logo
Unseen & Unsecured: The machine identity threat you can't ignore

Unseen & Unsecured: The machine identity threat you can't ignore

Techday NZ30-04-2025

Cybersecurity leaders have spent decades securing human identities through various identity governance measures. Yet, as progress in human identity management becomes clearer, machine identities have emerged as a critical weak point.
A 2024 SailPoint special report, Machine Identity Crisis: The Challenges of Manual Processes and Hidden Risks, reveals that 70% of organisations now manage more machine identities than human ones, yet only 38% have real-time visibility into them. This imbalance presents a growing security risk as machine identities proliferate across enterprise environments.
With Forrester predicting that global cybercrime will cost $12 trillion in 2025, organisations cannot afford to overlook this rapidly growing threat. Digital entities, from service accounts to bots, APIs, and autonomous AI agents, have become a serious concern in enterprise security. Attackers are already exploiting this vulnerability.
Why machine identities are a blind spot for organisations
As automation and AI adoption accelerate, machine identities are projected to grow 30% over the next 3–5 years, far outpacing human identity growth. According to the same report, nearly half of organisations (47%) already manage ten times more machine identities than human ones.
Unlike human users, these digital identities often operate without oversight. This visibility gap is compounded by a lack of ownership, with 75% of machine identities reportedly having no assigned owner. Without clear accountability, these identities drift across digital environments, accumulating unchecked permissions and increasing security risk. Meanwhile, 66% of organisations still rely on manual processes to manage machine identities, heightening the risk of human error and misconfigurations.
Even when security teams identify dormant or unnecessary machine identities, 88% hesitate to delete them for fear of disrupting business-critical systems creating a growing inventory of abandoned but active accounts.
The consequence of ignoring machine identity security
Failing to secure machine identities poses a direct threat to business resilience and financial performance. Well over half (57%) of organisations admit to having provided inappropriate access to machine identities, creating open pathways for attackers to exploit.
These security failures translate directly to compliance issues – 60% of organisations report facing regulatory challenges tied to machine identities. As the 2023-2030 Australian Cyber Security Strategy recommends and enforces tighter controls around identity security, failing to secure machine identities could result in financial penalties and loss of customer trust.
A stark example of this vulnerability is the MOVEit data breach. MOVEit, a managed file transfer software developed by Ipswitch (a subsidiary of Progress Software), became the target of a major cyberattack when a vulnerability allowed attackers to steal sensitive files through an SQL injection on public-facing servers. The breach exploited a machine-level vulnerability, highlighting how unmanaged machine identities can become a backdoor for attackers to infiltrate and extract critical data.
This risk profile expands with agentic AI. Autonomous agents often hold broad access across systems, making them high-value targets. If compromised, an AI agent could independently escalate permissions, alter business processes, or bypass security controls without triggering traditional alarms.
When machine identities control critical workflows, compromise can lead to catastrophic operational disruptions and reputational damage. The complexity of modern digital ecosystems makes isolating and resolving these incidents incredibly difficult, prolonging the recovery process and increasing financial fallout.
Why responsible AI-driven machine identity security is the answer
Here's where fighting fire with fire becomes essential. While AI may be the source of new threat vectors—from AI-driven impersonation to lifecycle mismanagement of AI agents—it also holds the key to managing these risks effectively.
Securing machine identities requires a fundamentally different approach. While most organisations have well-established frameworks for managing human identities, machine identities operate at a scale and speed that traditional methods simply can't match.
AI offers a powerful solution. It can detect anomalies, flag risky behaviour, and adjust permissions in real-time, enabling policy-aligned decisions on a scale far beyond human capability. When embedded into identity security, AI not only enhances detection and response but also ensures access decisions are explainable, governed, and visible by design.
By treating machine identities with the same rigour as human ones, organisations can transform their greatest vulnerability into a strategic advantage. A zero trust approach—rooted in least privilege—is critical. Machine identities must be continuously verified and granted only the access necessary for their function. As organisations increasingly rely on AI agents, the ability to manage their full identity lifecycle, including enforcing access certifications, becomes essential.
The machine identity attack surface will continue to grow in complexity, but with responsible AI and strong governance, it doesn't have to remain a blind spot. With the proper oversight, organisations can turn a potential vulnerability into a strategic advantage, transforming identity security into a frontline defence in the modern enterprise.

