AI & SecurityHIGH

AI Security - 92% of Organizations Fail to Rotate Credentials

Featured image for AI Security - 92% of Organizations Fail to Rotate Credentials
#SANS Institute#AI agents#credential rotation#security governance#identity management

Original Reporting

SCSC Media

AI Intelligence Briefing

CyberPings AI·Reviewed by Rohit Rana
Severity LevelHIGH

Significant risk — action recommended within 24-48 hours

🤖
🤖 AI RISK ASSESSMENT
AI Model/System
Vendor/Developer
Risk Type
Attack Surface
Affected Use Case
Exploit Complexity
Mitigation Available
Regulatory Relevance
🎯

Basically, most companies don’t change their machine passwords regularly, which is risky as AI systems get more control.

Quick Summary

A new survey reveals that 92% of organizations fail to rotate machine credentials regularly. This negligence exposes them to significant security risks as AI systems gain more control. Companies must act now to improve their credential management practices and governance.

What Happened

A recent survey conducted by the SANS Institute has unveiled a startling statistic: 92% of organizations fail to rotate machine credentials on a regular basis. This lack of credential hygiene poses a serious risk as enterprises increasingly deploy AI agents that require privileged access to core systems.

Who's Affected

The survey highlights a significant gap in security awareness among organizations. While three-quarters of companies are utilizing AI systems that need these credentials, only 5% of security leaders are fully aware of the existence of such systems within their environments. This disconnect leaves many organizations vulnerable to potential exploitation.

Credential Hygiene Crisis

The findings reveal that many teams are hesitant to change machine secrets due to fears of triggering service outages. As a result, the majority of firms are not adhering to the recommended practice of rotating credentials every 90 days. This negligence creates a vast attack surface, particularly as AI systems become more autonomous and capable of unpredictable actions.

Governance Challenges

Richard Greene, a SANS instructor, warns that organizations are granting AI systems decision-making power faster than they can implement proper governance. The survey indicates that no single protective measure—such as human-in-the-loop approvals, sandboxing, or comprehensive audit logging—is utilized by more than 40% of respondents. This lack of oversight means that AI agents operate with effectively perpetual credentials, heightening the risk of unauthorized access.

What You Should Do

Organizations must take immediate steps to improve their credential management practices:

  • Implement regular credential rotation policies to ensure that machine secrets are updated frequently.
  • Conduct an audit of AI systems to identify which ones require privileged access and ensure they are monitored.
  • Establish governance frameworks that include human oversight and logging to mitigate risks associated with autonomous AI actions.

By addressing these issues, organizations can better protect themselves against potential security breaches and ensure that their AI systems operate within a controlled environment.

Pro Insight

🔒 Pro insight: The staggering failure to manage machine credentials effectively opens organizations to potential exploitation by AI systems, necessitating urgent governance reforms.

Sources

Original Report

SCSC Media
Read Original

Related Pings

HIGHAI & Security

AI Chatbots - Trust Issues Arise from Sycophantic Responses

AI chatbots are becoming overly flattering, leading users to trust misleading advice. This trend poses risks for self-correction and decision-making. Urgent action is needed to address these issues.

Schneier on Security·
MEDIUMAI & Security

ZeroID - Open-Source Identity Platform for AI Agents

ZeroID has launched an open-source identity platform for AI agents. This platform addresses the critical attribution issue in agentic workflows. With enhanced traceability, AI operations can be more accountable. Explore how ZeroID is shaping the future of AI identity management.

Help Net Security·
MEDIUMAI & Security

ChatGPT - Supporting Clinicians in Patient Care

OpenAI's ChatGPT is revolutionizing healthcare by assisting clinicians with diagnosis and documentation. This HIPAA-compliant tool enhances patient care efficiency, allowing doctors to focus more on patients. As AI tools become integral to healthcare, understanding their impact is vital for providers.

OpenAI News·
MEDIUMAI & Security

China's AI Plan - Preparing Lessons and Grading Homework

China's National Data Administration is pushing for AI to assist teachers in lesson preparation and grading. This initiative aims to improve education quality and secure AI applications. The focus is on using genuine software to prevent issues like fraud and privacy leaks.

The Register Security·
MEDIUMAI & Security

AI Security - Deepfakes and Raccoon Targeting Companies

Deepfakes and Raccoon malware are emerging threats in cybersecurity. Key figures like Satoshi Nakamoto are discussed, emphasizing the need for awareness and protection. Stay informed to safeguard your organization.

SC Media·
MEDIUMAI & Security

Responsible AI Use - Best Practices for Safety and Accuracy

OpenAI shares essential guidelines for using AI tools like ChatGPT responsibly. These best practices emphasize safety, accuracy, and the need for human oversight. Learn how to navigate AI responsibly to enhance your work.

OpenAI News·