Cisco Spends Around $400 Million to Plug a Growing Security Blind Spot: AI Agents
Two rapid-fire acquisitions, Astrix Security and WideField Security, are Cisco's answer to a question most companies haven't thought to ask: who's watching the bots?

Key points
- Cisco agreed to acquire Astrix Security for a reported $400 million to secure non-human identities, digital credentials like API keys used by software rather than people.
- A second deal, WideField Security, follows weeks later and adds session-level tracking of human, machine, and AI-agent accounts inside Cisco's Splunk monitoring platform.
- A 2025 Deloitte survey of over 3,000 business and IT leaders found roughly one quarter already use AI agents; that figure is expected to reach 74% within two years.
- Most AI agents sit outside the security controls companies use to manage employee accounts, leaving a gap attackers can exploit.
- Analysts describe the acquisitions as closing a targeted gap in Cisco's identity security portfolio while extending its ability to detect threats tied to non-human identities.
Companies are deploying AI agents, software programs that act on instructions without a human clicking each step, faster than their security teams can keep up. These agents need credentials to do their jobs: API keys (a kind of digital password that lets one software system talk to another), service accounts (logins assigned to automated processes rather than people), and OAuth tokens (a type of permission slip that lets an app act on a user's behalf without seeing their password). Security professionals call these non-human identities, or NHIs.
Most companies manage employee accounts carefully, requiring passwords, multi-factor checks, and regular reviews. NHIs get almost none of that. They sit outside standard security tooling, often with sweeping access to critical business systems, and nobody is watching them.
How did Cisco's security stack end up with this gap?
Cisco's existing Zero Trust architecture, a security model built on the principle that nothing inside or outside a company's network should be automatically trusted, was designed around human users. Automated agents simply weren't part of the picture when those foundations were laid. The company has now made two acquisitions in quick succession to close that hole.
First came Astrix Security, a five-year-old startup that built a platform to find every NHI and AI agent inside an organisation, map what each one can access, and flag unusual behaviour. Published reports, first noted by Dark Reading, put the price at approximately $400 million. Astrix works by learning the normal patterns of each credential, which systems it touches and how often, then raising an alert when something deviates from that baseline.
Then came WideField Security. Cisco announced that deal last week, though financial terms were not disclosed. WideField adds what its makers call session intelligence: a continuous record of what each identity, human employee or AI agent, actually does during a given session. Cisco plans to fold this into Splunk, its security monitoring platform, so analysts can see a joined-up picture of activity across all identity types in one place. We covered the WideField deal on 19 June in "Cisco Acquires WideField Security to Wire Identity Intelligence Into Splunk's Agentic SOC".
Kamal Hathi, general manager of Cisco's Splunk business unit, wrote in a blog post that the integration will let Splunk "assemble context across human, non-human, and AI-agent activity" by pulling in signals from Cisco's own Identity Intelligence product.
The broader ambition is to shift how access decisions get made. Rather than asking where a request is coming from, a traditional network-based check, the platform asks who or what is making it, and whether that behaviour looks normal.
Chris Steffan of Enterprise Management Associates called NHI governance "the conspicuous gap in Cisco's agentic SOC narrative" (SOC stands for Security Operations Centre, the team responsible for monitoring and responding to threats). Forrester Research analyst Geoff Cairns described the acquisitions as closing "a targeted gap" while extending Cisco's ability to detect threats tied to non-human identities.
Cisco isn't alone here. Palo Alto Networks, CyberArk, Delinea, and ServiceNow have all moved into NHI management over the past two years. The market is moving because the underlying risk is real and growing. Our piece from 26 June, "Guardian Agents and the Identity Layer That Doesn't Exist Yet", made precisely this point: the IAM stack wasn't built for agents inheriting human permissions at machine speed, and the governance gap is widening faster than vendors are closing it.
The honest read on these two deals is that Cisco is buying time. Neither acquisition solves the cultural problem, that most security teams still don't know how many automated credentials their organisation has issued, let alone what those credentials are doing.
Should you worry if your company uses AI agents?
Yes, and the first step costs nothing. Make an accurate list of every automated credential in your environment. Many organisations can't. Check what each one can access: credentials with more access than they need are a gift to anyone who steals them. Set up alerts for unusual behaviour, because a service account that starts downloading files at 3 a.m. Warrants a look. Rotate credentials on a regular schedule so a stolen key has a limited useful life.



