logo
How Organizations Can Prepare For Machine Identity Attacks

How Organizations Can Prepare For Machine Identity Attacks

Forbes5 days ago
TK Keanini, CTO, DNSFilter.
Today's organizations are grappling with a massive number of identities, and it's not just humans (i.e., employees, contractors, vendors, etc.). There's also been an explosion of machine identities, known as non-human identities (NHIs), that enterprises have to contend with. Machines, including IoT devices, appliances and robotics, now vastly outnumber humans in digital environments. This is true even at the consumer level, given all of the various devices and appliances connected to the internet, even in the average home. Consider this—Cisco once forecasted that "the number of devices connected to IP networks will be more than three times the global population by 2023." 2023 was two years ago.
NHIs are becoming bigger targets for bad actors, and I believe that's only going to intensify. While cybersecurity has traditionally focused on humans, it's now necessary to shift the approach to include machine-centric security. Bad actors have attacked machines from the beginning, but now that there are so many more machine identities than human ones, the attack surface is larger than ever. Machines require a fundamentally different security strategy than humans do.
That means it's time to start thinking about this scenario from an attacker's mindset. In my years in cybersecurity, I've learned that attackers usually prioritize the amount of attack surface they can explore to find a way in. If, as a defender, you don't know your own attack surface, you're already in a weak position. It's simply not enough to secure your human resources; you must also account for machines. And with AI and generative AI creating even more non-human resources, you're likely already behind.
The Growth Of Machine Identities Requires A New Approach
A 2024 report consisting of research by TechTarget's Enterprise Strategy Group that was carried out for AppViewX found that organizations have '20X more non-human identities than human identities … with 52% of organizations predicting an additional 20% increase in NHIs they manage over the next year.'
If you were asked to guess how many machines are currently connected to your home network, you'd likely be underestimating. Many appliances on the market today can be connected to Wi-Fi (whether they should be able to, however, is a whole other debate).
The same question can be asked about your business: Most estimates of the number of connected devices any given organization has today are probably too low, especially for SaaS companies that service the needs of various customers.
This proliferation of machine identities creates massive attack surfaces. Even when machines are no longer in service, they can create problems. From my observations, at many organizations, machine offboarding gets neglected, leaving orphaned credentials and unmonitored access points—major vulnerabilities. De-provisioning is arguably more vital than provisioning, especially after staff turnover or organizational changes.
Organizations usually spend a lot of time and energy protecting their people with tactics like two-factor authentication and education for users. But such tactics aren't enough. Machines massively outnumber the people you are trying to protect, so if they don't get the same amount of cybersecurity attention, you're headed for trouble.
History provides many examples of the dangers of NHIs, as well as the fact that organizations have failed to learn from them.
In the 2013 Target breach, attackers gained access by stealing credentials from an HVAC subcontractor. The attack resulted in the theft of 40 million credit and debit card records.
In the 2016 Mirai botnet attacks, according to the Center for Internet Security (CIS), bad actors went after technology company OVH and the website Krebs on Security. Mirai and its variants still exist today and depend on "the weak security of IoT products and technology." For instance, in January 2025, it was reported by CyberScoop that Cloudflare "successfully managed and mitigated" an attack from a Mirai botnet variant that "originated from over 13,000 Internet of Things (IoT) devices."
Malware exploits weak passwords and remote code execution vulnerabilities. It can cause disruptions for major corporations and financial institutions that have long-term consequences. Systems that are addressable on the network deserve the same amount of care as those that are operated directly by humans. Everything on the network should, in my view, have a zero-trust strategy where AAA principles (authentication, authorization and audit) are enforced, giving users access when authenticated to only the resources they need to operate—nothing more.
Guiding Principles For Securing Machine Identities
While organizations' cybersecurity strategies should extend beyond zero trust in this machine-dominated landscape, the zero-trust model is still essential. Having a solid zero-trust strategy in place will go a long way toward keeping your organization safe. And thanks to having a zero-trust strategy, if an attack occurs, the event will be highly detectable and have a limited negative impact. For company leaders, now is also a good time to consider whether something should be connected to the internet just because it can be.
Getting a handle on machine identities requires a few best practices to all work in harmony with one another.
For one thing, establishing a baseline of behavior is key. Machines should follow strict "allow lists" and behavioral profiles. In other words, every machine identity should have an expected behavioral norm. Deviations in behavior, such as a building access system transferring large volumes of data to an external server, are red flags.
Another best practice is to implement the principle of least privilege access. Grant machines only the access they need, shaped tightly around their expected behavior. Use automation, but do so with caution; automating security policies can be helpful, but it must be done carefully.
One thing all networked-attached identities share is DNS, which means protective DNS can be a critical first line of defense. Nearly all internet-connected devices need to resolve domain names, which means they must perform DNS. Given that, company leaders should create policies so that devices can only receive updates from their manufacturers (and I'll reiterate that many devices don't actually need access to all of the internet).
Defending Against NHI Attacks
As the number of machines and machine identities increases, there's a growing need to rethink cybersecurity strategies in this machine-dominated world. Security models must shift from being primarily human-centric to machine-aware, with a focus on behavioral enforcement, automated policy management and robust identity life cycle practices. Organizations must develop practical, scalable methods to manage and secure machine identities, and the time to do so is now, not later.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Don't Miss Your Chance to Score the Eufy Robot Vacuum C10 at Its Lowest Price Ever
Don't Miss Your Chance to Score the Eufy Robot Vacuum C10 at Its Lowest Price Ever