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Younger buyers & AI tools reshape APAC business purchasing
Younger buyers & AI tools reshape APAC business purchasing

Techday NZ

time28-05-2025

  • Techday NZ

Younger buyers & AI tools reshape APAC business purchasing

Research from Forrester has revealed that business buying in Asia Pacific (APAC) is increasingly shaped by a younger demographic and by the adoption of generative AI in vendor evaluation. According to Forrester's Buyers' Journey Survey 2024, a significant majority of business buyers in the region are now under 45 years old, with 71% falling within this age group. In addition, 68% of APAC buyers use generative AI to research or compare vendors, a finding that underscores changing behaviours in the B2B purchase process. The data is detailed in The State Of Business Buying In Asia Pacific, 2024, which highlights the complexity of today's APAC business buying landscape and notes that younger buyers are increasingly rejecting conventional, seller-focused approaches in favour of more consultative and tailored engagement from vendors. An important driver of this shift is the widespread use of generative AI tools among business buyers. The report notes that the preference for self-service discovery is growing, as buyers look for rich and accessible digital content to guide their independent evaluations before engaging directly with vendors. Findings also show that the attitudes and values of younger buyers are shaping purchasing decisions. Nearly all younger buyers—94%—expressed dissatisfaction with their selected provider, pointing to issues such as failures in implementation or a lack of commitment to diversity, equity and inclusion (DEI). This age group is more inclined to choose a provider for their industry expertise rather than their history or brand legacy, emphasising the necessity for providers to offer personalised and consultative engagement. The research also reveals a trend towards more inclusive and larger buying groups. Around 18% of APAC buyers reported that purchase decisions now involve 30 or more internal stakeholders, a figure higher than that observed in other regions globally. In addition to this, an average of 10 external stakeholders are also included in these decisions. This trend requires marketers to refine their strategies and create targeted messaging that appeals to a wider array of decision-makers and personas involved in the purchasing process. This shift in the business buying environment is attributed to generational and technological factors, as well as to the broader and more collaborative decision-making typical of the APAC region. The report suggests that B2B marketers should move away from uniform strategies and towards approaches that are highly localised and data-driven to address the varied cultural and organisational contexts across Asia Pacific. The Buyers' Journey Survey 2024 includes responses from a wide regional segment and also provides comparative perspectives with business buyers in Europe and North America. Its findings shed further light on how demographic changes and digital fluency are influencing not only the tools buyers use, but also the values and expectations that shape vendor engagement. Mavis Liew, Executive Partner and Principal Analyst at Forrester, commented on the survey's findings. "The APAC business buying environment is undergoing a generational transformation," she said. "With younger, digitally-native fluent buyers in the majority, marketing strategies built for yesterday's buyers no longer apply. Today's business buyers value expertise, expect personalization, and demand authenticity - it is no longer just about product dominance. To stay competitive, B2B marketers must embrace localised, insight-driven approaches that speak relevance and align to the values, expectations, and complexity of this younger generation. It's time to stop selling and start connecting." Other data points highlighted in the report reinforce the move away from traditional engagement models. Younger business buyers were observed to place greater emphasis on diversity and subject matter expertise, while their approach to buying is more collaborative and inclusive than ever before. The data suggests that firms with strategies tailored around authenticity and relevance, and supported by insight into local market dynamics, are more likely to succeed in APAC's evolving business buying landscape.

Commercial drone automation set to soar across industries
Commercial drone automation set to soar across industries

