News Security Technology

Cybersecurity Warning For Indian Firms As Machine Identities Outpace Humans

As AI reshapes enterprises, experts warn that India’s cybersecurity priorities must shift from operational speed to strategic identity protection before breaches escalate further

A recent Identity Security Landscape Report 2025 by cybersecurity giant CyberArk has sounded the alarm: Indian organisations now have 82 machine identities for every human identity, but many are dangerously under-secured. Even more worrying, 77 per cent of businesses admitted prioritising operational speed and AI adoption over critical cybersecurity measures.

According to the report, 42 per cent of machine identities in India have privileged or sensitive access but remain unsecured. Meanwhile, 68 per cent of companies lack any identity security frameworks for their AI systems, making them vulnerable to increasingly sophisticated cyberattacks.

Fragmented Identities Create New Risks

The rising risk is not only about numbers — it is about visibility. 68 per cent of Indian firms report fragmented identity management, with different teams creating machine credentials ad hoc without centralised oversight. This has opened invisible vulnerabilities across enterprises, allowing credentials to sprawl unchecked.

Commenting on this trend, Neehar Pathare, MD, CEO and CIO, 63SATS Cybertech, said that identities—human and machine—have become the new perimeter and they are under siege from phishing, credential theft, and lateral movement attacks. He added that India, with its booming digital adoption and rapid AI integration, is uniquely vulnerable. Pathare explained that machine credentials, privileged accounts, and service integrations often reside outside centralised identity providers, created ad hoc by teams unaware of security best practices.

Machine Identities The New Threat Frontier

Sunil Peter, Vice President – Global IT at Maveric Systems, said the rapid rise of machine identities poses serious security risks when efficiency is prioritised over protection. He noted that these identities often hold privileged access yet remain poorly managed, making them prime targets for attackers. With AI systems controlling critical business functions, the cost of a breach is no longer limited to data theft — it now extends to operational sabotage and systemic disruption. Peter added that fragmented management of these identities fuels compliance failures and privilege sprawl, with 70 per cent of organisations admitting gaps in visibility.

Cybersecurity Must Move From Cost Centre To Growth Strategy

Despite these alarming signals, many businesses still treat cybersecurity as an afterthought rather than a strategic investment.

Kushal Rastogi, Founder and CEO, Knight Fintech, said many institutions still see cybersecurity as a cost centre rather than a core enabler of trust. He observed that security is not just about firewalls; it is about systemic resilience — real-time monitoring, data integrity, and seamless interoperability. According to Rastogi, new-age fintechs have embedded security by design, ensuring that as digital adoption scales, so does protection. He believes that future-ready banks will be those that treat security as a strategy, not merely insurance.

AI And Identity Silos Are Accelerating Risk
The situation is compounded by AI’s rapid integration into business operations. AI agents are now poised to create the highest number of new privileged identities in 2025, the report warns.

Manish Kumar Goyal, Chairman and Managing Director, Finkeda, pointed out that the AI boom, while boosting operational efficiency, is simultaneously inflating organisations’ cyber debt. He said the hype of AI adoption and digital transformation programmes has grown the identity attack surface. This cyber debt has exposed organisations to advanced threats like AI-based malware and phishing attacks. Goyal called for companies to integrate cybersecurity directly into their business strategies, noting that strong IAM (identity and access management) and AI-driven security tools are no longer optional but essential for sustainable growth.

Data Protection Rules Could Force Security Mindset Shift

There may be regulatory pressure soon that accelerates this shift. India’s new Digital Personal Data Protection (DPDP) rules are pushing businesses to rethink their attitudes towards cybersecurity.

Shankar Iyer, Director – Business Strategy, Infobip, said businesses have an opportunity to differentiate themselves by adopting privacy-first practices. He explained that those that treat security as a strategic advantage, rather than a compliance checkbox, will lead with confidence. Iyer stressed that as data becomes the new gold, companies that safeguard personal data effectively will build lasting customer loyalty and brand credibility.

Why Modernising Infrastructure Matters More Than Ever
It is not just about new policies; there is a deeper technical need for transformation. Pathare noted that the fragmented and outdated infrastructure supporting identities today has created massive unseen risks.

He said that many Indian banks still use outdated encryption like AES-128 or lower, and many digital experiences are built on deprecated web frameworks and legacy certificate pinning methods. He observed that while the world has moved to password-less logins and secure identity layers, banks in India are still dependent on OTPs and old net banking passwords. Pathare warned that real safety in digital finance is architectural, not cosmetic, and that domain suffixes alone will not fix fraud. Instead, modernising infrastructure must become the priority.

Unless Indian enterprises modernise their identity security strategies urgently, they risk trading short-term efficiency gains for long-term vulnerability — and in a rapidly digitising economy, that is a gamble few can afford.

-Satyam Mishra

Leave a Reply

Your email address will not be published. Required fields are marked *