Leadership1 distinct publisher3 min readPublished
Mitiga field CISO Brian Contos argues most enterprises cannot say what a live agent did after the fact, and the people who feel that first are the auditors and responders who have to produce a sequence.
The Board Room · Leadership desk

Compiled by The Board RoomSomething wrong?How this is made
Contos poses his question in the present tense, and that is the easier half of it [3]. Real-time visibility is a detection ambition, and detection ambitions can be deferred. Reconstruction after the fact is a documentation obligation, and obligations arrive with deadlines attached: an audit finding that needs a response, an incident timeline that counsel has to sign. That is why the agent identity gap shows up on the audit and response side of the house before it shows up as a breach.
The mechanism he describes is not exotic access abuse. An agent holding legitimate credentials performs actions that are technically authorized and operationally unintended [11]; one agent triggers a second, which touches a third system that widens access or starts a downstream workflow [12]. Contos argues most failures will come from ordinary agents doing exactly what they were allowed to do, just not what anyone expected [5]. The forensic consequence is precise: each hop is separately valid and separately logged, and the join between those hops exists nowhere in the record [13].
The board-deck version of the control story is a registry, an approval workflow and a policy framework that set boundaries before deployment [10]. That is worth having, and it answers exactly one question: was this permitted, at the moment permission was granted. What happened next is a different question, one the same record was never built to answer, because the permission predates the sequence it later governs. Contos adds that most organizations do not hold a complete inventory of the machine-to-machine delegation layered on top of enterprise identity [14], which means even the permission answer may rest on a partial register.
The provenance is worth stating plainly: this is a single Forbes Tech Council column by a security vendor's field CISO [1], carrying no incident counts and no dated cases [1]. Fair, and it should govern what the piece is used for: it is a problem statement, not a measurement. The load-bearing part does not depend on a number. Traditional identity models assume stable identities running known functions, with access reviewed and periodically audited [4], and role definitions and entitlement reviews were built for static conditions rather than dynamic ones [6]. Whether that assumption still describes your environment is checkable inside your own logs, without accepting anyone's threat narrative.
The tradeoff is velocity against reconstructability, and it is worth naming rather than implying. Contos describes development cycles compressed from weeks into days or hours [7], and a "turn it on and see what it does" posture that he attributes to velocity demands rather than to any security leader's preference [8]. Weeks saved at deployment are not free; some fraction of them is spent later rebuilding a sequence from fragments, at consultant rates, under someone else's clock.
Separating timescales keeps this honest. Cross-vendor agreement on how an agent's delegated identity and action chain are represented in a log is a decade of standards work, and nothing in this record suggests it is close. Whether you can produce a defensible sequence for the agents already wired into Salesforce, Workday, GitHub and Slack [9] is a question your own engineering can settle this quarter. Deferred work still needs doing later, at consultant rates, at the moment the narrative is demanded rather than requested.
Ranked by verification strength, evidence, and original report placement.
Brian Contos is the Field CISO at Mitiga with 30+ years of experience building companies and evangelising cybersecurity; his argument appeared as a Forbes Tech Council column on forbes.com.
Traditional identity models were built on the assumption that identities are stable and their actions predictable: a user logs in, a service account runs a known function, and access is reviewed, granted and periodically audited.
Role definitions, entitlement reviews and periodic audits are built for static conditions, while agents operate in dynamic ones.
The column supplies no incident counts, no rates and no dated cases; its evidence base is the author's stated professional observation.
Contos writes that AI agents now operate as autonomous actors with credentials, delegated access and the ability to chain actions across cloud and SaaS environments.
Contos writes that most organizations can no longer answer a basic question in real time: what did my agent just do once I put it in motion?
Distinct publishers with included, body-backed reporting in this cluster.
forbes.com
1 article · September 2, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
Running the agent server-side hands every ticket's commits to one shared service account1 distinct publisher
leadership
Rent the ledger, build the screen: where AI actually moved the buy-versus-build line1 distinct publisher
security
Thousands of credentials survived five years of pentests inside Jira ticket comments1 distinct publisher
invest
Salesforce's double digits, minus Informatica: agentic AI is real and still 2% of revenue1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One column, no counts
Everything traces to a single Forbes Tech Council column by Mitiga's field CISO. The mechanics it describes are specific and internally coherent — credentialed agents chaining calls through Salesforce, Workday, GitHub and Slack, each hop individually authorized — but the warrant for every prevalence statement is 'I've observed this time and time again.' No figure, date, sample or named organization appears anywhere in it.
No deployment record to read
There is simply nothing here to count. Contos says agents are 'live, wired into workflows' and lists platforms they reach, but names no organization, product, rollout or date, and reports no logged incident. Enterprise agent deployment may well be widespread; this reporting gives us no way to measure it.
Crisis framing runs ahead of the receipts
Forbes' headline promises an identity crisis nobody is logging; the body delivers one practitioner's pattern recognition. 'Most organizations can no longer answer' is a prevalence claim without a denominator, and the forecast that most failures will come from authorized-but-unexpected agent behavior has no case behind it. The underlying observation — that pre-deployment authorization certifies nothing about post-deployment behavior — is sound as design reasoning. The overstatement is in the scale and the urgency, not the mechanism.
Vendor field CISO in a paid contributor slot
The diagnosis and the author's day job point the same way: an enterprise that cannot reconstruct what its agents did is exactly the buyer for cloud detection and investigation work, and Contos writes as Mitiga's field CISO. Forbes' Tech Council is a membership channel, not its newsroom, so no editor independent of the argument vetted the prevalence claims. Notably, the column never pitches a product — which limits the pull without removing it.
Clear text, thin corroboration
Two things are easy to establish: what this column says, and what it declines to quantify. What we cannot pin down is whether 'most organizations' means one field CISO's client base or the wider market — and with a single publisher in play there is no second read to triangulate against. Our read of the argument is firm; our read of its reach is not.