<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[The Control Plane ]]></title><description><![CDATA[Insights and analysis from Kiteworks for cybersecurity, compliance, and risk management leaders working to control, monitor, and protect every data interaction between humans and AI agents.]]></description><link>https://kiteworks.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!-Fqi!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd563556a-3610-4760-a881-1a941423f056_257x257.png</url><title>The Control Plane </title><link>https://kiteworks.substack.com</link></image><generator>Substack</generator><lastBuildDate>Sat, 15 Aug 2026 18:12:41 GMT</lastBuildDate><atom:link href="https://kiteworks.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Kiteworks]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[kiteworks@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[kiteworks@substack.com]]></itunes:email><itunes:name><![CDATA[Kiteworks]]></itunes:name></itunes:owner><itunes:author><![CDATA[Kiteworks]]></itunes:author><googleplay:owner><![CDATA[kiteworks@substack.com]]></googleplay:owner><googleplay:email><![CDATA[kiteworks@substack.com]]></googleplay:email><googleplay:author><![CDATA[Kiteworks]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[SharePoint Just Compromised 200 Government Accounts in One Patch Cycle.]]></title><description><![CDATA[Switzerland patched within days. The compromise happened before the patch mattered.]]></description><link>https://kiteworks.substack.com/p/sharepoint-just-compromised-200-government</link><guid isPermaLink="false">https://kiteworks.substack.com/p/sharepoint-just-compromised-200-government</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Fri, 14 Aug 2026 15:01:58 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!U3_i!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff77ee607-4007-43a7-9a69-1720033f54c6_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!U3_i!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff77ee607-4007-43a7-9a69-1720033f54c6_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!U3_i!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff77ee607-4007-43a7-9a69-1720033f54c6_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!U3_i!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff77ee607-4007-43a7-9a69-1720033f54c6_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!U3_i!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff77ee607-4007-43a7-9a69-1720033f54c6_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!U3_i!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff77ee607-4007-43a7-9a69-1720033f54c6_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!U3_i!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff77ee607-4007-43a7-9a69-1720033f54c6_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f77ee607-4007-43a7-9a69-1720033f54c6_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:411900,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/211054771?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff77ee607-4007-43a7-9a69-1720033f54c6_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!U3_i!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff77ee607-4007-43a7-9a69-1720033f54c6_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!U3_i!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff77ee607-4007-43a7-9a69-1720033f54c6_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!U3_i!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff77ee607-4007-43a7-9a69-1720033f54c6_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!U3_i!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff77ee607-4007-43a7-9a69-1720033f54c6_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>On July 28, 2026, security specialists at Switzerland&#8217;s Federal Office for Information Technology and Telecommunication (BIT) noticed something wrong on their on-premises SharePoint servers. Three days later, BIT </span><a href="https://www.admin.ch/de/newnsb/1CjmpBBHQaMV82PjKEpcL"><span>confirmed</span></a><span> that roughly 200 user and technical accounts had been compromised. Passwords reset, external access blocked -- then the servers came down entirely for a clean reinstall. By any reasonable standard, that&#8217;s a fast, competent </span><a href="http://kiteworks.com/risk-compliance-glossary/incident-response/"><span>incident response</span></a><span>. No notes.</span></p><p><span>That&#8217;s not the story.</span></p><p><span>The story is that BIT did almost everything a security team is supposed to do -- detect quickly, contain same-day, patch, reset </span><a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/"><span>credentials</span></a><span>, bring in outside help -- and still ended up disclosing 200 compromised accounts three weeks after Microsoft shipped the fix. If a well-run federal IT agency gets this outcome from a textbook response, &#8220;patch faster&#8221; was never going to be the control that saved you.</span></p><h3><strong><span>Two CVEs, One Attack Surface, 200 Accounts</span></strong></h3><p><span>BIT hasn&#8217;t confirmed exactly which </span><a href="http://kiteworks.com/risk-compliance-glossary/vulnerability/"><span>vulnerability</span></a><span> the attackers used, but the timeline points at one of two flaws Microsoft disclosed in its July 2026 Patch Tuesday cycle. </span><a href="https://www.cycognito.com/blog/emerging-threat-cve-2026-56164-sharepoint-server-privilege-escalation-via-missing-authentication/"><span>CVE-2026-56164</span></a><span> is a missing-authentication flaw in on-premises SharePoint Server that lets an unauthenticated attacker escalate privilege remotely -- no </span><a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/"><span>credentials</span></a><span>, no user interaction required. CISA </span><a href="https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitations"><span>added it to the Known Exploited Vulnerabilities catalog</span></a><span> with a three-day remediation deadline for federal agencies.</span></p><p><span>The second candidate, </span><a href="https://www.bleepingcomputer.com/news/security/critical-sharepoint-rce-flaw-exploited-to-steal-machine-keys/"><span>CVE-2026-50522</span></a><span>, is worse. It&#8217;s a deserialization flaw that gives a remote, unauthenticated attacker code execution on the SharePoint server -- and once inside, the documented objective isn&#8217;t data theft. It&#8217;s stealing the IIS machine keys that sign authentication tokens. BleepingComputer reported that watchTowr&#8217;s honeypot network caught exploitation attempts within hours of a public proof-of-concept going live on July 20. The Swiss agency&#8217;s own disclosure lines up with both flaws -- </span><a href="https://therecord.media/swiss-bit-foitt-hacked-possibly-sharepoint-vulnerabilities"><span>The Record</span></a><span> noted BIT acknowledged the intrusion &#8220;presumably&#8221; exploited vulnerabilities patched that same month.</span></p><p><span>Two hundred accounts. One Patch Tuesday. Read that again.</span></p><h3><strong><span>This Is the Second Time in a Year</span></strong></h3><p><span>Here&#8217;s the part that should bother you more than the Swiss disclosure itself: this exact failure mode already happened in 2025. The &#8220;ToolShell&#8221; wave -- CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 -- hit on-premises SharePoint Server through the same combination of authentication bypass and deserialization RCE. Palo Alto&#8217;s Unit 42 </span><a href="https://unit42.paloaltonetworks.com/microsoft-sharepoint-cve-2025-49704-cve-2025-49706-cve-2025-53770/"><span>warned at the time</span></a><span> that organizations exposing SharePoint Server to the internet should assume compromise, and that patching wouldn&#8217;t undo what attackers had already taken.</span></p><p><span>A year later, the mechanism repeated almost exactly: unauthenticated access, deserialization RCE, machine key theft. </span><a href="https://cert.europa.eu/publications/security-advisories/2026-009/"><span>CERT-EU&#8217;s advisory</span></a><span> on the July 2026 cluster put it plainly: &#8220;Given the number of recent critical vulnerabilities affecting SharePoint, organizations should reconsider exposing any Microsoft SharePoint Server directly to the internet.&#8221; Not &#8220;patch faster.&#8221; Reconsider the exposure.</span></p><p><span>This tracks with a broader pattern CrowdStrike documented in its </span><a href="https://www.crowdstrike.com/en-us/global-threat-report/"><span>2026 Global Threat Report</span></a><span>: adversaries are systematically targeting internet-facing, under-monitored infrastructure because patch cycles measured in weeks are mismatched against exploitation timelines measured in hours. SharePoint Server, sitting on-premises with a monthly patch cadence, is exactly that kind of target. Twice in twelve months isn&#8217;t a </span><a href="http://kiteworks.com/risk-compliance-glossary/vulnerability/"><span>vulnerability</span></a><span>. It&#8217;s a category.</span></p><h3><strong><span>The Patch Closes the Hole. The Keys Don&#8217;t Care.</span></strong></h3><p><span>Here&#8217;s what gets me about the machine-key detail: &#8220;we patched&#8221; doesn&#8217;t close the loop the way everyone assumes it does. When an attacker exploits a deserialization flaw to grab IIS machine keys, they walk away with the cryptographic material that signs and validates session tokens. As </span><a href="https://therecord.media/swiss-bit-foitt-hacked-possibly-sharepoint-vulnerabilities"><span>The Record reported</span></a><span>, citing CISA&#8217;s guidance on the cluster: once stolen, those keys let an attacker forge legitimate-looking requests that a fully patched server will still accept. The patch fixes the door. It does nothing about the copy of the key already sitting in the attacker&#8217;s pocket.</span></p><p><span>Call it the eviction gap -- the space between &#8220;vulnerability patched&#8221; and &#8220;attacker actually gone.&#8221; It&#8217;s exactly why CISA and CERT-EU are both telling defenders to rotate machine keys and restart IIS rather than trust the patch by itself. BIT is reinstalling its affected servers from scratch instead of relying on a patch-and-rotate cycle. That&#8217;s the correct call. It&#8217;s also an admission that the patch was never going to be enough on its own.</span></p><p><span>It also explains why BIT&#8217;s language is so carefully hedged: &#8220;no indication&#8221; data was accessed beyond </span><a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/"><span>credentials</span></a><span>, &#8220;analysis is ongoing.&#8221; That caveat isn&#8217;t evasive -- it&#8217;s honest. Kiteworks&#8217; </span><a href="https://www.kiteworks.com/cybersecurity-risk-management/2026-data-security-forecast-ai-governance-predictions/"><span>2026 Data Security and Compliance Risk Forecast Report</span></a><span> found that 61% of organizations are trying to build evidence-quality </span><a href="http://kiteworks.com/regulatory-compliance/audit-log/"><span>audit trails</span></a><span> on top of fragmented infrastructure, and 33% don&#8217;t have one at all. When your proof of what an attacker touched depends on logs scattered across a general-purpose collaboration platform, &#8220;we found no evidence&#8221; and &#8220;we have no evidence to find&#8221; start to look the same from the outside.</span></p><h3><strong><span>Patching Fast Isn&#8217;t the Architecture Question</span></strong></h3><p><span>None of this means any specific vendor would have stopped this particular attack chain -- that depends on patch cadence, exposure, and configuration on any platform. But the July 2026 SharePoint cluster does surface the actual question every CISO running sensitive data through on-premises collaboration infrastructure should be asking, and it isn&#8217;t &#8220;how fast can we patch.&#8221;</span></p><p><span>It&#8217;s this: is your sensitive-data platform a general-purpose collaboration tool that got extended into data exchange over a decade, or was it built for governed data exchange from the start? On-premises SharePoint Server requires the customer to independently secure the authentication pipeline, manage the deserialization attack surface, and protect the IIS machine key store -- then repeat that exercise every Patch Tuesday. A platform architected around vendor-managed patching, isolated tenancy, and </span><a href="http://kiteworks.com/regulatory-compliance/audit-log/"><span>audit trails</span></a><span> built to hold up as evidence rather than scattered log files shifts that ongoing burden off the customer&#8217;s side of the ledger entirely. That&#8217;s an architecture comparison worth having with your own vendors -- not a claim that unpatched CVEs are survivable everywhere else. Bring the comparison to your board before they bring it to you.</span></p><h3><strong><span>What to Do by Next Week</span></strong></h3><ol><li><p><strong><span>Inventory every internet-facing SharePoint Server instance</span></strong><span> in your environment today. If it&#8217;s exposed and unpatched against CVE-2026-56164 or CVE-2026-50522, treat it as compromised until proven otherwise -- not &#8220;vulnerable.&#8221;</span></p></li><li><p><strong><span>Rotate IIS and ASP.NET machine keys and restart IIS</span></strong><span> on any server that was exposed before patching. Patching alone does not evict an attacker holding stolen keys.</span></p></li><li><p><strong><span>Pull your </span><a href="http://kiteworks.com/regulatory-compliance/audit-log/"><span>audit logs</span></a><span> and ask a hard question</span></strong><span>: can you produce a defensible timeline of exactly what was accessed, by whom, in the last 90 days -- or are you, like 61% of organizations Kiteworks surveyed, reconstructing it from fragmented logs across systems that were never built to talk to each other?</span></p></li><li><p><strong><span>Separate regulated and sensitive workflows from general collaboration infrastructure.</span></strong><span> Not everything needs to move. The workflows carrying </span><a href="http://kiteworks.com/risk-compliance-glossary/cmmc-cui-and-what-it-means/"><span>CUI</span></a><span>, </span><a href="http://kiteworks.com/risk-compliance-glossary/pii-phi/"><span>PHI</span></a><span>, or contractual data are the ones that need a platform built for evidentiary-grade governance, not a platform that happens to store files.</span></p></li><li><p><strong><span>Brief your board before a regulator or a reporter does it for you.</span></strong><span> Five CISA KEV entries and a national government disclosure in the same cycle is a board-level question, not a patch-ticket footnote.</span></p></li></ol><p><span>BIT did the fast version of everything right and still had to reset 200 accounts and reinstall its servers from scratch. The lesson isn&#8217;t that Switzerland was careless. It&#8217;s that &#8220;patched&#8221; and &#8220;safe&#8221; stopped being the same word the moment machine key theft entered the playbook -- and if your sensitive data still lives on the same kind of platform, that gap is yours too.</span></p>]]></content:encoded></item><item><title><![CDATA[The Sector That Builds AI Has a 65% Blind Spot.]]></title><description><![CDATA[Technology posts the second-highest security score in the 2026 Data Security and Compliance Risk Report. Then you look at where its AI governance actually sits.]]></description><link>https://kiteworks.substack.com/p/the-sector-that-builds-ai-has-a-65</link><guid isPermaLink="false">https://kiteworks.substack.com/p/the-sector-that-builds-ai-has-a-65</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Thu, 13 Aug 2026 15:02:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!g8x9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70dcc5e3-db2e-4340-abdf-29ae6cea61ef_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!g8x9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70dcc5e3-db2e-4340-abdf-29ae6cea61ef_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!g8x9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70dcc5e3-db2e-4340-abdf-29ae6cea61ef_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!g8x9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70dcc5e3-db2e-4340-abdf-29ae6cea61ef_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!g8x9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70dcc5e3-db2e-4340-abdf-29ae6cea61ef_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!g8x9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70dcc5e3-db2e-4340-abdf-29ae6cea61ef_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!g8x9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70dcc5e3-db2e-4340-abdf-29ae6cea61ef_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/70dcc5e3-db2e-4340-abdf-29ae6cea61ef_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:495010,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/210914849?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70dcc5e3-db2e-4340-abdf-29ae6cea61ef_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!g8x9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70dcc5e3-db2e-4340-abdf-29ae6cea61ef_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!g8x9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70dcc5e3-db2e-4340-abdf-29ae6cea61ef_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!g8x9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70dcc5e3-db2e-4340-abdf-29ae6cea61ef_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!g8x9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70dcc5e3-db2e-4340-abdf-29ae6cea61ef_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Picture the CISO scorecard review at a mid-sized software company on a Tuesday morning. <a href="http://kiteworks.com/secure-file-sharing/public-vs-private-key-encryption/">Encryption</a>: deployed. <a href="http://kiteworks.com/risk-compliance-glossary/what-is-security-information-and-event-management/">SIEM</a> integration: mostly there. <a href="http://kiteworks.com/risk-compliance-glossary/managed-file-transfer/">MFT</a>: locked down. The security team walks out of that meeting feeling good, and by the numbers, they should. Now picture the AI governance review two floors down, covering the copilot embedded in the codebase, the customer-facing support agent, and the internal chatbot employees have been pasting client data into since March. That review does not happen. Not because nobody scheduled it. Because almost nobody in Technology has built the muscle to run it.</p><p>That is the finding buried in the 2026 Data Security and Compliance Risk Report, based on 459 security, compliance, and technology leaders surveyed in Q2 2026. Technology&#8217;s mean Data Security Maturity Score (DSMS) is 40.7 &#8211; the second-highest of any sector measured, behind only Financial Services (43.3) and just ahead of Energy &amp; Utilities (43.2) and Manufacturing (43.0). Its AI Governance Maturity Score (AIGMS) is 35.3, tracking almost exactly to the survey mean of 34.7. On paper, an above-average sector with an average governance posture. Read that again, because the paper is lying to you.</p><h3>The quadrant that names the problem</h3><p>The report&#8217;s DSMS &#215; AIGMS framework sorts organizations into four profiles: Dual Exposure (weak on both), Foundation First (AI governance ahead of security, rare), AI-Ready (both strong, 11% of the survey), and one the report calls &#8220;False Confidence&#8221; &#8211; high DSMS, low AIGMS. Its one-line description of that quadrant: &#8220;Strong general security, no AI governance. Technology sector profile. Feels protected. Is not.&#8221;</p><p>Not implied. Named. Technology is the profile the framework was built to catch.</p><p>Here is where the aggregate numbers stop telling the truth. Despite that above-average DSMS, 65% of Technology respondents fall into the EXPOSED quadrant &#8211; DSMS below 50 and AIGMS below 50 simultaneously. Another 16% sit specifically in the FORTIFIED/False-Confidence pocket: strong security infrastructure, weak AI governance. Combined, that&#8217;s 81% of the sector sitting somewhere between blind and half-blind, propped up by a sector average that masks how unevenly the maturity is actually distributed. The mean flatters. The distribution convicts.</p><h3>Sophisticated reputation, ordinary score</h3><p>Here&#8217;s the uncomfortable part for anyone who has ever pitched Technology as the sector that &#8220;gets&#8221; AI. Its Data Security and Compliance Readiness Index &#8211; DSMS multiplied by the AI governance factor &#8211; comes in at 16.8, just above the survey mean of 16.2. Neither dimension distinguishes it meaningfully from an average organization. I&#8217;ve sat through enough of these scorecard reviews to know which number gets the applause and which one gets buried in the appendix, and it&#8217;s rarely the honest one. That gap between perception and measurement also shows up at the top: the World Economic Forum&#8217;s <a href="https://www.weforum.org/publications/global-cybersecurity-outlook-2026/">Global Cybersecurity Outlook 2026</a>, published in January 2026, found 87% of cyber leaders now name AI-related vulnerabilities as the fastest-growing cyber risk, yet CEOs still rank data leaks as their single highest AI-related concern. Leaders can see the risk and still misjudge their own exposure to it.</p><p>And the representation analysis is worse than the readiness score. Across the survey, Technology produces DSMS/AIGMS &#8220;leaders&#8221; &#8211; organizations scoring 45 or above on both &#8211; at only 1.04 times the expected rate. Barely above proportional. Healthcare, a sector nobody nominates for a security award, produces leaders at 1.57 times the expected rate. The sector building the tools is not the sector governing them best. It is, statistically, an average performer wearing a sophisticated-industry costume.</p><h3>Why the math got worse this year</h3><p>None of this would matter much if Technology&#8217;s AI footprint were small. It is not. Across the full survey, 64% of organizations have AI deployed in production, and among those, 70% are running three or more distinct AI use cases at once. Copilots, customer-facing agents, internal chatbots, code-generation tools: each one is a separate data access point, and Technology, as the heaviest AI adopter in the sample, carries more of them than anyone else. It&#8217;s not a coincidence that the <a href="https://cpl.thalesgroup.com/data-threat-report">Thales 2026 Data Threat Report</a> finds only 47% of sensitive cloud data is actually encrypted, and only one in three organizations claims to know where its sensitive data lives. Stacking AI use cases on top of a data estate you can&#8217;t fully see doesn&#8217;t produce governance. It just produces more surface you can&#8217;t see.</p><p>Here&#8217;s the whole game: containment has not kept pace with deployment, in Technology or anywhere else. No AI containment control measured in the survey &#8211; kill switch, purpose binding, AI-specific <a href="http://kiteworks.com/risk-compliance-glossary/data-loss-prevention-dlp/">DLP</a>, behavioral monitoring &#8211; is deployed by more than 35% of organizations, regardless of sector. Technology&#8217;s above-average DSMS buys <a href="http://kiteworks.com/secure-file-sharing/public-vs-private-key-encryption/">encryption</a>, <a href="http://kiteworks.com/risk-compliance-glossary/managed-file-transfer/">MFT</a>, and <a href="http://kiteworks.com/risk-compliance-glossary/what-is-security-information-and-event-management/">SIEM</a> coverage for the data infrastructure it already understood. It doesn&#8217;t buy a kill switch for the agent nobody tested. CrowdStrike&#8217;s <a href="https://www.crowdstrike.com/en-us/global-threat-report/">2026 Global Threat Report</a> clocked the fastest recorded eCrime breakout time at 27 seconds. Google Cloud&#8217;s <a href="https://cloud.google.com/security/resources/m-trends">Mandiant M-Trends 2026</a> report backs up the trend: the window to intervene has collapsed from hours to seconds. An untested kill switch doesn&#8217;t help at 27 seconds. It doesn&#8217;t help at 27 minutes either.</p><h3>The architectural question</h3><p>Two easy answers exist here, and both fail. The first is &#8220;Technology doesn&#8217;t need to worry, its DSMS is above average.&#8221; The quadrant data kills that outright: 65% exposed, a 16.8 DSCRI, a 1.04x leadership rate. The second is &#8220;just buy more AI security tools,&#8221; which treats the gap as a shopping problem. It isn&#8217;t. The report&#8217;s own math shows AI governance investment returns more DSCRI improvement per dollar than incremental security spend at current baselines, because DSMS and AIGMS sit on separate axes. You can&#8217;t buy your way up one with money spent on the other.</p><p>What actually closes the gap is architecture, not another point tool. Organizations that score well on both axes treat data access and AI governance as one control plane instead of two disconnected budgets: a single place where policy, logging, and containment apply whether a human or an AI agent is requesting the file, so an agent&#8217;s access gets reviewed and revoked using the same evidence trail as an employee&#8217;s. Technology has plenty of the data infrastructure and not enough of the AI-specific containment governing it. Closing that gap is an architecture decision, not a shopping list.</p><p>The Kiteworks <a href="https://www.kiteworks.com/cybersecurity-risk-management/2026-data-security-forecast-ai-governance-predictions/">2026 Forecast Report</a>, published in December 2025, projected this exact widening gap between AI deployment and AI containment. The Annual Survey confirms it arrived on schedule, and worse than modeled.</p><h3>What to do Monday morning</h3><p>If you run security for a Technology company, or any organization whose DSMS makes you feel comfortable, the scorecard review is not the meeting that matters this week. This one is:</p><p><span>1. </span><strong>Pull your AI use case inventory.</strong> If you have not counted every production AI system touching sensitive data, you cannot govern what you have not found. The report puts the sector average at three-plus concurrent use cases &#8211; confirm your own count before you assume it&#8217;s lower.</p><p><span>2. </span><strong>Test the kill switch you think you have.</strong> Across the survey, 23% of AI-deploying organizations have never tested their AI agent termination capability. A documented policy is not a tested control.</p><p><span>3. </span><strong>Separate the DSMS conversation from the AIGMS conversation</strong> in your next board update. If they&#8217;re one line item, they&#8217;re getting one budget, and one budget is how you end up in the False Confidence quadrant.</p><p><span>4. </span><strong>Check purpose binding, not just DLP.</strong> General <a href="http://kiteworks.com/risk-compliance-glossary/data-loss-prevention-dlp/">DLP</a> policies do not restrict what an AI agent is authorized to touch. That&#8217;s a distinct control, and most organizations don&#8217;t have it.</p><p><span>5. </span><strong>Ask who owns AI governance, specifically.</strong> Not &#8220;who owns security.&#8221; Who owns the 19 AI-specific capabilities the AIGMS actually measures.</p><p>Technology built the AI. That does not mean Technology governs it. The data says the opposite, and the data is not impressed by the reputation.</p><p><em>Read the full findings in the <a href="https://www.kiteworks.com/sites/default/files/resources/kiteworks-report-2026-data-security-compliance-risk-report.pdf">2026 Data Security and Compliance Risk Report</a>.</em></p>]]></content:encoded></item><item><title><![CDATA[A Defense Contractor’s Mailbox Just Became Export-Control Evidence.]]></title><description><![CDATA[The phishing kit is not the story. The mailbox architecture is.]]></description><link>https://kiteworks.substack.com/p/a-defense-contractors-mailbox-just</link><guid isPermaLink="false">https://kiteworks.substack.com/p/a-defense-contractors-mailbox-just</guid><dc:creator><![CDATA[Danielle Barbour]]></dc:creator><pubDate>Wed, 12 Aug 2026 15:03:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!TrD3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd88f7cf2-8d01-4660-be56-6ce1d539a7f7_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TrD3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd88f7cf2-8d01-4660-be56-6ce1d539a7f7_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TrD3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd88f7cf2-8d01-4660-be56-6ce1d539a7f7_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!TrD3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd88f7cf2-8d01-4660-be56-6ce1d539a7f7_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!TrD3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd88f7cf2-8d01-4660-be56-6ce1d539a7f7_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!TrD3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd88f7cf2-8d01-4660-be56-6ce1d539a7f7_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TrD3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd88f7cf2-8d01-4660-be56-6ce1d539a7f7_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d88f7cf2-8d01-4660-be56-6ce1d539a7f7_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:517295,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/210776287?