CNET

time15 minutes ago

  • CNET

Don't Miss Your Chance to Score the Eufy Robot Vacuum C10 at Its Lowest Price Ever

If you're like me, vacuuming is a chore you put off as long as possible. I'm grateful that it's one of the easiest tasks to hand off to a robot. The world of modern robot vacuums is constantly getting new upgrades, and these dynamic household tools are becoming more affordable. Right now, you can get the Eufy Robot Vacuum C10 while it's down to just $230. That's a record-low price and 52% off what it normally costs. Not only is this a great deal, but buying now could potentially save you money if you were planning to make upgrades soon on your electronics and smart home devices. Hey, did you know? CNET Deals texts are free, easy and save you money. The Eufy app gives you access to additional features, such as map management and scheduling, so you can set the robot vacuum to clean your home while you're away. If you have Amazon Alexa, you can use the Eufy app to sync this robot vacuum to the hub and use voice controls. With enough space to hold debris for up to 60 days, upkeep is a cinch. Plus, it's self-emptying. Keep in mind that this robot vacuum only works with 2.4GHz band Wi-Fi and doesn't support 5GHz or other Wi-Fi bandwidths. If you're looking for a new vacuum but aren't sure if this deal is for you, we've also got lists of the best robot vacuums and best vacuum deals. Why this deal matters This Eufy robot vacuum C10 is down to its lowest-ever recorded price of $230. This saves you $250 on a budget-friendly robot vacuum that provides a ton of value and includes voice controls. If you've been looking for a more affordable robot vacuum, consider grabbing this deal before it expires.

The New Face of Batteries: How One Founder Extracts 3X More Lithium Than Conventional Methods
The New Face of Batteries: How One Founder Extracts 3X More Lithium Than Conventional Methods

Entrepreneur

time15 minutes ago

  • Entrepreneur

The New Face of Batteries: How One Founder Extracts 3X More Lithium Than Conventional Methods

