As organizations adopt AI agents and expand their digital environments, the identity landscape is becoming increasingly difficult to secure. Human users are no longer the only identities that need protection—service accounts, tokens, certificates, AI agents, and sub-agents are creating a rapidly expanding attack surface.
In this episode of CyberTech Edition, Tal Marom, CPO & Co-Founder of Oak, examines how the rise of non-human and agentic identities is changing the way organizations need to think about cybersecurity.
Marom argues that identity should be treated as a critical security asset, particularly as attackers increasingly rely on compromised credentials and legitimate identities to gain access and move through organizations. He highlights service accounts as a frequently overlooked weakness and explains why organizations need greater visibility into not only what identities exist, but also who owns them, how they are being used, and which identities can invoke others.
The discussion also explores the limitations of traditional identity security approaches built around static directories and standing privileges. Marom outlines a shift toward least-privilege, just-in-time and context-based access, alongside the need to revoke active sessions and tokens when identities no longer require access.
At the center of this approach is a continuously updated identity graph that can help organizations understand relationships between human and non-human identities and identify potential weak points across the environment.
As AI agents become more autonomous and increasingly embedded in enterprise workflows, the conversation highlights a broader challenge for security teams: understanding and controlling an identity ecosystem that is no longer limited to people.
Marom also shares his perspective on the future of cybersecurity, the growing role of agentic AI, and the need to rethink siloed approaches to identity management.
