#identity and access management
8 stories taggedidentity and access management.

New US Government Token Security Guide Leaves AI Agents in a Grey Zone
NIST and CISA have published fresh guidance on protecting the digital passes that systems use to grant access. It is solid work, but it sidesteps the hardest problem: nobody yet agrees how much to trust an AI agent holding a perfectly valid pass.

Microsoft Makes Passkeys the Default Login for Business Accounts. Passwords Aren't Dead Yet.
From September 2026, Microsoft's business identity system defaults to passkeys instead of passwords. But the shift will take years, and most companies will run both systems side by side for a long time.

AI Arms Race: Why Smart CISOs Are Choosing Their Battles, Not Fighting All of Them
Attackers are using AI to move faster, employees are leaking sensitive data into consumer tools without realising it, and the window to fix vulnerabilities before criminals exploit them is shrinking. Here is what security leaders should actually prioritise.

Cyera Buys Oasis Security for $1 Billion to Rein In AI Agents Before They Run Wild
Two Israeli-founded security firms are merging to solve a problem most companies haven't fully noticed yet: AI agents that grab every permission they're given and never let go.

Your Security Team Is Flying Blind on AI. Here Is Why.
The tools built to catch hackers and bad code were designed for a world where humans made every decision. AI agents don't ask permission, and your defences weren't built to watch them.

What is zero trust? A plain-English guide
Zero trust means your network stops assuming anyone inside it is safe, and checks every user and device every single time.

AI Agents Are Taking Over Enterprise Systems. Nobody Knows Who They Are.
A four-hour outage. A room full of people who couldn't say which human authorized the last action. A new six-stage model explains why AI agents are breaking identity security, and what it takes to fix it.

12 Questions That Expose Whether Your Security Program Is Actually Working
Hard questions CISOs should already be asking, about blast radius, nonhuman identities, and whether vibe coding has eaten your attack surface.