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd88f7cf2-8d01-4660-be56-6ce1d539a7f7_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TrD3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd88f7cf2-8d01-4660-be56-6ce1d539a7f7_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!TrD3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd88f7cf2-8d01-4660-be56-6ce1d539a7f7_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!TrD3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd88f7cf2-8d01-4660-be56-6ce1d539a7f7_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!TrD3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd88f7cf2-8d01-4660-be56-6ce1d539a7f7_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On August 4, 2026, IEH Corporation discovered that a phished Microsoft 365 <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credential</a> had been sitting inside its network for an unknown stretch of time. IEH makes hyperboloid connectors that fly inside PATRIOT, AMRAAM, THAAD, and the MARK-48 torpedo. Here is what is not the story: an employee fell for a fake Microsoft sharing link from someone posing as a prospective business contact, and handed over their password. That happens constantly. Here is what is the story: for however long that account sat compromised, <a href="https://www.theregister.com/security/2026/08/07/ieh_corp_says_phished_staffer_opened_gates_to_company_m365/5284523">the entire contents of a defense contractor&#8217;s inbox were sitting in plaintext</a> &#8211; purchase orders, engineering documentation, and potentially export-controlled technical data &#8211; one login away from anyone holding the keys.</p><p>IEH says it found no evidence the data was copied. It also says it cannot determine when access actually began. Sit with that for a second. A company that makes parts for missile defense systems cannot tell you how long an outsider had standing access to its correspondence with customers and suppliers. That is not a failure of this one IT team. It is the default behavior of every mailbox built this decade.</p><h3><span>The Phishing Kit Got a Serious Upgrade</span></h3><p><a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">Credential</a> phishing used to mean a bad Outlook lookalike page and hope. Not anymore. CrowdStrike&#8217;s 2026 Threat Hunting Report found <a href="https://www.darkreading.com/cybersecurity-analytics/device-code-phishing-vishing-doubles">device-code phishing attempts jumped 15-fold</a> in the first half of 2026 compared to the second half of 2025, and voice <a href="http://kiteworks.com/risk-compliance-glossary/phishing-attacks/">phishing</a> doubled in that same window after already climbing 134% the year before. These techniques exist specifically to slide past the controls organizations already bought. As CrowdStrike&#8217;s Adam Meyers put it to reporters: attackers realized email filters catch email phishing, so they stopped emailing and started calling the help desk instead. &#8220;You don&#8217;t have to hack in,&#8221; he said. &#8220;You just have to log in.&#8221;</p><p>That is precisely the move IEH&#8217;s attacker made. A fake sharing link, a convincing login page, one set of harvested credentials. No <a href="http://kiteworks.com/risk-compliance-glossary/malware-based-attacks/">malware</a>, no exploit, no CVE. Just a key that opened every door in the building at once.</p><h3><span>Credentials Are Still Doing Most of the Damage</span></h3><p>The <a href="https://www.verizon.com/business/resources/reports/dbir/">2026 Verizon Data Breach Investigations Report</a> found the human element &#8211; error, manipulation, or misuse &#8211; involved in 62% of breaches this year, and credential abuse showed up somewhere in the intrusion chain of 39% of them, even as raw <a href="http://kiteworks.com/risk-compliance-glossary/vulnerability/">vulnerability</a> exploitation edged ahead as the single leading initial-access vector. Read the two findings together and the story is not that <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credential</a> theft is declining. It is that attackers increasingly pair a stolen credential with something else &#8211; a vendor relationship, an exposed system, a moment of trust &#8211; to get further than the credential alone would take them. IEH&#8217;s attacker did not need to go further. The mailbox itself was the whole prize.</p><h3><span>The Login Moat Problem</span></h3><p>Security teams keep fighting this the same way: better training, better <a href="http://kiteworks.com/risk-compliance-glossary/multifactor-authentication-mfa/">MFA</a>, faster detection. All of it targets the login. None of it addresses what happens once someone is past it.</p><p>Call it the login moat. Everything defensive gets built around the perimeter &#8211; the password, the <a href="http://kiteworks.com/risk-compliance-glossary/multifactor-authentication-mfa/">MFA</a> prompt, the conditional access policy &#8211; and once an attacker clears that single moat, there is nothing behind it. Not because organizations are careless, but because the mailbox itself was never designed to be anything other than a wide-open filing cabinet once you are inside. Native email platforms store messages and attachments as plaintext, and access control lives entirely at authentication. That architecture is fine right up until the authentication fails, and <a href="http://kiteworks.com/risk-compliance-glossary/phishing-attacks/">phishing</a> guarantees it periodically will.</p><p>The <a href="https://www.kiteworks.com/cybersecurity-risk-management/2026-data-security-forecast-ai-governance-predictions/">Kiteworks Data Security and Compliance Risk: 2026 Forecast Report</a> found only 39% of organizations have unified data exchange governance with actual policy enforcement across channels &#8211; the rest are running partial coverage, channel-specific point tools, or close to nothing. That gap is exactly where an incident like IEH&#8217;s lives: not in the phishing email, but in the fact that nothing downstream of the login screen was watching what left the building, or even watching what an authenticated session could see.</p><h3><span>The Architectural Fix Nobody Wants to Talk About</span></h3><p>The uncomfortable answer is that you cannot patch your way out of this. You have to stop treating the mailbox as a passive container and start treating it as a governed asset with its own policy layer, independent of whoever is currently logged in.</p><p>This is the premise behind email gateways built to enforce data-level policy rather than just scan for <a href="http://kiteworks.com/risk-compliance-glossary/malware-based-attacks/">malware</a>: <a href="http://kiteworks.com/secure-file-sharing/public-vs-private-key-encryption/">encrypt</a> or quarantine sensitive and export-controlled content automatically based on what it is, not who happened to send it; apply digital rights controls &#8211; view-only, expiration, no forwarding &#8211; so a compromised account cannot simply harvest years of correspondence; and log every message, sensitive or not, in an immutable <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trail</a> that can actually answer &#8220;what did this account touch and when.&#8221; Kiteworks&#8217; <a href="https://www.kiteworks.com/platform/simple/email-protection-gateway/">Email Protection Gateway</a> is one example built on that premise, running inside a single-tenant <a href="http://kiteworks.com/platform/security/hardened-virtual-appliance">hardened virtual appliance</a> rather than a shared mailbox architecture &#8211; not because it is the only approach, but because it illustrates what &#8220;governed at the content layer&#8221; actually looks like in practice. The point is not the vendor. The point is that the policy has to live below the login, not just at it.</p><h3><span>What to Do Now</span></h3><p><span>1. </span>Inventory what is actually sitting unprotected in your mailboxes right now &#8211; <a href="http://kiteworks.com/risk-compliance-glossary/cmmc-cui-and-what-it-means/">CUI</a>, export-controlled data, contracts, engineering files. Most security teams have never run this exercise.</p><p><span>2. </span>Move to <a href="https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf">phishing-resistant MFA</a>, per CISA&#8217;s own guidance, not the push-notification kind that device-code and vishing attacks are specifically built to defeat.</p><p><span>3. </span>Stop treating <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit logging</a> as a checkbox. If you cannot answer &#8220;how long was this account compromised&#8221; within hours, you have a logging architecture problem, not just a <a href="http://kiteworks.com/risk-compliance-glossary/phishing-attacks/">phishing</a> problem.</p><p><span>4. </span>If you are in the <a href="http://kiteworks.com/risk-compliance-glossary/defense-industrial-base/">defense industrial base</a>, map this exposure to <a href="http://kiteworks.com/platform/compliance/cmmc-compliance/">CMMC 2.0</a> and <a href="http://kiteworks.com/risk-compliance-glossary/risk-compliance-glossary-itar/">ITAR</a> now. That mapping matters more, not less, after the Pentagon <a href="https://federalnewsnetwork.com/cybersecurity/2026/07/pentagon-suspends-cmmc-phase-two-requirements-launches-review-of-program/">suspended CMMC&#8217;s third-party assessment requirement</a> on July 13 and reverted to self-assessment for the foreseeable future. No assessor is coming to catch what your own <a href="http://kiteworks.com/risk-compliance-glossary/protect-cui-with-nist-800-171-compliance/">NIST 800-171</a> score misses.</p><p><span>5. </span>Ask your security team one direct question: if a <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credential</a> gets phished today, what stops the attacker from reading everything, not just logging in?</p><p>The next phished employee is not the risk. The unprotected inbox waiting for them is.</p>]]></content:encoded></item><item><title><![CDATA[The 27-Second War: Your Attacker Moves at Machine Speed. Your AI Governance Moves at Meeting Speed.]]></title><description><![CDATA[Mandiant just measured how fast a breach spreads. Most security teams still measure their own response in business days.]]></description><link>https://kiteworks.substack.com/p/the-27-second-war-your-attacker-moves</link><guid isPermaLink="false">https://kiteworks.substack.com/p/the-27-second-war-your-attacker-moves</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Tue, 11 Aug 2026 16:16:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!JwG7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d168c-8acf-4d05-8137-90ad60d8265b_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JwG7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d168c-8acf-4d05-8137-90ad60d8265b_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JwG7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d168c-8acf-4d05-8137-90ad60d8265b_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!JwG7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d168c-8acf-4d05-8137-90ad60d8265b_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!JwG7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d168c-8acf-4d05-8137-90ad60d8265b_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!JwG7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d168c-8acf-4d05-8137-90ad60d8265b_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JwG7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d168c-8acf-4d05-8137-90ad60d8265b_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/969d168c-8acf-4d05-8137-90ad60d8265b_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:436950,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/210773025?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d168c-8acf-4d05-8137-90ad60d8265b_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JwG7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d168c-8acf-4d05-8137-90ad60d8265b_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!JwG7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d168c-8acf-4d05-8137-90ad60d8265b_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!JwG7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d168c-8acf-4d05-8137-90ad60d8265b_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!JwG7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d168c-8acf-4d05-8137-90ad60d8265b_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Here is a number that should ruin your morning coffee. CrowdStrike&#8217;s <a href="https://www.crowdstrike.com/global-threat-report/">2026 Global Threat Report</a> documents AI-enabled lateral movement in as little as 27 seconds. Mandiant&#8217;s <a href="https://cloud.google.com/security/resources/m-trends">M-Trends 2026 report</a> tracked the same collapse from a different angle: the median time from initial access to secondary threat group handoff fell from more than eight hours in 2022 to 22 seconds in 2025. Both figures show up in the 2026 Data Security and Compliance Risk Report, cited from those two source reports, and both describe the same event. Attackers do not need hours anymore. They need less time than it takes to read this paragraph.</p><p>Now put a second number next to it. Fifty percent of organizations cannot produce a complete AI data access audit record within one business day. Eighty-three percent cannot produce one within one hour. Ten percent cannot produce one at all.</p><p>Read that again. Twenty-seven seconds to compromise. A business day, or longer, to even find out what happened. That is not a gap. That is two different centuries trying to occupy the same network.</p><h3>Here&#8217;s the Whole Game</h3><p>Every AI governance conversation I sit in eventually drifts toward the same comfortable framing: &#8220;We&#8217;re closing the gap.&#8221; Boards like that phrase. It implies a plan, a timeline, a Gantt chart. It is also wrong, and it is wrong in a way that matters. You cannot &#8220;close&#8221; a 27-second exposure window with a governance program that convenes quarterly. Closing implies both sides are moving toward each other. They are not. The attacker&#8217;s clock keeps compressing &#8211; eight hours to 22 seconds in three years &#8211; while the average enterprise&#8217;s audit-response clock is still measured in days. This is not a gap to close. It is a structural mismatch between two systems operating on incompatible units of time, and no amount of incremental investment changes the unit.</p><h3>The Control Built for This Moment Doesn&#8217;t Exist at Most Companies</h3><p>An AI kill switch is exactly what it sounds like: the ability to sever an agent&#8217;s access the instant it misbehaves. It is the one control purpose-built for a 27-second threat window. Only 30% of organizations have one formally deployed. Seventy percent do not.</p><p>It gets worse before it gets better. Of organizations running AI in production, 23% have never tested the kill switch they have deployed. An untested kill switch is not a control. It is a rumor about a control, repeated in a compliance questionnaire until someone believes it.</p><p>Human-in-the-loop review for high-risk AI actions fares no better &#8211; deployed at only 30% of organizations, meaning 70% have no human checkpoint standing behind the missing automated one. So the honest inventory, for most companies, looks like this: no automated stop, no manual stop, and an adversary that closes the distance between &#8220;in&#8221; and &#8220;everywhere&#8221; in the time it takes to glance at a phone.</p><h3>The Logging Infrastructure That Can&#8217;t Answer the Question</h3><p>Containment gaps compound with visibility gaps. Only 37% of organizations have real-time alerting for AI data access anomalies. Only 33% forward AI <a href="http://kiteworks.com/regulatory-compliance/audit-log/">access logs</a> to a <a href="http://kiteworks.com/risk-compliance-glossary/what-is-security-information-and-event-management/">SIEM</a>. Only 29% generate any logs of AI system data access at all. One in four organizations &#8211; 25% &#8211; has no formal AI detection process whatsoever.</p><p>Sit with that last figure. A quarter of the market has put AI systems into production against sensitive data and built no formal mechanism to notice when those systems touch something they shouldn&#8217;t. Not a slow mechanism. No mechanism.</p><p>None of this is speculative risk sitting on a heat map somewhere. Eighty percent of organizations experienced at least one security <a href="http://kiteworks.com/risk-compliance-glossary/incident-response/">incident</a>, general or AI-specific, in the past 12 months. The incidents already happened. The only open question is whether the organization found out in 27 seconds or 27 days.</p><h3>Two Comfortable Answers, Both Wrong</h3><p>Faced with numbers like these, organizations reach for one of two comfortable answers. The first: slow AI adoption until governance catches up. That fails on contact with the business &#8211; AI deployment is not waiting for anyone&#8217;s governance committee, and freezing rollout just delays the reckoning while competitors ship. The second: keep adding monitoring dashboards and call the accumulation &#8220;progress.&#8221; That fails on contact with the math. A dashboard a human checks on a schedule is still bound to human tempo, and human tempo cannot answer a 27-second question no matter how many dashboards you stack on top of it.</p><p>The real variable is not adoption speed and it is not dashboard count. It is whether containment and <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit logging</a> happen at the point of data access itself, automatically, or whether they happen afterward, manually, on a schedule a human set. That is the only variable that moves your response time from days to seconds.</p><h3>The Architecture, Not the Meeting</h3><p>This is where a unified <a href="https://www.kiteworks.com/risk-compliance-glossary/data-governance/">data governance</a> control plane earns its place in the conversation &#8211; not as a silver bullet, but as one working example of governing at machine speed instead of meeting speed. Kiteworks&#8217; Control Plane applies one policy engine and one tamper-evident <a href="https://www.kiteworks.com/regulatory-compliance/audit-log/">audit trail</a> across every channel where sensitive data moves &#8211; email, <a href="http://kiteworks.com/risk-compliance-glossary/managed-file-transfer/">managed file transfer</a>, <a href="http://kiteworks.com/risk-compliance-glossary/sftp/">SFTP</a>, web forms, APIs &#8211; and extends that same enforcement to AI agents, governing human and machine data access under a single plane rather than as separate, unevenly instrumented systems. The point isn&#8217;t the product category. It&#8217;s the principle: logging and containment have to be a condition of access, generated the instant data moves, not a report someone assembles after the fact. The <a href="https://www.kiteworks.com/cybersecurity-risk-management/2026-data-security-forecast-ai-governance-predictions/">Kiteworks 2026 Forecast Report</a> called this exact containment gap the central battleground for 2026. It was right about the direction. This survey shows it was optimistic about the pace.</p><h3>What to Do Monday Morning</h3><p>Stop scheduling the meeting. Start doing this instead:</p><p><span>1. </span><strong>Test your kill switch this week.</strong> If nobody has fired it against a live agent session, you don&#8217;t have a kill switch. You have an assumption with a name.</p><p><span>2. </span><strong>Run a mock audit request today.</strong> Give your team one hour to produce a complete AI data access record for a single system. Whatever you get back, that&#8217;s your real number &#8211; not the one in last quarter&#8217;s board deck.</p><p><span>3. </span><strong>Check whether &#8220;real-time alerting&#8221; actually means real time.</strong> If AI <a href="http://kiteworks.com/regulatory-compliance/audit-log/">access logs</a> hit your <a href="http://kiteworks.com/risk-compliance-glossary/what-is-security-information-and-event-management/">SIEM</a> on a batch job, you are in the 63% without it, regardless of what the dashboard says.</p><p><span>4. </span><strong>Put a human checkpoint in front of every high-risk AI action that doesn&#8217;t have one</strong>, as a stopgap while you build the automated version.</p><p><span>5. </span><strong>Retire the phrase &#8220;closing the gap.&#8221;</strong> It describes a process. What you have is a mismatch, and mismatches get fixed by architecture, not by patience.</p><p>Your attacker already reset the clock to 27 seconds. The only decision left is whether your governance runs on that clock or on the old one.</p><p><em>Read the full findings in the <a href="https://www.kiteworks.com/sites/default/files/resources/kiteworks-report-2026-data-security-compliance-risk-report.pdf">2026 Data Security and Compliance Risk Report</a>.</em></p>]]></content:encoded></item><item><title><![CDATA[54% of Boards Ignored AI Governance. Still 54% Today.]]></title><description><![CDATA[The industry&#8217;s own data proved board engagement predicts AI maturity better than any other variable measured. Boards read the finding. They did nothing with it anyway.]]></description><link>https://kiteworks.substack.com/p/54-of-boards-ignored-ai-governance</link><guid isPermaLink="false">https://kiteworks.substack.com/p/54-of-boards-ignored-ai-governance</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Mon, 10 Aug 2026 15:00:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!YH-g!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe049134e-3bcd-43ae-b40f-82570d182dd7_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YH-g!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe049134e-3bcd-43ae-b40f-82570d182dd7_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YH-g!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe049134e-3bcd-43ae-b40f-82570d182dd7_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!YH-g!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe049134e-3bcd-43ae-b40f-82570d182dd7_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!YH-g!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe049134e-3bcd-43ae-b40f-82570d182dd7_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!YH-g!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe049134e-3bcd-43ae-b40f-82570d182dd7_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YH-g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe049134e-3bcd-43ae-b40f-82570d182dd7_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e049134e-3bcd-43ae-b40f-82570d182dd7_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:481125,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/210090048?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe049134e-3bcd-43ae-b40f-82570d182dd7_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YH-g!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe049134e-3bcd-43ae-b40f-82570d182dd7_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!YH-g!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe049134e-3bcd-43ae-b40f-82570d182dd7_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!YH-g!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe049134e-3bcd-43ae-b40f-82570d182dd7_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!YH-g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe049134e-3bcd-43ae-b40f-82570d182dd7_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In December 2025, Kiteworks published the <em>2026 Data Security and Compliance Risk: Forecast Report</em>, surveying 225 security and risk leaders. One finding stood out from the other fourteen: 54% of organizations had no standing <a href="http://kiteworks.com/cybersecurity-risk-management/ai-data-governance-guide/">AI data governance</a> agenda item at board level. The report called it the strongest correlation in the entire survey &#8211; organizations with board engagement scored 26 to 28 points higher on every single AI maturity metric measured. Not a marginal edge. A structural one.</p><p>That was six months ago. The new <em>2026 Data Security and Compliance Risk Report</em> surveyed 459 security and risk leaders in Q2 2026, explicitly built as what its authors call &#8220;the accountability document&#8221; &#8211; a test of all fifteen Forecast predictions against what actually happened. On board governance, the verdict lands in one sentence: 54%. Identical. Not directionally similar. The same number, to the point.</p><p>Here&#8217;s the whole game: this was never a measurement problem, a tooling gap, or a maturity curve that needed more time. It was a decision, made once in December and made again in June by simply not making it. Boards had six months, a named correlation, and a specific number telling them exactly what to do. They did not move.</p><h3>The Best Control in the Survey Is Still a Minority Practice</h3><p>Look at what &#8220;engaged&#8221; actually means before you assume your board clears this bar. Board-level <a href="http://kiteworks.com/cybersecurity-risk-management/ai-data-governance-guide/">AI data governance</a> reporting as a standing agenda item &#8211; the highest-rated governance control in the entire survey &#8211; is present at only 46% of organizations that have deployed AI systems. Across all organizations surveyed, regardless of AI deployment status, that figure drops to 30%.</p><p>Read that again. The single best-performing control Kiteworks measured, out of nineteen AI governance capabilities, is still something most organizations don&#8217;t do. This isn&#8217;t a case of boards lagging behind a strong industry norm. There is no strong industry norm. There is a minority practice that happens to correlate with everything else going right, and a majority that has decided it can wait.</p><h3>Boards Can Do This. They Choose Not To.</h3><p>The excuse writes itself: boards are generalists, AI is technical, directors can&#8217;t be expected to govern what they don&#8217;t build. That excuse doesn&#8217;t survive contact with how boards behave on adjacent risk.</p><p>The National Association of Corporate Directors&#8217; <a href="https://www.prnewswire.com/news-releases/nacd-report-economic-uncertainty-and-cyber-risks-top-board-priorities-302516123.html">2025 Public Company Board Practices and Oversight Survey</a> found 77% of directors now discuss the material and financial implications of cyber incidents at the board level &#8211; a 25-point jump since 2022. Boards moved on cyber risk in three years. They have had AI data governance sitting in front of them, with a named correlation attached, for six months and haven&#8217;t moved at all.</p><p>So the capacity argument fails. Boards can absorb a technical risk category into standing governance when they decide it matters enough. On cyber, they decided. On <a href="http://kiteworks.com/cybersecurity-risk-management/ai-data-governance-guide/">AI data governance</a>, at 54% of organizations, they haven&#8217;t.</p><p>Gartner&#8217;s own <a href="https://www.gartner.com/en/newsroom/press-releases/2026-05-26-gartner-says-applying-uniform-governance-across-ai-agents-will-lead-to-enterprise-ai-agent-failure">2026 predictions</a> forecast that 40% of enterprises will demote or decommission autonomous AI agents by 2027 because governance gaps only surface after a production incident. That is the cost of deferring the board conversation: you find out what you should have governed after it&#8217;s already broken.</p><h3>Why This Is Getting More Expensive, Not Less</h3><p>While boards sat still, the exposure compounded. The Annual Survey found 80% of organizations experienced at least one security incident &#8211; general or AI-specific &#8211; in the past twelve months, and 63% faced a compliance consequence: an audit finding, a remediation order, a regulatory investigation, or a board escalation that arrived only after something had already gone wrong. The World Economic Forum&#8217;s <a href="https://www.weforum.org/publications/global-cybersecurity-outlook-2026/">Global Cybersecurity Outlook 2026</a> puts data leaks at the top of CEOs&#8217; AI-related concerns &#8211; which makes the board&#8217;s silence on <a href="http://kiteworks.com/cybersecurity-risk-management/ai-data-governance-guide/">AI data governance</a> specifically, not AI generally, harder to explain away.</p><p>Ownership tells the same story from a different angle. Only 24% of organizations have a dedicated team for AI data governance. Thirty-nine percent bolt it onto an existing role &#8211; usually the CISO or CIO, who already owns general security, <a href="http://kiteworks.com/risk-compliance-glossary/incident-response/">incident response</a>, and now, apparently, AI governance too, without a board mandate or a budget line to match. IBM&#8217;s <a href="https://www.ibm.com/reports/data-breach">2025 Cost of a Data Breach Report</a>, produced with the Ponemon Institute, found 97% of organizations reporting an AI-related security incident lacked proper AI <a href="http://kiteworks.com/secure-file-sharing/secure-file-sharing-with-access-control/">access controls</a>, and 63% had no AI governance policy at all to stop it. The people closest to the problem know it. The people who set organizational priority have not said so.