Who's inside your network? Why identity is cybersecurity's critical frontier

As AI adoption grows, Australian authorities emphasize accountability, oversight, and identity controls

About the Author

Mathew Graham

Chief Security Officer, Asia Pacific

Mathew Graham is the Chief Security Officer (CSO) for Asia Pacific at Okta, where he leads the regional security strategy. He is focused on helping organizations navigate the complexities of AI and rising cyber threats by advancing phishing-resistant authentication, identity governance, and security posture management. With over 20 years of experience spanning government, cloud, and enterprise SaaS security, Graham works to strengthen digital trust, emphasizing that Identity remains the constant in securing people, systems, and "digital colleagues." 

30 July 2026 Time to read: ~

For decades, cybersecurity focused on keeping bad actors out of a network. Now, the challenge is knowing what an organisation’s artificial intelligence is doing on the inside. 

While there is no doubt that protecting systems from compromise remains critical, the environments organisations are securing today look very different from those of even a few years ago. This critical shift is driving a wave of warnings from global cybersecurity authorities.

Global cybersecurity authorities warn of AI-driven security risks

The Five Eyes (FVEY), an alliance of intelligence entities from Australia, the US, UK, Canada, and New Zealand, have called on leaders to prepare for the changing cyber risk landscape created by AI. The Australian Signals Directorate (ASD) has strengthened its guidance around secure software development and AI-enabled systems through updates to the Information Security Manual (ISM). The Australian Cyber Security Centre (ACSC) has released guidance on the careful adoption of agentic AI services.

Most recently, ASD announced plans to transition beyond the Essential Eight—a framework of cyberthreat mitigation strategies—towards a broader "Essentials" series covering enterprise IT, cloud, operational technology, and potentially agentic AI.

While each initiative addresses a different aspect of cyber security, they all point to the same underlying challenge: Who, or what, is authorised to do what inside an organisation?

The number of non-human identities is growing

Applications communicate directly with other applications. Machine identities authenticate and exchange information across systems. Automated processes execute business workflows without human intervention. AI-powered systems are increasingly interacting with sensitive information and making decisions that influence business outcomes.

The number of identities operating inside organisations is growing rapidly, and many of them are no longer human. Industry estimates indicate that non-human identities already outnumber human identities by as much as 45 to 1 in some enterprise environments.

This shift changes how organisations need to think about cyber resilience. Historically, security teams focused on users, devices, and networks. Increasingly, they also need visibility into a growing ecosystem of applications, services, machine identities, and AI-powered systems operating across their environment.

Key questions organisations must answer about identity and access

That raises a new set of governance questions:

  • Do we know what identities exist in our environment?

  • What systems, applications and data can they access?

  • Why was that access granted?

  • Who is accountable for it?

  • And can it be modified or removed when circumstances change?

These are no longer purely technical questions.

Securing agentic AI: A practical framework

A secure agentic enterprise establishes clear accountability and visibility before agents scale. Okta's blueprint for the secure agentic enterprise outlines the identity and access controls needed to safely adopt agentic AI while maintaining visibility and accountability.

Identity management as a core security strategy

The recent Five Eyes guidance highlights the importance of strengthening identity and access controls as AI increases the speed and sophistication of cyber threats. The ACSC's guidance on agentic AI emphasises ownership, accountability, and oversight before autonomous systems are deployed at scale. The ASD's latest ISM updates reinforce the importance of building security into systems from the outset rather than attempting to address risk later.

Together, they reflect a broader shift underway across the industry. Cyber resilience is now less about managing individual technologies and more about governing access across increasingly complex environments.

Identity sits at the centre of that challenge, providing the context organisations need to understand who, or what, is operating within their environment, what resources they can access and what actions they are authorised to perform. It creates accountability across both human and non-human identities and provides a foundation for governance as environments continue to evolve.

How organisations can adopt AI without compromising security

This isn't about slowing innovation. AI, automation and machine-driven processes will continue to create significant opportunities for organisations. The challenge is ensuring governance evolves alongside the technology.

As organisations adopt more AI-powered systems, applications, and automation, cyber resilience will increasingly be measured by their ability to maintain visibility, accountability and control across a growing mix of human and non-human identities.

This common thread running through the latest guidance from the Five Eyes agencies, ASD, and ACSC signals what organisations should prioritise: establishing identity governance frameworks that support secure AI adoption, innovation, and operational resilience. 

About the Author

Mathew Graham

Chief Security Officer, Asia Pacific

Mathew Graham is the Chief Security Officer (CSO) for Asia Pacific at Okta, where he leads the regional security strategy. He is focused on helping organizations navigate the complexities of AI and rising cyber threats by advancing phishing-resistant authentication, identity governance, and security posture management. With over 20 years of experience spanning government, cloud, and enterprise SaaS security, Graham works to strengthen digital trust, emphasizing that Identity remains the constant in securing people, systems, and "digital colleagues." 

Get our Identity newsletter

Okta newsletter image