Every second Tuesday in April, the tech industry pauses to shine a spotlight on one of the most foundational, and most underestimated, pillars of cybersecurity: identity management. Now in its sixth year, Identity Management Day 2026 arrives at a moment when the stakes have never been higher. The explosive growth of AI-driven attacks, the continued expansion of hybrid and multi-cloud environments, and the relentless sophistication of credential-based breaches have collectively made identity the undisputed new perimeter. It is no longer enough to simply know who is asking for access — organizations must continuously verify, monitor, and govern every identity, human or machine, across their entire digital ecosystem.
The numbers tell a sobering story. Identity-based attacks remain the leading vector in data breaches year after year, yet many organizations still struggle with sprawling, ungoverned identity infrastructure, orphaned accounts, over-privileged users, and security teams stretched too thin to keep pace. Identity Management Day exists precisely to cut through that inertia, to serve as an annual call to action for IT leaders, security professionals, and everyday users alike to reassess their identity posture, close the gaps, and embrace the principle that strong identity hygiene is everyone’s responsibility, not just the security team’s.
To help mark the occasion and capture where the industry stands heading into the second half of the year, VMblog reached out to a broad range of cybersecurity and identity management experts to gather their insights, thoughts, and best practices for Identity Management Day 2026. Here is what they had to say.
++
Kevin Murphy, Senior Product Marketing Manager, Index Engines
Identity Management Day is a reminder that digital identity is only as strong as its foundation. And data integrity validation is that foundation.
When the records tied to your identity are accurate, consistent, and verified, trust follows. But when data goes unchecked — stale credentials, unvalidated permissions, inconsistent records — the cracks appear quietly, until a breach makes them impossible to ignore.
Don’t assume your identity data is clean because it was clean once. Validate it today and build the habit of validating it always.
++
DARREN GUCCIONE, CEO AND CO-FOUNDER, KEEPER SECURITY
Identity has always been at the front line of enterprise security – and the attack surface is growing significantly larger. Every AI agent an organization deploys introduces new identities, and new risks. Most security teams don’t yet have full visibility into those identities, and that’s where attackers are focused.
The fundamentals haven’t changed: enforce least privilege, require strong authentication and monitor access continuously. What has changed is the scope. Identity security used to mean protecting people. Today it means protecting people, machines, service accounts and AI agents – all operating simultaneously, and all requiring the same rigor. Non-human identities now outnumber human identities in most enterprise environments, and they’re being targeted precisely because they’re often provisioned with excessive, static permissions and minimal monitoring.
Compromised credentials remain the most reliable path into an organization. Identity Management Day is a useful reminder that closing that path across every identity type, both human or non-human, is the most consequential investment any organization can make.
++
Alex Bovee, co-founder and CEO at ConductorOne
Identity is no longer a background IT function. It’s become the control plane for how modern work happens: the system that determines what people, applications, and AI agents can actually do.
When thousands of users are delegating work to autonomous agents, you need infrastructure that governs which tools an agent can reach, what operations it can perform, and whose authority it acts under. Without that, you don’t have an AI strategy. The organizations that treat identity as a living, responsive layer rather than a login system will be the ones that let AI deliver real value without creating unnecessary risk.
++
Mark Wojtasiak, SVP Product Research & Strategy at Vectra AI
Identity has become the control plane of the modern enterprise, yet most teams still treat it like a gate instead of a signal. As non-human identities outnumber people, and attackers simply log in instead of break in, misuse isn’t the exception – it’s expected.
The reality is that identity management comes down to the ability to continuously answer critical questions: Who is doing what on our network? Are we exposed – which really means who or what has access to what, and should they? Are we under attack, meaning is someone or something doing something they shouldn’t? Are we safe and compliant? And can we confidently explain what’s happening as it happens?
If you can’t answer these questions clearly, identity management becomes impossible.
++
Ravi Soin, CIO/CISO at Smartsheet
Organizations that treat AI identity seriously, making every agent action traceable and auditable, will be the ones that scale safely. That’s how governance stops being a bottleneck and becomes a business accelerator.
Building an enterprise-ready platform starts with a strong security foundation—especially in work management environments where teams, tools, and integrations are constantly exchanging data. Every interaction requires trust, and that trust starts with identity. When we can confidently verify who and what is accessing your systems, we protect sensitive data without slowing teams down.
The harder challenge now is governing AI agents and non-human actors with the same rigor we apply to people. Attackers have already identified this as the next point of entry. Service-based workloads running across cloud environments often carry elevated privileges with limited oversight, that exposure is real, and securing it isn’t optional.
++
Vibhuti Sinha, Chief Product Officer, Saviynt
AI is forcing a hard truth on identity security teams: it is both an efficiency accelerator and a major security risk. On one hand, AI is transforming identity programs by accelerating workflows through intelligent automation, surfacing risks faster, and compressing time-to-value from months to hours. On the other hand, it introduces a new class of identities (agents, copilots, and orchestration platforms that operate autonomously at machine speed) that must be governed with the same (if not greater) rigor as humans.
