COMMENTARY: Picture the organization's identity infrastructure as a sprawling metropolis where human users, service accounts, AI agents, and cloud workloads all hold keys to different buildings – except no one has a complete map of who has access to what, or which keys can unlock the most critical assets.Under those circumstances, building a cross-domain defense strategy has become essential given that identity has become the new perimeter.[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]If the last decade reinforced anything, it's that security starts with identity, and privileged identities sit at the blast-radius center.Today's identity security environment has evolved into a fast-moving tangle of human, machine, cloud, and Agentic AI identities, all making real-time access decisions across hybrid environments. Each identity may possess privileges, permissions, and entitlements – including ones that are exceedingly hard to see or understand – creating access routes to assets and resources that are often even harder to detect.During the holidays, identity chaos peaks. While employees sign in from airports, use guest Wi-Fi, and work odd hours, threat actors seize on this distraction and exploit lean IT teams. Businesses must now have unified visibility, consistent identity policies, and automated responses in place to catch threats before they spread.As automation and cloud-native patterns have proliferated, non-human identities (NHIs) – service accounts, workloads, agents, pipelines – now outnumber human identities by many multiples. This exponential growth, paired with "secrets sprawl" where credentials are scattered across code, configurations, and CI/CD pipelines, creates a perfect recipe for account hijacking, privilege escalation, and lateral movement.While NHIs, including AI agents, offer tremendous productivity potential, they also multiply the risk surface. Security best practices for NHIs are falling behind – a reality that’s not unexpected during phases of fast-emerging technological innovation, but one that is becoming increasingly dangerous as threat actors sharpen their exploitation techniques.Three gaps that undermine enterprise securityYears of working with enterprise security teams has revealed three predictable identity security gaps:Build a cross-domain defense strategyLeading organizations are moving beyond fragmented point tools to implement cohesive identity security strategies. Here's how to build an effective approach:1. Implement Comprehensive Discovery and ModelingMap not just "who" but "what" (services, agents, pipelines) and where permissions combine into exploitable paths. Deploy AI/ML intelligence layers to understand the full picture of identity access patterns. And, establish continuous asset discovery that spans cloud, on-premises, and hybrid environments.2. Unify Control MechanismsConsolidate privileged account management, secrets management, JIT elevation, and least privilege management under consistent policies. Extend these same policies to govern cloud entitlements and AI agents. And, streamline policy management across platforms and domains to reduce administrative overhead and gaps.3. Automate Response and RemediationWhen anomalous privileged behavior gets identified, automate fixes like token expiration, secret rotation, session termination, and access control tightening. Ensure visibility seamlessly translates into mitigations through integrated control planes. And, implement feedback loops that continuously measure and reduce residual risk.4. Establish Continuous ValidationTrack metrics like over-entitled identities, stale credentials, and shadow admins. Demonstrate risk reduction trends quarter over quarter. And, regularly test detection and response capabilities across all identity types.The path forward requires treating the entire identity estate as one singular attack surface. This means achieving visibility and control from Active Directory to Okta, from Azure to Google Cloud, and from GitHub to Salesforce. Identity security intelligence must flow cleanly across boundaries, enabling you to understand, share, and act on risk holistically.This unified approach can result in continuous, measurable risk reduction across human and NHIs, cloud and on-premises infrastructure – even as the company’s IT footprint expands and the organization embraces new technologies.In an era where identity is the new perimeter, can security teams afford to manage it any other way?Kyle Benson, senior director of product marketing, BeyondTrustSC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Each contribution has a goal of bringing a unique voice to important cybersecurity topics. Content strives to be of the highest quality, objective and non-commercial.
- Visibility: Point tools see different fragments – sessions, secrets, cloud roles, and single domains. Without a unified identity graph, toxic combinations slip through. Our Identity Security Risk Assessment uncovered dormant service accounts with privilege in over 70% of environments – evidence that discovery and rotation aren't closing the loop when tools operate in isolation.
- Policy: Managing hybrid environments with different toolsets administered by different teams results in policy inconsistencies and continual drift. A user might have just-in-time (JIT) access in Windows and Azure but maintain unnecessary persistent privileges in VMware or ServiceNow. Privileged credentials might be centrally managed across endpoints while DevOps secrets and CI/CD processes are left to individual teams – if managed at all.
- Response: When something gets detected but not appropriately acted upon, critical mitigation steps fall through the cracks. One system might rotate secrets while failing to revoke or tighten access. Other tools might detect activity that appears isolated because the tools themselves are isolated, missing the bigger picture of a coordinated attack.





