International Cyber Expo International Cyber Expo
  • About Us
Thursday, 17 September, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

6 Ways Security Teams Can Reduce Non-Human Insider Risk

by James Turnbill
September 17, 2026
in News, Uncategorized
6 Ways Security Teams Can Reduce Non-Human Insider Risk
Share on FacebookShare on Twitter

AI agents are rapidly becoming part of everyday business operations and this increases non-human insider risk. They can improve productivity, reduce repetitive work and help organisations accomplish tasks far more efficiently.

The answer, therefore, is not to ban them. Instead, organisations need to manage AI agents with the same discipline applied to human identities, privileged accounts and other powerful technologies.

Following on from last weeks article where we explained the ways organisations create non-human insider risk, here are six practical steps security teams can take:

1. Start with visibility

You cannot secure AI agents you do not know exist.

Organisations should maintain an inventory of deployed agents, record who owns them, identify the systems and data they can access, and document the actions they are authorised to perform. This inventory must remain current as agents, integrations and business requirements change.

2. Apply least privilege aggressively

An agent should receive only the access required to perform its specific task.

If it summarises support tickets, for example, it should not be able to modify customer records or access financial systems. Narrowly scoped credentials and permissions reduce the potential blast radius if an agent makes a mistake, is manipulated or behaves unexpectedly. Least privilege for agentic AI must be treated as an ongoing control, not a one-time configuration exercise.

3. Use temporary privileges whenever possible

Standing administrative access creates unnecessary risk for both humans and machines.

Where an agent occasionally needs elevated privileges, access should be granted only for the specific task and revoked automatically when that task ends. Particularly sensitive actions should require an additional approval or other step-up control.

4. Monitor behaviour, not just authentication

A valid identity can still perform a dangerous action.

Security teams need to understand what normal activity looks like for each agent: which systems it usually accesses, how much data it retrieves, which tools it uses and what actions it performs. Sudden deviations, such as an unexpected data export or access to a new system, should trigger investigation.

Logging what happened is important. Determining whether it should have happened is the real challenge.

5. Keep humans involved in high-risk decisions

Large data exports, financial transactions, privilege changes, production deployments and customer-impacting decisions should include meaningful human oversight.

This does not mean requiring approval for every routine action. Controls should focus on decisions with significant security, financial or operational consequences. The goal is to ensure that someone verifies the action makes sense before it becomes irreversible.

6. Build an offboarding process

AI agents do not always disappear when projects end.

Forgotten agents can retain credentials, integrations and permissions long after their original purpose has gone away. Organisations should establish clear processes for disabling unused agents, revoking their credentials, removing connected tools and preserving relevant audit records.

AI agents may not be human, but they should still have owners, defined responsibilities and complete identity lifecycles. As their autonomy increases, the security controls surrounding them must become equally mature.

You can read the full blog from Erich Kron, CISO Advisor at KnowBe4.

Tags: artificial intelligencecybersecurityTechnology
ShareTweet
Previous Post

CSIDES Unveils Full Agenda for 2026 Cybersecurity Community Event

Recent News

6 Ways Security Teams Can Reduce Non-Human Insider Risk

6 Ways Security Teams Can Reduce Non-Human Insider Risk

September 17, 2026
CSIDES Unveils Full Agenda for 2026 Cybersecurity Community Event

CSIDES Unveils Full Agenda for 2026 Cybersecurity Community Event

September 17, 2026
Cybersecurity Innovation Takes Centre Stage in International Cyber Expo Awards Shortlist

Cybersecurity Innovation Takes Centre Stage in International Cyber Expo Awards Shortlist

September 16, 2026
Could blame culture be cybersecurity’s next Achilles heel?

Could blame culture be cybersecurity’s next Achilles heel?

September 16, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol