Newsletter Subscribe
Enter your email address below and subscribe to our newsletter

Seventy-nine percent of South African organisations experienced at least three successful identity-related breaches in the last 12 months, driven largely by the explosion of agentic and machine identities. This is according to the Identity Security Landscape Report 2026 by CyberArk, a Palo Alto Networks company, which reveals that the attack surface is expanding faster than businesses can defend it.
Ninety-four percent of businesses have already deployed AI agents, yet governance frameworks are struggling to keep pace. Machine identities vastly outnumber human ones, with a ratio of 92 to 1. All three identity types are expected to grow over the next 12 months. Machine and AI agent identities are expected to see the steepest increases, anticipated by 84% and 82% of respondents, respectively, while 59% expect human identities to follow suit.
Among those already anticipating identity growth, the main factors driving this are machine identities such as IoT and bots (53%), the adoption of more cloud applications (52%), and AI and LLMs (51%). With digital expansion overtaking workforce growth as the primary driver of new identities, security teams are under increasing pressure to extend visibility, control and governance across an ever more complex identity mix.
At the enterprise level, identity threats are now a sustained operational reality, not isolated incidents, with 93% of businesses having experienced an identity-related breach. Security professionals acknowledge that identity complexity is outpacing control. South Africa is among the least prepared for the impending shortening of certificate lifecycles, with 80% not fully automating renewals and monitoring across all certificate environments. These incomplete automation risks are turning operational strain into financial and security exposure, with businesses expecting an average financial impact of approximately $248,051 (R4.1 million) from certificate-related failures.
Cyber insurers are also taking notice: 97% of security leaders say insurance requirements have directly shaped their identity security investment decisions over the past year.
Other key findings from the research include:
The path forward is clear: as machine and AI identities become the primary inhabitants of enterprises, businesses must transition from fragmented, manual oversight to a unified, automated identity security approach. Managing the machine identity to human ratio requires a platform-driven strategy that allows companies to keep pace with innovation while securing every entity, human, machine, or agent.
The research coincides with the launch of Idiraâ„¢ by Palo Alto Networks, a next-generation identity security platform designed to address the governance gaps the data exposes. With 61% of privileged access requests still granted permanently rather than on-demand globally, and machine and AI identities outnumbering humans, the platform aims to eliminate standing privileges and extend dynamic controls across every human, machine and agentic identity.
For those navigating an identity landscape that continues to grow with complexity, a platform-driven approach to identity security is no longer a future consideration. It is the baseline.
//Staff writer