</p><h3>The Architectural Question Boards Keep Avoiding</h3><p>Here&#8217;s where it gets uncomfortable. A board agenda item is a governance decision, not a technology purchase &#8211; but it is also true that boards defer decisions when the underlying evidence is hard to produce. Ask a typical security leader for a complete AI data access <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit record</a> and half can&#8217;t deliver one within a business day. That is not a board failing to ask the right question. That is a board with nowhere to point when it does ask.</p><p>Architecture won&#8217;t make a board show up. But it can take away the excuse that the evidence doesn&#8217;t exist. A unified policy engine that governs how humans and AI systems alike access, move, and exchange sensitive data &#8211; built on a hardened, single-tenant architecture with evidence-quality, tamper-evident <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trails</a> &#8211; gives a board something to review on a quarterly cadence instead of a status update built on trust. Kiteworks&#8217; Control Plane is one example of a platform built on that premise. It doesn&#8217;t manufacture board accountability. It just removes the last excuse for not having it. The Annual Survey&#8217;s Mean AI Governance Maturity Score across all 459 respondents is 35 out of 100 &#8211; the average organization has deployed roughly 7 of 19 measured governance capabilities. That gap closes faster with a board paying attention than without one.</p><h3>What to do Monday morning</h3><p><span>1. </span>Put <a href="http://kiteworks.com/cybersecurity-risk-management/ai-data-governance-guide/">AI data governance</a> on the board agenda as a standing line item &#8211; not folded into general cybersecurity reporting, not addressed ad hoc when something breaks.</p><p><span>2. </span>Bring the board a number, not a narrative: your AI Governance Maturity Score, your audit-record turnaround time, your percentage of AI systems with logged, reviewable access.</p><p><span>3. </span>Assign dedicated ownership. If AI data governance is still an add-on to your CISO&#8217;s or CIO&#8217;s existing job description, name that as the gap it is, on the record, to the board.</p><p><span>4. </span>Ask your board directly whether it has discussed AI data governance in the past two quarters. If the honest answer is no, that answer is now the first agenda item.</p><p>Six months bought this industry nothing. The next six are optional in exactly the same way the last six were: boards can keep choosing not to decide, or they can act on a correlation they already have the data to justify. The number doesn&#8217;t move on its own. Someone with a board seat has to move it.</p><p><em>Read the full findings in the <a href="https://www.kiteworks.com/sites/default/files/resources/kiteworks-report-2026-data-security-compliance-risk-report.pdf">2026 Data Security and Compliance Risk Report</a>.</em></p>]]></content:encoded></item><item><title><![CDATA[You Didn’t Solve Shadow AI. You Just Stopped Calling It Forbidden.]]></title><description><![CDATA[Removing the ban was not a governance decision. It was the absence of one.]]></description><link>https://kiteworks.substack.com/p/you-didnt-solve-shadow-ai-you-just</link><guid isPermaLink="false">https://kiteworks.substack.com/p/you-didnt-solve-shadow-ai-you-just</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Fri, 07 Aug 2026 15:00:14 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!xA8O!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7487b83e-d6ee-41c5-a727-b6ddf0b9d62a_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xA8O!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7487b83e-d6ee-41c5-a727-b6ddf0b9d62a_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xA8O!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7487b83e-d6ee-41c5-a727-b6ddf0b9d62a_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!xA8O!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7487b83e-d6ee-41c5-a727-b6ddf0b9d62a_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!xA8O!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7487b83e-d6ee-41c5-a727-b6ddf0b9d62a_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!xA8O!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7487b83e-d6ee-41c5-a727-b6ddf0b9d62a_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xA8O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7487b83e-d6ee-41c5-a727-b6ddf0b9d62a_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7487b83e-d6ee-41c5-a727-b6ddf0b9d62a_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:551339,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/209967756?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7487b83e-d6ee-41c5-a727-b6ddf0b9d62a_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xA8O!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7487b83e-d6ee-41c5-a727-b6ddf0b9d62a_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!xA8O!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7487b83e-d6ee-41c5-a727-b6ddf0b9d62a_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!xA8O!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7487b83e-d6ee-41c5-a727-b6ddf0b9d62a_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!xA8O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7487b83e-d6ee-41c5-a727-b6ddf0b9d62a_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Bans dropped 21 points in a year. Technical controls didn&#8217;t move. That&#8217;s not progress &#8211; that&#8217;s a policy department admitting defeat and calling it strategy.</p><p>Picture the memo. Some VP of Security Policy, sometime in late 2025, drafts an update to the acceptable-use policy. The line that once read &#8220;employees may not use unauthorized AI tools to process company data&#8221; quietly disappears. Nobody frames it as surrender. It gets filed under &#8220;modernizing our AI governance approach.&#8221; The all-hands slide says the company is &#8220;embracing AI while managing risk.&#8221; What actually happened is simpler: the ban wasn&#8217;t working, nobody built the thing that should have replaced it, and someone decided the cleanest fix was to stop having a rule that everyone was already breaking.</p><p>That&#8217;s not a hypothetical. It&#8217;s the finding.</p><p>The <a href="https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2026/m01/ai-data-privacy-investments-governance-cisco-report.html">Cisco 2026 Data and Privacy Benchmark Study</a> found that outright bans on AI tool usage fell from 28% of organizations in 2025 to 7% in 2026. Twenty-one points, gone in twelve months. Cisco found no corresponding rise in the technical controls that would need to exist for that retreat to be safe. Same study: enterprise AI usage more than doubled in 2025, and 62% of workers now use AI at work. Adoption accelerated. Governance did not follow it. Those two facts sitting next to each other are the entire story of this piece.</p><h3>What actually happened while nobody was watching</h3><p>Here&#8217;s the whole game: organizations didn&#8217;t defeat <a href="http://kiteworks.com/cybersecurity-risk-management/zero-trust-generative-ai/">shadow AI</a>. They ran out of the will to keep pretending the ban was enforceable, and quietly downgraded the problem from &#8220;prohibited&#8221; to &#8220;somebody else&#8217;s responsibility to notice.&#8221;</p><p>The 2026 Data Security and Compliance Risk Report puts a number on how much there is to notice. Sixty-five percent of organizations discovered employees using unapproved AI tools with organizational data in the past twelve months. Sixteen percent are finding it monthly or more. Twenty-eight percent quarterly. Twenty-one percent have caught it at least once, rarely. Add those up and you get an organizational habit, not an isolated incident.</p><p>The 35% who report no discovery at all deserve a second look, and not a reassuring one. Detection gaps and clean environments look identical from the outside. An organization with no logging on AI data flows and no alerting on anomalous transmissions will report zero <a href="http://kiteworks.com/cybersecurity-risk-management/zero-trust-generative-ai/">shadow AI</a> incidents right up until the breach notification arrives. Absence of evidence, in this specific case, is evidence of a blind spot.</p><h3>The data isn&#8217;t generic, and that&#8217;s the part that should worry you</h3><p>Shadow AI usage isn&#8217;t employees asking a chatbot to summarize a press release. Among organizations using employee-facing AI chatbots, 36% report customer and client data flowing through them. Thirty-three percent route IT <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credentials</a> and access requests. Thirty-one percent route employee personal and HR data. Thirty percent route financial data.</p><p>Read that again. A third of these organizations have employees handing IT credentials to a consumer AI tool with no enterprise contract, no data processing agreement, and no <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trail</a>. That&#8217;s not a training gap. That&#8217;s a <a href="http://kiteworks.com/cybersecurity-risk-management/data-exfiltration/">data exfiltration</a> channel that happens to be voluntary.</p><h3>Why the response doesn&#8217;t match the exposure</h3><p>Here&#8217;s where it gets uncomfortable. Discovering <a href="http://kiteworks.com/cybersecurity-risk-management/zero-trust-generative-ai/">shadow AI</a> and doing something about it are two different events, and the report shows most organizations stop after the first one. Among organizations that found shadow AI in use, the most common response was issuing updated policy guidance. Fewer than half went on to deploy technical controls that would actually prevent it from happening again.</p><p>Training keeps winning the budget argument anyway. Thirty-six percent of organizations name workforce training on AI data security as a top investment priority &#8211; the single most commonly planned response to a problem that training cannot structurally fix. An employee who has read the policy and still has an unblocked path to a consumer AI tool hasn&#8217;t been protected. They&#8217;ve been informed of a rule they remain fully capable of breaking, with documentation now proving they knew better.</p><p>The <a href="https://www.helpnetsecurity.com/2026/02/26/insider-risk-costs-2026/">2026 Cost of Insider Risks Global Report</a> from the Ponemon Institute names <a href="http://kiteworks.com/cybersecurity-risk-management/zero-trust-generative-ai/">shadow AI</a> as the leading driver of negligent insider incidents, pushing average annual insider risk cost to $19.5 million per organization. That figure isn&#8217;t rising because employees got worse at following instructions. It&#8217;s rising because the instructions were never backed by anything that could stop the behavior.</p><h3>The architectural question everyone is avoiding</h3><p>Stop asking whether employees should be trusted to follow the updated AI policy. Here&#8217;s the question that actually matters: what, mechanically, stops sensitive data from reaching an unapproved AI tool if an employee decides to send it anyway?</p><p>For 72% of organizations, the answer is nothing. Only 28% have AI-specific <a href="http://kiteworks.com/risk-compliance-glossary/data-loss-prevention-dlp/">data loss prevention</a> deployed &#8211; the control that blocks sensitive data at the transmission layer instead of just documenting the violation after the fact. Purpose binding, which restricts AI agents and tools to authorized tasks and data scopes, is deployed at just 27%. Both numbers are governed the same way for human users and for the AI agents acting on their behalf &#8211; an unbound agent is exactly as capable of moving data somewhere it shouldn&#8217;t as an unsupervised employee, and neither has anything stopping them without a technical layer in place.</p><p>This is the point where the industry usually reaches for a policy fix, because policy fixes are cheap and fast to announce. But a policy is a sentence. A transmission-layer control is an architecture &#8211; something that inspects and blocks AI-bound traffic across every channel sensitive data actually moves through, rather than relying on a general-purpose network tool that was never built to recognize an AI destination in the first place. Detection after the fact is documentation. Enforcement at the transmission layer is the only thing that changes behavior that policy alone has already failed to change.</p><h3>What to do Monday morning</h3><p>The ban was never the control. It was a placeholder standing in for a control that most organizations never built, and now the placeholder is gone too. Here&#8217;s what closes the gap it leaves behind:</p><p><span>1. </span>Pull your AI data access logs and check them for gaps, not incidents. If you have no real-time alerting on AI data transmissions, your &#8220;no shadow AI discovered&#8221; result measures blindness, not safety.</p><p><span>2. </span>Map which of the four high-risk data categories &#8211; customer data, <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credentials</a>, HR data, financial data &#8211; has an actual technical block in front of unapproved AI tools. If the answer is policy language instead of a control, you don&#8217;t have a mitigation.</p><p><span>3. </span>Stop funding training as the primary response to a discovered <a href="http://kiteworks.com/cybersecurity-risk-management/zero-trust-generative-ai/">shadow AI</a> incident. Budget the transmission-layer control instead, and treat training as the secondary layer, not the first line of defense.</p><p><span>4. </span>Ask your vendor governance team the blunt question: can we verify, technically, whether our approved AI vendors use our data for model training, or are we relying on a signed attestation we&#8217;ve never actually tested?</p><p><span>5. </span>If your organization dropped its AI ban in the last year, find out what replaced it. If the honest answer is &#8220;updated guidance,&#8221; you didn&#8217;t modernize your policy. You repealed your only control and never built the next one.</p><p>Twenty-one points of bans disappeared in a single year. Zero points of technical control appeared to take their place. That&#8217;s not an evolution in AI governance. It&#8217;s a governance vacancy with a press release attached.</p><p><em>Read the full findings in the <a href="https://www.kiteworks.com/sites/default/files/resources/kiteworks-report-2026-data-security-compliance-risk-report.pdf">2026 Data Security and Compliance Risk Report.</a></em></p>]]></content:encoded></item><item><title><![CDATA[60% of Enterprises Can’t Shut Down a Rogue AI Agent]]></title><description><![CDATA[Not &#8220;won&#8217;t.&#8221; Can&#8217;t. There is no kill switch, no purpose limit, no verified identity check standing between a compromised agent and your data.]]></description><link>https://kiteworks.substack.com/p/60-of-enterprises-cant-shut-down</link><guid isPermaLink="false">https://kiteworks.substack.com/p/60-of-enterprises-cant-shut-down</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Thu, 06 Aug 2026 15:02:39 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NUvL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc71124c2-7b16-4f03-85cc-660cb0ab5b35_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NUvL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc71124c2-7b16-4f03-85cc-660cb0ab5b35_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NUvL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc71124c2-7b16-4f03-85cc-660cb0ab5b35_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!NUvL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc71124c2-7b16-4f03-85cc-660cb0ab5b35_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!NUvL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc71124c2-7b16-4f03-85cc-660cb0ab5b35_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!NUvL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc71124c2-7b16-4f03-85cc-660cb0ab5b35_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NUvL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc71124c2-7b16-4f03-85cc-660cb0ab5b35_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c71124c2-7b16-4f03-85cc-660cb0ab5b35_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:467455,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/209966310?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc71124c2-7b16-4f03-85cc-660cb0ab5b35_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NUvL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc71124c2-7b16-4f03-85cc-660cb0ab5b35_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!NUvL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc71124c2-7b16-4f03-85cc-660cb0ab5b35_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!NUvL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc71124c2-7b16-4f03-85cc-660cb0ab5b35_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!NUvL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc71124c2-7b16-4f03-85cc-660cb0ab5b35_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Here&#8217;s what a live red-team exercise just proved about what happens next.</p><p>It&#8217;s a Tuesday morning in February 2026, and a researcher at a security lab is about to break an AI agent using nothing but a Discord display name. Twenty researchers from MIT, Stanford, Carnegie Mellon, and Harvard spent two weeks running live, non-sandboxed agents built on the open-source OpenClaw framework, then attacked them the way a bored teenager would. One researcher renamed themselves to match an agent&#8217;s owner. The agent caught it instantly inside the channel it already knew. Then the same researcher opened a fresh private channel with no history attached, and the agent, faced with an identity it had no way to verify, handed over its memory files, its name, and its administrative access. No exploit. No <a href="http://kiteworks.com/risk-compliance-glossary/malware-based-attacks/">malware</a>. Just a display name.</p><p>Here&#8217;s the whole game: enterprises are deploying agentic AI faster than they are building any way to govern it, and the industry has quietly agreed to call this &#8220;early days&#8221; instead of what it is, which is a governance failure at scale. Agents will always outrun policy. That&#8217;s not a prediction, it&#8217;s a design fact, and every number below is just a different way of measuring the gap.</p><h3><span>What the researchers actually found</span></h3><p>The study, <a href="https://agentsofchaos.baulab.info/report.html">Agents of Chaos</a>, documented at least ten significant security breaches across eleven representative case studies, and the pattern across them is not sophistication &#8211; it&#8217;s the absence of a stakeholder model. In one case, an agent refused a direct request for &#8220;the SSN in the email&#8221; but handed over the entire email, unredacted Social Security number and bank details included, when the same person asked it to forward the message instead. The agent could recognize an explicit ask for sensitive data. It could not recognize that the container holding that data was the identical exposure wearing a different hat.</p><p>The researchers call this a structural problem, not a bug. Large language model agents process instructions and data as the same kind of token in the same context window, which means the model has no reliable way to tell &#8220;do this&#8221; from &#8220;here is information&#8221; once both arrive in the same stream. Prompt injection isn&#8217;t a <a href="http://kiteworks.com/risk-compliance-glossary/vulnerability/">vulnerability</a> you patch. It&#8217;s a property of how these systems currently work.</p><h3><span>The pattern is bigger than one lab</span></h3><p>If this were confined to one open-source framework, you could file it under &#8220;early days&#8221; and move on. It isn&#8217;t. <a href="https://www.crowdstrike.com/en-us/global-threat-report/">CrowdStrike&#8217;s 2026 Global Threat Report</a> tracked an 89% year-over-year increase in operations by AI-enabled adversaries and found attackers injecting malicious prompts into GenAI tools at more than 90 organizations, on top of abusing AI development platforms directly. The <a href="https://www.weforum.org/publications/global-cybersecurity-outlook-2026/">World Economic Forum&#8217;s Global Cybersecurity Outlook 2026</a> adds the enterprise-side mirror image: roughly a third of organizations have no process at all to validate an AI system&#8217;s security before deployment, and only about 40% run periodic AI security reviews once it&#8217;s live.</p><p>Put those two findings next to each other: an 89% jump in AI-enabled attacks on one side, 63% of organizations unable to enforce a purpose limit on their own agents on the other. Attackers are getting faster at exploiting AI systems. Most defenders aren&#8217;t checking whether their own AI systems are exploitable in the first place. That&#8217;s not a gap. That&#8217;s an open door with a welcome mat.</p><h3><span>Why the math got worse this year</span></h3><p>Governance debt on agentic AI has been accumulating quietly for two years. What changed is that agents stopped being a lab curiosity and became a procurement line item. The <a href="https://www.kiteworks.com/cybersecurity-risk-management/2026-data-security-forecast-ai-governance-predictions/">Kiteworks Data Security and Compliance Risk: 2026 Forecast Report</a> found that 100% of surveyed organizations now have agentic AI on their roadmap. Sixty-three percent cannot enforce purpose limitations on what those agents do once deployed. Sixty percent have no way to terminate a misbehaving agent. Fifty-five percent cannot isolate their AI systems from the broader network if something does go wrong.</p><p>Read that again. Every organization surveyed is building toward agentic AI. Most of them have no brakes, no steering, and no wall between the car and the rest of the building.</p><p>Inside government specifically, the same report found 90% lack purpose binding for AI agents and 76% have no kill switch at all. That&#8217;s the sector with the most sensitive data and the least ability to stop an agent mid-task. The <a href="https://www.nist.gov/news-events/news/2026/02/announcing-ai-agent-standards-initiative-interoperable-and-secure">NIST AI Agent Standards Initiative</a>, announced this February, names agent identity, authorization, and security as the priority areas for standardization. Standards bodies only move this fast when the field has already outpaced them.</p><h3><span>The architectural question</span></h3><p>The tactical response to all of this &#8211; write better system prompts, add a content filter, tell the agent to &#8220;be careful&#8221; &#8211; was never going to hold. You cannot patch your way out of a structural problem in how the model separates instruction from data. The fix has to sit outside the model, at the point where the agent actually touches a file, a folder, or a record, evaluating every request against policy the agent cannot argue its way around.</p><p>That&#8217;s the premise a small number of platforms are now building toward: treat the AI client as a governed identity, not a trusted one, and enforce the same <a href="http://kiteworks.com/risk-compliance-glossary/role-based-access-control/">role-based</a> and attribute-based <a href="http://kiteworks.com/secure-file-sharing/secure-file-sharing-with-access-control/">access controls</a> on it that already apply to human users. Kiteworks&#8217; Secure MCP Server is one example &#8211; it routes every AI request through a policy engine before data ever reaches the model, running on <a href="http://kiteworks.com/risk-compliance-glossary/fips/">FIPS</a> 140-3 validated cryptography, so the access decision, not the agent&#8217;s judgment, determines what comes back. For what it&#8217;s worth, we run this internally too: our own teams connect through the Connector day to day, which is a useful forcing function for finding the gaps in your own story before a customer does. It&#8217;s a narrow example of a broader architectural shift: governance has to move to the front of the request, for humans and agents alike, or it doesn&#8217;t count.</p><h3><span>What to do this week</span></h3><p><span>1. </span>Ask your AI/ML team a direct question: can we terminate any deployed agent within sixty seconds, and can you show me the control that does it? If the answer is &#8220;we&#8217;d have to shut down the whole service,&#8221; you don&#8217;t have a kill switch, you have a hope.</p><p><span>2. </span>Audit whether any AI agent in production has standing access to a data store, versus access gated per-request against <a href="http://kiteworks.com/risk-compliance-glossary/role-based-access-control/">RBAC</a> or <a href="http://kiteworks.com/risk-compliance-glossary/attribute-based-access-control/">ABAC</a> policy. Standing access is the CS8 failure mode waiting to happen with your data instead of a researcher&#8217;s.</p><p><span>3. </span>Check whether identity verification for an AI client persists across sessions or channels, or resets to zero the moment context changes. If it resets, you have the same cross-channel gap the OpenClaw agents had.</p><p><span>4. </span>Stop treating &#8220;the agent behaved correctly in testing&#8221; as evidence of anything. The Agents of Chaos researchers weren&#8217;t testing average-case behavior. They were looking for one counterexample, because demonstrating a <a href="http://kiteworks.com/risk-compliance-glossary/vulnerability/">vulnerability</a> only takes one.</p><p><span>5. </span>Put a number on your purpose-binding and containment controls this quarter, not next year&#8217;s roadmap. Sixty-three percent of your peers already can&#8217;t answer this question. Being able to is now a competitive fact, not a compliance nicety.</p><p>The agent that deleted its own memory files didn&#8217;t do anything an attacker forced it to do in the technical sense. It did exactly what it was designed to do: trust the identity in front of it. That&#8217;s the whole problem, and it&#8217;s the whole opportunity. Fix what the agent trusts, and you fix the incident before it has a chance to happen.</p>]]></content:encoded></item><item><title><![CDATA[Your AI Agent Just Handed Its Credentials to a Stranger.]]></title><description><![CDATA[Venture capital already knows the fix. Most enterprises haven&#8217;t shipped it.]]></description><link>https://kiteworks.substack.com/p/your-ai-agent-just-handed-its-credentials</link><guid isPermaLink="false">https://kiteworks.substack.com/p/your-ai-agent-just-handed-its-credentials</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Wed, 05 Aug 2026 15:03:02 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9RYg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36dd47c2-d41f-4759-bca7-53bc9d52f175_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9RYg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36dd47c2-d41f-4759-bca7-53bc9d52f175_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9RYg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36dd47c2-d41f-4759-bca7-53bc9d52f175_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!9RYg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36dd47c2-d41f-4759-bca7-53bc9d52f175_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!9RYg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36dd47c2-d41f-4759-bca7-53bc9d52f175_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!9RYg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36dd47c2-d41f-4759-bca7-53bc9d52f175_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9RYg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36dd47c2-d41f-4759-bca7-53bc9d52f175_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/36dd47c2-d41f-4759-bca7-53bc9d52f175_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:499937,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/209826203?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36dd47c2-d41f-4759-bca7-53bc9d52f175_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9RYg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36dd47c2-d41f-4759-bca7-53bc9d52f175_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!9RYg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36dd47c2-d41f-4759-bca7-53bc9d52f175_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!9RYg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36dd47c2-d41f-4759-bca7-53bc9d52f175_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!9RYg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36dd47c2-d41f-4759-bca7-53bc9d52f175_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>DataTribe published its <a href="https://datatribe.com/news/insights-report-q2-2026-its-all-about-agents-these-days/">Q2 2026 Insights Report</a> on July 27. Two days later, <a href="https://www.helpnetsecurity.com/2026/07/31/ai-agents-cybersecurity-seed-funding/">Help Net Security</a> ran the number that mattered: AI and agent security is now the single largest category of cybersecurity seed-stage investment, close to a quarter of every deal done last quarter. That is not the story. The story is why investors are suddenly this specific about it.