HomeCyber BalkansCybersecurity Awareness Month: AI Agents as Users Demanding Governance

Cybersecurity Awareness Month: AI Agents as Users Demanding Governance

Published on

spot_img

Cybersecurity Awareness Month Broadens Focus to Include AI Agents

For over twenty years, Cybersecurity Awareness Month has primarily concentrated on human behavior, highlighting the risks posed by employees who might unwittingly click on malicious links, reuse passwords, or approve dubious login attempts. However, with the campaign for this October themed "Don’t Make It Easy for Them," experts in identity security are advocating for an expanded conversation that includes a rapidly increasing group of users: AI agents. This development marks a pivotal shift in how organizations approach cybersecurity, necessitating new strategies and awareness.

Darren Guccione, the CEO and co-founder of Keeper Security, emphasizes that the traditional focus on human behavior surrounding cybersecurity must evolve. "Cybersecurity Awareness Month has generally spotlighted recognizing phishing attempts, safeguarding credentials, and making prudent decisions about accessing an organization’s network, data, and accounts. However, this dialogue now requires expansion," he states. With organizations hastily implementing AI agents across their operational frameworks, a whole new class of digital users is emerging, often without the same identity governance measures applied to employees, contractors, or administrators.

Guccione asserts that AI is no longer just an experimental component of IT infrastructure; it has become integral. "AI is evolving from a form of intelligence to an essential enterprise infrastructure," he explains. AI agents are now capable of authenticating systems, retrieving sensitive information, interacting with applications, executing workflows, and making critical decisions at machine speed. Each AI agent with credentials and permissions represents an identity, and each identity inherently carries risk when access is excessive, persistent, or inadequately monitored.

Supporting this view, John Cannava, Chief Information Officer at Ping Identity, notes that the parameters of what security teams must protect have fundamentally shifted. "As technology advances, so does the definition of whom or what organizations need to secure," he states. According to Cannava, AI agents increasingly interact with applications, data, and vital business systems at machine speed, leading to a new layer of risk that companies must manage on a daily basis.

Of particular concern is scale, as highlighted by Guccione. "The most significant issue is scale," he warns. Organizations can deploy numerous non-human identities far quicker than onboarding human employees. If these agents are granted standing credentials, broad permissions, or long-lasting secrets without adequate governance, the surface area vulnerable to attacks can expand just as rapidly. A compromised AI agent with privileged access could potentially provide an adversary direct entry into critical systems and sensitive data.

This sentiment is echoed by Michael Marino, Senior Vice President of strategy for identity security at Keeper Security, who has observed dramatic changes within the realm of privileged access. "Cybersecurity Awareness Month is a moment to reflect on the evolution of cyber threats and our defensive strategies," he says, pointing out the notable transformation in Privileged Access Management (PAM).

Marino elaborates on this shift by recalling that PAM once focused mainly on securing administrator passwords within a controlled vault. Such measures made sense when most infrastructure was on-premises, where privileged users were easily identifiable within sharply defined network boundaries. The overarching goal was clear: safeguard powerful credentials while maintaining an audit trail for their usage.

However, Marino contends that this traditional model has faltered with the migration to cloud computing. "The era of a contained network perimeter is over," he states, indicating that organizations now operate within cloud, hybrid, and remote infrastructures. A diverse array of employees, contractors, applications, service accounts, and automated systems now require varying levels of access. Citing Keeper’s 2025 report, "Securing Privileged Access: The Key to Modern Enterprise Defense," Marino notes that 94% of organizations are now functioning in hybrid or cloud-first environments. As access becomes more distributed, the conventional idea of privilege must adapt accordingly.

Consequently, Marino asserts that the scope of PAM must now encompass more than simply protecting passwords. "Modern PAM must extend beyond just safeguarding passwords," he insists. It should manage when privileged access is granted, what specific resources can be accessed, and what occurs during that session. Implementing principles like least privilege, just-in-time access, and zero standing privilege helps organizations transition from persistent administrative rights to intentional, temporary, and auditable access.

AI is increasingly playing a critical role in this ongoing evolution, both as a source of risk and a defensive tool. Marino asserts that automation and AI are driving the next stage, as non-human identities and AI agents generate privileged access at scales beyond manual management. Simultaneously, AI can assist security teams in analyzing privileged activity and spotting suspicious behavior with remarkable speed.

Despite these challenges, the experts remain optimistic that organizations don’t need to overhaul established protocols. Guccione believes that the security principles required to protect AI agents are not new: organizations should apply the same zero-trust protocols to AI agents as they do for people. "Every identity must be verified, the principle of least privilege enforced, unnecessary standing access eliminated, privileged activity continuously monitored, and credentials and secrets rotated," he asserts.

Cannava reinforces this notion, stating that accountability still lies with humans. "The problems associated with non-human identities ultimately boil down to human oversight," he remarks. Organizations need clarity on who authorized an agent, the extent of its authority, and its permitted actions, which entails providing AI agents verifiable identities, clear ownership, and specific access aligned with the least privilege principle.

The crux of the matter fastens around the enforcement of these principles. Cannava expresses, "Businesses should implement proven identity principles for machines operating on behalf of people, embedding these frameworks into enforceable controls."

Marino encapsulates the significance of this month by stating, "The lesson for Cybersecurity Awareness Month is that fundamental cybersecurity concepts do not vanish amid technological advancements; instead, they evolve to meet emerging challenges." He emphasizes that privileged access always harbors concentrated risk, and effective PAM must continually adapt as identities, infrastructures, and technologies evolve.

Finally, Guccione insists that awareness must also progress. "Cybersecurity awareness should evolve in tandem with technological advancements," he stresses. After years of instilling the necessity of governance for every employee identity, the understanding must now extend to AI agents.

"The next frontier of cybersecurity awareness is recognizing that AI agents are users too," he concludes. Organizations that manage these identities vigilantly can reap the benefits of agentic AI without inadvertently cultivating an unmanaged layer of privileged access.

Cannava cautions against relegating the focus to just one month. "Cybersecurity Awareness Month is a vital reminder to prioritize security, but it should not begin and end in October," he advises. As organizations prepare for the future, cultivating a culture of security and maintaining vigilance over all forms of identity year-round is crucial.

Source link

Latest articles

Safari History Database Tags Reveal Users’ Browsing Themes in Forensic Investigations

Safari's History Database: A Crucial Tool for Digital Forensics The Safari web browser, widely utilized...

Google Launches Gemini 4 Argon AI Model

Google Unveils Gemini 4 Argon: A New Frontier in Specialized AI for Cybersecurity and...

More like this

Safari History Database Tags Reveal Users’ Browsing Themes in Forensic Investigations

Safari's History Database: A Crucial Tool for Digital Forensics The Safari web browser, widely utilized...