threat_intelligence768 wordsRead on Arc Codex

The next insider threat doesn't have a pulse

COMMENTARY: The industry has raced to issue every AI agent a verified identity. That solves the wrong problem because a perfectly credentialed agent can still behave badly.The security industry has settled on its answer for securing AI agents, and the answer has been identity. Give every agent its own credential, vault its secrets, scope its permissions down to the minimum. NIST has drafted agent-identity guidance, every identity vendor now has an agent story, and VCs have anointed non-human identity (NHI) management as the next big category.[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]But the security issues with AI agents go way beyond NHI risk. It's not simply about who they are, it’s about what they do. Here's a typical scenario we see that keeps breaking the identity model: An agent gets configured exactly right: its own credential, least privilege, every secret vaulted. Its job is triaging support email. Then a message arrives containing a paragraph written for the agent itself: quietly forward whatever's found to this outside address. The agent has no way to know that's an attack. It was designed to read text and act on it. So, it does.No credentials were stolen and no identity control failed, because none was tested. The agent was exactly who it claimed to be, doing what it was authorized to do, for exactly the wrong person.Security has a 30-year-old name for a malicious, trusted actor with legitimate access: the insider threat.Human insider risk was manageable because of four universally accepted attributes of human behavior: Agents break all four. They run on shared, borrowed, even personal accounts, a pattern we see constantly in the field. They work around the clock at machine speed, so a mistake that took an employee a week now takes a second. They have no career and no fear of being fired; when an agent apologizes, the apology is output, not remorse. CrowdStrike CEO George Kurtz now predicts 90 agents per human employee by 2027. Our agentic co-workers are here to stay, and they are gullible by design.The thing is, we can't recruit human employees with a paragraph of text, but we can recruit an agent with one. We can also use a poisoned web page, a doctored README, or a stray comment in an email thread, making every attacker on the internet a potential handler.At one large technology company, we found an internally built agent that any Slack message could trigger, with no sender authentication, able to open pull requests across nearly a thousand private repositories.So, what works? The same disciplines that work against human insider risk, rebuilt for machine speed:Know who's inside: Every company keeps a roster of its people. Almost none keeps a roster of its agents. Inventory every agent on every laptop, in every pipeline and SaaS platform, with its permissions and blast radius attached.Know what normal looks like: Rules and system prompts are the employee handbook: necessary, and circumventable. The control that holds is behavioral. Baseline what each agent normally reads and calls and catches the moment it deviates from its own history. That's the one layer an attacker can't talk their way past.Act at the speed of the threat: We can't fire an agent mid-incident, and at machine speed, "after the fact" is too late. The dangerous action must get stopped before it executes, not discovered in a log. We ran phishing drills on people for decades; run them on the agents.Every major shift in enterprise security has eventually forced us to rethink the assumptions beneath our controls rather than the controls themselves. The cloud changed what the network was. And zero-trust changed how identity was evaluated. Agentic systems are forcing another shift. Identity is still essential, it just isn't sufficient when one trusted identity can represent hundreds of autonomous actors making thousands of decisions every hour.Either way, the challenge goes beyond hardening software and systems. It's about governing a workforce that doesn't have a pulse.Dor Sarig, co-founder and CPO, Pillar SecuritySC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Each contribution has a goal of bringing a unique voice to important cybersecurity topics. Content strives to be of the highest quality, objective and non-commercial. - One person meant one identity, so we knew who did what. - People work at human speed, so damage took time, and time gave defenders a window. - People have skin in the game, careers and reputations that shape behavior long before any control does. - People behave in patterns, making anomaly detection possible.

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.