</p><p>They are not funding &#8220;AI security&#8221; in the abstract. They are funding one mechanism: an agent that spins up a second agent, mid-task, and hands it live <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credentials</a> &#8211; no verification, no scoping, no log. DataTribe found roughly a quarter of deployed agents can do this today. Read that again. A quarter of the agents already running in production environments can silently create a new, unaccountable identity and give it the keys.</p><h3>The Number Investors Actually Priced</h3><p>Here&#8217;s the whole game: DataTribe measured every control in its dataset for impact on incident rates, and one control beat all the others by a wide margin. Scoping agent privileges to least-privilege access took incident rates from more than two-thirds of deployments down to below 20%. Not a modest improvement. A collapse.</p><p>That is what seed money is chasing &#8211; not agent security as a category, but the specific, provable lever inside it. Everything else investors funded this quarter is downstream of that one finding.</p><h3>The Handoff Nobody Is Watching</h3><p>Call it silent succession: an agent, mid-task, creates a subordinate agent and passes it working authority without telling anyone. No identity provider checks who the new agent is. No policy engine scopes what it can touch. No log records that the handoff happened at all.</p><p>This is not a hypothetical. It is the mechanism DataTribe is describing when it says a quarter of deployed agents can spawn sub-agents and hand off live <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credentials</a> with no verification, scoping, or <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trail</a>. The sub-agent inherits whatever access its parent happened to be holding, which is almost always broader than the actual sub-task requires. Nobody approved that grant. Nobody is accountable for it. It just happened, in milliseconds, because the architecture allows it.</p><p>Kiteworks&#8217; own <a href="https://www.kiteworks.com/cybersecurity-risk-management/2026-data-security-forecast-ai-governance-predictions/">Data Security and Compliance Risk: 2026 Forecast Report</a> found 60% of organizations cannot terminate a misbehaving AI agent once it is running, and 63% cannot enforce purpose limitations on what an agent is allowed to do in the first place. Those two numbers explain why silent succession works as an attack path. You cannot scope what you cannot see, and you cannot kill what you have no switch for.</p><h3>Why the Math Got Worse This Quarter</h3><p>None of this would matter as much if defenders still had time to notice. They don&#8217;t. DataTribe cites <a href="https://www.crowdstrike.com/en-us/global-threat-report/">CrowdStrike&#8217;s 2026 Global Threat Report</a>, which puts the fastest observed breakout time this year &#8211; initial compromise to lateral movement &#8211; at 27 seconds.</p><p>Twenty-seven seconds. That is not a detection window. That is barely enough time for a SOC dashboard to refresh. A human analyst cannot triage an alert, rule out a false positive, and contain an incident inside 27 seconds. Nothing built around &#8220;detect, then respond&#8221; survives contact with that number.</p><p>Meanwhile the old front door hasn&#8217;t closed. <a href="https://www.verizon.com/about/news/2025-data-breach-investigations-report">Verizon&#8217;s 2025 Data Breach Investigations Report</a> found edge device and VPN exploitation rising sevenfold. So attackers are getting through the perimeter faster than ever, and once inside, they are increasingly finding unscoped, unlogged agent identities waiting for them. Fast entry plus ungoverned agent sprawl plus a 27-second window is not three separate problems. It&#8217;s one compounding one.</p><h3>The Architectural Question</h3><p>Here&#8217;s where it gets uncomfortable for anyone still thinking about this as a detection problem. If breakout happens in 27 seconds and a quarter of your agents can silently mint new identities with inherited access, faster alerting does not save you. The only control that acts inside that window is one that was already in place before the agent asked for anything.</p><p>That means the fix has to live at the point of the request, not at the perimeter and not in a <a href="http://kiteworks.com/risk-compliance-glossary/what-is-security-information-and-event-management/">SIEM</a> dashboard after the fact. Every time an agent &#8211; or a sub-agent it just created &#8211; asks to touch a file, a record, or a dataset, something has to evaluate that specific request against policy before access is granted, and log it regardless of the outcome. This is the architectural bet a handful of vendors are making, Kiteworks among them: a <a href="https://www.kiteworks.com/platform/security/mcp-ai-integration/">unified policy engine</a> that enforces per-request <a href="http://kiteworks.com/risk-compliance-glossary/role-based-access-control/">RBAC</a> and <a href="http://kiteworks.com/risk-compliance-glossary/attribute-based-access-control/">ABAC</a> for both human and agent identities under one plane, so a sub-agent inherits governance the moment it&#8217;s created instead of inheriting whatever access its parent happened to be holding. It is one example of the pattern, not the only one, and it does nothing for the edge and VPN exploitation Verizon is describing. Perimeter hardening and content-layer governance are two different budget lines that need to move together.</p><h3>What to Do This Week</h3><p><span>1. </span>Inventory which of your deployed agents can spawn sub-agents. Most security teams cannot currently answer this question. That is the actual gap, not a lack of tooling.</p><p><span>2. </span>Require that any sub-agent creation event triggers its own identity verification and scoped credential issuance &#8211; never inherited, unscoped access from the parent.</p><p><span>3. </span>Confirm you have a working kill switch. If 60% of organizations can&#8217;t terminate a misbehaving agent, assume you&#8217;re in that group until you&#8217;ve tested it.</p><p><span>4. </span>Push least-privilege scoping to the top of the AI governance roadmap, ahead of general AI policy work. It is the only control DataTribe measured that cut incident rates by two-thirds.</p><p><span>5. </span>Stop treating this as a perimeter problem or a content-governance problem. It is both, funded from the same conversation, on the same timeline.</p><p>Venture capital isn&#8217;t betting on agentic AI security because it sounds forward-looking. It&#8217;s betting on it because DataTribe just showed the industry which control actually works, and most enterprises haven&#8217;t installed it yet. That gap is not a research question anymore. It&#8217;s a Monday morning task list.</p>]]></content:encoded></item><item><title><![CDATA[53% of Sysadmins Won’t Trust AI Alone With Your Servers.]]></title><description><![CDATA[The patch is not the story. The accountability gap is.]]></description><link>https://kiteworks.substack.com/p/53-of-sysadmins-wont-trust-ai-alone</link><guid isPermaLink="false">https://kiteworks.substack.com/p/53-of-sysadmins-wont-trust-ai-alone</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Tue, 04 Aug 2026 15:03:03 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!8WJb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b16a25d-094e-4d58-9f90-8f0742e7dd93_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8WJb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b16a25d-094e-4d58-9f90-8f0742e7dd93_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8WJb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b16a25d-094e-4d58-9f90-8f0742e7dd93_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!8WJb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b16a25d-094e-4d58-9f90-8f0742e7dd93_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!8WJb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b16a25d-094e-4d58-9f90-8f0742e7dd93_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!8WJb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b16a25d-094e-4d58-9f90-8f0742e7dd93_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8WJb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b16a25d-094e-4d58-9f90-8f0742e7dd93_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0b16a25d-094e-4d58-9f90-8f0742e7dd93_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:470923,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/209690344?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b16a25d-094e-4d58-9f90-8f0742e7dd93_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8WJb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b16a25d-094e-4d58-9f90-8f0742e7dd93_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!8WJb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b16a25d-094e-4d58-9f90-8f0742e7dd93_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!8WJb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b16a25d-094e-4d58-9f90-8f0742e7dd93_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!8WJb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b16a25d-094e-4d58-9f90-8f0742e7dd93_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Picture a Tuesday morning in July 2026: your patch dashboard has already ranked forty new CVEs by exploitability, and the AI did that ranking overnight, unsupervised, while you slept. All that is left is one click: deploy across production. You do not click it. Neither would 53% of your peers, according to Action1&#8217;s newly released <em><a href="https://www.helpnetsecurity.com/2026/07/31/action1-sysadmins-ai-expectations-report/">2026 Survey Report: AI Impact on Sysadmins</a></em>. Two years ago, this same population told researchers that by now AI would be running patch management, <a href="http://kiteworks.com/risk-compliance-glossary/vulnerability/">vulnerability</a> prioritization, and <a href="http://kiteworks.com/risk-compliance-glossary/incident-response/">incident response</a> with minimal human involvement. It is not. And the reason has nothing to do with whether the models got good enough.</p><h3>What Sysadmins Actually Said</h3><p>Start with the number that should embarrass every AI roadmap slide from 2024: fewer than one in five sysadmins currently use AI for patch management or <a href="http://kiteworks.com/risk-compliance-glossary/vulnerability/">vulnerability</a> prioritization &#8211; the two workflows they themselves flagged as most automatable. Twenty-three percent said they have never used AI professionally at all. Not &#8220;rarely.&#8221; Never.</p><p>Then look at where trust actually breaks. Only 14% would let AI deploy patches across production systems without supervision. Just 11% would let AI override an existing patching policy under any circumstance, and 40% said they never would. Sysadmins will let AI schedule maintenance windows and triage alert noise. They will not let it touch the thing that keeps the business running, unwatched.</p><p>Here is the sentence in the report that matters more than any of those percentages: when AI acting on file or identity management makes an error, accountability for the resulting harm is left ambiguous. Read that again. The industry has spent two years debating whether AI is capable enough. Nobody built the part where someone is on the hook when it is wrong.</p><h3>The 2024 Predictions Didn&#8217;t Miss. They Inverted.</h3><p>AI did not fail to keep pace with a 2024 roadmap. A different fear just won out. Back then, sysadmins worried the technology would mature too slowly. Now the worry has flipped: it matured fast enough to act, not fast enough to be trusted with the blast radius of that action.</p><p>That fear is not isolated to IT operations. IBM&#8217;s <em>2026 Cost of a Data Breach Report</em>, based on Ponemon Institute interviews with staff at more than 600 breached organizations, found that among organizations reporting an AI-related security incident, <a href="https://www.helpnetsecurity.com/2026/07/30/ibm-cost-of-a-data-breach-2026/">92% were missing basic role-based access controls, MFA, or equivalent safeguards</a> on the AI systems involved. Fewer than half of organizations secure the non-human identities their AI workflows depend on. Close to seven in ten of those breached organizations lack governance policies for AI use at all. The sysadmin who will not let a model touch production unsupervised is not being a Luddite. He has seen the breach data the rest of the industry is still catching up to.</p><h3>Why the Math Got Worse, Not Better</h3><p>Two years ago, &#8220;AI in IT operations&#8221; mostly meant a chatbot summarizing logs. In 2026, it means agents with standing access to systems, <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credentials</a>, and file stores &#8211; acting continuously, not on request. That shift changes the risk calculus entirely, and a separate 2026 survey from 1Password of 1,000 security and engineering staff at large U.S. firms shows exactly how. Seventy-one percent said their AI agents can reach sensitive information. At roughly four in ten organizations, <a href="https://www.helpnetsecurity.com/2026/07/29/1password-ai-agent-governance/">agents reach data outside what was ever approved for them</a> &#8211; agents touched, on average, twice as much data as anyone had signed off on. Forty percent of developers grant agents persistent access that outlives the task. One in three respondents who use agents reported a breach or incident tied specifically to overprivileged non-human identities.</p><p>Then ask who answers for it. In that same survey, 65% of respondents said accountability should sit with someone other than whoever is currently assigned it. Five percent said the agent itself should be accountable. An agent cannot be fired, sued, or deposed. That five percent is not an edge case. It is what happens when an organization deploys autonomy faster than it defines ownership.</p><p>Gartner has already priced this in at the portfolio level: it predicts <a href="https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027">more than 40% of agentic AI projects will be canceled by the end of 2027</a>, largely on escalating costs and inadequate <a href="http://kiteworks.com/risk-compliance-glossary/security-risk-management/">risk controls</a>. The sysadmins in the Action1 survey are not lagging the roadmap. They are the roadmap correcting itself.</p><h3>The Architectural Question</h3><p>Here is the question I keep coming back to: why does every conversation about AI trust default to &#8220;is the model good enough&#8221; instead of &#8220;can we see and constrain what it just did?&#8221; Those are different problems, and only one of them has a mature answer today.</p><p>Faster patch algorithms do not close an accountability gap. Better prompts do not either. What closes it is treating every AI action &#8211; human-initiated or agent-initiated &#8211; as a governed, logged request against a defined policy, the same way you would treat a privileged employee action, not as a separate autonomous actor operating outside the rules humans follow. A handful of vendors are starting to build access-governance layers on exactly that premise: a single policy engine that enforces per-request rules on what any identity, human or AI agent, can actually reach, and that logs each request in an <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trail</a> detailed enough to survive a post-incident investigation. None of that makes an AI model trustworthy on its own merits. It makes an organization&#8217;s exposure visible and provable when the model gets it wrong, the exact accountability layer the Action1 and 1Password data show is missing. One boundary matters here, though: that kind of access governance covers content and <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credential</a> access, not the IT operations task of pushing a patch to a production server. Those are neighboring problems, not the same problem, and Kiteworks&#8217; own <a href="https://www.kiteworks.com/cybersecurity-risk-management/2026-data-security-forecast-ai-governance-predictions/">2026 Data Security and Compliance Risk Forecast Report</a> tracks them separately for that reason.</p><h3>What This Means Monday Morning</h3><p><span>1. </span>Pull your own numbers before you argue with the sysadmins. What percentage of your patch, <a href="http://kiteworks.com/risk-compliance-glossary/vulnerability/">vulnerability</a>, and identity workflows actually touch AI unsupervised right now? Most teams do not know.</p><p><span>2. </span>Write down who is accountable for an AI-driven access error before one happens, not after. If your answer is &#8220;the vendor&#8221; or &#8220;the model,&#8221; you have the same gap 65% of the 1Password respondents flagged.</p><p><span>3. </span>Separate the two governance problems on your roadmap: operational autonomy (should AI deploy the patch) and data access governance (what can the agent touch while doing anything). Different controls, different owners, different timelines.</p><p><span>4. </span>Audit non-human identities the way you audit privileged human accounts &#8211; expiration, scope, logging &#8211; because fewer than half of organizations currently do, per IBM&#8217;s 2026 data.</p><p><span>5. </span>Demand an <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trail</a> before you demand autonomy. The sysadmins already figured this out. The rest of the industry is still arguing about model capability.</p><p>The gap was never between what AI could do and what sysadmins would let it do. It was between what AI could do and what anyone could prove it did.</p>]]></content:encoded></item><item><title><![CDATA[EU AI Act Transparency Enforcement Exposes Your Shadow AI Problem.]]></title><description><![CDATA[The transparency rules everyone is talking about are not the hard part. The AI systems your security team does not know exist are.]]></description><link>https://kiteworks.substack.com/p/eu-ai-act-transparency-enforcement</link><guid isPermaLink="false">https://kiteworks.substack.com/p/eu-ai-act-transparency-enforcement</guid><dc:creator><![CDATA[Marc ten Eikelder]]></dc:creator><pubDate>Mon, 03 Aug 2026 20:30:24 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!rwzo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa695f13b-a53a-4095-b5ab-4e958ba9b1cb_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rwzo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa695f13b-a53a-4095-b5ab-4e958ba9b1cb_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rwzo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa695f13b-a53a-4095-b5ab-4e958ba9b1cb_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!rwzo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa695f13b-a53a-4095-b5ab-4e958ba9b1cb_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!rwzo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa695f13b-a53a-4095-b5ab-4e958ba9b1cb_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!rwzo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa695f13b-a53a-4095-b5ab-4e958ba9b1cb_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rwzo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa695f13b-a53a-4095-b5ab-4e958ba9b1cb_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a695f13b-a53a-4095-b5ab-4e958ba9b1cb_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:486315,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/209688555?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa695f13b-a53a-4095-b5ab-4e958ba9b1cb_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rwzo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa695f13b-a53a-4095-b5ab-4e958ba9b1cb_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!rwzo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa695f13b-a53a-4095-b5ab-4e958ba9b1cb_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!rwzo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa695f13b-a53a-4095-b5ab-4e958ba9b1cb_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!rwzo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa695f13b-a53a-4095-b5ab-4e958ba9b1cb_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On August 2, 2026, the European Commission&#8217;s AI Office and national authorities stopped publishing guidance about the AI Act and started enforcing it. Chatbots now have to say they are chatbots. Deepfakes need labels. AI-generated content needs a machine-readable mark. The Commission paired the date with its <a href="https://digital-strategy.ec.europa.eu/en/news/commission-starts-enforcing-ai-act-rules-and-new-transparency-requirements-2-august">first published list</a> of more than 180 organizations that signed the EU&#8217;s Code of Practice on transparency of AI-generated content.</p><p>None of that is the interesting part. The interesting part is that most compliance teams could not produce a complete inventory of the AI systems this enforcement action now applies to if a regulator asked tomorrow. That gap, not the labeling rule, is what should keep you up tonight.</p><h3><span>What Article 50 actually requires</span></h3><p>The AI Act&#8217;s transparency obligations sit in Article 50, and they are narrower and more mechanical than the headlines suggest. Providers must disclose when a user is interacting with an AI system rather than a human. Deployers of emotion-recognition or biometric-categorization systems must inform the people exposed to them. Anyone generating or altering image, audio, or video content must label it, and that label has to be machine-detectable, not just a footer disclaimer a human might read. <a href="https://www.techpolicy.press/the-eus-ai-transparency-code-of-practice-explained/">Legal analysis from the AI Transparency Code of Practice rollout</a> makes clear the Commission built the Code specifically so signatories get &#8220;streamlined compliance&#8221; and more predictable enforcement, which is a polite way of saying: everyone else gets first-in-line scrutiny.</p><p>That is a narrow, mechanical set of obligations. It is also the easy 20% of the problem. The hard 80% is knowing which systems in your environment are subject to it in the first place.</p><h3><span>The governance gap the enforcement sweep will not find</span></h3><p>Here is the uncomfortable arithmetic. A 2026 study from Smarsh found that <a href="https://www.marketscale.com/industries/software-and-technology/shadow-ai-is-outpacing-enterprise-governance-smarsh-study-finds">55% of enterprises are actively deploying AI, but only 26% believe their governance keeps pace with that deployment</a>. Separately, Salesforce&#8217;s 2026 Workforce AI Survey found that <a href="https://redteampartner.com/blog/shadow-ai-enterprise-risk/">67% of employees now use AI tools at work, while only 18% of their employers have a formal AI security policy in place</a>. Read those two numbers together and the picture is not subtle: most of the AI activity touching enterprise data is happening outside whatever governance process exists to catch it.</p><p>This is not a new problem. It is the same shadow IT story security teams have been telling since the first employee synced a work file to a personal Dropbox account. What is new is that regulators now have a specific, dated, enforceable hook to hang it on. You cannot disclose that a system is AI, or label its output, if nobody on your compliance team knows the system is running.</p><h3><span>Why the math got worse this time</span></h3><p>This enforcement date is different from the last five years of &#8220;AI governance is coming&#8221; warnings, and not for one reason. It is horizontal: it applies across sectors, not to a single regulated vertical, which means the DIY AI tool your marketing team adopted last quarter is now in scope alongside your core product&#8217;s chatbot. The penalty structure is not theoretical, either. Under <a href="https://artificialintelligenceact.eu/article/99/">Article 99 of the AI Act</a>, the most serious violations carry fines up to &#8364;35 million or 7% of global annual turnover, whichever is higher, calculated on worldwide revenue regardless of where the company is headquartered.</p><p>And this transparency enforcement does not replace <a href="http://kiteworks.com/risk-compliance-glossary/gdpr/">GDPR</a>, <a href="http://kiteworks.com/risk-compliance-glossary/nis2-directive/">NIS 2</a>, or <a href="http://kiteworks.com/risk-compliance-glossary/dora/">DORA</a> obligations already layered on the same data. It stacks on top of them. An AI system that mishandles personal data while also failing to disclose that it is AI is now looking at two separate regulatory exposures from the same incident.</p><p>Regulators are not asking whether you have an AI policy document. They are asking whether you can produce evidence, for a specific system, on a specific date, that the required disclosures and controls were actually in place. That is an audit-trail problem before it is a labeling problem.</p><h3><span>The architectural question underneath the labels</span></h3><p>Most organizations will respond to this the way they respond to every new compliance deadline: patch the visible gap. Add a disclosure banner to the customer-facing chatbot. Update the AI usage policy. Neither of those actions touches the actual exposure, which is that AI systems &#8211; chatbots, retrieval pipelines, and a growing number of AI agents &#8211; request and generate content from enterprise data through dozens of uncoordinated paths, each with its own logging, its own <a href="http://kiteworks.com/secure-file-sharing/secure-file-sharing-with-access-control/">access rules</a>, and its own blind spots.</p><p>The organizations in better shape here are the ones that already treat AI-to-data interactions &#8211; whether initiated by a human user or an AI agent &#8211; as something to be governed under one policy engine and one <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trail</a>, rather than as a bolted-on afterthought scattered across whatever tool happened to generate the content. That architecture does not solve deepfake labeling. It solves the prior question &#8211; whether you can even see what your AI systems touched &#8211; that has to be answered before labeling means anything. Kiteworks&#8217; <a href="https://www.kiteworks.com/cybersecurity-risk-management/2026-data-security-forecast-ai-governance-predictions/">2026 Data Security and Compliance Risk: Annual Forecast Report</a> has tracked this same pattern across multiple 2026 enforcement actions: regulators increasingly want evidence of continuous control, not a policy binder.</p><h3><span>What this means Monday morning</span></h3><p>Skip the debate about whether this enforcement date is a big deal. It is not going away, and the penalty structure means the cost of guessing wrong is not trivial. A few things worth doing this week, in order:</p><p><span>1. </span>Build a real inventory of every interactive AI system and content-generation tool touching customer or enterprise data, including the ones marketing and sales adopted without a security review.</p><p><span>2. </span>Assign an owner to each system on that list. An inventory with no accountable owner is just a spreadsheet.</p><p><span>3. </span>Check whether your existing AI usage policy is technically enforced or merely documented. If a system can access data the policy says it should not, the policy is decorative.</p><p><span>4. </span>Confirm your <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit logging</a> actually captures AI-to-data interactions with enough detail to answer &#8220;what did this system access, and when&#8221; without a multi-day forensic exercise.</p><p><span>5. </span>Map which of your AI systems fall under Article 50&#8217;s disclosure and labeling duties, and which owner is accountable for each disclosure.</p><p>The label on the chatbot was never the hard part. Knowing the chatbot exists, and what it touched, always was.</p>]]></content:encoded></item><item><title><![CDATA[90 Days of Email, One Compromised Mailbox, Zero Containment.]]></title><description><![CDATA[A CISA advisory and a bank&#8217;s dark-web leak share the same root cause: one mailbox nobody governs like the data repository it actually is.]]></description><link>https://kiteworks.substack.com/p/90-days-of-email-one-compromised</link><guid isPermaLink="false">https://kiteworks.substack.com/p/90-days-of-email-one-compromised</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Fri, 31 Jul 2026 15:03:38 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!a15u!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3421fa05-1209-4903-8e51-e7b0d8b06b29_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!a15u!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3421fa05-1209-4903-8e51-e7b0d8b06b29_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!a15u!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3421fa05-1209-4903-8e51-e7b0d8b06b29_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!a15u!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3421fa05-1209-4903-8e51-e7b0d8b06b29_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!a15u!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3421fa05-1209-4903-8e51-e7b0d8b06b29_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!a15u!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3421fa05-1209-4903-8e51-e7b0d8b06b29_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!a15u!