CIOs must rethink identity now people are being outnumbered by nonhuman entities
AI-driven nonhuman identities are growing, forcing CIOs to rethink security, access and identity management.
The ratio of nonhuman identities (NHIs) to human identities in the enterprise is growing at an alarming rate, with some estimates suggesting up to 50:1. These NHIs include machines, processes, service principals, accounts, virtualized workloads, applications with digital credentials, and more. Examples range from helpdesk chatbots to IoT endpoints and autonomous agents.
CIOs, identity experts, and CISOs must now consider how to manage and secure these nonhuman entities just as they do human employees. This is a shift from the identity access management (IAM) systems of the early 2000s, which were focused on compliance and rigid permission structures. Today, CIOs need a central, visible platform to manage and monitor not only human identities but also the ever-expanding range of nonhuman assets.
This includes ensuring that context is king when it comes to understanding risks and permissions for NHIs. The focus should be on holistic oversight of all identity types, recognizing when a nonhuman identity is leveraging a human identity, and vigilantly guarding against credential misuse, misconfigured tokens, and unauthorized API access.
By adopting a dynamic, CI/CD-based approach to technology inventory and control, CIOs can transform the identity management landscape into a powerful asset, enhancing security while gaining respect and influence within their organizations.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.