惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
Docker
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - Franky
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
A
About on SuperTechFans
博客园 - 【当耐特】
Microsoft Security Blog
Microsoft Security Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
The GitHub Blog
The GitHub Blog
雷峰网
雷峰网
博客园_首页
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
IT之家
IT之家
博客园 - 叶小钗
Google DeepMind News
Google DeepMind News
aimingoo的专栏
aimingoo的专栏
博客园 - 聂微东
B
Blog RSS Feed
H
Help Net Security
Recent Announcements
Recent Announcements
阮一峰的网络日志
阮一峰的网络日志
D
DataBreaches.Net
L
LangChain Blog
Vercel News
Vercel News

Search Security Resources and Information from TechTarget

How to operationalize threat modeling with AI | TechTarget CISO First fully agentic ransomware attack sparks readiness concerns | TechTarget Evaluating secure enterprise browsers vs. security plugins | TechTarget The AI vulnerability storm is here: Is your security program ready? | TechTarget Perimeter to posture: A roadmap to zero trust maturity | TechTarget TLS certificate lifetime changes: What CISOs must do now | TechTarget The agentic AI 8 key aspects of a mobile device security audit program | TechTarget Why mobile security audits are important in the enterprise | TechTarget Beyond the perimeter: The shift to data-centric protection | TechTarget How agentic AI threat intelligence aids NGO cyber defense: Case study | TechTarget How to conduct a mobile app security audit | TechTarget NO FAKES Act advances: What CISOs need to know | TechTarget What CISOs should know about AI runtime security | TechTarget As Q-Day looms, 90% of systems are unprepared for PQC | TechTarget A CISO Most security pros say their culture is Zscaler lays out its vision to secure the AI era at Zenith Live | TechTarget The OpenClaw security risks every CISO needs to know | TechTarget Cloud security metrics and KPIs: A CISO Florida public sector training on SimSpace cyber range: Case study | TechTarget Reporters' Notebook — Focus on Cyber Insurance: How Quantifying Risk Is Reshaping Security It's time to update incident response for the AI era How to build AI security guardrails without blocking innovation The prosecution gap: Why cybercrimes go unpunished AI in cyberdefense: Learning from threat actors' playbooks Top identity and access management risks CISO role changes as cyber-risk appetites in the C-suite grow CISO's guide to data minimization
Identity security at RSAC 2026: The new enterprise dynamics
2026-04-07 · via Search Security Resources and Information from TechTarget

Todd Thiemann

By

  • Todd Thiemann, Principal Analyst
  • Omdia

    Intelligence and advice powered by decades of global expertise and comprehensive coverage of the tech markets.

Published: 07 Apr 2026

As I was hanging out with more than 40,000 of my closest cybersecurity friends at RSAC Conference 2026 -- CISOs, practitioners and vendor leaders -- I learned the dominant theme was widespread adoption of AI agents. This has a variety of implications for identity and data security across its use cases, including adversaries using AI agents, security for AI agents and applying agents to improve cybersecurity tools. These are the key identity and security themes from the show.

Threat landscape: Increasing threat velocity

RSAC week kicked off with events from Microsoft and Google, and the consistent message that adversaries were using AI to increase the volume, speed and sophistication of their attacks. Long story short, adversaries are using AI to dramatically amp up their efforts. While the attacks might not be super-sophisticated today -- better phishing lures, etc. -- attackers will learn and get progressively better, especially because they can now deploy agents for malicious purposes.

While everyone has opinions on the risks and where the threats will emerge, these are early days for deploying AI agents, and the risks in the field have yet to emerge in volume. Researchers have found many vulnerabilities, but actual events or compromises causing significant business damage have yet to appear. Given how enterprises are embracing agentic AI across their businesses, it is a matter of when -- rather than if -- they will face attacks or incidents.

The increased attacker velocity with AI needs to be countered by defender velocity that is also powered by AI. The topics on most RSAC attendees' minds were how defenders can up their game using AI agents and ensuring that enterprises use agents securely.

Finding the signal in the AI security marketing noise

From a defender's perspective, the volume of the AI agent message was cranked to 10, but there was distortion coming out of the speaker. Signage blared "security for AI agents," but there was little clarity about the layers comprising a complete solution for AI agent security. An AI agent security stack has many layers: AI security posture management; data security, including data security posture management and data loss prevention; identity security -- i.e., governance, fine-grained access control, lifecycle management; and data and cyber-resilience for AI agents, including backup and recovery, ensuring AI infrastructure, retaining AI agent logs, etc.

The AI agent phenomenon is relatively new, and it will take time for enterprises, security practitioners and the cybersecurity ecosystem to figure out how the cybersecurity pieces fit together. The various technology providers are approaching it from different perspectives. When it comes to identity security for AI agents, three approaches stand out:

  • Cybersecurity platform players. Bigger cybersecurity players have a comprehensive "we will solve your AI agent issues" approach to solve the broad range of AI agent security challenges. That runs the gamut from prompt injection attacks and model poisoning to governing and securing agent identities. These players include Cisco, CrowdStrike, Microsoft, Palo Alto Networks/CyberArk and Thales.
  • Identity platform players. Enterprises have already invested in identity governance and administration, privileged access management, access management, identity security posture management and identity threat detection and response. It is a natural extension for vendors such as Delinea, SailPoint Technologies, Saviynt, BeyondTrust, ConductorOne, Teleport, Andromeda Security and Xage Security to expand their portfolios to manage and secure AI agent identities alongside existing platforms for securing and governing human and nonhuman identities.
  • AI agent identity management and security players. These are pure-play technology providers focused on the specific problem of AI agent identity security. They include Astrix Security, Barndoor AI, GitGuardian, Natoma Labs, Oasis Security, Token Security, and AppViewX and Eos Cyber.

Identity and security teams have a job to do and need to be ruthless about achieving their goals. Teams typically want to extract more value from the existing technology stack. However, if an incumbent platform doesn't solve the problem or meet their needs, teams are more than willing to consider a best-of-breed tool that will. Time will tell which approach predominates as the market distinguishes between strong AI agent identity tools that can work today and roadmaps that might require some patience.

Changing enterprise budget dynamics for AI agents

AI agents are a recent phenomenon, and the management and security of these initiatives frequently vary from other IT and security processes. While a CEO might tap a subordinate to lead the AI initiative -- and hand them a budget to do so -- conversations at RSAC underscored that the budget dynamics for AI agent security can differ. CISOs and CIOs continue to have budgets, but there is often a standalone AI budget that could be owned by a CDO, CTO or other C-level executive tasked with driving AI initiatives.

If you are a security or identity team leader, you need to help the enterprise AI leader grasp the business value of security and identity management needed for production AI agent deployment. Identity security teams, in particular, recognize that AI agents still have compliance obligations, require security best practices, and need common identity governance and management processes to deliver efficiency and scalability across the enterprise. The vendor community needs to arm its constituents with the information to make the case for security investments.

It is an amazing time to work in security; the dynamism of it can make your head spin. If you are a new technology player solving an interesting new identity or data security problem, or you have an innovative approach to an existing challenge, I would like to hear about it. You can reach me on LinkedIn.

Todd Thiemann is a principal analyst covering identity access management and data security for Omdia. He has more than 20 years of experience in cybersecurity marketing and strategy.

Omdia is a division of Informa TechTarget. Its analysts have business relationships with technology vendors.

Next Steps

Why identity is the new perimeter -- and how to defend it

Identity security tool sprawl: Origins and the way forward

Key identity and access management benefits

RSAC 2026 recap: AI security and network security trends

Dig Deeper on Identity and access management