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3421fa05-1209-4903-8e51-e7b0d8b06b29_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3421fa05-1209-4903-8e51-e7b0d8b06b29_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:529339,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/209132801?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3421fa05-1209-4903-8e51-e7b0d8b06b29_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!a15u!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3421fa05-1209-4903-8e51-e7b0d8b06b29_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!a15u!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3421fa05-1209-4903-8e51-e7b0d8b06b29_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!a15u!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3421fa05-1209-4903-8e51-e7b0d8b06b29_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!a15u!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3421fa05-1209-4903-8e51-e7b0d8b06b29_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On July 23, 2026, CISA, the NSA, the FBI, the UK&#8217;s National Cyber Security Centre, and agencies from more than a dozen allied nations published <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a">Advisory AA26-204A</a>, attributing a sustained espionage campaign to a Russian state-supported group tracked as LAUNDRY BEAR, Void Blizzard, CL-STA-1114, and TA488. The group has been exploiting a cross-site scripting flaw in Zimbra Collaboration Suite webmail since at least July 2025, according to the advisory and <a href="https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-zimbra-zero-click-flaw-for-email-theft/">BleepingComputer&#8217;s reporting</a>. The patch timeline is not the interesting part. Zimbra shipped a fix in November 2025 and victims kept getting hit anyway, which says something about patch cadence but isn&#8217;t the point. The point is what got taken: 90 days of email history per victim, the organization&#8217;s internal directory, live two-factor authentication tokens, and any application passcode generated after compromise, all routed to a backend the actor internally calls &#8220;Flowerbed.&#8221;</p><p>Four days later, on the other side of the world, Bank of Baroda confirmed a breach with an uncomfortably familiar shape. No nation-state attribution, no CVE, no CISA advisory. Just a <a href="https://gulfnews.com/business/banking/bank-of-baroda-data-leak-what-we-know-so-far-about-alleged-cyber-breach-1.500621898">compromised employee email account</a>, and, per the bank&#8217;s own statement, customer identity documents, loan and appraisal records, internal audit reports, and internal communications showing up on a dark-web marketplace. Two continents. Two unrelated threat actors. One shared architecture failure: the mailbox held more than anyone was governing.</p><h3><span>What LAUNDRY BEAR actually took</span></h3><p>CVE-2025-66376 is a persistent cross-site scripting flaw in Zimbra Collaboration Suite&#8217;s Classic UI webmail client, CVSS 7.2. LAUNDRY BEAR delivered it through <a href="http://kiteworks.com/risk-compliance-glossary/phishing-attacks/">phishing</a> emails engineered so that Zimbra&#8217;s own webmail interface executed attacker-supplied JavaScript inside the victim&#8217;s authenticated session the moment the message was opened. The attack needed no separate <a href="http://kiteworks.com/risk-compliance-glossary/malware-based-attacks/">malware</a> payload, no macro. Just an opened email. From that foothold, per CISA, the group pulled the last 90 days of the victim&#8217;s mail, the organization&#8217;s global address list, active two-factor authentication tokens, and any application passcode generated afterward. Victims span the <a href="http://kiteworks.com/risk-compliance-glossary/defense-industrial-base/">Defense Industrial Base</a>, federal and local government, education, energy, law enforcement, media, NGOs, and technology. The campaign ran undetected from July 2025 until Zimbra patched it in ZCS 10.0.18 and 10.1.13 that November &#8211; four months as an unpatched zero-day, and organizations were still getting compromised in July 2026, eight months after a fix existed. <a href="https://securityboulevard.com/2026/07/response-to-cisa-advisory-aa26-204a-russian-state-supported-cyber-actors-conduct-phishing-campaign-targeting-users-of-zimbra-collaboration-suite/">AttackIQ&#8217;s response</a> built adversary emulation scenarios so defenders can test detection coverage against the exact technique rather than wait for the next advisory to explain what already happened to them.</p><h3><span>Why Bank of Baroda isn&#8217;t a different story</span></h3><p>Reuters reported that metadata attached to the leaked cache suggested more than 700GB of data. Other outlets, citing unverified researcher claims, put the figure near 1TB. Neither number is bank-confirmed, and readers should treat both as attacker- and researcher-sourced until forensics says otherwise. What Bank of Baroda has confirmed is the initial access vector: one employee&#8217;s email account, not its core banking systems, which the bank says remain secure. No group has formally claimed the breach. Some researchers have linked it to an actor called TripleX, previously associated with an attack on Indonesia&#8217;s PT Bank Negara Indonesia, per <a href="https://gulfnews.com/business/banking/bank-of-baroda-data-leak-what-we-know-so-far-about-alleged-cyber-breach-1.500621898">Gulf News&#8217;s reporting</a> &#8211; unconfirmed, and the forensic investigation is still open.</p><p>Here&#8217;s why that matters beyond one bank. The <a href="https://www.helpnetsecurity.com/2026/05/20/verizon-2026-dbir-findings/">2026 Verizon Data Breach Investigations Report</a> found <a href="http://kiteworks.com/risk-compliance-glossary/vulnerability/">vulnerability</a> exploitation overtook <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credential</a>-based access as the single largest initial-access category for the first time, climbing to 31% of breaches from 20% the year before. Add <a href="http://kiteworks.com/risk-compliance-glossary/phishing-attacks/">phishing</a> (16%), <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credential</a> abuse (13%), and pretexting (6%) back together, though, and identity- and email-adjacent access still accounts for 35% of breaches, with the human element present in 62% of all incidents DBIR tracked. LAUNDRY BEAR and whoever hit Bank of Baroda are not exploiting a rare <a href="http://kiteworks.com/risk-compliance-glossary/security-misconfigurations/">misconfiguration</a>. They are exploiting the modal path in.</p><h3><span>Why the math got worse</span></h3><p>Here&#8217;s where it gets uncomfortable. For a decade, the standard advice for exactly this scenario was: turn on <a href="http://kiteworks.com/risk-compliance-glossary/multifactor-authentication-mfa/">MFA</a>. LAUNDRY BEAR didn&#8217;t need to defeat multi-factor authentication. It stole live two-factor tokens and freshly generated application passcodes straight out of the browser session the cross-site scripting flaw handed it. A stolen session token walks past MFA entirely, because the second factor was never the barrier. The authenticated session was.</p><p>The 90-day retention window that made LAUNDRY BEAR&#8217;s haul so large isn&#8217;t a Zimbra <a href="http://kiteworks.com/risk-compliance-glossary/security-misconfigurations/">misconfiguration</a>, either. It&#8217;s the default. Most webmail platforms keep months of history live and searchable because that is what users expect from an inbox. Nobody designed that retention policy assuming an attacker would eventually read all of it in a single sitting. Layer in that the same DBIR found 44% of AI-assisted initial-access attempts were <a href="http://kiteworks.com/risk-compliance-glossary/phishing-attacks/">phishing</a>-related, and the one thing that used to give defenders a fighting chance &#8211; a lure with broken grammar or a mismatched domain &#8211; is disappearing as a reliable tell.</p><h3><span>The architectural question</span></h3><p>This is where &#8220;patch faster&#8221; runs out of road. Patch discipline matters, obviously. It is not sufficient on its own, because the thing an attacker steals is not the mail server. It&#8217;s the content that accumulated inside it while nobody was treating the mailbox as a data repository requiring its own controls.</p><p>The architectural alternative treats inbound and outbound email as a governed content channel rather than a trusted internal system. Kiteworks&#8217; <a href="https://www.kiteworks.com/risk-compliance-glossary/email-protection-gateway-epg-securing-email-while-making-encryption-invisible-to-end-users/">Email Protection Gateway</a> is one example of that category: it scans inbound and outbound mail with <a href="http://kiteworks.com/cybersecurity-risk-management/antivirus/">antivirus</a>, <a href="http://kiteworks.com/risk-compliance-glossary/data-loss-prevention-dlp/">DLP</a>, and <a href="http://kiteworks.com/risk-compliance-glossary/comprehensive-guide-to-advanced-threat-protection-atp/">advanced threat protection</a> ahead of delivery, and logs access to a unified <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trail</a> independent of the mail client itself. Neither incident here ran through a Kiteworks-governed environment. LAUNDRY BEAR&#8217;s victims were running native Zimbra webmail; Bank of Baroda&#8217;s compromise ran through a native corporate mailbox. So this is a description of an architectural category, not a claim about what would have happened in either case &#8211; a scanning gateway in front of webmail doesn&#8217;t eliminate every application-layer <a href="http://kiteworks.com/risk-compliance-glossary/vulnerability/">vulnerability</a> in the webmail platform itself, and its value is bounded by what gets scanned and how long content sits under policy versus how long it sits by default. What it changes is the assumption underneath the mailbox: instead of an unmonitored 90-day archive that the platform&#8217;s own code can be tricked into executing, email content becomes something to which access is scanned, logged, and provable after the fact. The <a href="https://www.kiteworks.com/cybersecurity-risk-management/2026-data-security-forecast-ai-governance-predictions/">Kiteworks Data Security and Compliance Risk: 2026 Forecast Report</a> treats ungoverned communication channels, email chief among them, as a structural exposure organizations will keep re-discovering through 2026 rather than a one-off headline they can patch their way out of.</p><h3><span>What this means Monday morning</span></h3><p><span>&#8226; </span>Pull your webmail platform&#8217;s default retention window and ask who approved it. If the answer is &#8220;nobody, it&#8217;s just the default,&#8221; that&#8217;s your 90-day exposure figure sitting unmanaged right now.</p><p><span>&#8226; </span>Inventory which webmail and email gateway products in your environment handle XSS and injection in user-supplied content, and check each against CVE-2025-66376&#8217;s disclosure timeline. A four-month zero-day window followed by an eight-month patch gap is not a Zimbra problem. It&#8217;s an update-cadence problem you likely share.</p><p><span>&#8226; </span>Treat stolen session tokens and application passcodes as a distinct incident category from stolen passwords. Your <a href="http://kiteworks.com/risk-compliance-glossary/multifactor-authentication-mfa/">MFA</a> metrics do not cover this failure mode.</p><p><span>&#8226; </span>Ask your <a href="http://kiteworks.com/risk-compliance-glossary/incident-response/">incident response</a> team, in writing, whether your email logging would let you answer &#8220;what exactly did the attacker read&#8221; &#8211; not &#8220;did they get in,&#8221; but the actual content scope &#8211; within 24 hours of detection.</p><p><span>&#8226; </span>If the answer to that last question is no, that gap is the finding. Both of these incidents made the news because of what leaked, not because of how the attacker got in. Your mailbox is not a communication tool anymore. It&#8217;s the least-governed data warehouse in your environment, and it already has a door.</p>]]></content:encoded></item><item><title><![CDATA[92% of AI Breaches Had Zero Access Controls.]]></title><description><![CDATA[The model isn&#8217;t the vulnerability. The wiring around it is.]]></description><link>https://kiteworks.substack.com/p/92-of-ai-breaches-had-zero-access</link><guid isPermaLink="false">https://kiteworks.substack.com/p/92-of-ai-breaches-had-zero-access</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Thu, 30 Jul 2026 19:00:49 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!E7SE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfb23faa-5bac-4393-b455-d8a1dc6a69bd_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!E7SE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfb23faa-5bac-4393-b455-d8a1dc6a69bd_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!E7SE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfb23faa-5bac-4393-b455-d8a1dc6a69bd_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!E7SE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfb23faa-5bac-4393-b455-d8a1dc6a69bd_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!E7SE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfb23faa-5bac-4393-b455-d8a1dc6a69bd_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!E7SE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfb23faa-5bac-4393-b455-d8a1dc6a69bd_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!E7SE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfb23faa-5bac-4393-b455-d8a1dc6a69bd_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bfb23faa-5bac-4393-b455-d8a1dc6a69bd_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:495379,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/209129307?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfb23faa-5bac-4393-b455-d8a1dc6a69bd_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!E7SE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfb23faa-5bac-4393-b455-d8a1dc6a69bd_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!E7SE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfb23faa-5bac-4393-b455-d8a1dc6a69bd_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!E7SE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfb23faa-5bac-4393-b455-d8a1dc6a69bd_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!E7SE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfb23faa-5bac-4393-b455-d8a1dc6a69bd_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In April 2026, a frontier AI model found thousands of high-severity vulnerabilities buried across every major operating system and browser &#8211; flaws human researchers had missed for years. That&#8217;s the finding everyone&#8217;s been talking about since IBM&#8217;s <a href="https://www.ibm.com/reports/data-breach">2026 Cost of a Data Breach Report</a> came out this month. It&#8217;s not the one that should worry you.</p><p>Page 40 has the real number. Among organizations that suffered a security incident involving their own AI models or applications, 92% lacked proper AI <a href="http://kiteworks.com/secure-file-sharing/secure-file-sharing-with-access-control/">access controls</a> at the time. Not weak controls. Not partial coverage. No <a href="http://kiteworks.com/risk-compliance-glossary/role-based-access-control/">role-based</a> access, no <a href="http://kiteworks.com/risk-compliance-glossary/multifactor-authentication-mfa/">MFA</a>, nothing standing between a compromised AI system and the data it could reach.</p><p>Read that again. These are companies already breached through AI, and the postmortem still found no lock on the door.</p><h3><span>What ninety-two percent actually means</span></h3><p>IBM and Ponemon studied 602 organizations across 17 industries this year, and security incidents involving an organization&#8217;s own AI models grew from 13% of breaches to 21% &#8211; a 61% jump in twelve months. The average cost when AI was involved: USD 5.33 million, against USD 4.70 million when it wasn&#8217;t.</p><p>Break down the incident types and the pattern gets sharper. Model inversion attacks, where an attacker reconstructs sensitive training data from a model&#8217;s outputs, averaged USD 6.07 million &#8211; the costliest AI incident type in the report. Prompt injection came in close behind at USD 5.89 million. Cloud <a href="http://kiteworks.com/risk-compliance-glossary/security-misconfigurations/">misconfigurations</a> touching AI workloads: USD 5.25 million.</p><p>None of that is a model behaving badly. IBM&#8217;s own language: the root causes were &#8220;structural &#8211; compromise of connected APIs, applications and cloud <a href="http://kiteworks.com/risk-compliance-glossary/security-misconfigurations/">misconfigurations</a>, indicating governance failures, not model risk.&#8221; Translation, from the people who ran 3,558 interviews to produce this data: you didn&#8217;t get breached because the AI hallucinated. You got breached because nobody put a fence around it.</p><h3><span>This is shadow IT&#8217;s sequel, and it&#8217;s worse</span></h3><p>Ten years ago it was Dropbox accounts and unsanctioned Slack workspaces. Security teams eventually built visibility programs and moved on. <a href="http://kiteworks.com/cybersecurity-risk-management/zero-trust-generative-ai/">Shadow AI</a> is repeating that exact failure, except this time the unapproved tool doesn&#8217;t just store your data &#8211; it reads it, transforms it, and sometimes retains it in ways a personal cloud drive never could.</p><p>IBM found <a href="http://kiteworks.com/cybersecurity-risk-management/zero-trust-generative-ai/">shadow AI</a> security incidents more than doubled this year, from 20% to 43% of breached organizations, pushing average costs from USD 4.63 million to USD 5.39 million. Regulatory fines now show up in roughly one in five of those incidents &#8211; a new data point this year, and the clearest sign yet that <a href="http://kiteworks.com/cybersecurity-risk-management/zero-trust-generative-ai/">shadow AI</a> has crossed from an internal-controls problem into a compliance exposure with a dollar figure attached.</p><p>Verizon&#8217;s <a href="https://www.verizon.com/business/resources/reports/dbir/">2026 Data Breach Investigations Report</a> backs this up from a different angle: across more than 22,000 confirmed breaches, unauthorized AI use is now the third most common non-malicious insider action in its dataset, a fourfold increase year over year, with source code the single most common thing employees upload to unauthorized AI tools. The World Economic Forum&#8217;s <a href="https://www.weforum.org/publications/global-cybersecurity-outlook-2026/">Global Cybersecurity Outlook 2026</a> found 94% of security leaders now call AI the single biggest driver of change in their threat landscape this year &#8211; and yet roughly a third of organizations still have no process at all to assess an AI tool&#8217;s security before someone starts using it.</p><p>Three separate research organizations, three different datasets, the same finding: adoption outran oversight, and nobody closed the gap behind it.</p><h3><span>Why the math just got worse</span></h3><p>Governance debt is not new. What&#8217;s new is what happens when frontier AI models are the ones finding the cracks. Researchers at UC Berkeley, in a <a href="https://rdi.berkeley.edu/frontier-ai-impact-on-cybersecurity/">study on frontier AI&#8217;s impact on the cybersecurity landscape</a> that IBM cites directly, project that within two years AI capability will favor attackers over defenders by 31.7%. Not eventually. Within two years.</p><p>IBM&#8217;s own numbers already show this compounding. AI-driven attacks &#8211; attackers using AI as the weapon, not the target &#8211; rose 56% year over year and now add roughly USD 1 million to the average cost of a malicious breach. <a href="http://kiteworks.com/risk-compliance-glossary/ransomware-attacks/">Ransomware</a> operators are folding AI into extortion too: 41% of ransomware incidents this year threatened public shaming and media leaks alongside <a href="http://kiteworks.com/secure-file-sharing/public-vs-private-key-encryption/">encryption</a>, a shift toward reputational pressure that a governance program built around &#8220;detect and patch&#8221; was never designed to counter.</p><p>Here&#8217;s where it gets uncomfortable for anyone still treating this as a 2027 problem. Only 36% of organizations use security AI and automation extensively, and even among those, adoption skews hard toward detection and response. Just 18% apply AI agents to <a href="http://kiteworks.com/risk-compliance-glossary/vulnerability/">vulnerability</a> scanning &#8211; precisely the area where frontier models are moving fastest. Defenders are pointing their best tools at cleanup while attackers point theirs at the front door.</p><h3><span>The architectural question nobody&#8217;s asking</span></h3><p>Every fix under discussion right now is tactical: patch faster, hire more analysts, buy another detection tool. Those all help. None of them close a 92%-lacked-access-controls gap, because that gap isn&#8217;t a tooling problem. It&#8217;s an architecture problem &#8211; the absence of a governed layer between AI systems and the sensitive data they touch, the same layer <a href="http://kiteworks.com/risk-compliance-glossary/zero-trust-security/">zero trust</a> already demands for human users.</p><p>That&#8217;s the premise a small number of platforms are actually built around: apply one policy engine, one <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trail</a>, and one identity model to AI systems and agents that already governs human access, instead of bolting controls on after the model is in production. Kiteworks is one example &#8211; its architecture runs on a single-tenant, <a href="http://kiteworks.com/platform/security/hardened-virtual-appliance">hardened virtual appliance</a> rather than shared multi-tenant infrastructure, and it extends the same <a href="http://kiteworks.com/risk-compliance-glossary/role-based-access-control/">role-based</a> and attribute-based <a href="http://kiteworks.com/secure-file-sharing/secure-file-sharing-with-access-control/">access controls</a> to AI and <a href="http://kiteworks.com/platform/security/mcp-ai-integration/">MCP</a>-based integrations that it applies to a human opening a file. The Kiteworks <a href="https://www.kiteworks.com/cybersecurity-risk-management/2026-data-security-forecast-ai-governance-predictions/">2026 Data Security and Compliance Risk: Annual Forecast Report</a> found the same governance lag IBM did: security programs are extending policy to AI agents far more slowly than they&#8217;re extending AI adoption itself. That&#8217;s the variable. Not whether you deploy AI. Whether you govern it with the same seriousness you govern everyone else.</p><h3><span>What this means Monday morning</span></h3><p><span>1. </span>Pull the <a href="http://kiteworks.com/regulatory-compliance/audit-log/">access logs</a> on every AI system and application your organization runs in production, including the ones nobody remembers approving. If you can&#8217;t produce <a href="http://kiteworks.com/risk-compliance-glossary/role-based-access-control">role-based access</a> and <a href="http://kiteworks.com/risk-compliance-glossary/multifactor-authentication-mfa/">MFA</a> evidence for each one today, you already match the 92%.</p><p><span>2. </span>Force a coordination meeting between whoever owns AI governance and whoever owns security operations. IBM found only 19% of organizations have these two functions actually talking to each other &#8211; ask that question in your next staff meeting and watch the room go quiet.</p><p><span>3. </span>Extend identity and lifecycle management to your non-human identities. Only 46% of organizations currently do this, and every AI agent, service account, and API key you can&#8217;t inventory is an access-control gap you haven&#8217;t found yet.</p><p><span>4. </span>Stop budgeting AI security as a 2027 line item. Eighty-five percent of breached organizations now say they&#8217;re increasing spend specifically because of frontier AI threats &#8211; that number was 64% before they understood what these models could do. Move before the incident forces the conversation.</p><p>The model was never the weak point. It never is. The question was always whether anyone built a fence before turning it loose &#8211; and this year&#8217;s data says most of you didn&#8217;t.</p>]]></content:encoded></item><item><title><![CDATA[AI Agents Now Touch Twice the Data Anyone Approved ]]></title><description><![CDATA[Three independent studies on AI agent governance published within days of each other this quarter. Kiteworks&#8217; own primary research had already measured the same gap.]]></description><link>https://kiteworks.substack.com/p/ai-agents-now-touch-twice-the-data</link><guid isPermaLink="false">https://kiteworks.substack.com/p/ai-agents-now-touch-twice-the-data</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Thu, 30 Jul 2026 15:01:46 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!WqzC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f5e1f8-b49f-4f5e-a8b5-ec5ba4c5a836_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WqzC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f5e1f8-b49f-4f5e-a8b5-ec5ba4c5a836_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WqzC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f5e1f8-b49f-4f5e-a8b5-ec5ba4c5a836_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!WqzC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f5e1f8-b49f-4f5e-a8b5-ec5ba4c5a836_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!WqzC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f5e1f8-b49f-4f5e-a8b5-ec5ba4c5a836_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!WqzC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f5e1f8-b49f-4f5e-a8b5-ec5ba4c5a836_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WqzC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f5e1f8-b49f-4f5e-a8b5-ec5ba4c5a836_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e9f5e1f8-b49f-4f5e-a8b5-ec5ba4c5a836_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:501679,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/209026215?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f5e1f8-b49f-4f5e-a8b5-ec5ba4c5a836_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WqzC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f5e1f8-b49f-4f5e-a8b5-ec5ba4c5a836_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!WqzC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f5e1f8-b49f-4f5e-a8b5-ec5ba4c5a836_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!WqzC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f5e1f8-b49f-4f5e-a8b5-ec5ba4c5a836_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!WqzC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f5e1f8-b49f-4f5e-a8b5-ec5ba4c5a836_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Three independent studies on AI agent governance landed within days of each other this quarter: a developer survey from a password-management vendor, a CISO survey from an identity vendor, and an offensive-security research disclosure headed to Black Hat. None of the three research teams compared notes. All three converged on the same underlying condition &#8211; AI agents already reach more data than anyone approved, and almost nothing is watching for it. That convergence isn&#8217;t a coincidence, and it isn&#8217;t a coding problem. It&#8217;s a governance problem, and <a href="https://www.kiteworks.com/sites/default/files/resources/kiteworks-annual-report-2026.pdf">Kiteworks&#8217; own 459-respondent primary research</a> had already put a number on it before any of these three studies published.</p><h3>Developers already know their agents are overreaching</h3><p>Start with the people closest to the keyboard. 1Password surveyed 1,000 security and engineering professionals at large U.S. firms in late May and early June 2026, and 46% said they now run AI agents in production. 71% said those agents can reach sensitive information as a matter of course, not as an edge case. In roughly four out of ten organizations, agents reach data outside their approved scope. Across the full sample, agents touched, on average, twice as much data as anyone had actually signed off on.</p><p>Read that again.</p><p>Forty percent of developers grant agents persistent access to systems and secrets that stays live after the task that justified it has ended. Forty-seven percent had an agent take an unintended action after following instructions buried in a webpage, a document, an email, or tool output &#8211; textbook prompt injection, working exactly as attackers designed it to. A third of developers using agents said their company had already had a breach or incident tied to overprivileged non-human identities. And when <a href="https://www.helpnetsecurity.com/2026/07/29/1password-ai-agent-governance/">Help Net Security&#8217;s coverage</a> of the survey asked who should be accountable when an agent causes harm, 65% said someone other than the person currently holding the bag. Five percent said the agent itself should answer for it.