# Cisco Secures the Agentic Workforce: What NHI Governance Means for Enterprise Security


Cisco has announced a strategic pair of acquisitions designed to address one of enterprise security's newest and most overlooked vulnerabilities: the rapidly growing fleet of non-human identities (NHIs) deployed across corporate infrastructure. With agreements to acquire Astrix Security and WideField Security, Cisco is placing a calculated bet that managing AI agents and their digital identities will become the foundation of modern security architecture — shifting the control plane from networks and endpoints to identity itself.


The timing reflects an urgent reality. As enterprises accelerate AI agent deployment to automate everything from API orchestration to security operations, these autonomous systems now possess human-level access privileges while operating completely outside the identity and access management systems designed to protect them. For most organizations, this represents a critical blind spot: no visibility, no governance, and no accountability for what could be the most privileged accounts in their infrastructure.


## The Growing Scope of AI Agent Deployment


The scale of this challenge is expanding rapidly. According to a recent Deloitte survey of over 3,000 business and IT leaders, approximately 25% of enterprises currently report using agentic AI in some operational capacity. More striking: that figure is projected to reach 74% within the next two years, representing one of the fastest technology adoption cycles in enterprise history.


This acceleration has caught most security teams off guard. Unlike human users, who are typically enrolled in identity management systems with role-based access controls, multi-factor authentication, and activity logging, AI agents and their associated non-human identities often bypass these protections entirely.


Common NHI types include:

  • API keys and service accounts
  • OAuth applications and machine-to-machine (M2M) credentials
  • Automation service accounts
  • Scheduled job runners
  • CI/CD pipeline credentials
  • Third-party integration identities

  • Most organizations lack any centralized inventory of these identities, let alone controls governing their permissions or monitoring their behavior.


    ## What Are Non-Human Identities, and Why Do They Matter Now?


    Non-human identities represent a fundamental shift in how privilege flows through modern systems. Unlike human users who authenticate once and then operate within defined roles, NHIs often maintain persistent credentials with standing privileges. An AI agent executing financial transactions, provisioning cloud infrastructure, or managing customer data may have been granted broad permissions months ago — and no one is monitoring whether it's operating within intended bounds.


    The security implications are severe:


    | Risk | Impact |

    |------|--------|

    | Compromised API keys | Direct access to production systems without triggering human authentication logs |

    | Privilege creep | Agents granted "temporary" elevated permissions that are never revoked |

    | Orphaned credentials | Service accounts tied to discontinued projects that remain active and privileged |

    | Supply chain exposure | Third-party integrations with standing access to critical infrastructure |

    | Lateral movement | Compromised agent credentials used as pivot points for broader network infiltration |


    The problem is compounded by the fact that traditional SOCs (Security Operations Centers) have no framework for monitoring NHI behavior. Most SIEM platforms and security alert systems are tuned to detect anomalies in human user activity. An AI agent behaving differently — executing thousands of API calls in seconds, operating at 3 AM, or accessing systems it's legitimately entitled to use — registers as normal rather than suspicious.


    ## Cisco's Strategic Acquisitions: Addressing the Blind Spot


    Cisco's two acquisitions represent a deliberate strategy to embed NHI governance across its security portfolio.


    ### Astrix Security: Discovery and Governance


    The first acquisition, announced last month, targets Astrix Security, an early-stage startup specializing in discovering and governing non-human identities and AI agents. Astrix's core capability addresses the foundational problem: most organizations don't have a complete inventory of their NHIs.


    Astrix's approach combines:

  • Passive discovery across cloud infrastructure, repositories, and application configurations
  • Credential scanning to identify exposed API keys and secrets
  • Access governance frameworks to assign appropriate permissions to each NHI
  • Lifecycle management to deprovision unused credentials and agents

  • ### WideField Security: Identity and Session Intelligence


    The second acquisition, announced last week, brings WideField Security into the fold. WideField extends identity governance into the operational layer, adding session intelligence and behavior correlation across human and non-human identities.


    WideField's distinguishing feature is its integration with Splunk, allowing security teams to normalize identity, session, and activity telemetry from disparate sources. This enables SOCs to answer critical questions:

  • Is this agent operating within historical behavior patterns?
  • Which humans or systems provisioned this credential, and when?
  • What cascading effects might result from revoking this credential?
  • Which agents have the most sensitive access, and how are they being monitored?

  • ## The Identity-First Control Plane: A Paradigm Shift


    The strategic thesis underlying both acquisitions reflects a fundamental rethinking of enterprise security architecture. Rather than asking "Where is the request coming from?" (the network-centric question), Cisco and other platform providers are shifting to "Who or what is making this request, and should they be allowed?"


    This represents a shift to identity as the primary control plane — the foundational layer on which all other security decisions rest.


    In practice, this means:


    1. Complete identity inventory: Every human, every service account, every API credential, every AI agent must be enumerated and tracked

    2. Continuous identity verification: Rather than one-time authentication, ongoing proof that identities are operating within authorized parameters

    3. Behavioral correlation: Normal behavior baselines established for each identity, with deviations triggering investigation

    4. Risk-based access: Permissions dynamically adjusted based on identity type, current context, and organizational risk tolerance


    ## Industry Context: Why Now?


    Cisco is not pioneering this market alone. Other major security platforms — including Okta, CrowdStrike, Microsoft Entra, and SentinelOne — are simultaneously expanding into NHI governance. This convergence suggests that identity-centric security is becoming the new table stakes for enterprise platforms.


    The convergence also reflects a painful lesson from recent breaches and security incidents: many of the most damaging incidents have involved compromised API keys, service accounts, or machine credentials rather than stolen human user credentials. The 2024 MOVEit Transfer vulnerability, which exposed hundreds of organizations' data, was weaponized primarily through automated credential-based attacks. Similarly, most major cloud compromises involve overly permissioned service accounts.


    Organizations that have experienced breaches increasingly report that their incident response process was hampered by the lack of visibility into non-human identity usage and permissions.


    ## Implications for Enterprise Security Teams


    For most security organizations, the Cisco acquisitions signal an industry shift they need to prepare for:


    Immediate actions:

  • Conduct a complete audit of existing API keys, service accounts, and machine credentials — most organizations will be shocked at the scale
  • Implement secret rotation policies (currently, most organizations have no formal process for rotating API keys)
  • Map which human personnel have the ability to provision or modify NHIs (often scattered across development, DevOps, and platform teams with no centralized governance)

  • Medium-term strategic work:

  • Evaluate IAM platforms that include NHI governance as a native capability
  • Develop monitoring and alerting rules specific to agent behavior rather than repurposing human user baselines
  • Establish access review cycles that include non-human identities — currently, many organizations review human access quarterly but never review agent credentials

  • Organizational restructuring:

  • Create accountability for NHI governance — this function often falls between DevOps, Security, and Platform teams with no clear owner
  • Develop naming and tagging standards for NHIs that allow rapid triage and access decisions
  • Build incident response playbooks that address compromised agents, which operate differently than compromised human accounts

  • ---


    ## HackWire Analysis


    The Cisco acquisitions underscore a critical reality: the enterprise security industry has been managing today's threats with yesterday's frameworks. For two decades, IAM and SIEM platforms were designed for human users operating within discrete roles during business hours. The agentic AI wave has introduced a new class of actor — one with human-level privileges, inhuman speed, and no natural fatigue or accountability constraints.


    What makes this moment particularly acute is the velocity of adoption. A 49-point jump in agent deployment over two years (from 25% to 74%) means most security teams will face this problem having never managed NHI governance at scale. This is a migration problem similar in scope to the cloud transition, but with even less industry consensus on best practices.


    The broader pattern is also worth noting: every major security platform provider is rushing into this space simultaneously, which typically indicates that a new security category is calcifying into a mandatory capability. Just as endpoint protection, network segmentation, and cloud identity became non-negotiable over the past decade, NHI governance is likely to become a compliance expectation within 18-24 months. Organizations that haven't inventoried their NHIs before that transition will face both increased security risk and significant remediation overhead.


    The hidden risk that most reporting is missing: the gap between technical capability and organizational readiness. Cisco is acquiring the tools to see and govern NHIs, but most enterprises lack the operational maturity to use them effectively. This creates a window of vulnerability where organizations deploy these tools but fail to integrate them into their access review cycles, incident response procedures, and governance structures. The result: visibility without control, which creates a false sense of security.


    — *HackWire Editorial*


    ---


    ## Related Coverage


  • Read more in our [Security Operations](https://www.hackwire.news/category/security-operations) coverage
  • Cross-reference with [Identity & Access Management](https://www.hackwire.news/category/identity-and-access-management) and [Cloud Security](https://www.hackwire.news/category/cloud-security)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)