Enterprises spend an average of 11 person-hours resolving a single identity security-related alert, according to research from Enterprise Strategy Group. The cumulative effect on security teams is tough, creating bottlenecks, draining team capacity, and increasing workload pressure.

You might be thinking, “how did we end up here?” The answer: the growing number of “borders” that security teams need to defend, and the lack of visibility across these technology silos.

So the question becomes: what can organizations do to improve their visibility across tech borders and minimize the risk of attack?

The identity dilemma

These borders include every point where users, applications, or systems interact with infrastructure – cloud platforms, developer tools, identity providers, on-premises systems … the lot. Most cybersecurity tools provide visibility within a defined domain. However, when an identity moves between environments (say, from on-premises systems to cloud services), security teams often lose full context of its activity, leaving visibility gaps that attackers can exploit.

Think of it this way: identity management today resembles an archipelago of islands. Each island (system) has its own rules and passport checks, but there’s no unified coordination or control across the region. For customs officers (security teams), it’s practically impossible to track who’s moving between islands – enabling a malicious identity to easily slip through unnoticed.

To understand why tech borders are so hard to defend, we need to think about what’s happened to identity within tech systems. Back in the day, businesses could manage identities with a handful of technologies. Today, it’s typical for every new service and platform to introduce a massive number of accounts, permissions, and policies, leaving a patchwork of fragmented identities across systems in its wake.

With these identity islands, companies are unable to answer questions about how identities are behaving. Who accessed this database and with what permissions? Is this behavior regular or unusual for this identity? What accounts still have access to production after an organization change?

The lack of visibility, understandably, invites security risks, but it also kills the productivity of engineers running infrastructure at scale, when so much time is spent answering those questions instead of doing meaningful work.

Now, once an attacker realizes it can exploit these blind spots, they don’t break in but blend in, stealing valid credentials, mimicking real behavior, and hiding in plain sight. As soon as an attacker assumes a valid identity, most traditional defenses like firewalls, antivirus, and security information and event management (SIEM) technology are useless. The front door isn’t being broken in; it’s being unlocked from the inside.

And just as security teams have started to catch on to these challenges, a new variable has entered the scene: artificial intelligence.

Is AI the straw to break identity management’s back?

Security teams are already alert to familiar inbound AI risks like AI-powered phishing or fake traffic overwhelming security operation center (SOC) teams. But a more profound shift is underway: AI agents are emerging as identities in their own right. It’s no surprise that 52% of companies now rank data privacy as their biggest AI-related risk.

The risks around AI agents are far-reaching, and there are a lot of them. Unlike traditional software, AI is unique in the sense that it can be exploited via malware and manipulation of its inputs and behavior, making it vulnerable to technical attacks and social engineering. Without strict access controls and guardrails, AI agents can be manipulated to give out sensitive information, which in turn potentially violates compliance laws or bypasses security policies altogether. Fragmented identity management creates blind spots, orphaned accounts, and inconsistent access privileges – gaps that increase the difficulty of auditing AI activity as well as the risk of breaches and compliance failures.

Fundamentally, most security strategies still focus on protecting human users (managing logins, passwords, access rights, etc.) while attackers are already exploiting the overlooked landscape of machine and AI agent identities.

A survival guide

To address these challenges, organizations need to stop thinking about perimeter-based security strategies and start focusing on making identity unstealable.

At the heart of the challenge is the misunderstanding of what identity really is. Most security strategies equate credentials (like passwords) with identity, but these can be stolen, copied, or otherwise misused. In reality, true digital identity is tied to the person it belongs to and can’t be taken. When organizations create and manage all their identities from one “source of truth,” they gain a clear and consistent view of who’s accessing what. If that identity layer is protected by strong, hardware-based encryption, each identity is securely linked to a private key, making them impossible to steal or clone.

On top of this, by issuing every identity – human, machine, or otherwise – through the same trusted system, organizations can apply the same security rules everywhere. That means giving people access only when they need it, removing standing admin rights, and continuously checking for unusual activity to spot any potential risks early.

With this kind of foundation firmly in place, security teams don’t need to manage endless individual accounts or fix problems one by one. They can operate within a consolidated, resilient infrastructure where every identity is connected and nothing falls through the cracks.

Technology will keep moving fast, and AI will accelerate the rate of change. But the organizations that take the time to rethink security around real, verifiable identity will be the ones ready to adapt and stay secure, no matter how much the digital landscape changes.