</p><p>That last number tells you what&#8217;s actually broken here. It isn&#8217;t the technology. It&#8217;s the chain of custody.</p><h3>CISOs confirm it from the boardroom down</h3><p>If this looked like a developer-floor problem that leadership had already contained, Okta&#8217;s Global CISO Insights 2026 report says otherwise. Okta surveyed 306 security executives globally and found 81% worry about excessive AI access &#8211; worry, not merely acknowledge. Fewer than half can do anything about it. Less than half are confident they can identify every AI agent running in their environment (47%), control what those agents can reach (46%), or say what any individual agent is actually allowed to do (45%).</p><p>These aren&#8217;t executives who lack awareness. They lack visibility, and there&#8217;s a difference.</p><p><a href="https://www.scworld.com/resource/loss-of-control-the-ai-agent-governance-crisis">SC World&#8217;s coverage</a> of the report lists what&#8217;s keeping them up at night: AI-powered <a href="http://kiteworks.com/risk-compliance-glossary/phishing-attacks/">phishing</a> (61%), malicious AI agents (49%), deepfake authentication bypass (54%). Meanwhile, only 31% of CISOs globally, and just 12% in the U.S., say they&#8217;re fully aligned with their own C-suite and board on what level of AI risk is acceptable. One in four organizations applies the same identity-lifecycle discipline to agents that it applies to humans. Twenty-one percent are still running agents on shared <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credentials</a> or broad-permission service accounts. Twenty percent leave agent management to individual teams, ad hoc, with no central policy at all.</p><p>Two false stories get told about this gap. One says CISOs are behind the curve and just need better dashboards. The other says the technology is moving too fast for any governance model to keep pace, so the sensible move is to wait. Both are wrong. The dashboards exist. What&#8217;s missing is a policy layer that applies to non-human identities with the same rigor organizations already apply, however imperfectly, to human ones.</p><h3>The vulnerability that passes every safety check</h3><p>Here&#8217;s where it gets uncomfortable, because this isn&#8217;t a story about misconfigured permissions. It&#8217;s a story about permissions that were configured correctly and still failed.</p><p>Novee Security researcher Elad Meged found that Claude Code Action, Gemini CLI, and Codex CLI could each be manipulated into leaking secrets despite passing every safety check the harness runs. Anthropic patched the disclosed issues in its tools and paid bounties for the findings. Google&#8217;s advisory for the Gemini CLI flaw, tracked as GHSA-wpqr-6v78-jr5g, carries a CVSS score of 10.0 &#8211; the maximum severity <a href="https://nvd.nist.gov/vuln-metrics/cvss">NVD&#8217;s scoring scale</a> recognizes, reserved for flaws that are both trivially exploitable and catastrophic in impact.</p><p>The mechanism matters more than the patch. Per <a href="https://www.helpnetsecurity.com/2026/07/29/ai-agent-security-safety-check/">Help Net Security&#8217;s reporting</a>, the flaw isn&#8217;t in the prompt layer at all. A command gets approved as safe at one point in a workflow, then gets consumed downstream by a different component running with different privileges &#8211; and nothing re-validates whether that command is still safe in its new context. The safety check did its job. The architecture just didn&#8217;t ask it to check twice. Meged presents the full research at Black Hat USA 2026, roughly two weeks from this writing.</p><p>That&#8217;s the tell. Nobody can patch their way out of a design where trust, once granted anywhere in a pipeline, is assumed to travel everywhere in that pipeline.</p><h3>The architectural question nobody&#8217;s tooling answers</h3><p>Here&#8217;s the whole game: none of this is a detection problem. It&#8217;s a containment problem, and containment requires purpose-bound access, a way to cut it off, and a record of what happened, for every identity touching sensitive data, human or agent, under one policy plane rather than two.</p><p>Kiteworks put an actual number on it. Kiteworks&#8217; <a href="https://www.kiteworks.com/sites/default/files/resources/kiteworks-annual-report-2026.pdf">2026 Data Security and Compliance Risk: Annual Survey Report</a>, fielded in Q2 2026 across 459 respondents, measures the same gap the other three studies describe from the outside. The average organization&#8217;s AI Governance Maturity Score came in at 35 out of 100, roughly 6.7 of 19 measured capabilities actually deployed. Data Security Maturity Score averaged 39 out of 100. Multiply the two into the combined Data Security and Compliance Readiness Index and the mean drops to 16.2 out of 100, with a median of 11.5.</p><p>Half of organizations are below 11.5. Sit with that for a second.</p><p>Now look at the specific controls that would close this gap. Purpose binding, restricting an agent to the task and scope it was actually authorized for, is deployed at just 26% of organizations; 74% lack it entirely. An AI kill switch, the control that would cut off an agent&#8217;s lingering access after a task ends, exists at only 21%. Human-in-the-loop review for high-risk AI actions sits at 30%. AI-specific <a href="http://kiteworks.com/risk-compliance-glossary/data-loss-prevention-dlp/">DLP</a>: 28%. AI access logs actually forwarded to <a href="http://kiteworks.com/risk-compliance-glossary/what-is-security-information-and-event-management/">SIEM</a>: 33%.</p><p>Then there&#8217;s the <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trail</a>, which is the part that should worry you most. The survey asked whether organizations could produce a complete AI audit record within one business day &#8211; the artifact needed after an incident, not before one. Only 27% said yes. Roughly half couldn&#8217;t produce one at all. Within one hour, only 17% could. No AI containment control measured is deployed at more than 31% of organizations, and this isn&#8217;t a theoretical gap: 64% of organizations have already put AI into production, and 70% of those are running three or more use cases simultaneously. Eighty percent had at least one security incident, general or AI-specific, in the past year. Sixty-three percent faced a compliance consequence. Sixty-five percent discovered <a href="http://kiteworks.com/cybersecurity-risk-management/zero-trust-generative-ai/">shadow AI</a> usage they didn&#8217;t know existed.</p><p>This is the same gap 1Password measured in developers, Okta measured in CISOs, and Meged demonstrated in production tooling. It just has a number attached now.</p><p>The fix isn&#8217;t a new layer bolted onto agents. It&#8217;s one governance plane covering every identity that touches sensitive data, human employee or AI agent, with the same purpose binding, the same revocation, and the same evidence-quality <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trail</a> &#8211; one policy, not two. That&#8217;s the premise behind platforms like <a href="https://www.kiteworks.com/cybersecurity-risk-management/ai-data-governance-guide/">Kiteworks&#8217; approach to AI data governance</a>: single-tenant isolation and one policy engine covering email, <a href="http://kiteworks.com/risk-compliance-glossary/managed-file-transfer/">managed file transfer</a>, <a href="http://kiteworks.com/risk-compliance-glossary/sftp/">SFTP</a>, web forms, and APIs, instead of five systems each guessing independently at what &#8220;safe&#8221; means. Whether the request comes from a person or an agent, the same access rule, the same kill switch, and the same <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trail</a> apply. Kiteworks is one example of that architecture, not the only one, and not a checkbox to tick either.</p><h3>What to do Monday morning</h3><p><span>1. </span>Inventory every agent with production access this week &#8211; not the ones IT knows about, the ones actually running. Nobody can govern what nobody can enumerate, and roughly half of CISOs in the Okta data can&#8217;t fully enumerate their own agents.</p><p><span>2. </span>Bind every agent&#8217;s access to the task it was provisioned for, with an expiration, not a standing grant. Persistent access that outlives the task is the default failure mode in the 1Password data, not the exception.</p><p><span>3. </span>Build the kill switch before it&#8217;s needed. Test it quarterly. Twenty-one percent of organizations have one today; the goal is to be in that group before an incident forces the question.</p><p><span>4. </span>Route agent access logs to <a href="http://kiteworks.com/risk-compliance-glossary/what-is-security-information-and-event-management/">SIEM</a> and set a one-business-day SLA for producing a complete audit record. Roughly half of organizations currently cannot do this at all.</p><p><span>5. </span>Re-scope safety checks to re-validate at every privilege boundary a command crosses, not just at the point of initial approval. That&#8217;s the exact gap Meged is presenting at Black Hat.</p><p><span>The agent that reached data nobody approved didn&#8217;t break any rule it was given. It just wasn&#8217;t given enough rules that traveled with it.</span></p>]]></content:encoded></item><item><title><![CDATA[Technology Risk Jumped 40 Points. AI Governance Didn’t.]]></title><description><![CDATA[700 board members say risk is spiking. 225 security leaders say they can&#8217;t shut off a misbehaving AI agent in under five minutes. Same gap, two different rooms.]]></description><link>https://kiteworks.substack.com/p/technology-risk-jumped-40-points</link><guid isPermaLink="false">https://kiteworks.substack.com/p/technology-risk-jumped-40-points</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Wed, 29 Jul 2026 15:01:27 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!4vnO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e141f4-492a-40d9-b0a6-6da1e1cdb56f_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4vnO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e141f4-492a-40d9-b0a6-6da1e1cdb56f_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4vnO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e141f4-492a-40d9-b0a6-6da1e1cdb56f_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!4vnO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e141f4-492a-40d9-b0a6-6da1e1cdb56f_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!4vnO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e141f4-492a-40d9-b0a6-6da1e1cdb56f_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!4vnO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e141f4-492a-40d9-b0a6-6da1e1cdb56f_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4vnO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e141f4-492a-40d9-b0a6-6da1e1cdb56f_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/16e141f4-492a-40d9-b0a6-6da1e1cdb56f_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:529356,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/208888961?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e141f4-492a-40d9-b0a6-6da1e1cdb56f_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4vnO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e141f4-492a-40d9-b0a6-6da1e1cdb56f_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!4vnO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e141f4-492a-40d9-b0a6-6da1e1cdb56f_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!4vnO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e141f4-492a-40d9-b0a6-6da1e1cdb56f_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!4vnO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e141f4-492a-40d9-b0a6-6da1e1cdb56f_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Something strange showed up in Clyde &amp; Co&#8217;s newest boardroom survey. The same executives who spent the last two years building out AI governance committees are now telling researchers, anonymously, that the risk outran the committee. <a href="https://www.clydeco.com/en/reports/2026/06/corporate-risk-radar-2026-navigating-risk-without">Clyde &amp; Co&#8217;s Corporate Risk Radar 2026</a> polled 700 board members, C-suite executives, and General Counsel across ten sectors and eight regions, and the technology risk number didn&#8217;t inch up this year. It jumped from 46% to 86% rating it high impact, in twelve months. Forty points. Read that again. That&#8217;s not a trend line. That&#8217;s a category getting re-priced in real time.</p><h3><span>The confidence number and the capability number don&#8217;t match</span></h3><p>Here&#8217;s the part that should bother a skeptical CISO more than the 40-point jump itself. Seventy-six percent of Clyde &amp; Co&#8217;s respondents say AI, <a href="http://kiteworks.com/risk-compliance-glossary/data-privacy/">data privacy</a>, and cybersecurity regulation is evolving faster than their organization can absorb. Only 68% say they have a mature AI governance framework in place. And yet 88% say they feel prepared to mitigate technology risk overall.</p><p>Sit with that math for a second. Confidence: 88%. Regulatory pace outrunning capability: 76%. Actual governance maturity: 68%. Those numbers describe three different organizations, except they&#8217;re the same organization, answering three different questions on the same survey. Clyde &amp; Co&#8217;s own researchers called it out directly, noting the 88% figure &#8220;may suggest confidence is running ahead of maturity.&#8221; That&#8217;s the polite version.</p><h3><span>This isn&#8217;t one survey&#8217;s anomaly</span></h3><p>Here&#8217;s where it gets uncomfortable. Kiteworks ran its own survey of 225 security, IT, and risk leaders for the <a href="https://www.kiteworks.com/cybersecurity-risk-management/2026-data-security-forecast-ai-governance-predictions/">2026 Data Security Forecast</a>, published five months before Clyde &amp; Co&#8217;s, across a completely different sample. It found the same gap, gave it a name, and the name is worse than &#8220;governance maturity.&#8221; Call it the containment gap. Sixty-three percent of organizations cannot enforce purpose limitations on their own AI agents. Sixty percent cannot quickly terminate an agent that&#8217;s misbehaving. Fifty-five percent cannot isolate an AI system from the broader network once something goes wrong. Organizations are watching their AI systems closely. Watching is not the same as stopping.</p><p>The timing makes it worse. CrowdStrike&#8217;s <a href="https://www.crowdstrike.com/en-us/global-threat-report/">2026 Global Threat Report</a> found AI-enabled adversary operations increased 89% year over year, and average breakout time, the window between initial access and lateral movement, fell to 29 minutes, with the fastest observed intrusion completing in 27 seconds. A governance model built around quarterly reviews and after-the-fact log analysis was already slow. Against a 29-minute breakout window, it isn&#8217;t a governance model. It&#8217;s a postmortem.</p><h3><span>Why the math got worse this year</span></h3><p>Three things compounded at once, and none of them are going to reverse.</p><p>Start with dependency. It concentrated. Clyde &amp; Co found that as AI adoption accelerated, organizations became more reliant on a smaller pool of third-party technology providers and more exposed at the integration points between systems. Verizon&#8217;s <a href="https://www.verizon.com/about/news/2025-data-breach-investigations-report">2025 Data Breach Investigations Report</a> shows exactly where that leads: third-party involvement in breaches doubled year over year, to 30% of all incidents analyzed. Fewer vendors, more blast radius per vendor.</p><p>Then there&#8217;s geopolitics. It stopped being background noise. Clyde &amp; Co found geopolitical risk&#8217;s direct commercial impact rose from 49% to 72% in a single year, and the World Economic Forum&#8217;s <a href="https://www.weforum.org/publications/global-risks-report-2026/">Global Risks Report 2026</a> puts geoeconomic confrontation at the top of its global risk list, with half of the 1,300-plus experts it surveyed expecting a turbulent world over the next two years, up 14 points from last year. Hostile actors use instability as cover. Instability is no longer occasional.</p><p>The piece that actually ties the first two together is <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trails</a>, the thing that would let a security team prove what happened and shut it down fast, and they&#8217;re the weakest link in most environments. Kiteworks&#8217; Forecast Report found 33% of organizations lack evidence-quality audit trails entirely, and another 61% have logs fragmented across systems, present but not aggregated, normalized, or usable in a timeframe that matters. Organizations without evidence-quality audit trails trail by 20 to 32 points on every AI governance metric measured, more than industry, region, or budget explains on its own.</p><h3><span>The architectural question</span></h3><p>None of this gets fixed by buying another monitoring dashboard. Monitoring is precisely the capability everyone already has. Sixty-three percent purpose-limitation failure and 60% containment failure exist <em>alongside</em> heavy investment in visibility tools, not because of their absence. The gap isn&#8217;t seeing the problem. It&#8217;s stopping it before the 29-minute window closes.</p><p>That reframes the actual question. Not &#8220;how do we watch AI systems more closely,&#8221; but &#8220;where does the decision to allow or block a specific data access get made, and how fast can it execute.&#8221; An architecture that enforces access, <a href="http://kiteworks.com/secure-file-sharing/public-vs-private-key-encryption/">encryption</a>, and audit logging at the point where data actually moves, rather than reconstructing it later from five different systems, closes exactly the gap both surveys describe. Kiteworks is one example of a platform built on that premise: a single-tenant <a href="http://kiteworks.com/platform/security/hardened-virtual-appliance">hardened virtual appliance</a> with one policy engine governing email, <a href="http://kiteworks.com/risk-compliance-glossary/managed-file-transfer/">managed file transfer</a>, <a href="http://kiteworks.com/risk-compliance-glossary/sftp/">SFTP</a>, web forms, and APIs, generating one evidence-quality <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit log</a> instead of the fragmented version 61% of organizations are stuck reconciling. It&#8217;s not the only way to build this. It is the property the containment gap is actually asking for.</p><h3><span>What to do Monday morning</span></h3><p><span>&#8226; </span>Pull your AI agent inventory. For each one, ask: can you terminate its access in under five minutes, without a change ticket? If the answer isn&#8217;t yes across the board, that&#8217;s a containment problem, not a monitoring problem.</p><p><span>&#8226; </span>Check whether your <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit logs</a> are aggregated or just accumulated. Five systems logging separately isn&#8217;t an audit trail. It&#8217;s a filing cabinet you&#8217;ll open after the damage is done.</p><p><span>&#8226; </span>Get AI governance onto the board&#8217;s top-five list this quarter. Boards that already prioritize it run 26 to 28 points ahead on every maturity metric measured &#8211; the biggest single lever in either survey.</p><p><span>&#8226; </span>Map your third-party AI and data providers the way you&#8217;d map a single point of failure. A 30% third-party breach rate says that&#8217;s what they are.</p><p>The organizations that get hit hardest in 2026 won&#8217;t be the ones with the smallest security budget. They&#8217;ll be the ones whose board minutes never mentioned AI governance until the incident report did.</p>]]></content:encoded></item><item><title><![CDATA[Australia Just Fined a Lab $1.6M for Being Slow.]]></title><description><![CDATA[The breach cost Australian Clinical Labs $4.2 million. Not knowing fast enough cost another $1.6 million.]]></description><link>https://kiteworks.substack.com/p/australia-just-fined-a-lab-16m-for</link><guid isPermaLink="false">https://kiteworks.substack.com/p/australia-just-fined-a-lab-16m-for</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Tue, 28 Jul 2026 15:02:16 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!iiMr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad830ca-ab3a-4dc7-b22e-6891f314923c_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iiMr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad830ca-ab3a-4dc7-b22e-6891f314923c_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iiMr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad830ca-ab3a-4dc7-b22e-6891f314923c_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!iiMr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad830ca-ab3a-4dc7-b22e-6891f314923c_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!iiMr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad830ca-ab3a-4dc7-b22e-6891f314923c_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!iiMr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad830ca-ab3a-4dc7-b22e-6891f314923c_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iiMr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad830ca-ab3a-4dc7-b22e-6891f314923c_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8ad830ca-ab3a-4dc7-b22e-6891f314923c_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:508947,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/208744657?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad830ca-ab3a-4dc7-b22e-6891f314923c_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!iiMr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad830ca-ab3a-4dc7-b22e-6891f314923c_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!iiMr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad830ca-ab3a-4dc7-b22e-6891f314923c_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!iiMr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad830ca-ab3a-4dc7-b22e-6891f314923c_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!iiMr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad830ca-ab3a-4dc7-b22e-6891f314923c_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On June 23, 2026, a general practice network running 21 clinics across Sydney, Melbourne, Canberra, and Queensland discovered someone had been inside its systems, reading Medicare numbers, pathology results, and referral letters. Patients found out more than three weeks later, according to <a href="https://www.sbs.com.au/news/article/australian-patient-details-exposed-in-gp-network-cyberattack/44kzw6pmr">SBS News&#8217;s reporting on the Partnered Health breach</a>.</p><p>That three-week gap between discovery and disclosure is not the interesting part of this story. Regulators already told you what is. In October 2025, Australia&#8217;s Federal Court fined a different pathology company $1.6 million for exactly that kind of gap, stacked on top of $4.2 million for the breach itself. Read the judgment and you&#8217;ll notice something practitioners rarely say out loud in a vendor briefing: not knowing fast enough is now its own compliance failure, penalized separately from whatever let the attacker in.</p><h3><span>What actually happened at Australian Clinical Labs</span></h3><p>The case is <em><a href="https://www.oaic.gov.au/news/media-centre/australian-clinical-labs-ordered-to-pay-penalties-in-relation-to-medlab-pathology-data-breach-in-first-for-privacy-act">Australian Information Commissioner v Australian Clinical Labs Limited (No 2)</a></em> [2025] FCA 1224 &#8211; the first civil penalty ever ordered under Australia&#8217;s Privacy Act 1988. The underlying event was a 2022 <a href="http://kiteworks.com/risk-compliance-glossary/ransomware-attacks/">ransomware</a> attack on IT systems Australian Clinical Labs (ACL) had inherited three months earlier through its acquisition of Medlab Pathology. Health data belonging to more than 223,000 people ended up on the dark web.</p><p>The Federal Court split the $5.8 million penalty three ways: $4.2 million for failing to take reasonable steps to protect the data in the first place, $800,000 for taking too long to assess whether the breach was serious, and another $800,000 for taking too long to tell the regulator once it was. ACL also picked up a $400,000 costs order.</p><p>Two of those three penalty lines have nothing to do with the <a href="http://kiteworks.com/risk-compliance-glossary/ransomware-attacks/">ransomware</a>. They exist because the organization couldn&#8217;t work out fast enough what had happened and who needed to know. That&#8217;s the part worth sitting with. The court didn&#8217;t treat detection speed as a mitigating factor in sentencing. It treated detection speed as a standalone legal obligation, with its own price tag.</p><h3><span>The pattern: regulators are pricing the gap, not just the breach</span></h3><p>Under Australia&#8217;s <a href="https://www.oaic.gov.au/privacy/notifiable-data-breaches/about-the-notifiable-data-breaches-scheme">Notifiable Data Breaches scheme</a>, once an entity has reasonable grounds to suspect an eligible breach, it gets 30 calendar days to complete an assessment, full stop, and the OAIC treats that as a ceiling, not a target. Notification to affected individuals and the regulator has to follow &#8220;as soon as practicable&#8221; after that.</p><p>Partnered Health is currently living out the same math in public. Twenty-one clinics, a malicious actor with access to clinical data, and a three-week window between discovery and patient notification, per the same SBS reporting and coverage from <a href="https://ia.acs.org.au/article/2026/australian-gp-network-hit-in-data-breach.html">ACS&#8217;s Information Age</a>. Nobody outside the organization yet knows whether that timeline will draw the same kind of penalty ACL did. What we do know, from the ACL precedent, is that the regulator now has a court-tested template for arguing it should.</p><h3><span>Why the math got worse</span></h3><p>Here&#8217;s the part that should bother you more than the fines. According to <a href="https://www.crowdstrike.com/en-us/global-threat-report/">CrowdStrike&#8217;s 2026 Global Threat Report</a>, the average eCrime breakout time &#8211; how long it takes an attacker to move from initial access to lateral movement inside your environment &#8211; fell to 29 minutes in 2025, with the fastest observed breakout clocked at 27 seconds. In one case in the report, <a href="http://kiteworks.com/cybersecurity-risk-management/data-exfiltration/">data exfiltration</a> started within four minutes of the initial compromise.</p><p>Attackers now operate on a clock measured in minutes. Regulators now expect an answer measured in days. Most security organizations are still operating on a clock measured in weeks, because their evidence about what happened lives in five or six different systems: email logs, file-share logs, VPN logs, endpoint telemetry, whatever the <a href="http://kiteworks.com/risk-compliance-glossary/sftp/">SFTP</a> box happens to keep. None of those speak the same language, and nobody owns correlating them until an incident forces the question. That mismatch &#8211; attacker speed, regulatory expectation, and actual organizational capability all moving at different velocities &#8211; is why a three-week disclosure delay increasingly reads as negligence rather than diligence.</p><h3><span>The architectural question</span></h3><p>The tactical response to this is &#8220;hire more forensics analysts&#8221; or &#8220;buy another <a href="http://kiteworks.com/risk-compliance-glossary/what-is-security-information-and-event-management/">SIEM</a> connector.&#8221; Neither fixes the actual problem, which is architectural: if sensitive data moves across email, file sharing, <a href="http://kiteworks.com/risk-compliance-glossary/sftp/">SFTP</a>, APIs, and increasingly AI agent workflows acting on an employee&#8217;s behalf, and each of those channels logs independently, you don&#8217;t have a security gap so much as an accounting gap. You cannot answer &#8220;what left, through which channel, to whom, and when&#8221; quickly if the answer requires reconciling five formats first.</p><p>This is the argument behind platforms built as a single control plane for data exchange rather than a stack of point tools. Kiteworks, for instance, is built around one consolidated, tamper-evident <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit log</a> across every channel it governs &#8211; rather than a separate log per protocol that a security team has to normalize by hand during an incident. That&#8217;s an architectural choice, not a feature checkbox, and it&#8217;s the kind of gap <a href="https://www.kiteworks.com/cybersecurity-risk-management/2026-data-security-forecast-ai-governance-predictions/">Kiteworks&#8217; 2026 Data Security and Compliance Risk: 2026 Forecast Report</a> flags as a recurring blind spot across sensitive data channels. Whether you buy Kiteworks or build the equivalent yourself, the point stands regardless of vendor: a fragmented logging architecture is now a legal liability, not just an operational inconvenience.</p><h3><span>What this means Monday morning</span></h3><p><span>1. </span><strong>Time yourself.