Skip to content

Leadership1 publisher3 min readPublished

Your fastest-moving insider now holds an API token, not a grudge

BeyondTrust's Morey Haber counts a 466.7% year-over-year rise in AI agents inside enterprises. They authenticate, hold privileges and move data, and insider-threat programs still assume a human.

The Board Room · Leadership desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Photograph accompanying Your fastest-moving insider now holds an API token, not a grudge
Photo: technadu.com

What happened

  • Morey J. Haber is Chief Security Advisor at BeyondTrust, an identity and technical evangelist with over 25 years of IT industry experience, writing for the Forbes Tech Council.
  • For decades security teams have treated insider threats as a human problem (the disgruntled employee copying files to USB, the administrator abusing privileged credentials, the over-privileged contractor), all resting on the assumption that the threat actor is a person; Haber writes that assumption is no longer true.
  • Haber cites a 466.7% year-over-year increase in AI agents operating inside enterprise environments.
  • A 466.7% year-over-year increase implies the agent population is approximately 5.7 times its level a year earlier.
  • Agentic AI systems can authenticate to services, access sensitive data, trigger workflows, connect to third-party data sources and interact with infrastructure with little or no human intervention.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

A Forbes Tech Council column by Morey J. Haber, chief security advisor at BeyondTrust, argues that the entire insider-threat discipline rests on one assumption, that the threat actor is a person, and that the assumption has stopped being true [1][2]. The figure he attaches to it is a 466.7% year-over-year increase in AI agents operating inside enterprise environments [3], which works out to an agent population roughly 5.7 times what it was a year earlier [4].

The operational point is not that agents are clever. It is that they need credentials to do anything at all. Haber notes that agents authenticate to services, reach sensitive data, trigger workflows, connect to third-party sources and touch infrastructure with little or no human involvement [5], and that to do so they are issued API tokens, service accounts, machine identities, cloud roles, delegated credentials or the ability to impersonate a human [6]. Once provisioned, an agent moves through the estate the way a staff member does, with more speed and scale [7]. That is a headcount decision made by an engineering team, usually without an onboarding review.

His worked example is unremarkable, which is the problem. An agent asked to analyse customer data may hit CRMs, ERPs, cloud storage buckets and other agents in a single run, with every request properly authenticated and, from the monitoring side, indistinguishable from an attack [8]. Turn that same agent, and it can pull every past-due invoice with full client detail, which feeds an automated phishing campaign carrying fraudulent payment terms and attacker-controlled bank accounts [9]. Attackers have adjusted accordingly, going after the agent through prompt injection, poisoned data, compromised plug-ins or stolen credentials, because the agent's privileges become theirs and no malware is required [10].

The privilege posture is self-inflicted. Haber writes that teams routinely bypass the guardrails their own insider programs mandate, least privilege, access reviews and monitoring, granting broad entitlements so the agent plugs in and works immediately [11][12]. The residue is a super-user population: excessive cloud permissions, long-lived API tokens and secrets sitting in code [13].

The governance gap is structural rather than cultural. Machine identities, service accounts and API keys already outnumber human users in nearly every organisation, and each new agent adds more [14]. Identity governance, meanwhile, has been anchored for twenty years to the employee life cycle of joiners, movers and leavers [15][16], and agents do not observe it: they can be created instantly, cloned across environments and embedded into applications without the security team seeing it [17]. An agent nobody enrolled cannot be reviewed, and cannot be offboarded. Haber's position is that the controls needed already exist and simply have to be aimed at agents [18].

What to watch is whether anyone can produce a number. Ask for the count of agent identities in production, who owns each one, what entitlements it holds and what expires those entitlements; a firm that cannot answer for its human joiners and leavers will not answer for a population growing at Haber's rate [3][15]. Watch also whether agents get named owners in the access review cycle, and whether token lifetimes shorten, since long-lived tokens and in-code secrets are the specific failure Haber identifies [13]. Note that this case is argued by a vendor executive at an identity security company [1], and the growth figure is presented without a stated source [3].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories