The Growing Risk of Unsecured Machine Identities: From Enterprise Blind Spots to National Concern
They Are Needed, Sure, But They Need to Be Monitored Vigilantly as Well

Cybersecurity conversations in boardrooms have generally revolved around people—employees, contractors, and customers—and how best to control their access to systems and data. But there is now a fast-emerging identity population that do not belong to people but need to be accounted for nonetheless. These are machine identities, and are becoming disruptors in this digital age.
But what, exactly, are machine identities?
Ssu Han Koh, Solutions Engineering Director at Cyber Ark, defined machine identity to Cybersecurity Asia as “the digital credential that allows non-human entities, such as applications, containers and devices, to authenticate and securely communicate within an enterprise ecosystem or even across enterprises as part of their business needs.” These identities, according to Koh, are just like humans who use usernames and passwords, as these machines rely on certificates, SSH keys, and tokens to prove who they are.”
Machine Identities Now Outnumber Human Identities
Tellingly, machine identities have grown at such an unprecedented rate that they now outnumber human identities 82:1, according to the CyberArk 2025 Identity Security Landscape study. But the growth of machine identities in the digital footprint of every organisation is necessary as these are the backbone of automation and are critical in securing cloud workloads and Artificial Intelligence (AI) systems.
But, as with most things innovation-related, the rise of machine identities is a double-edged sources as they can be exploited without proper governance, in turn leading to unauthorised access, data breaches, and operational disruption. Even worse, some 42% of machine identities are either the privileged kind or have some level of sensitive access, and this is why it is now a business imperative to safeguard these machines at all costs.
“Unlike human identities, which are relatively static and governed by HR processes, machine identities are dynamic, ephemeral, and often created automatically. The risks are different too: compromised machine identities can allow attackers to silently move laterally across networks, bypassing detection,” Koh pointed out. “In today’s AI-driven landscape, where machines make decisions and execute tasks autonomously, securing their identities is foundational to trust, compliance, and resilience. This is why its imperative for enterprises to look at securing their machine identities now.”
Again, that’s a lot of identities to secure given how machine indentities now outnumber their human counterparts. This imbalance is not just a technical footnote. It is a structural shift that is redefining the attack surface of the modern enterprise—and one that governments are beginning to recognise as a matter of national cyber resilience.

Why Machine Identities Matter More Than Ever
The rapid proliferation of machine identities is a direct consequence of digital transformation. Cloud-native architectures, DevOps pipelines, containerisation, and AI systems all depend on machines that authenticate, communicate, and act autonomously. In these environments, machine identities are not peripheral—they are foundational. They underpin automation, enable scalability, and allow AI systems to function at speed. And this crucial role is likely the reason machine identities aren’t being talked about much in board rooms and cybersecurity meetings.
“Machine identities are quickly becoming one of the most overlooked cybersecurity threats. In today’s AI-driven environment, machines—whether APIs, containers, bots, or autonomous agents—are constantly exchanging data, making decisions, and accessing sensitive systems. Yet many of these identities are created automatically, live only briefly, and often go unmanaged. This creates a perfect storm for attackers,” explained Koh.
For attackers, in particular, the lack of focus on machine identities represents an opportunity. Compromised machine identities can be exploited quietly, allowing adversaries to impersonate trusted systems, move laterally across networks, and access sensitive data without triggering traditional security alerts. Unlike compromised user accounts, these breaches often unfold silently, untracked most of the time but doing plenty of damage all the while.
AI and Its Amplifying Effect
The rise of AI has further heightened the stakes. In today’s AI-driven landscape, machines are no longer just executing predefined instructions. APIs, containers, bots, and autonomous agents are exchanging data, making decisions, and interacting with critical systems at scale. As enterprises move towards agentic AI—where systems operate with increasing autonomy—machine identities gain access to broader and deeper pools of privileged information.
Yet many of these identities remain poorly governed. Hardcoded secrets, expired certificates, and a lack of credential rotation continue to plague enterprise environments. These weaknesses are not theoretical. The industry has observed a rise in access broker activity on the dark web, specifically targeting machine credentials. Once stolen or misconfigured, these identities allow attackers to bypass defences that were designed primarily with human users in mind.
Without strong governance, organisations risk losing visibility into who—or what—is operating inside their digital environment. In an era where machines increasingly act on behalf of the business, that loss of control carries profound operational and reputational consequences.