</strong> Pick a random 72-hour window and see how long it actually takes your team to produce a complete list of who accessed what, from where, across every channel you run. If the honest answer is more than an hour, you&#8217;ve found your gap.</p><p><span>2. </span><strong>Count your consoles.</strong> If answering that question above requires logging into more than one system, you don&#8217;t have a <a href="http://kiteworks.com/risk-compliance-glossary/what-is-security-information-and-event-management/">SIEM</a> problem &#8211; you have an architecture problem that a SIEM can&#8217;t fully solve on its own.</p><p><span>3. </span><strong>Check your <a href="http://kiteworks.com/risk-compliance-glossary/incident-response/">incident response</a> plan for a hard clock.</strong> Not &#8220;notify when we&#8217;re confident,&#8221; but a documented 30-day assessment deadline that maps to the actual NDB scheme requirement, with an owner attached.</p><p><span>4. </span><strong>Ask your board a specific question, not a general one.</strong> Not &#8220;are we secure,&#8221; but &#8220;how long would it take us to answer the four forensic questions regulators will ask after a breach: what, through which channel, to whom, and when.&#8221;</p><p><span>5. </span><strong>Read the ACL judgment before your next tabletop exercise.</strong> It is the closest thing Australia has to a court-tested rubric for how slow is too slow.</p><p>The <a href="http://kiteworks.com/risk-compliance-glossary/ransomware-attacks/">ransomware</a> attack against ACL happened in 2022. The penalty for not knowing fast enough landed in 2025. Regulators are no longer willing to wait for your forensics team to finish before deciding whether you were negligent &#8211; which means your architecture can&#8217;t wait either.</p>]]></content:encoded></item><item><title><![CDATA[NRC's New Reactor Rule Assumes Evidence Most Licensees Lack.]]></title><description><![CDATA[Part 53 doesn't ask whether you have a cybersecurity policy. It asks whether you can prove it worked.]]></description><link>https://kiteworks.substack.com/p/nrcs-new-reactor-rule-assumes-evidence</link><guid isPermaLink="false">https://kiteworks.substack.com/p/nrcs-new-reactor-rule-assumes-evidence</guid><dc:creator><![CDATA[Danielle Barbour]]></dc:creator><pubDate>Mon, 27 Jul 2026 21:01:44 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!M5iV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b00da89-676c-4972-9207-db614354d628_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!M5iV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b00da89-676c-4972-9207-db614354d628_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!M5iV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b00da89-676c-4972-9207-db614354d628_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!M5iV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b00da89-676c-4972-9207-db614354d628_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!M5iV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b00da89-676c-4972-9207-db614354d628_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!M5iV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b00da89-676c-4972-9207-db614354d628_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!M5iV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b00da89-676c-4972-9207-db614354d628_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6b00da89-676c-4972-9207-db614354d628_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:633404,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/208743626?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b00da89-676c-4972-9207-db614354d628_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!M5iV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b00da89-676c-4972-9207-db614354d628_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!M5iV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b00da89-676c-4972-9207-db614354d628_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!M5iV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b00da89-676c-4972-9207-db614354d628_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!M5iV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b00da89-676c-4972-9207-db614354d628_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On March 25, 2026, the Nuclear Regulatory Commission approved <a href="https://www.federalregister.gov/documents/2026/03/30/2026-06048/risk-informed-technology-inclusive-regulatory-framework-for-advanced-reactors"><span>10 CFR Part 53</span></a>, the first entirely new reactor licensing framework since 1989. It took effect five weeks later, on April 29. The trade press covered it as a licensing story: faster paths to market for small modular and advanced reactors, a win for an industry riding AI-driven power demand. That&#8217;s not wrong. It&#8217;s also not the story that matters to you. The real story is buried in the framework&#8217;s design: Part 53 is risk-informed and technology-inclusive, which means it trades fixed prescriptive checklists for continuous, metric-driven proof. You don&#8217;t file a safety case once. You maintain one. And most of the sector currently cannot.</p><h3><strong><span>The rule everyone is reading wrong</span></strong></h3><p>10 CFR already required more than paperwork before Part 53 showed up. Section 73.54 requires licensees to maintain &#8220;high assurance&#8221; that digital systems tied to safety, security, and emergency preparedness are protected against cyberattack, consistent with <a href="http://kiteworks.com/risk-compliance-glossary/nist-800-53-compliance/">NIST SP 800-53</a> and NRC Regulatory Guide 5.71. Section 73.77 requires notification of a qualifying cyberattack within a fixed window, followed by a written report. Part 21 makes suppliers, vendors, and licensees jointly responsible for evaluating and reporting defects in safety-relevant components, across everything from fuel fabrication to waste storage.</p><p>None of that is new law. What&#8217;s new is that Part 53 removes the fallback option. Under the older frameworks, a licensee could point to a static safety analysis report and call it done. Part 53&#8217;s risk-metric model assumes you&#8217;re continuously generating the evidence that report used to freeze in place. &#8220;High assurance&#8221; was always supposed to mean assurance, not intention. Part 53 just removed the last places to hide that distinction.</p><h3><strong><span>This is not a nuclear problem</span></strong></h3><p>Here&#8217;s the uncomfortable part: nuclear&#8217;s evidence gap isn&#8217;t unique to nuclear. It&#8217;s the default condition of regulated industry, and the data says so directly. The <a href="https://blackkite.com/reports/third-party-breach-report-2026"><span>Black Kite Third-Party Breach Report 2026</span></a> found that across roughly 200,000 organizations it monitors, the average cyber-risk grade is a 90.27 -- an A. At the same time, 53.77% of those same organizations carry at least one active critical <a href="http://kiteworks.com/risk-compliance-glossary/vulnerability/">vulnerability</a>. Read that twice. A grade that good and a failure rate that high are not supposed to coexist, and yet they do, because a compliance grade measures whether you documented the right things, not whether the things you documented are actually enforced.</p><p>The <a href="https://www.kiteworks.com/cybersecurity-risk-management/2026-data-security-forecast-ai-governance-predictions/"><span>Kiteworks Data Security and Compliance Risk: 2026 Forecast Report</span></a> found the same split inside the energy and utilities sector specifically, the category nuclear sits within: the highest AI governance maturity score of any industry surveyed, second-highest data security maturity score, and a dominant behavioral pattern the report labels &#8220;Policy-Led&#8221; -- governance and regulatory awareness running roughly 1.86 times further ahead of enforced technical controls than the survey&#8217;s baseline expectation. Translation: the sector knows exactly what good compliance looks like. It has not finished building the plumbing that proves it&#8217;s happening.</p><h3><strong><span>Why the timing makes it worse</span></strong></h3><p>Three things are converging on nuclear at once, and none of them were designed with the others in mind. AI-driven power demand is pulling a wave of new reactor developers into the licensing pipeline right as that pipeline shifts to a continuous-evidence model. Operational technology threat activity is accelerating industry-wide -- Dragos&#8217;s <a href="https://www.dragos.com/resources/press-release/dragos-2026-year-in-review-new-ot-threats-ransomware"><span>2026 OT Cybersecurity Report</span></a> tracked 119 distinct <a href="http://kiteworks.com/risk-compliance-glossary/ransomware-attacks/">ransomware</a> groups hitting more than 3,300 industrial organizations in 2025, up from 80 groups the year before, and found elevated weaknesses in secure remote access configurations in nearly half of its services engagements. And Part 21&#8217;s supply-chain obligation depends on visibility the sector&#8217;s own vendor base doesn&#8217;t reliably provide: Black Kite&#8217;s analysis of its &#8220;Elite 50&#8221; -- the vendors most shared across the Forbes Global 2000 -- found 70% carry at least one unpatched, already-known-exploited <a href="http://kiteworks.com/risk-compliance-glossary/vulnerability/">vulnerability</a>, and the median gap between breach detection and public disclosure runs 73 days, stretching to a 117-day average. Black Kite calls that gap the &#8220;silent window.&#8221; A nuclear supplier sitting inside that window is still, for months at a time, a supplier whose defect attestations a licensee is legally relying on.</p><p>Stack a growth cycle, an accelerating OT threat curve, and a <a href="http://kiteworks.com/risk-compliance-glossary/supply-chain-risk-management/">supply chain</a> with a multi-month blind spot on top of a licensing framework that assumes continuous proof, and you get a sector where the compliance program most people built for the old rules is already behind the rules that just replaced them.</p><h3><strong><span>The architectural question</span></strong></h3><p>The instinct here is to answer with more documentation: a longer policy, a more detailed supplier questionnaire, another audit checklist. That instinct is not wrong, exactly. It&#8217;s just no longer sufficient, because the thing Part 53 and Section 73.77 actually test is whether you can produce a real-time, defensible record of who touched what data, when, and through which channel -- on demand, not reconstructed after the fact from five disconnected systems.</p><p>That&#8217;s an architecture problem, not a policy problem. The <a href="https://www.weforum.org/publications/global-cybersecurity-outlook-2026/digest/"><span>World Economic Forum&#8217;s Global Cybersecurity Outlook 2026</span></a> found that organizations it classifies as highly resilient are far more likely than less-resilient peers to build security into procurement and formally assess supplier maturity as a standing practice, not a point-in-time gate. That only works if the underlying exchange of data, between licensees, suppliers, and regulators, runs through a system built to log and prove it continuously, not five disconnected tools stitched together after the fact. The specific vendor matters less than the requirement: one policy layer across every channel data actually moves through, generating a single exportable record instead of five partial ones. And whatever architecture you land on, it needs to govern people and AI agents under the same policy from the outset -- Part 53&#8217;s technology-inclusive framing means more of this data traffic will be agent-touched soon, and a system that governs humans carefully while leaving machine access as an afterthought hasn&#8217;t actually closed the gap.</p><h3><strong><span>What this means Monday morning</span></strong></h3><p>If you&#8217;re inside 10 CFR, or watching it because your industry is three years behind nuclear on the same curve, the checklist is short:</p><p><span>1. </span>Pull your Section 73.54 evidence trail and time how long it takes to produce a real-time access record for a single safety-relevant system. If the answer involves exporting logs from more than two tools, you&#8217;ve found your gap.</p><p><span>2. </span>Map which of your suppliers fall under Part 21&#8217;s reporting obligation, and ask when each last had its security posture independently assessed -- not attested, assessed.</p><p><span>3. </span>Time-box a tabletop for Section 73.77: from detection to a defensible written report, how many hours, and how many of them are spent reconciling data instead of writing the notification.</p><p><span>4. </span>If you&#8217;re a new entrant building a Part 53 program from scratch, build the evidence architecture before the point solutions, not after.</p><p>A compliance program that looks finished on paper and one that survives a Section 73.77 clock are not the same program. Part 53 was written to make sure everyone finds out which one they built.</p>]]></content:encoded></item><item><title><![CDATA[CEOs Plan for 10-Day Recovery. Reality Runs Six Months.]]></title><description><![CDATA[Accenture surveyed 505 CEOs and 495 CISOs. They answered the same questions and still don't agree on what "resilient" means.]]></description><link>https://kiteworks.substack.com/p/ceos-plan-for-10-day-recovery-reality</link><guid isPermaLink="false">https://kiteworks.substack.com/p/ceos-plan-for-10-day-recovery-reality</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Fri, 24 Jul 2026 14:03:02 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!rIxb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3408574-3ed7-4ac9-8975-27fa30d7d3c9_720x480.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rIxb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3408574-3ed7-4ac9-8975-27fa30d7d3c9_720x480.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rIxb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3408574-3ed7-4ac9-8975-27fa30d7d3c9_720x480.webp 424w, https://substackcdn.com/image/fetch/$s_!rIxb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3408574-3ed7-4ac9-8975-27fa30d7d3c9_720x480.webp 848w, https://substackcdn.com/image/fetch/$s_!rIxb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3408574-3ed7-4ac9-8975-27fa30d7d3c9_720x480.webp 1272w, https://substackcdn.com/image/fetch/$s_!rIxb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3408574-3ed7-4ac9-8975-27fa30d7d3c9_720x480.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rIxb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3408574-3ed7-4ac9-8975-27fa30d7d3c9_720x480.webp" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b3408574-3ed7-4ac9-8975-27fa30d7d3c9_720x480.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:16614,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/208212465?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3408574-3ed7-4ac9-8975-27fa30d7d3c9_720x480.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rIxb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3408574-3ed7-4ac9-8975-27fa30d7d3c9_720x480.webp 424w, https://substackcdn.com/image/fetch/$s_!rIxb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3408574-3ed7-4ac9-8975-27fa30d7d3c9_720x480.webp 848w, https://substackcdn.com/image/fetch/$s_!rIxb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3408574-3ed7-4ac9-8975-27fa30d7d3c9_720x480.webp 1272w, https://substackcdn.com/image/fetch/$s_!rIxb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3408574-3ed7-4ac9-8975-27fa30d7d3c9_720x480.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>It&#8217;s Tuesday morning. Your identity provider is degraded, half your file shares won&#8217;t resolve, and the board wants a recovery timeline before the 10am bridge call. You say &#8220;a few days, tops.&#8221; Everyone on the call nods. That nod is the problem.</p><p>Accenture&#8217;s newly released <a href="https://www.accenture.com/us-en/insights/security/redefining-cyber-resilience">cyber resilience research</a> -- a pulse survey of 1,000 C-suite executives across 13 countries -- found that 81% of leaders assume critical IT downtime will run 10 days or less in a serious incident. The measured average: three to six months. That&#8217;s not an estimation error. That&#8217;s a plan built on a number that has almost nothing to do with what actually happens once the plan gets tested.</p><h3><span>The 10-Day Number Was Never Real</span></h3><p>Start with what the survey actually measured. Eighty-seven percent of organizations now describe cyber disruption as a recurring operating condition, not a rare event. Seventy-two percent say preventing all disruption is no longer realistic given how interconnected their systems have become. Fifty-four percent still believe strong protection controls are sufficient to guarantee continuity after an attack -- and CEOs are 136% more likely than CISOs to say <a href="http://kiteworks.com/risk-compliance-glossary/regulatory-compliance-definition/">regulatory compliance</a> alone assures resilience.</p><p>Put those together and you get an executive population that is, on average, more confident than its own security leadership and less accurate. Sixty-four percent of respondents told Accenture they design and govern technology on the assumption that systems stay generally stable and available, even though eight in ten of those same people expect degraded operations during a real disruption. They are planning around a condition they already admit won&#8217;t hold.</p><h3><span>This Is a Structural Gap, Not a Knowledge Gap</span></h3><p>Here&#8217;s the part that should bother you more than the wrong number: Accenture frames this as a &#8220;false consensus.&#8221; CEOs and CISOs aren&#8217;t uninformed. They&#8217;re each assuming the other one already agrees on ownership, on sequencing, on what gets protected first. Seventy-four percent of organizations report that resilience is treated primarily as a security or IT responsibility. Only 43% actually govern it as a shared enterprise outcome. That gap between &#8220;we agree&#8221; and &#8220;we&#8217;ve never actually tested whether we agree&#8221; is what turns a contained technical incident into a business-wide one.</p><p>The World Economic Forum&#8217;s <a href="https://www.weforum.org/publications/global-cybersecurity-outlook-2026/">Global Cybersecurity Outlook 2026</a>, produced in partnership with Accenture, backs this up from a different angle: 94% of respondents now name AI as the most significant driver of change facing their security programs, yet CEO and CISO risk priorities still diverge on what to do about it. Two roles, one incident, two different mental models of who&#8217;s supposed to act first.</p><h3><span>AI Broke the Math That Made &#8220;10 Days&#8221; Plausible</span></h3><p>Ten days used to be a defensible planning number, back when the gap between a <a href="http://kiteworks.com/risk-compliance-glossary/vulnerability/">vulnerability</a> being discovered and being weaponized ran in weeks. That gap is gone. CrowdStrike&#8217;s <a href="https://www.crowdstrike.com/en-us/global-threat-report/">2026 Global Threat Report</a> clocked average breakout time -- the interval between initial compromise and lateral movement -- at 29 minutes, down from 48 minutes the year before, with a fastest observed breakout of 27 seconds. AI-enabled attacks were up 89% year over year. Separately, a benchmark cited in Accenture&#8217;s research found frontier AI models now succeed at finding and exploiting a <a href="http://kiteworks.com/risk-compliance-glossary/vulnerability/">vulnerability</a> on the first attempt 83% of the time, a rate that was close to zero not long ago.</p><p>A response plan built for weeks-long attacker timelines cannot survive contact with a 29-minute breakout. That&#8217;s not a tooling problem you patch your way out of. It&#8217;s a design assumption that quietly expired while most <a href="http://kiteworks.com/risk-compliance-glossary/incident-response/">incident response</a> plans stayed exactly as written.</p><h3><span>Your Recovery Plan Assumes You Own the Failure. You Often Don&#8217;t.</span></h3><p>Sixty-nine percent of organizations in Accenture&#8217;s survey say their operations increasingly depend on complex internal and third-party digital ecosystems. Sixty-one percent say their ability to sustain critical operations depends directly on external partners. Only 38% have a clear view of which of those dependencies actually matter most. That&#8217;s not a hypothetical exposure -- Black Kite&#8217;s <a href="https://blackkite.com/reports/third-party-breach-report-2026">2026 Third-Party Breach Report</a> found a median disclosure lag of 73 days between a vendor&#8217;s breach and public notification, with an average silent window stretching to 117 days. Attacks get detected in a median of 10 days. Everyone downstream of that vendor finds out months later, if they&#8217;re told at all.</p><p>This is the point where &#8220;patch faster&#8221; and &#8220;buy another detection tool&#8221; stop being sufficient answers, because neither one addresses a partner&#8217;s breach happening on their timeline, not yours. The trait that actually separates a fast recovery from a six-month slog is simpler than most <a href="http://kiteworks.com/risk-compliance-glossary/incident-response/">incident response</a> plans admit: knowing exactly where sensitive data lives, who -- internal or external, human or automated -- can reach it, and being able to prove and revoke that access without waiting on someone else&#8217;s process. That&#8217;s an architectural property, not a control you bolt on afterward. It&#8217;s the premise behind treating <a href="http://kiteworks.com/risk-compliance-glossary/data-governance/">data governance</a> as a single, unified plane rather than a stack of point tools with their own logs and their own blind spots -- which is the design idea behind platforms like Kiteworks, built with single-tenant isolation and a consolidated, real-time <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trail</a> specifically so an organization can answer &#8220;who touched this file, when, and from where&#8221; without stitching together five systems during an active incident. And the standing-access problem isn&#8217;t limited to human partners anymore: Kiteworks&#8217; own <a href="https://www.kiteworks.com/cybersecurity-risk-management/2026-data-security-forecast-ai-governance-predictions/">2026 Data Security and Compliance Risk: Annual Forecast Report</a> found that among organizations already running AI agents in production, 63% cannot enforce purpose limitations on what those agents are allowed to touch, and 60% cannot terminate a misbehaving one. AI agents are a fast-growing category of identity with standing access to sensitive data, right alongside your human users -- and most organizations still haven&#8217;t extended the same access governance and kill-switch controls to them that they&#8217;d never skip for a new employee.</p><h3><span>What This Means Monday Morning</span></h3><p>You don&#8217;t need a new framework. You need five uncomfortable conversations this week.</p><p><span>1. </span>Ask your CEO, in the same room as your CFO and general counsel, what recovery timeline they&#8217;re actually assuming. Write the number down. Compare it to Accenture&#8217;s three-to-six-month average.</p><p><span>2. </span>Identify the smallest set of functions the business cannot survive without, and name who owns the decision to sequence their recovery -- before an incident, not during the bridge call.</p><p><span>3. </span>Pull the list of third parties with standing access to your sensitive data. If you can&#8217;t produce it in an afternoon, that&#8217;s your answer to whether you have &#8220;a clear view of your value chain.&#8221;</p><p><span>4. </span>Test your <a href="http://kiteworks.com/risk-compliance-glossary/incident-response/">incident response</a> plan against a 30-minute breakout window, not a 30-day one. Most tabletop exercises still assume the slower world.</p><p><span>5. </span>Ask who can revoke a partner&#8217;s data access right now, without a change request or a ticket queue. If the answer takes more than a sentence, fix that first.</p><p>The 10-day number was never a forecast. It was a story executives told each other because testing it felt unnecessary until the week it wasn&#8217;t. Accenture just handed every CISO the data to have that conversation before the incident forces it.</p>]]></content:encoded></item><item><title><![CDATA[Your AI Agent Has No Identity. It Borrowed Yours.]]></title><description><![CDATA[Okta tracked sign-on data from more than 20,000 companies for four years. It found the audit trail disappearing exactly where agents took over the work.]]></description><link>https://kiteworks.substack.com/p/your-ai-agent-has-no-identity-it</link><guid isPermaLink="false">https://kiteworks.substack.com/p/your-ai-agent-has-no-identity-it</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Thu, 23 Jul 2026 15:01:56 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!OxfF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a50b43f-de11-4a70-90a8-0a8f60a2849c_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OxfF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a50b43f-de11-4a70-90a8-0a8f60a2849c_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OxfF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a50b43f-de11-4a70-90a8-0a8f60a2849c_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!OxfF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a50b43f-de11-4a70-90a8-0a8f60a2849c_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!OxfF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a50b43f-de11-4a70-90a8-0a8f60a2849c_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!OxfF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a50b43f-de11-4a70-90a8-0a8f60a2849c_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OxfF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a50b43f-de11-4a70-90a8-0a8f60a2849c_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9a50b43f-de11-4a70-90a8-0a8f60a2849c_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:389755,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/207967703?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a50b43f-de11-4a70-90a8-0a8f60a2849c_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!OxfF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a50b43f-de11-4a70-90a8-0a8f60a2849c_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!OxfF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a50b43f-de11-4a70-90a8-0a8f60a2849c_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!OxfF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a50b43f-de11-4a70-90a8-0a8f60a2849c_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!OxfF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a50b43f-de11-4a70-90a8-0a8f60a2849c_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Consider a coding agent inside your engineering org that merges nine pull requests before your first standup. It authenticates the same way it did last Tuesday: as a senior engineer, through a service account nobody ever got around to replacing. Nothing breaks. Nothing trips an alert. That&#8217;s the problem. The agent didn&#8217;t hack anything. It just used a login nobody built for it, and now nobody can prove who did what.</p><p>That scene isn&#8217;t a stretch. It&#8217;s the pattern a new dataset just confirmed at scale.</p><h3>The Okta numbers say the quiet part out loud</h3><p>The <em>Okta Enterprise AI Index</em>, built from anonymized sign-on data spanning June 2022 through June 2026 across more than 20,000 organizations, tracked over a hundred distinct AI products and consolidated them into 74 vendor suites. The market split in two. AI-native companies (Anthropic, OpenAI, Cursor) grew their enterprise customer base more than four times over that period, while established software makers like Microsoft, Google Workspace, and Adobe added AI features at a slower clip. Anthropic passed OpenAI in enterprise accounts in March 2026 and led it in monthly active users the month after, according to <a href="https://www.helpnetsecurity.com/2026/07/21/report-enterprise-ai-identity-risk/">Help Net Security&#8217;s coverage</a> of the index. Microsoft 365 still dwarfs both on raw volume.</p><p>None of that growth is the real story. The real story is what rides along with it: every new AI platform shows up with its own logins, its own permissions, and its own web of app-to-app connections built on secrets and tokens that nobody centrally tracks.</p><h3>Vendors multiply. Credentials sprawl faster.</h3><p>Fei Liu, Principal Emerging Tech Researcher at Okta, put it plainly: &#8220;Our data shows that as the number of platforms grows, so does the risk of over-permissioned apps and orphaned tokens.&#8221; Her prescription is a mindset shift. Security teams need to stop treating each new AI tool as &#8220;adding a new software vendor&#8221; and start treating it as an expansion of the identity fabric they&#8217;re already failing to fully govern.</p><p>Here&#8217;s where it gets worse. When agents need <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credentials</a> to actually do the work (read a repo, query a database, send an email), most organizations reach for what&#8217;s already lying around. &#8220;We&#8217;re seeing a heavy reliance on traditional service accounts and static API keys, and unfortunately, we still see instances of shared human logins being used to authorize agentic workflows,&#8221; Liu told Help Net Security. The consequence isn&#8217;t abstract. &#8220;When an AI agent inherits a human&#8217;s login, you completely lose your <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trail</a> &#8211; you can no longer distinguish whether a critical action was taken by an employee or autonomously by an algorithm.&#8221;</p><p>Sit with that sentence. You cannot answer &#8220;who did this&#8221; for actions your own agents took, using logins your own IT team issued. That&#8217;s not a hardening gap. That&#8217;s a structural blind spot in the thing every <a href="http://kiteworks.com/risk-compliance-glossary/incident-response/">incident response</a> plan assumes exists: a trustworthy log.</p><h3>Why this is worse than the same problem looked last year</h3><p>Credential-based blind spots aren&#8217;t new. What&#8217;s new is the speed at which adversaries exploit them and the sheer number of machine identities piling up behind each human one.</p><p>CrowdStrike&#8217;s <a href="https://www.crowdstrike.com/en-us/press-releases/2026-crowdstrike-global-threat-report/">2026 Global Threat Report</a> found AI-enabled adversary operations up 89% year over year. Average eCrime breakout time fell to 29 minutes; the fastest observed breakout occurred in 27 seconds. Attackers are already moving through trusted identities and SaaS sessions at machine speed. An <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit log</a> that reads &#8220;the engineer&#8221; when an agent actually took the action isn&#8217;t just a compliance headache during an audit. It&#8217;s a detection failure at the exact moment defenders have the least time to notice anything is wrong.</p><p>Layer on the sheer scale of the identity sprawl. CyberArk&#8217;s 2025 Identity Security Landscape study found <a href="https://www.cyberark.com/press/machine-identities-outnumber-humans-by-more-than-80-to-1-new-report-exposes-the-exponential-threats-of-fragmented-identity-security/">82 machine identities for every human</a> in the average enterprise, with 42% of those machine identities carrying privileged or sensitive access. That&#8217;s despite 88% of organizations still defining &#8220;privileged user&#8221; as something that only applies to humans, a gap between what security teams think privileged access covers and what it actually covers. And Verizon&#8217;s 2026 Data Breach Investigations Report found that <a href="https://www.helpnetsecurity.com/2026/05/20/verizon-2026-dbir-findings/">&#8220;shadow AI is now the third most common non-malicious insider action&#8221;</a> in enterprise data-loss-prevention datasets, a fourfold increase over the year before. The unsanctioned, ungoverned instance of AI is growing faster than any identity program built to contain it.</p><p>Put those three data points together and you get an uncomfortable picture: more machine identities than anyone can track, a growing share of them privileged, attackers who already know how to move through trusted sessions in minutes, and an expanding chunk of agent activity that never shows up as agent activity in the log.</p><h3>The architectural question</h3><p>The instinct is to patch this the way security teams patch everything: more identity tickets, faster service-account rotation, a project to inventory every API key by Q4. That instinct doesn&#8217;t scale, because it treats an agent&#8217;s identity as a provisioning artifact, something you set up once and forget, rather than something you govern continuously, at the moment of data access, alongside every human who touches the same content. I don&#8217;t think this is really a technology problem. It&#8217;s a laziness-at-scale problem: it&#8217;s easier to hand an agent somebody&#8217;s login than to build it one of its own.</p><p>The alternative is to stop asking <a href="http://kiteworks.com/risk-compliance-glossary/identity-access-management/">IAM</a> to solve a data-access problem. The architectural approach worth examining evaluates every agent request at the moment it&#8217;s made, against role- and <a href="http://kiteworks.com/risk-compliance-glossary/attribute-based-access-control/">attribute-based</a> policy scoped to that specific agent and task, so <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credentials</a> never sit in a config file or a prompt where they can be copied or exposed. Done right, every action lands in an <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trail</a> that names the agent that acted, not a human whose login it happened to be using. It&#8217;s one policy plane governing what humans and agents alike are allowed to touch. Not a separate, looser set of rules for whichever agent got provisioned last. Kiteworks&#8217; <a href="https://www.kiteworks.com/cybersecurity-risk-management/2026-data-security-forecast-ai-governance-predictions/">2026 Data Security and Compliance Risk Forecast Report</a> names this exact failure mode (agents inheriting human <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credentials</a> to reach sensitive content) as one of the defining AI governance gaps enterprises will be graded on this year.</p><p>That&#8217;s the architectural bet worth making: govern the access, not just the account.</p><h3>What this means Monday morning</h3><p><span>&#8226; </span>Pull your SSO logs this week and separate &#8220;service account doing agent work&#8221; from any identity that was actually provisioned as non-human. Most organizations can&#8217;t currently answer this question in under an hour.</p><p><span>&#8226; </span>For every agent with write access to anything sensitive, answer Okta&#8217;s three questions in writing: where does it run, what can it connect to, and what can it actually do.</p><p><span>&#8226; </span>Stop provisioning new agents against shared human logins, even as a temporary bridge. Temporary is how an unauditable action shows up in a breach investigation eight months from now.</p><p><span>&#8226; </span>Push authorization decisions down to the data layer, per request, so revoking one agent&#8217;s access doesn&#8217;t mean rotating a password that nine humans also use.</p><p><span>&#8226; </span>Put a lifecycle and an access review on every non-human identity you create, the same way you already do for employees who change roles or leave.</p><p>The next nine pull requests your agent merges will carry somebody&#8217;s name in the log. Make sure it&#8217;s the agent&#8217;s, and not yours.</p>]]></content:encoded></item><item><title><![CDATA[AI Maturity Confidence Fell 17 Points. Blame Non-Human Identity.]]></title><description><![CDATA[Fewer IT leaders call their organization "mature" in AI deployment than they did six months ago. That's not the market losing faith in AI. It's the market finally measuring the right thing.]]></description><link>https://kiteworks.substack.com/p/ai-maturity-confidence-fell-17-points</link><guid isPermaLink="false">https://kiteworks.substack.com/p/ai-maturity-confidence-fell-17-points</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Wed, 22 Jul 2026 15:01:59 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!-EA0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca846296-b69d-481e-9c56-dc752d170a1c_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-EA0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca846296-b69d-481e-9c56-dc752d170a1c_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-EA0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca846296-b69d-481e-9c56-dc752d170a1c_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!-EA0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca846296-b69d-481e-9c56-dc752d170a1c_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!-EA0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca846296-b69d-481e-9c56-dc752d170a1c_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!-EA0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca846296-b69d-481e-9c56-dc752d170a1c_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-EA0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca846296-b69d-481e-9c56-dc752d170a1c_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ca846296-b69d-481e-9c56-dc752d170a1c_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:531495,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/207965678?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca846296-b69d-481e-9c56-dc752d170a1c_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-EA0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca846296-b69d-481e-9c56-dc752d170a1c_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!-EA0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca846296-b69d-481e-9c56-dc752d170a1c_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!-EA0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca846296-b69d-481e-9c56-dc752d170a1c_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!-EA0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca846296-b69d-481e-9c56-dc752d170a1c_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Picture a mid-size insurer&#8217;s Tuesday standup in early July: the security architect pulls up a dashboard of active AI agents provisioning claims data, and nobody in the room can say with confidence how many of those agents still hold <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credentials</a> from a pilot that ended back in March. That&#8217;s not a hypothetical. It&#8217;s the ordinary condition VentureBeat&#8217;s Q3 2026 trends survey of 800 IT leaders across the US and UK just put a number on, and the number is worse than a slow news week would suggest, in exactly the way that matters. The share of IT leaders describing their organization as &#8220;mature&#8221; in AI deployment fell from 40% six months ago to 23% today, a 17-point drop, according to <a href="https://venturebeat.com/security/ai-confidence-just-dropped-17-points-in-six-months-thats-actually-great-news"><span>VentureBeat&#8217;s coverage</span></a> of the survey. Read that as bad news and you&#8217;ve missed the point. Read it as the first honest self-assessment IT leaders have produced all year, and here&#8217;s the real thesis: the confidence gap isn&#8217;t eroding trust in AI. It&#8217;s exposing a governance gap that was there the whole time, hiding behind six months of overstated maturity claims.</p><h3><strong><span>Twenty-three percent now call themselves mature. Six months ago it was forty.</span></strong></h3><p>The VentureBeat survey didn&#8217;t ask leaders to guess at industry sentiment. It asked them to self-report against a defined maturity model, and the honest answers dropped by nearly half. The same survey isolated why: of every AI security practice measured, non-human identity governance is the least adopted, in place at just 21% of organizations -- the practice covering service accounts, API keys, and autonomous agents. <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">Credentials</a> that don&#8217;t sleep and don&#8217;t show up in a quarterly access review unless somebody builds one specifically to catch them.</p><p>Here&#8217;s the number that makes the gap indefensible rather than merely inconvenient: non-human identities now outnumber human users at 83% of organizations surveyed. In four out of five organizations, the majority identity type accessing systems and data is the one with the least governance attached to it. VentureBeat&#8217;s own maturity tiering makes the payoff for closing that gap explicit: organizations in the top tier were five times more likely to report no barriers to expanding their AI agent deployments than the average organization surveyed. Maturity isn&#8217;t a badge. It&#8217;s the gap between scaling agents on purpose and discovering how many you have after something goes wrong.</p><h3><strong><span>The machines already outnumber you, and nobody governs them</span></strong></h3><p>This lines up with every other identity-focused research shop&#8217;s numbers, too, just with different figures attached. Palo Alto Networks&#8217; 2026 Identity Security Landscape report, based on a survey of nearly 2,930 cybersecurity decision-makers, put the ratio of machine identities to human identities at 109 to 1, up from 82 to 1 just a year earlier, according to <a href="https://www.helpnetsecurity.com/2026/05/14/2026-identity-security-landscape-report/"><span>Help Net Security&#8217;s coverage</span></a> of the report. Of those 109 machine identities per human, 79 are AI agents specifically. The same report found nine out of ten organizations had suffered a successful identity-related breach in the prior twelve months.</p><p>Put the two data sets side by side and the pattern stops looking like a coincidence. Identity governance programs were built for humans who get onboarded, badge in, and get offboarded on a predictable schedule. They were never built for a population that now dwarfs the human one and keeps growing. CrowdStrike&#8217;s 2026 Global Threat Report adds the attacker&#8217;s view of what that gap costs: 82% of detections last year were <a href="http://kiteworks.com/risk-compliance-glossary/malware-based-attacks/">malware-free</a>, meaning adversaries increasingly succeeded by using valid <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credentials</a> and trusted identity flows rather than breaking anything, with valid account abuse behind 35% of cloud intrusions, per <a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-2026-global-threat-report-findings/"><span>CrowdStrike&#8217;s own summary</span></a> of its findings. An unmanaged non-human identity is a standing credential an attacker doesn&#8217;t even need to steal cleverly. They just need to find it sitting there, unattended.</p><h3><strong><span>More agents, same credentials, compounding debt</span></strong></h3><p>Here&#8217;s a question I keep coming back to: why is this getting worse now, after years of warnings about service-account sprawl? The answer is velocity. Palo Alto&#8217;s report projects machine identities will grow 77% over the next twelve months, with AI agent identities specifically growing 85% in that window. Gartner, meanwhile, <a href="https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027"><span>predicts that over 40% of agentic AI projects will be canceled by the end of 2027</span></a>, citing escalating costs and inadequate <a href="http://kiteworks.com/risk-compliance-glossary/security-risk-management/">risk controls</a> as leading causes.</p><p>Those two numbers describe the same problem from opposite ends. Agent deployment is accelerating faster than any identity program built around human onboarding cycles can absorb, and a meaningful share of those deployments will get killed specifically because nobody built the governance layer first. Most organizations are still provisioning agents the way they provisioned service accounts a decade ago: one shared credential, broad scope, renewed automatically, reviewed rarely. That approach was already a liability when the ratio of machines to humans sat in the single digits. At 109 to 1, and climbing, it&#8217;s not a liability anymore. It&#8217;s an admission that nobody is actually in control of what has access to what.</p><h3><strong><span>Identity provisioning was never built for this volume</span></strong></h3><p>The tactical response -- buy another identity governance module, extend the existing <a href="http://kiteworks.com/risk-compliance-glossary/identity-access-management/">IAM</a> tool to cover service accounts, run a quarterly cleanup script -- treats this as a scale problem. It&#8217;s an architecture problem. Human identity governance answers &#8220;who is this person, and what should they be allowed to do.&#8221; Non-human identity governance at 109-to-1 ratios has to answer a harder question continuously and automatically: what specific data can this specific agent touch, for this specific task, right now, not what it was granted eighteen months ago when somebody provisioned it in a hurry.</p><p>That reframing is why a handful of vendors are building AI governance directly into the data access layer instead of bolting it onto the identity layer after the fact: mediating every agent request against a unified policy engine at the point of access, rather than issuing agents standing credentials to a file share or a database, and logging each access as an evidence-quality <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit record</a> instead of a line in a log file nobody reads. Kiteworks&#8217; own <a href="https://www.kiteworks.com/cybersecurity-risk-management/2026-data-security-forecast-ai-governance-predictions/"><span>2026 Data Security and Compliance Risk Forecast Report</span></a> names exactly this gap -- ungoverned non-human identity access to sensitive content -- as one of the defining exposures organizations will carry into next year. This isn&#8217;t the only architecture built on that premise, one that treats agents as governed identities alongside humans rather than an afterthought bolted onto human <a href="http://kiteworks.com/risk-compliance-glossary/identity-access-management/">IAM</a>. But it&#8217;s a credible answer to a question every organization in the VentureBeat survey is now being forced to answer, whether it has a vendor picked out or not.</p><h3><strong><span>What this means Monday morning</span></strong></h3><p>The 17-point confidence drop is a market correcting its own instrumentation, not a market losing faith. Treat it as your cue to act, not your excuse to wait until the number stabilizes.</p><p><span>1. </span><strong>Inventory non-human identities as a standalone exercise</strong>, separate from your human identity <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit</a>. If you can&#8217;t produce a current count of active service accounts, API keys, and agent <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credentials</a>, you don&#8217;t have a governance program. You have an assumption.</p><p><span>2. </span><strong>Map access at the data layer, not the account layer.</strong> Knowing an agent exists isn&#8217;t the same as knowing what content it can reach. Build the second map.</p><p><span>3. </span><strong>Kill standing, broad-scope credentials for agents wherever you find them.</strong> Replace blanket access with per-agent, per-task authorization that expires by default.</p><p><span>4. </span><strong>Demand evidence-quality logs for every non-human access event</strong>, not just alerts. An auditor asking &#8220;prove it&#8221; six months from now won&#8217;t accept &#8220;we believe so.&#8221;</p><p><span>5. </span><strong>Re-run your own maturity self-assessment honestly</strong> before your next board update. A lower, accurate number this quarter beats a flattering, wrong one from last quarter.</p><p>The organizations whose confidence dropped 17 points didn&#8217;t get worse at AI. They got honest about it first. Everyone else is still measuring the wrong thing.</p>]]></content:encoded></item><item><title><![CDATA[Executives Break Their Own Shadow AI Rules Twice as Often.]]></title><description><![CDATA[The people who wrote your AI policy are the ones breaking it -- and they knew exactly what it would cost before they did it.]]></description><link>https://kiteworks.substack.com/p/executives-break-their-own-shadow</link><guid isPermaLink="false">https://kiteworks.substack.com/p/executives-break-their-own-shadow</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Tue, 21 Jul 2026 15:01:28 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Hftr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe814708a-2ccb-43b3-91bb-66dc05cb943f_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Hftr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe814708a-2ccb-43b3-91bb-66dc05cb943f_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Hftr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe814708a-2ccb-43b3-91bb-66dc05cb943f_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!Hftr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe814708a-2ccb-43b3-91bb-66dc05cb943f_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!Hftr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe814708a-2ccb-43b3-91bb-66dc05cb943f_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!Hftr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe814708a-2ccb-43b3-91bb-66dc05cb943f_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Hftr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe814708a-2ccb-43b3-91bb-66dc05cb943f_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e814708a-2ccb-43b3-91bb-66dc05cb943f_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:451866,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/207825913?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe814708a-2ccb-43b3-91bb-66dc05cb943f_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Hftr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe814708a-2ccb-43b3-91bb-66dc05cb943f_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!Hftr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe814708a-2ccb-43b3-91bb-66dc05cb943f_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!Hftr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe814708a-2ccb-43b3-91bb-66dc05cb943f_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!Hftr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe814708a-2ccb-43b3-91bb-66dc05cb943f_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>It&#8217;s Tuesday morning. The board deck is due at noon. Somewhere in your building, a senior executive who personally signed off on the AI acceptable use policy is pasting a client contract into a personal ChatGPT account to get a faster first draft, because the sanctioned enterprise tool requires two extra approval clicks and this is due in three hours. This is not a hypothetical. It&#8217;s the median behavior of your leadership team, and the data says so with a straight face.</p><h3><strong>Two-thirds of the C-suite is doing this right now</strong></h3><p><a href="https://www.businesswire.com/news/home/20260519849160/en/TrustedTech-Global-and-U.S.-Data-Reveals-Senior-Leaders-Are-the-Biggest-Source-of-Shadow-AI-Risk-in-Organizations">A 2026 survey by Microsoft solutions partner TrustedTech</a> found that 65% of senior decision-makers admit to using unapproved, unsanctioned AI tools at work, more than double the 31% rate among lower-level employees. Three in four employees in that same survey said they understand the security and privacy risks involved. Read that twice. This isn&#8217;t a knowledge gap. It&#8217;s a compliance gap, and it&#8217;s concentrated exactly where the blast radius is largest.</p><p><a href="https://www.teramind.co/news/teramind-research-your-approved-ai-tools-are-the-new-governance-blind-spot/">Teramind&#8217;s 2026 Shadow AI Behavior Report</a> puts a finer point on it: 69% of C-suite leaders prioritize speed over security when using AI, against 37% of frontline staff. And 67% of enterprise AI activity now runs through personal accounts on platforms the company already licenses. Not unvetted tools. Not shadow startups nobody heard of. The same enterprise-grade platform IT paid for, minus every control that made it enterprise-grade in the first place.</p><p><strong>This isn&#8217;t shadow IT. It&#8217;s something worse</strong></p><p>Classic shadow IT is an employee reaching for a tool nobody approved. What TrustedTech and Teramind describe is different, and it&#8217;s harder to defend in front of a board. The tool is approved. The contract is signed. The admin controls, the retention limits, the training opt-out, all of it negotiated and paid for. The executive just isn&#8217;t using any of it, because the personal login is one tab over and nobody&#8217;s checking.</p><p><a href="https://www.helpnetsecurity.com/2026/05/25/trustedtech-workplace-shadow-ai-use-report/">TrustedTech&#8217;s own research team doesn&#8217;t dance around the motive</a>: most <a href="http://kiteworks.com/cybersecurity-risk-management/zero-trust-generative-ai/">shadow AI</a> users aren&#8217;t ignorant of the risk. They&#8217;re deliberately choosing to take it. A meaningful share, 24% of senior decision-makers by TrustedTech&#8217;s count, said they route around approved tools specifically because they worry the company is watching how often they use AI and that it could affect how they&#8217;re perceived. So the honest read isn&#8217;t &#8220;leadership doesn&#8217;t understand AI risk.&#8221; It&#8217;s &#8220;leadership understands the risk, weighed it against looking slow or looking surveilled, and picked convenience.&#8221; That&#8217;s not a training failure. That&#8217;s a decision, made repeatedly, by the people who are supposed to model the opposite.</p><h3><strong>Why the excuse doesn&#8217;t hold anymore</strong></h3><p>For years, the industry let executives off easy with some version of &#8220;they&#8217;re busy, they&#8217;re not technical, cut them slack.&#8221; That excuse dies here. These are the same people asking a board about AI ROI on Thursday and asking IT why the sanctioned tool is &#8220;too slow&#8221; on Friday. They know what a <a href="http://kiteworks.com/cybersecurity-risk-management/data-exfiltration/">data exfiltration</a> headline costs the company, they&#8217;ve probably approved the budget for the <a href="http://kiteworks.com/risk-compliance-glossary/incident-response/">incident response</a> retainer, and they&#8217;re routing regulated content through an account with zero of the contractual protections anyway. This isn&#8217;t a literacy gap in a population that reads breach disclosures for a living. It&#8217;s a rank-has-its-privileges problem, and it&#8217;s compounding as AI-forward pressure from boards and investors gets louder every quarter.</p><h3><strong>The fix isn&#8217;t another policy. It&#8217;s governing the data</strong></h3><p>Every acceptable use policy assumes the reader intends to comply and just needs reminding. That assumption collapsed the moment 65% of the people who wrote the policy admitted to breaking it with open eyes. A document has no enforcement mechanism against someone who has already decided the personal account is worth the risk.</p><p>The only approach that survives contact with this data moves control off the login screen and onto the content itself: every AI request against sensitive data evaluated against classification and policy at the moment it happens, regardless of which account, which device, or which job title is asking. That&#8217;s a different architecture than most AI governance programs have built. It puts per-request <a href="http://kiteworks.com/secure-file-sharing/secure-file-sharing-with-access-control/">access control</a> and <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit logging</a> on the data, enforced through a single-tenant, hardened deployment rather than left to whichever account an executive happens to be logged into that afternoon. It doesn&#8217;t ask the CFO to behave. It doesn&#8217;t care whether the CFO behaves. The content either meets the access rule or it doesn&#8217;t.</p><p>That&#8217;s the uncomfortable design principle here: the control has to work precisely because you cannot count on the person with the most access and the least oversight to opt into being governed.</p><h3><strong>What this means Monday morning</strong></h3><p><span>1. </span>Pull actual usage data comparing sanctioned-account AI activity to total estimated AI usage across your org. If the Teramind ratio holds, two-thirds of your activity is probably happening somewhere your logs can&#8217;t see.</p><p><span>2. </span>Build an executive-specific track for AI governance, separate from the general staff training deck a VP skims and deletes. The population driving this risk isn&#8217;t the population most compliance programs are built to reach.</p><p><span>3. </span>Audit friction on your sanctioned AI tools honestly. If the personal version is faster, that&#8217;s a product complaint hiding inside a compliance violation, and it needs a product fix, not just a policy memo.</p><p><span>4. </span>Move enforcement to the data layer: per-request <a href="http://kiteworks.com/secure-file-sharing/secure-file-sharing-with-access-control/">access control</a> and <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit logging</a> that applies the same way whether the request comes from a governed account, a personal one, or an AI agent acting on someone&#8217;s behalf.</p><p><span>5. </span>Stop presenting <a href="http://kiteworks.com/cybersecurity-risk-management/zero-trust-generative-ai/">shadow AI</a> to the board as an awareness problem. Three in four employees already know the risk. Present it as what it is: an accountability gap at the level with the least accountability pressure on it.</p><p>The people who approved your AI policy are, by the numbers, the people most likely to be routing around it right now, on a platform your company already pays for. Governance that depends on them choosing otherwise has already failed. Build the version that doesn&#8217;t ask.</p>]]></content:encoded></item></channel></rss>