimg&amp;utm_medium=NHIForum">How should security teams govern non-human identities alongside workforce access?</a></strong></p>
<p><strong>A:</strong> Security teams should govern non-human identities with the same ownership, lifecycle, and review discipline used for people, but with tighter rotation and revocation expectations.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/when-does-identity-security-become-more-important-than-perimeter-controls/?utm_source=nhimg&amp;utm_medium=NHIForum">When does identity security become more important than perimeter controls?</a></strong></p>
<p><strong>A:</strong> Identity security becomes more important when attackers can reach critical systems through valid credentials, delegated access, or over-privileged accounts.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-is-the-difference-between-compliance-driven-access-review-and-real-identity/?utm_source=nhimg&amp;utm_medium=NHIForum">What is the difference between compliance-driven access review and real identity security?</a></strong></p>
<p><strong>A:</strong> Compliance-driven review checks whether a process was completed, while real identity security checks whether access risk was actually reduced.</p>
<h2>Practitioner guidance</h2>
<ul>
<li><strong>Map identity blast radius across human and non-human access</strong> Build an inventory that links each <a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum">identity to its privileges</a>, downstream systems, and automation paths.</li>
<li><strong>Reduce standing privilege in high-risk paths</strong> Prioritize <a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum#key-challenges-and-risks">just-in-time elevation</a> for admin, pipeline, and integration accounts that currently hold persistent rights.</li>
<li><strong>Tie identity telemetry to detection engineering</strong> Feed <a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum">identity events into SIEM</a> and endpoint workflows so privilege escalation, token misuse, and anomalous delegation can trigger response actions.</li>
</ul>
<p><em>Teams that cannot measure blast radius will struggle to prove control effectiveness?</em></p>
<p>&#x1f449; <strong><a href="https://saviynt.com/blog/identity-security-foundation-cyber-defense/?utm_source=nhimg&amp;utm_medium=NHIForum">Read Saviynt's analysis of EY's view on identity security and defense in depth →</a></strong></p>
<blockquote>
<p><strong>Explore further</strong></p>
<p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a>  |  <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a>  |  <a href="/services/?utm_source=nhimg&amp;utm_medium=NHIForum">Our Services →</a></p>
</blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/non-human-identity-management-general-discussions/">General NHI, AI &amp; IAM Discussions</category>                        <dc:creator>Saviynt</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/non-human-identity-management-general-discussions/identity-security-and-ai-agents-is-your-defense-model-ready/</guid>
                    </item>
				                    <item>
                        <title>What does infrastructure identity leadership mean for security teams?</title>
                        <link>https://nhimg.org/community/non-human-identity-management-general-discussions/what-does-infrastructure-identity-leadership-mean-for-security-teams/</link>
                        <pubDate>Thu, 14 May 2026 14:05:28 +0000</pubDate>
                        <description><![CDATA[TL;DR: Teleport’s interview with its senior sales director frames a familiar enterprise gap: identity tools often stop short of securing infrastructure itself, where humans, machines, worklo...]]></description>
                        <content:encoded><![CDATA[<blockquote>
<p><strong>TL;DR:</strong> Teleport’s interview with its senior sales director frames a familiar enterprise gap: identity tools often stop short of securing infrastructure itself, where humans, machines, workloads, and AI agents still need cryptographic control and policy enforcement. The practical lesson is that infrastructure identity remains a governance problem, not just a sales story.</p>
</blockquote>
<p><em>NHIMG editorial — based on content published by Teleport: Meet the Sales Leader Who Leads From the Front and Won't Let You Settle for Less</em></p>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-security-teams-govern-infrastructure-identities-alongside-user-identi/?utm_source=nhimg&amp;utm_medium=NHIForum">How should security teams govern infrastructure identities alongside user identities?</a></strong></p>
<p><strong>A:</strong> Treat infrastructure identities as part of the same governance programme, but manage them with tighter lifecycle controls.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/when-does-policy-based-access-control-reduce-risk-for-nhi-environments/?utm_source=nhimg&amp;utm_medium=NHIForum">When does policy-based access control reduce risk for NHI environments?</a></strong></p>
<p><strong>A:</strong> It reduces risk when policy is enforced at runtime and paired with short-lived credentials.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-is-the-difference-between-managing-human-access-and-managing-agent-access/?utm_source=nhimg&amp;utm_medium=NHIForum">What is the difference between managing human access and managing machine access?</a></strong></p>
<p><strong>A:</strong> Human access is usually governed through joiner-mover-leaver processes and interactive authentication.</p>
<h2>Practitioner guidance</h2>
<ul>
<li><strong>Inventory infrastructure identities by control plane</strong> Create a single register for service accounts, workload identities, certificates, API keys, and agent credentials.</li>
<li><strong>Convert standing access into task-scoped access</strong> Replace persistent entitlements with short-lived approvals for administrative and machine access.</li>
<li><strong>Define separate trust paths for humans and agents</strong> Do not allow autonomous agents to inherit human operator assumptions.</li>
</ul>
<p><em>With 79% of organisations having experienced secrets leaks, the governance bar is already higher than many teams assume, and audit evidence will matter as much as control design?</em></p>
<p>&#x1f449; <strong><a href="https://goteleport.com/blog/meet-the-sales-leader-leading-from-the-front/?utm_source=nhimg&amp;utm_medium=NHIForum">Read Teleport's interview on infrastructure identity leadership and the security gap →</a></strong></p>
<blockquote>
<p><strong>Explore further</strong></p>
<p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a>  |  <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a>  |  <a href="/services/?utm_source=nhimg&amp;utm_medium=NHIForum">Our Services →</a></p>
</blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/non-human-identity-management-general-discussions/">General NHI, AI &amp; IAM Discussions</category>                        <dc:creator>Teleport</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/non-human-identity-management-general-discussions/what-does-infrastructure-identity-leadership-mean-for-security-teams/</guid>
                    </item>
				                    <item>
                        <title>Closing Identity Blind Spots: Unochariot for Hard-to-Reach Security Controls</title>
                        <link>https://nhimg.org/community/non-human-identity-management-general-discussions/closing-identity-blind-spots-unochariot-for-hard-to-reach-security-controls/</link>
                        <pubDate>Tue, 28 Apr 2026 17:24:04 +0000</pubDate>
                        <description><![CDATA[Executive Summary
Identity security gaps in on-premise systems remain a critical challenge for enterprises despite advancements in cloud visibility. Many organizations have robust identity ...]]></description>
                        <content:encoded><![CDATA[<h2>Executive Summary</h2>
<p>Identity security gaps in on-premise systems remain a critical challenge for enterprises despite advancements in cloud visibility. Many organizations have robust identity management for SaaS and cloud applications but neglect their on-prem and self-hosted environments. This oversight heightens identity risk as permissions multiply and governance processes fail to encompass these systems. Addressing these gaps is complicated, as integrating cloud tools often necessitates opening private network access, creating further security vulnerabilities.</p>
<p>&#x1f449; Read the full article from <strong>Unosecur</strong> <a href="https://www.unosecur.com/resources/blog/unochariot-governing-the-identities-your-security-program-cant-reach?utm_source=nhimg">here</a> for comprehensive insights.</p>
<h2>Key Insights</h2>
<h3>The Challenge of On-Premise Identity Security</h3>
<ul>
<li>Organizations excel in identity management for cloud environments but often ignore on-premise systems.</li>
<li>Self-hosted applications like GitHub and Jira pose significant security risks due to unmanaged permissions.</li>
<li>The lack of visibility leads to unreviewed access and unsupervised governance processes.</li>
</ul>
<h3>Why Gaps Persist</h3>
<ul>
<li>While security teams acknowledge the risks, solutions remain elusive due to the complexities involved.</li>
<li>Creating connectivity between on-premise and cloud tools may further exacerbate security vulnerabilities.</li>
<li>Altering firewall rules and ports can inadvertently open up the network to threats.</li>
</ul>
<h3>Impact on Security Programs</h3>
<ul>
<li>The inability to manage identities in on-premise systems undermines overall security posture.</li>
<li>Legacy applications and systems predating cloud adoption often lack modern governance frameworks.</li>