Many enterprises are now realizing that traditional identity programs don’t hold up in the AI era. Addressing this challenge requires more than any single approach. It’s not just identity governance, visibility, just-in-time access, or access control alone. All of these systems must work together.
My number one piece of advice to leaders navigating the challenge of securing and governing AI identities: don’t treat it as a tooling decision, but as a control plane shift. If you want to harness AI for real productivity gains while keeping AI agents secure and controlled, identity must be the foundation.
++
Dany Naigeboren, Senior Director, Risk, Forter
Amid advancements in AI, identity has become the foundation of digital commerce. As machine and agentic identities rapidly outnumber human ones, the challenge has shifted from simply verifying users at a single point in time to continuously identifying genuine users and establishing trust across the entire customer journey. In this environment, even legitimate AI agents and malicious bots can appear indistinguishable without a deeper, more holistic view of identity.
To keep pace, organizations must adopt a more dynamic, context-driven approach, one that connects behavioral, device, and network signals to build a real-time picture of identity in motion. This shift is critical not only for mitigating increasingly automated threats, but also for preserving trust and enabling seamless digital experiences. Identity Management Day is a reminder that the future of identity lies in intelligent, continuous orchestration across humans, machines, and the systems that connect them.
++
John Cannava, CIO, Ping Identity
From an IT leadership perspective, Identity Management Day takes on new urgency this year as both individuals and organizations are managing human identities while also governing AI as it takes on increasingly agentic roles. The impact AI will have on identity will likely be far greater than we anticipate, which means our approach to security has to evolve in lockstep.
In this new reality, the login is no longer the primary security boundary – access must be continuously evaluated and enforced. In agentic systems, risk doesn’t end at sign-in; it evolves dynamically at runtime as users and systems interact. Identity can no longer be verified once and trusted indefinitely. It must be continuously evaluated at every high-impact action.
That’s why approaches like zero trust and decentralized identity are becoming critical to reducing risk while still enabling the business to move quickly. As AI-driven attacks increasingly target centralized data and try to imitate legitimate users, organizations need to move away from single points of failure and verify every access request in real time, no matter who or what is behind it. This requires rethinking identity across both workforce and customer environments.
As the way we work continues to change, the focus has to be on securing the workforce, maintaining customer trust, and delivering digital experiences that are both seamless and secure. The future of identity will depend on how well we adapt to this more dynamic, continuous model of trust.
++
Rob Ainscough, Chief Identity Security Advisor at Silverfort and former Head of Identity and Access Management at Tesco
Identity has become the control layer of modern cybersecurity, but most organizations still treat it as an access management problem, not a security one. Today’s hybrid identity environment creates seams that attackers exploit with ease – that’s why compromised credentials remain their most reliable path. They aren’t breaking in; they’re logging in and moving laterally across disconnected environments.
We’re approaching an inflection point where AI will enable attackers to discover and exploit unprotected identities faster than defenders can respond, making it critical to get the fundamentals right, then scale with consistency and certainty.
At the same time, organizations must balance two priorities: addressing the fragile foundations adversarial AI will expose, while enabling the business to adopt AI safely. As AI agents introduce a new class of identity, defenders need more resilient approaches that focus on inspecting and controlling behavior rather than just access. We’re starting to see more practical approaches emerge to address this, from runtime-level monitoring (RLM) to open-source tools that detect malicious prompts and agent misuse in real time. These give defenders a way to actually inspect and control behavior, not just access to it. The priority now is establishing a consistent baseline of protection across all identities, with continuous verification and guardrails that can catch misuse, even when access looks legitimate.
++
Crystal Morin, Chief Cybersecurity Strategist at Sysdig
Identity management has undergone a massive shift: humans now make up less than 3% of managed identities in cloud environments. The rest belong to machines that don’t log off, don’t take breaks, and often operate with elevated permissions.
As automation and AI-driven development explode, the gap between human and machine identities is becoming one of the defining security challenges of our time. Machine identities are ephemeral, autonomous, and often difficult to manage at scale with traditional controls, which were never designed for this speed. Identity is the primary access control, it defines an environment’s boundaries, and it’s the most common source of initial access in a breach.
To keep up, organizations must rethink identity security as a continuous, lifecycle-driven discipline. Businesses must treat machine identities as the new firewall.
++
Ryan Heidorn, CTO at C3 Integrated Solutions
For defense contractors, the recent breach at Stryker, where an Iranian-backed hacker group allegedly compromised ‘dev’ and ‘qa’ administrative identities to wipe ~80,000 devices, is a clear example of why identity management is not only a CMMC requirement, but one of the most effective defenses against real-world threats.