From Enterprise Risk to National Concern
Perhaps more worryingly, machine identities now underpin even critical services, which means the issue extends beyond individual organisations. Governments are now confronting the reality that national infrastructure—from financial systems and healthcare platforms to transport and energy grids—relies heavily on machine-to-machine communication. A breach involving compromised machine credentials, therefore, could disrupt essential services at scale—and to sometimes catastrophic levels. This is why elevating machine identity security to a national cybersecurity mandate is becoming both logical and necessary.
“Elevating machine identity security to a mandate would establish consistent standards, accountability, and resilience across sectors, like how data privacy laws like GDPR reshaped enterprise behaviour,” Koh pointed out. “Some good initiatives are already in place. For example are The Cyber Security Agency of Singapore (CSA) released Guidelines and Companion Guide on Securing AI Systems.”
Taken together, these measures could minimise, if not completely eliminate, the adverse impact and inherent dangers of a growing machine identity population—particularly on critical infrastructure and vital services.
What This Means for Enterprises
While the rise of machine identities are very much a national concern, private enterprises need to be just as vigilant about it. It is no small task, to be clear, according to Koh as nearly half of organisations lack complete visibility into entitlements and permissions across their cloud environments. Moreover, 70% identify organisational silos as a root cause of risk. Addressing machine identity security, therefore, requires both new security tools and structural changes.
Companies need to take a proactive, structured approach,” Koh recommends. The first step is gaining full visibility into all machine identities across cloud, on-prem, and hybrid environments. This includes certificates, SSH keys, API tokens, and service accounts.”
“Companies should implement centralised lifecycle management to automate the issuance, rotation, and revocation of machine credentials. This approach helps eliminate common vulnerabilities such as hardcoded secrets and expired certificates, which remain frequent entry points for attackers,” added Koh. “To align with evolving national cybersecurity mandates —like Singapore’s Smart Nation strategy or the EU’s NIS2 Directive—organisations should adopt globally recognised frameworks, including NIST SP 800-207 for Zero Trust Architecture, ISO/IEC 27001 for Information Security Management, and CIS Controls v8 for Identity and Access Management.”
The challenge becomes more complicated for organisations that operate across multiple jurisdictions. National cybersecurity standards are evolving at different speeds, with varying requirements around certificate lifetimes, data handling, and auditability. To navigate this landscape, Koh recommends that companies adopt a unified policy framework that can accommodate regional variations without sacrificing global consistency.
But all that begins with full visibility where all machine identities across cloud, on-premises, and hybrid environments are catalogued consistently. From there, centralised lifecycle management becomes essential, automating credential issuance, rotation, and revocation to eliminate common vulnerabilities. Aligning with globally recognised frameworks such as NIST SP 800-207, ISO/IEC 27001, and CIS Controls v8 provides a common language for compliance, even as local mandates differ.
Crucially, machine identity governance must be embedded into DevOps and CI/CD pipelines so that every new workload is secure by design. Treating machine identity as a board-level issue—integrated into risk, compliance, and digital transformation strategies—is what separates resilient organisations from reactive ones.
Building Trust in a Machine-Led World

As digital ecosystems become increasingly machine-driven, trust hinges on identity. CyberArk’s role in this evolving landscape is to provide the visibility, automation, and governance required to secure machine identities at scale. Whether it is a container spinning up in a Kubernetes cluster, an API accessing sensitive data, or an AI agent making autonomous decisions, the objective is the same: ensuring that every machine identity is authenticated, authorised, and governed according to policy.
“CyberArk is uniquely positioned to equip organisations in meeting this challenge. Our Machine Identity Management and Secrets Management solutions provide the visibility, automation, and governance required to secure non-human credentials at scale,” Koh explained. “Whether it is a container spinning up in a Kubernetes cluster, an API calling sensitive data, or an AI agent making autonomous decisions, we ensure that every machine identity is authenticated, authorised, and managed according to policy.
Meeting this challenge, not coincidentally, is critical to moving ahead, especially in the hyper-competitive Asia Pacific region, where regulatory frameworks are evolving rapidly. Put simply, securing machine identities without slowing innovation is no longer a competitive advantage but a necessity, according to Koh.
The ultimate goal, therefore, is to build resilience and trust in a machine-led world. That’s because when machine identities are secure, everything else, from infrastructure to AI, can operate safely and confidently.