<li>Continuous permissions accumulation can lead to data breaches and compliance issues.</li>
</ul>
<h3>Revamping Governance Strategies</h3>
<ul>
<li>Fostering governance processes that extend to on-premise systems is paramount.</li>
<li>Organizations must prioritize visibility and identity management across all environments.</li>
<li>Innovative strategies and tools are essential for managing identity risks effectively.</li>
</ul>
<p>&#x1f449; Access the full expert analysis and actionable security insights from <strong>Unosecur </strong><a href="https://www.unosecur.com/resources/blog/unochariot-governing-the-identities-your-security-program-cant-reach?utm_source=nhimg">here</a>.</p>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/non-human-identity-management-general-discussions/">General NHI, AI &amp; IAM Discussions</category>                        <dc:creator>Unosecur</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/non-human-identity-management-general-discussions/closing-identity-blind-spots-unochariot-for-hard-to-reach-security-controls/</guid>
                    </item>
				                    <item>
                        <title>Vercel Attack 2026: How a Major Web Platform Was Compromised</title>
                        <link>https://nhimg.org/community/non-human-identity-management-general-discussions/vercel-attack-2026-how-a-major-web-platform-was-compromised/</link>
                        <pubDate>Tue, 28 Apr 2026 17:22:54 +0000</pubDate>
                        <description><![CDATA[Executive Summary
In April 2026, a significant security breach at Vercel, a leading web infrastructure platform, compromised production workloads for major companies like OpenAI and Pintere...]]></description>
                        <content:encoded><![CDATA[<h2>Executive Summary</h2>
<p>In April 2026, a significant security breach at Vercel, a leading web infrastructure platform, compromised production workloads for major companies like OpenAI and Pinterest. The incident revealed that attackers exploited a routine OAuth request approved by a Vercel employee, gaining access through an AI tool, Context.ai, rather than through malware or code vulnerabilities. This incident underscores the risks of integrating AI tools and highlights the importance of vigilant identity management and OAuth security.</p>
<p>&#x1f449; Read the full article from <strong>Unosecur</strong> <a href="https://www.unosecur.com/resources/blog/they-didnt-hack-vercel-they-walked-in-through-the-ai-tool-you-approved-last-quarter?utm_source=nhimg">here</a> for comprehensive insights.</p>
<h2>Main Highlights</h2>
<h3>The Attack Overview</h3>
<ul>
<li>The Vercel security breach occurred without exploiting zero-day vulnerabilities or traditional malware.</li>
<li>Access was obtained via a routine OAuth process already approved by an employee, highlighting a crucial oversight.</li>
<li>This incident serves as a cautionary tale for reliance on automated processes within modern engineering environments.</li>
</ul>
<h3>The Role of Context.ai</h3>
<ul>
<li>Context.ai, an AI assistant, was integral to the workflow, learning from internal documents and communications.</li>
<li>It used Google Workspace OAuth grants to function, which ultimately led to its compromise.</li>
<li>The simplicity of the approval process masked a significant security vulnerability.</li>
</ul>
<h3>Identity Management Shortcomings</h3>
<ul>
<li>The breach underscored weaknesses in identity management, with four identities exploited without malicious intent.</li>
<li>This incident illustrates the need for stricter controls over third-party integrations and OAuth permissions.</li>
<li>Organizations must develop robust policies to oversee the use of AI tools in workplace environments.</li>
</ul>
<h3>Lessons Learned from the Incident</h3>
<ul>
<li>Employers should prioritize education and awareness about security risks associated with OAuth requests.</li>
<li>Implementing multi-factor authentication could mitigate risks from unauthorized access granted through routine approvals.</li>
<li>Security protocols should evolve alongside technological advancements to protect sensitive data and infrastructure.</li>
</ul>
<p>&#x1f449; Access the full expert analysis and actionable security insights from <strong>Unosecur </strong><a href="https://www.unosecur.com/resources/blog/they-didnt-hack-vercel-they-walked-in-through-the-ai-tool-you-approved-last-quarter?utm_source=nhimg">here</a>.</p>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/non-human-identity-management-general-discussions/">General NHI, AI &amp; IAM Discussions</category>                        <dc:creator>Unosecur</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/non-human-identity-management-general-discussions/vercel-attack-2026-how-a-major-web-platform-was-compromised/</guid>
                    </item>
							        </channel>
        </rss>
		