Techday NZ

time23-05-2025

  • Techday NZ

Commercial drone automation set to soar across industries

A new report by Forrester has revealed that 78% of automation decision-makers said their organisation has implemented or plans to implement aerial drone automation within the next year. The Forrester report, titled The State Of Drones, 2025, highlights the growing interest in drone technologies across a range of sectors, including logistics, energy, construction, agriculture, and media, as these industries look to increase efficiency and address operational challenges. In its definition, Forrester describes an aerial drone as "an unmanned aerial system, controlled remotely by a human operator or autonomously by onboard computers, that is designed to fulfil commercial tasks in indoor and outdoor environments for business and government organizations by performing functions like mapping, surveying, product delivery, surveillance, and inspections of machines and infrastructure." Forrester's research draws on its 2024 Automation Survey and market analysis to assess the commercial readiness of drones, outline key use cases, and consider the regulatory and technical challenges that organisations may face during implementation. One of the report's major findings is that drones can halve operational timelines in some cases. According to the study, autonomous drones equipped with AI-powered vision and navigation are streamlining activities such as field inspections, surveys, and surveillance. This technology reduces manual labour, speeds up project delivery, and can improve the accuracy of collected data. The report also notes the role of advanced sensors and AI-powered analytics. Drones armed with high-resolution cameras, LiDAR, and edge computing options are capable of converting raw data such as aerial imagery into actionable intelligence. This, the report says, is particularly beneficial in industries like energy, insurance, and logistics, as it can support decision-making processes. Sectors where operational hazards and fragmented data are significant concerns are emerging as early adopters. The report states that energy, telecom, construction, and agriculture are seeing immediate benefits from using drones for asset monitoring, mapping, and targeted pesticide application. Meanwhile, the logistics and insurance sectors are experiencing technical and regulatory challenges that have slowed adoption rates but show strong future potential. The report draws attention to ongoing technical, regulatory, and economic issues that may hamper the scalability of these technologies. Payload and battery limitations currently restrict delivery drones to cargo weights under 2 kg, making them less viable for retail and healthcare deliveries on a large scale. Public anxiety about surveillance is also highlighted as a factor behind restrictive drone legislation in regions such as the US and Europe. Charlie Dai, Vice President and Principal Analyst at Forrester, commented on the growing significance of drones for commercial use. "As physical automation evolves, aerial drones are no longer experimental — they're operational imperatives. Organisations must move beyond pilots and integrate drones into core processes to bridge data gaps, protect workers, and drive strategic outcomes. To fully realise the potential of drone technologies, leaders must align drone deployment with measurable business goals, regulatory engagement, and sustainable innovation." The report concludes that while there are obstacles to wider adoption and scalability, drones are set to play a pivotal role in advancing automation and operational efficiency across multiple industries.

Qualtrics named leader in employee experience platform ranking
Qualtrics named leader in employee experience platform ranking

Techday NZ

time21-05-2025

  • Techday NZ

Qualtrics named leader in employee experience platform ranking

Qualtrics has been named a Leader in The Forrester Wave: Employee Experience Management Platforms, Q2 2025. The independent Forrester report assessed 12 service providers, examining a variety of criteria in areas including Strength of Offering and Strength of Strategy. Qualtrics received the highest possible score across 16 different criteria, which included features such as surveys and solicited feedback, data analysis and correlation of results, privacy and confidentiality, data visualisation and dashboards, AI-driven analysis and natural language processing, as well as vision, innovation roadmap, and partner ecosystem. The company was also rated highly on supporting services and offerings, digital exhaust and unsolicited feedback, social media and third-party data, the democratisation of insights and data, customer experience analysis and correlation, implementation and deployment, and coverage of multiple languages and geographies. According to the Forrester report, Qualtrics "achieved above average customer feedback" and demonstrated particular strengths in its surveying tools and analytics capabilities. The report further stated, "Qualtrics' strengths come from a rich set of surveying capabilities with myriad targeting, deployment and triggering options…[It] offers powerful analytics suitable for data scientists, with customisable dashboards and reports for business users. Qualtrics uses AI to analyse comments and to look for trends like attrition risk, while offering recommendation." Forrester also noted Qualtrics' ongoing expansion into new capabilities: "By expanding from surveys into multichannel passive listening that produces meaningful insights from unstructured internal and external social sources, the company can offer deeper insights into employee experiences and how they relate to business outcomes." The evaluation highlighted the ability for organisations to analyse customer and employee experiences together. The report stated, "Customers also like being able to analyse CX [customer experience] and EX [employee experience] together to spot patterns and correlations, which helps them to improve business outcomes." Brad Anderson, President of Product and Engineering at Qualtrics, commented on the company's position in the report: "Organisations that create superior employee experiences financially outperform their competitors, and the best companies are increasingly investing in their employee experience with Qualtrics. Our recognition as a Leader by Forrester underscores for us our strong market presence and innovative AI capabilities that allow organisations to build engaged, productive, and high performing teams, increase employee retention, and enhance manager and team effectiveness." Qualtrics' XM for Employee Experience suite is designed to help organisations collect and analyse a wide range of employee feedback, using the resulting insights to recommend and implement actions that improve factors such as engagement, satisfaction and productivity. The AI-powered tools offered include Qualtrics Assist for Employee Experience, Comment Summaries, and Conversational Feedback components, aiming to reduce bias and provide clear recommendations compiled from employee feedback data. The capabilities highlighted by the Forrester assessment reflect Qualtrics' growing suite of solutions developed to help businesses and governments analyse employee experience alongside broader organisational outcomes.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into the world of global news and events? Download our app today from your preferred app store and start exploring.
app-storeplay-store