Skip navigation
AI Security

Identity security is now a business change agent

In identity security, the hardest questions often sound simple.

Who should have access? What should they be allowed to do? What happens when they change roles, leave the company, join as contractors, or create AI agents to act on their behalf?

These questions are not new, but the speed, scale, and stakes around them have changed. To better capture how identity is shifting, Cisco Duo engaged third-party research firm AimPoint Group to interview more than two dozen CISOs and security executives across industries and company sizes.

The final 2026 CISO Perspectives report shows how identity has become both a challenge and a potential change agent. Here are four key takeaways.

1. Expanding identity controls beyond authentication

Artificial Intelligence (AI) adoption has renewed urgency around identity and access management (IAM). Identity security is a top-three priority for most organizations; AI-driven business questions run through security, and nearly every important security question now runs through identity.

If you do not know who or what has access to your environment, what credentials they are using, what they can reach, and what data they are touching, you cannot make good security decisions.

For years, security and IT teams have been trying to solve this problem for human users. The joiner, mover, leaver (JML) lifecycle has always been harder than it looks: people change roles, contractors come and go, legacy systems get passed from admin to admin, and privileges silently accumulate.

In the report, security leaders identified the traditional JML lifecycle, third-party access, and non-human identities (NHIs) as contributors to identity sprawl and complexity. More than half expressed concern about managing leavers in particular. In our previous report on the State of Identity Security, we found that a significant 86% of leaders expressed concern about inadequate controls for contractors and third-party access.

CISO perspective: Lifecycle management

"Any issues with an identity usually come down to lifecycle management."

-Head of Identity Governance and Architecture, electric utility company

"A successful IAM program relies on collaboration across multiple departments and partners. It involves your security team, provisioning team, HR, management, and vendor partners working together to define and uphold appropriate processes, roles, and permissions."

-Monique Hart, CISO, Piedmont Healthcare

That lifecycle gap matters because identity risk is not limited to login. Identity security extends across the full lifecycle: enrollment, access, authorization, privilege changes, device posture, session activity, help desk flows, and eventual deprovisioning. CISOs must reduce real risk while maintaining business continuity.

2. Agentic AI turns identity sprawl into an exponential problem

Every CISO we spoke with mentioned agentic AI, and for good reason. But if you work in identity, you immediately see the second-order questions: How do we give access to agents? How do we monitor their behavior? And how do we control things like data exfiltration?

Security leaders repeatedly pointed to agentic AI as a force that could exponentially increase identity sprawl, or a rapid expansion of identities, permissions, and access paths without consistent visibility or control.

CISO perspective: Agentic AI governance

"Agentic AI is not two or three years away; it's here, and there's little governance over it."

-Head of Identity Governance and Architecture, electric utility company

"I think the agentic AI footprint, as it starts to manifest, is going to create a ton of issues for us, and nearly all of them involve identity. Because these are machine identities, there's going to be an inherent trust with the agent-to-agent communication."

-Business Information Security Officer, Product Security, data management platform provider

AI agents are not just another application category; they are autonomous actors that can query data, trigger workflows, communicate with other systems, and operate at machine speed. They may inherit credentials or touch sensitive resources in ways existing identity systems were never designed to govern.

To secure these new workflow demands, organizations need identity, access, and behavior working together. We can give agents the right tokens all day long. But unless you are in the path between the agent and the resource, you cannot enforce anything or look at the specific actions being taken in real time.

That is why leaders believe agentic AI will become a catalyst for broader security modernization, forcing organizations to address what secure access looks like while closing gaps in visibility, cleaning up overprivileged accounts, and improving lifecycle controls.

3. Legacy identity debt is now a business risk

While we’d all love to spend our time just focused on the new stuff, the reality is organizations still face existing identity infrastructure challenges.

The board wants AI, the business wants speed, and yet security must stay comprehensive. Underneath a drive for digital transformation, organizations may still be holding on to legacy identity systems, generations of service accounts, and applications with password-only systems that were never designed for the world we are moving into.

CISO perspective: Active Directory baggage

"AD has been in place for 20 years, it's a foundational piece and people are trying to move away, but there've been so many hands inside of AD that it's indecipherable, and unfortunately, you drag that baggage with you."

-CISO, ecommerce company

Active Directory and other legacy identity providers remain foundational, but they also carry decades of operational baggage. Take overused service accounts as an example. You use it for one script, then you just borrow the same service account for the next script you write—no harm done.

Now imagine that same pattern in an agentic AI environment: every agent spun up could be using the same old service account that was created years ago, with very little tracking around what it can access or why it still exists.

Modernization has to be practical. Most organizations cannot rip and replace identity infrastructure overnight. They need ways to consolidate, improve visibility, add stronger controls, and protect legacy authentication flows while keeping the business running.

Sometimes reducing risk means cleaning up traditional NHIs or extending MFA into a legacy environment. While not glamorous, this is where reducing tech debt can meaningfully reduce risk.

4. Zero Trust principles persist

CISO perspective: AI-driven phishing

"With AI, phishing is more convincing, deepfakes are more convincing, and now you can automate credential stuffing. All of a sudden it's . . . you don't sleep nights."

-Joe Russo, Vice President IT and Security, ISAAC

AI makes phishing, deepfakes, credential stuffing, and social engineering more convincing, scalable, and adaptive. It can be used to find and exploit “edge case” weaknesses in security.

One of the most important themes in the report is that CISOs are not just blindly adopting the newest controls. Rather, they are adapting existing Zero Trust principles of zero standing privileges and continuous verification to new scenarios.

CISO perspective: Measuring success

"A success is not having a breach that is attributed to an identity and recognizing that the majority of the breaches start with some sort of credential theft or credential compromise."

-Anahi Santiago, CISO, ChristianaCare

Identity modernization is not just about reducing logins or simplifying user experience, but also about building a Zero Trust identity program that can automate and adapt as AI changes both threat and defender landscapes.

Download the CISO Perspectives Report

My takeaway from the interviews is this: the organizations that move fastest will not be the ones that pretend they can skip the hard identity work. They will be the ones that build visibility, accountability, and security into identity from the start, while modernizing what already exists.

At Duo, we think about that as security-first IAM grounded in Zero Trust principles: deployable phishing-resistant authentication, identity verification at critical workflows, and tools to secure both legacy AD environments and the agentic systems emerging now.

For more CISO perspectives, head to duo.com/CISO and download CISO Perspectives: Identity is a Challenge and Change Agent in 2026 to hear from your peers on the priorities of today and what they believe will matter most in the year ahead.

Common questions about identity security in 2026

  • What is identity security?

    Identity security is the practice of verifying who or what is accessing systems, data, and applications. It includes authentication, authorization, lifecycle management, device trust, session monitoring, and deprovisioning. A strong identity security program helps reduce risk from human users, contractors, service accounts, machine identities, and AI agents.

  • How should CISOs modernize identity security?
  • How is identity security different from authentication?
  • Why does agentic AI increase identity risk?
  • How do Zero Trust principles apply to identity?