International Cyber Expo International Cyber Expo
  • About Us
Friday, 2 October, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Cybersecurity Awareness Month: AI agents are users too, and they need governing like it

by Lara Joseph
October 2, 2026
in Featured
Cybersecurity Awareness Month: AI agents are users too, and they need governing like it
Share on FacebookShare on Twitter

For more than two decades, Cybersecurity Awareness Month has centered on people: the employee who might click a malicious link, reuse a password or approve a suspicious login. This October, as the campaign runs under the banner “Don’t Make It Easy for Them”, identity specialists say the conversation must widen to include a fast-growing population of users that will never sit through a training module: AI agents.

“Cybersecurity Awareness Month has traditionally focused on human behavior: recognizing phishing, protecting credentials and making better decisions about access to an organization’s network, data and accounts. That conversation now needs to expand,” says Darren Guccione, CEO and co-founder of Keeper Security. “As organizations rapidly deploy AI agents across their environments, they are creating an entirely new class of digital users, often without applying the same identity governance expected for employees, contractors or administrators.”

Guccione is clear that this is no longer an experimental corner of the IT estate. “AI is transforming from intelligence to unremovable enterprise infrastructure. AI agents can now authenticate into systems, retrieve sensitive information, interact with applications, execute workflows and make critical decisions – all at machine speed. If an agent has credentials and permissions, it represents an identity, and every identity creates risk when its access is excessive, persistent or poorly monitored.”

John Cannava, CIO at Ping Identity, agrees that the boundaries of what security teams must protect have shifted. “As technology evolves, so does the definition of who, or what, organizations need to secure,” he says. “AI agents are increasingly accessing applications, data, and critical business systems while taking actions at machine speed, creating a new layer of risk that businesses need to manage every day.”

Scale is the real challenge

What makes agentic AI different from previous waves of automation is the speed at which new identities can appear. “The biggest problem is scale,” Guccione warns. “Organizations can deploy hundreds or thousands of non-human identities far faster than they onboard human employees. If those agents receive standing credentials, broad permissions or long-lived secrets without appropriate governance, the attack surface expands just as quickly. A compromised AI agent with privileged access can give an attacker direct access into critical systems and data.”

That concern resonates with Michael Marino, SVP of strategy, identity security at Keeper Security, who has watched the discipline of privileged access change dramatically. “Cybersecurity Awareness Month is an opportunity to reflect not only on how cyber threats have evolved, but on how our defenses have had to evolve alongside them,” he says. “Over my career in identity security, I’ve seen few areas change as significantly as Privileged Access Management (PAM).”

“PAM was once primarily about putting administrator passwords into a secure vault,” Marino explains. “That made sense when infrastructure was largely on-premises, privileged users were relatively easy to identify and access occurred within clearly defined network boundaries. The objective was straightforward: protect powerful credentials and maintain an audit trail around their use.”

That model has not survived the move to the cloud. “The days of contained network perimeter no longer exist,” he says. “Organizations now operate across cloud, hybrid and remote infrastructure, while employees, contractors, applications, service accounts and automated systems all require different levels of access.” Marino points to Keeper’s 2025 report, Securing Privileged Access: The Key to Modern Enterprise Defense, which “found that 94% of organizations operate in hybrid or cloud-first environments. As access has become more distributed, the traditional concept of privilege has expanded with it.”

As a result, he argues, the scope of PAM has had to grow. “Modern PAM, therefore, has to be about much more than protecting passwords. It must control when privileged access is granted, what someone or something can access and what happens during that session. Principles such as least privilege, just-in-time access and zero standing privilege help organizations replace persistent administrative rights with access that is intentional, temporary and auditable.”

AI is now driving the next phase of that evolution, both as a source of risk and as a defensive tool. “The next stage of this evolution will be driven by automation and AI,” Marino says. “Non-human identities and AI agents are creating privileged access at a scale that security teams cannot manage manually. At the same time, AI can help defenders analyze privileged activity and identify suspicious behavior much faster.”

Familiar principles, new identities

Encouragingly, none of the experts believe organizations need to tear up the rulebook. “The security principles needed to secure these identities are not new,” says Guccione. “Organizations should apply the same zero-trust discipline to AI agents that they apply to people: verify every identity, enforce the principle of least privilege, eliminate unnecessary standing access, continuously monitor privileged activity, and protect and rotate credentials and secrets. Access should be granted only to the resources required for a specific task and only for as long as that access is necessary.”

Cannava makes the same case, stressing that accountability ultimately sits with people. “The same security principles we’ve long applied to human access now need to extend to AI. At the end of the day, the nonhuman identity problem is still a human problem,” he says. “Organizations need to know who authorized an agent, what authority it has, and what it should be allowed to do. That means giving AI agents verifiable identities, clear ownership, and least-privilege access, with continuous authorization and accountability for their actions.”

The key, he adds, is enforcement rather than intent. “Businesses should extend proven identity principles to machines acting on behalf of people and build those principles into controls that can actually be enforced.”

For Marino, that continuity is the real lesson of the month. “The lesson for Cybersecurity Awareness Month is that cybersecurity fundamentals don’t disappear as technology changes – they evolve to meet the occasion. Privileged access will always represent concentrated risk. Effective PAM is about continually adapting how that risk is controlled as the identities, infrastructure and technologies around it change.”

Awareness beyond October

Guccione believes awareness itself has to evolve to keep up. “Cybersecurity awareness must evolve alongside technology. We have spent years teaching organizations that every employee identity requires governance. Now we need to extend that understanding to machines.”

“The next frontier of cybersecurity awareness is recognizing that AI agents are users too,” he concludes. “Organizations that govern them accordingly will be far better positioned to capture the benefits of agentic AI without creating an unmanaged layer of privileged access.”

Cannava, meanwhile, warns against treating the month as a one-off. “Cybersecurity Awareness Month is an important reminder to make security a priority, but it shouldn’t begin and end in October,” he says. “Looking ahead to secure the next 250 years, security cannot be in the spotlight for only one month. Leaders must build a culture of security and maintain visibility and control over every kind of identity year-round.”

ShareTweet
Previous Post

Malicious Email Could Hijack AI Agent and Access Connected Accounts

Next Post

Shadow AI and the permissions problem: what to check before handing AI the keys

Recent News

Shadow AI and the permissions problem: what to check before handing AI the keys

Shadow AI and the permissions problem: what to check before handing AI the keys

October 2, 2026
Cybersecurity Awareness Month: AI agents are users too, and they need governing like it

Cybersecurity Awareness Month: AI agents are users too, and they need governing like it

October 2, 2026
Malicious Email Could Hijack AI Agent and Access Connected Accounts

Malicious Email Could Hijack AI Agent and Access Connected Accounts

October 2, 2026
RMM abuse behind 45% of endpoint incidents as Huntress publishes inaugural Tragic Quadrant

RMM abuse behind 45% of endpoint incidents as Huntress publishes inaugural Tragic Quadrant

October 1, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol