They don't break in, they log in: 79% of intrusions are malware-free

Editor’s Note: Welcome to part one of an exciting two-part story. Don’t forget to check out part two here!

Hey there, readers! Today, we’re diving into the world of generative AI and how it’s reshaping identity security. Picture this: a high-stakes battle between adversaries and defenders in the ever-evolving gen AI arms race. Adversarial AI techniques like vishing and deepfakes are on the rise, with triple-digit growth rates seen in recent security research.

According to CrowdStrike’s 2025 Threat Hunting report, vishing attacks spiked by a whopping 442% from the first half to the second half of 2024. This surge marks a significant shift in eCrime tactics, as adversaries leverage AI-driven tools to outsmart traditional security measures. The report also highlights how compromised identities are often the gateway for exploiting vulnerabilities, with gen AI playing a crucial role in this trend.

Fast forward to today, where machine identities outnumber human users by a ratio of 45:1 in the average enterprise. Attackers can move laterally in just 51 seconds, making traditional static identity management systems obsolete in the face of rapidly evolving threats.

The year 2024 saw a dramatic acceleration in gen AI capabilities, with Gartner predicting a substantial increase in information security spending. Despite growth projections being revised down to 10.7%, the research firm anticipates a steady rise in spending, reaching $213 billion in 2025 and soaring to $323 billion in 2029. Organizations are increasingly shifting towards AI-powered platforms that can adapt and respond autonomously to security threats.

Looking ahead, IDC forecasts significant growth in the Identity and Access Management (IAM) market, doubling from $23.5 billion in 2024 to $47.1 billion by 2028.

Security leaders are experiencing these shifts firsthand, with CrowdStrike’s 2025 Global Threat Report revealing that the majority of detections are now malware-free. This highlights the shift towards attackers using valid credentials to gain unauthorized access. With 90% of organizations reporting identity-related intrusions, the need for better identity management tools has never been more apparent.

Cristian Rodriguez, Field CTO, Americas at CrowdStrike, emphasizes the importance of viewing identity as the new perimeter in today’s threat landscape. With gen AI tools enabling real-time detection and response, defenders are gaining an edge in preventing lateral movement by threat actors.

Behavioral Intelligence at enterprise scale: The Cushman & Wakefield case study

Let’s take a closer look at how gen AI is making a tangible impact on identity security through a real-world example. Cushman & Wakefield, a global commercial real estate services firm, faced the challenge of securing identities across a vast network of employees operating in different time zones.

Traditional security approaches proved insufficient for their needs, leading them to adopt CrowdStrike’s Falcon Next-Gen Identity Security. This platform harnesses gen AI to create behavioral profiles for every identity, whether human, machine, or AI agent. By monitoring multiple SaaS applications simultaneously and assigning dynamic risk scores, the system can take real-time actions to address anomalies.

Service accounts that deviate from their usual behavior trigger immediate automated responses, such as modifying access privileges or enforcing additional authentication measures. This proactive approach has been instrumental in enhancing Cushman & Wakefield’s overall security posture.

According to Rodriguez, the key to next-gen identity security lies in unifying visibility and control across all identity types. By treating human identities, machine accounts, and AI agents as interconnected elements, organizations can build a robust security framework that adapts to evolving threats.

Large Language Models are revolutionizing identity governance

Traditional identity governance systems are facing challenges in keeping up with today’s cyber threats. Mike Riemer, Field CISO at Ivanti, highlights the limitations of traditional vulnerability assessment systems in accurately prioritizing risks.

Ivanti’s Vulnerability Risk Rating (VRR) leverages real-time threat intelligence to assess vulnerabilities and prioritize patching efforts. This approach has enabled organizations to patch critical vulnerabilities 85% faster, leading to improved overall security posture.

Across the industry, companies like CrowdStrike, SentinelOne, Tenable, SailPoint, ForgeRock, CyberArk, Okta, Palo Alto Networks, and Microsoft are integrating gen AI into their security solutions to enhance threat detection and identity management capabilities.

Reputation is taking this a step further by embedding identity context directly into large language models (LLMs). This approach enhances the trustworthiness of AI security solutions, particularly in industries like healthcare where data privacy is paramount.

As security leaders continue to explore the potential of gen AI in identity governance, it’s crucial to address the security implications of using LLMs. Protecting user embeddings and ensuring compliance with regulations like HIPAA and GDPR are essential steps in safeguarding sensitive identity information.

These advancements in generative AI are reshaping identity governance and vulnerability management, enabling organizations to proactively address security threats in real-time.

The vendor landscape: leaders and capabilities

Security leaders evaluating identity security vendors are met with a diverse landscape of solutions powered by gen AI. Companies like CrowdStrike, Ivanti, Microsoft, Okta, ForgeRock, Ping Identity, SentinelOne, Abnormal Security, and Arctic Wolf are at the forefront of delivering innovative security technologies.

Each vendor brings unique capabilities to the table, ranging from natural language threat hunting to AI-driven patching and proactive threat detection. CISOs must carefully evaluate vendors based on their ability to translate AI innovation into tangible operational benefits.

Measuring real ROI: Where gen AI delivers value

Gen AI is proving its worth in identity security by delivering measurable ROI in key areas that CISOs should prioritize. From reducing investigation times and excessive privileges to accelerating threat detection and minimizing false positives, gen AI is transforming security operations and driving significant cost savings.

Enterprises deploying gen AI have seen notable improvements in investigation efficiency, privilege management, threat detection speed, and alert accuracy. The data speaks for itself, showcasing how gen AI is not just a futuristic concept but a practical solution that is reshaping the security landscape.

Leave a Reply

Your email address will not be published. Required fields are marked *