Most identity-related breakdowns accumulate over time: shared accounts with excessive permissions, inconsistent access reviews or limited visibility into how identities are used. As defense contractors adopt cloud-native enclaves where identity becomes the perimeter, authentication strength and privilege management are the front line of defense against the threats the Defense Industrial Base faces.
In regulated environments, identity management is the foundation that modern security and compliance are built on.
++
Nick Nikols, Vice President, NetIQ Products, OpenText Cybersecurity
Identity Management Day 2026 reinforces an essential principle: cybersecurity succeeds or fails at the point of identity. Every digital interaction depends on identity to establish trust and enforce access. As organizations operate across cloud platforms, partner ecosystems, and distributed environments, identity remains the most consistent mechanism for controlling risk and protecting critical assets.
Modern identity programs play a vital role in limiting exposure. Enforcing least privilege access, maintaining clear ownership, and continuously reviewing entitlements help reduce the impact of compromised credentials, prevent permission sprawl, and constrain lateral movement when incidents occur. Without strong identity governance, even advanced security architectures are vulnerable to identity driven attacks, insider misuse, and abuse of privileged access.
At the same time, the identity landscape continues to expand. Non human identities, from service accounts to emerging AI driven agents, are increasingly embedded in core workflows, executing tasks and accessing data without direct human involvement. While these systems deliver efficiency, they also reinforce the need for disciplined identity controls applied consistently across all actors.
Identity Management Day should be viewed as a call to action to make identity first security foundational. Organizations must combine robust authentication, access governance, lifecycle management, and continuous monitoring to protect systems, data, and operations as digital transformation accelerates.
++
Art Gilliland, CEO of Delinea
Identity doesn’t stop at people. Non-human identities, particularly AI agents, are quickly becoming one of the biggest sources of enterprise risk. Despite 87% of organizations claiming they’re ready for AI-driven automation at scale, nearly half admit their identity governance for AI systems falls short.
The problem is relatively simple, but often overlooked: teams are still treating AI agents as tools, when they actually behave like privileged users. This creates the “AI security paradox” where organizations are scaling their AI initiatives faster than they control which identities get access to what. Dangerous blind spots can form as a result, hiding unchecked privilege, quiet access paths, and little accountability for actions.
The pressure to move fast on AI is real, but so is the need to lock down identities. As AI agents continue to multiply across enterprise environments, identity can’t be viewed as just another part of security; it must be treated as the overarching control plane.
++
Ram Mohan, Chief Strategy Officer at Identity Digital
National Identity Management Day reminds us that as the internet evolves, so must our strategies for protecting and managing digital identities. AI is revolutionizing how individuals and businesses establish, scale, and maintain their online presence. While this rapid innovation creates opportunities for growth, it also introduces new challenges. The same AI tools that drive progress can be exploited by bad actors. As digital identities become easier to generate, distinguishing authenticity becomes increasingly complex, making trust a cornerstone of the digital ecosystem.
In this landscape, AI-driven risk and reputation systems that provide real-time verification signals to domains, websites, and brands could be immensely valuable. These systems could help instantly distinguish legitimate businesses from malicious actors. Building a safer, more trustworthy digital environment will require shared responsibility across registries, registrars, businesses, and users, but by combining technology, governance, and accountability, we can take the most meaningful steps to ensure our online personas remain both innovative and secure.
++
Sean Deuby, Principal Technologist, Semperis
Unless you’re a regulated business, identity governance and administration (IGA) is usually an afterthought. This has been the reality of IT as long as there’s been IT.
Even after 26 years of general availability, identity governance is far from a given in Active Directory environments, especially smaller ones. Organizations often find they have thousands of under-regulated NHIs accumulated over years or even decades. This is one of many reasons identity systems are a favorite target of threat actors; they know very well these NHIs are overprivileged, under protected, and neglected.
Take these same factors, surround them with the tinder of cloud services’ ease of use, pour the gasoline of AI onto it, and give developers the match. That’s the dumpster fire we’re looking at today, with NHIs outpacing human identities at what seems like a geometric progression.
We can’t just wring our hands about the situation; we need to take steps immediately. We must put controls in place as soon as possible. And we must discover what’s already out there, using any tools we have, so we know the scope. You don’t know the size of your dumpster fire until you’ve looked.
++
Cameron Matthews, CISO, Radiant Logic
Identity Management Day is a timely reminder that identity has become the primary control plane for modern security, especially as organizations expand across cloud, SaaS, and now AI-driven environments. The challenge is that most enterprises are still operating with fragmented identity data, making it difficult to see who has access to what, and whether that access is appropriate or risky. This lack of visibility creates blind spots that attackers increasingly exploit, particularly as non-human identities and automated processes multiply. To address this, organizations need to move beyond static identity governance and embrace continuous identity observability that provides real-time insight into access, behavior, and risk. Ultimately, treating identity as a dynamic, data-driven layer of security is imperative to enable Zero Trust to function as intended in today’s environment.
##