With EnergyX ready to transition to commercial scale, they've created an investment offering to help power this next phase. Disclosure: Our goal is to feature products and services that we think you'll find interesting and useful. If you purchase them, Entrepreneur may get a small share of the revenue from the sale from our commerce partners. Quick — name a resource more critical to the future than lithium. It's not easy. Lithium is the foundation of the modern energy economy, powering electric vehicles, smartphones, and renewable infrastructure. It is also a critical material for the nuclear energy revolution. And demand is only climbing – it is expected to surge 5X by 2040. This spike in demand is pushing governments and global corporations into a high-stakes race for supply. As Elon Musk famously put it: "Do you like minting money? The lithium business is for you." One entrepreneur took that to heart. Now he's leading what is arguably one of the most ambitious lithium ventures in the world with sights on staking claim to the renewable energy throne. Meet Teague Egan, founder of EnergyX, who has been dubbed by some as The Lithium King. To meet this moment, he created extraction technology that he says can recover up to 300% more lithium than traditional methods. It didn't take long for the industry to notice. EnergyX has already earned backing from General Motors, which led a $50M investment round to support its 2035 EV goals, an investment from energy giant Eni, a $5M U.S. Department of Energy grant, and a critical alliance with Korea's POSCO to expand in North America. Then came one of the biggest moves yet: In 2024, EnergyX secured one of the largest lithium brine assets in the Americas – more than 100,000 acres in Chile's "Lithium Triangle." A recent third-party study by engineering firm Worley and geologists Montgomery & Associates confirmed the site's immense potential, projecting it could generate more than $1.1 billion annually once fully operational, at projected market prices. Egan didn't stop there either. EnergyX is set to acquire land in America's Smackover Region from Pantera Lithium, which will bring their U.S. mining territory to nearly 50,000 acres in size. Importantly, this new EnergyX acreage in the U.S. is directly next to Exxon and Chevron's acreage, who have started lithium business units of their own. The result? Proven technology, vast reserves, strategic partnerships, and a clear path to commercial production. Now, they're scaling to make the most of it – and inviting everyday investors to join the next chapter. From concept to commercialization: 90%+ extraction efficiency Egan launched EnergyX with a mission to fix a broken industry. Traditional lithium extraction methods are outdated, inefficient, and damaging to the environment, so he set out to create a better way. The result was LiTAS®, EnergyX's patented extraction platform. Unlike legacy processes, LiTAS® uses a combination of membranes, solvents, and adsorbents – making it the only direct lithium extraction (DLE) platform with all three approaches. That breakthrough has helped the company raise more than $135 million from 35,000+ investors, including a $50M Series B led by General Motors. Now, EnergyX is entering its most exciting phase yet (and inviting everyday investors to join). EnergyX secures one of the largest lithium brine assets in the Americas After establishing its technology, EnergyX turned its sights to securing top-tier lithium resources. In 2023, the company secured mining rights to a 100,000+ acre mining territory in Chile's "Lithium Triangle," widely considered the most lithium-rich region on Earth. Dubbed Project Black Giant™, initial estimates were pegged at 2.6M metric tons of lithium. At the time of acquisition, it was already seen as a strategic win, but they were only just discovering the full extent of its potential. Independent study confirms this could be a $1.1B annual revenue generator Before any lithium asset can begin commercial production, it must undergo an independent pre-feasibility study (PFS). This rigorous engineering and economic assessment evaluates the resource's size, quality, and viability. The independent PFS for Project Black Giant™ revealed EnergyX's Chilean mining territory has even more upside than initially believed. Third-party research showed at least 4.5 million metric tons of lithium – and as much as 9.8 million. That's a significant leap from the early 2.6M estimate. Even more impressive? The study confirmed that EnergyX's LiTAS® system can recover lithium at industry-low capital and operating costs. With both a world-class asset and breakthrough tech under one roof, the study projected Project Black Giant™ could be a $1.1B annual revenue generator once fully operational, at projected market prices. With the PFS complete, EnergyX is now transitioning to commercial extraction to unlock the immense potential of this sleeping giant. Eni partnership and the global energy transition EnergyX's potential hasn't gone unnoticed. In addition to GM, the company earned an investment from Eni SpA, one of the world's largest oil and gas companies. Eni's involvement underscores a broader industry shift toward clean energy and critical minerals – and EnergyX's standing as a leader in the field. Together, Eni and EnergyX are exploring ways to deploy lithium extraction tech at scale — positioning EnergyX as a key player in reshaping global supply chains. As geopolitical tensions mount and domestic supply becomes a priority, partnerships like these couldn't come at a better time. The Americas: The next lithium frontier While China continues to dominate global lithium processing, EnergyX is betting big on the Americas. The Southern U.S., particularly the Smackover Region, has shown some of the highest lithium concentrations ever recorded. With the right tech, this region alone could power a major share of U.S. EV production — without relying on foreign sources. EnergyX's vertically integrated model — pairing extraction technology with proven reserves — puts it in rare company. No wonder more than 35,000 investors have jumped at the chance to share in EnergyX's growth. An opportunity to join the next chapter Last year, demand for EnergyX's stock was so overwhelming that investors maxed out the investment offering, with thousands more reaching out to ask for another chance to join the movement, the company says. Now, with EnergyX ready to transition to commercial scale, they've created another investment offering to help power this next phase. The earliest investors in this new opportunity will be eligible for 20% bonus shares if they meet one of the following criteria: Be an existing EnergyX shareholder as of July 1, 2025, or Invest $5,000 or more for this opportunity as a new investor This bonus is being distributed on a first-come, first-serve basis, with a 200,000-share cap. Once those shares are gone, the bonus will no longer be available. As Project Black Giant™ advances toward commercial production and global momentum accelerates, this is a rare opportunity to maximize your stake in one of the most ambitious clean energy ventures on the planet. To learn more about EnergyX, their roadmap for growth, or the investment opportunity, head to their website by clicking here. This is a paid advertisement for EnergyX's Regulation A+ Offering. Please read the offering circular at The testimonials presented are the opinions of the individuals providing them. They may not represent the experience of all clients or investors and are not a guarantee of future performance or success. No compensation was provided for these testimonials unless explicitly stated.

BHP's Profit Slides to Five-Year Low as China Economy Drags
BHP's Profit Slides to Five-Year Low as China Economy Drags

Bloomberg

time28 minutes ago

  • Bloomberg

BHP's Profit Slides to Five-Year Low as China Economy Drags

By Updated on Save BHP Group's full-year underlying profit fell by more than a quarter to its lowest level since the pandemic, broadly in line with market expectations, as prices of its key earners — iron ore and coking coal — came under pressure from softer Chinese demand. The world's largest miner sold iron ore at prices 19% lower than a year ago in the year to June 30 amid a sputtering China property sector and plentiful global supply, and steelmaking coal was down nearly a third. While its key growth commodity — copper — helped buffer the impact, it posted a $4.4 billion slide in annual revenue on Tuesday.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store