SecurityBrief Australia - Technology news for CISOs & cybersecurity decision-makers
Australia
When AI accelerates the threat, identity governance cannot afford to stand still

When AI accelerates the threat, identity governance cannot afford to stand still

Thu, 13th Aug 2026 (Today)
Takanori Nishiyama
TAKANORI NISHIYAMA Senior Vice President, APAC and Japan Country Manager Keeper Security

In a recent interview with Channel NewsAsia, Singapore's founding Cyber Security Agency Chief David Koh made an argument that every security leader in this region should take seriously: the way organisations have traditionally defended themselves against cyber attacks is no longer fit for purpose. Koh warned that previous approaches to organisation, operation and defence can no longer be effective in an environment where cyber threat actors are increasingly harnessing AI to conduct attacks at greater speed, scale and sophistication. His call for continuous surveillance over conventional annual assessments is a practical starting point, but the structural response the moment demands goes further than monitoring cadence. It goes to the question of identity governance. 

Across the Asia-Pacific (APAC) region, artificial intelligence has fundamentally compressed the timeline of a cyber attack. What once demanded weeks or months of adversarial effort now takes minutes to execute. For security leaders and chief information security officers across the region, this is not a future risk to prepare for, but a present operational reality that demands a structural response.

When Reactive Security Is No Longer Fast Enough

The acceleration of AI-powered attacks against connected infrastructure, operational technology and industrial systems exposes a structural flaw in how most organisations have typically approached security. When a threat actor deploying AI can probe, pivot and exfiltrate data in less time than it takes a human analyst to triage a single alert, reactive security fails by design. Organisations must move from detection-after-the-fact toward continuous, automated enforcement of policy-based access controls, combined with session monitoring capable of identifying and acting upon anomalous behaviour in seconds rather than hours or days.

The expanding attack surface compounds this challenge considerably in APAC, where the integration of Operational Technology (OT) with enterprise IT networks is accelerating across manufacturing, logistics and critical infrastructure. A manufacturing plant sensor, a network camera or an industrial controller each represents a potential entry point when connected to a broader system without consistent identity verification. 

The concept of a zero-trust security architecture addresses this directly. Under the model, no device, user or system receives access by default, regardless of whether it sits inside or outside the network perimeter. Every interaction is verified and access is time-limited and logged. Trust is earned continuously and not assumed permanently. For the manufacturing-heavy economies of Japan, South Korea and Southeast Asia, where the integration of OT and IT is already under way at scale, zero-trust is not a future-state aspiration, but rather, a baseline requirement for operational resilience.

Governing the Invisible

AI agents, APIs, automation scripts and service accounts now operate alongside human users, often with equivalent or greater levels of system access. The majority of organisations, however, do not govern them with the same rigour. Each Non-Human Identity (NHI) carries its own risk profile and compliance obligation. Privileged Access Management (PAM) must extend to cover these entities, assigning each a verifiable identity, enforcing least-privilege access and maintaining a complete audit record of every action taken. Organisations that deploy AI without these controls are not running AI securely. They are running it without supervision, without auditability and without a reliable means of containing the damage when something goes wrong.

The democratisation of AI-powered attacks has dismantled another long-held assumption: that smaller organisations could rely on low visibility as an informal line of defence. AI-assisted phishing and credential attacks are now cheap and easy to execute at scale, which means a regional logistics firm, a mid-tier manufacturer or a community clinic faces the same credential-based exposure as a large enterprise if access controls are inadequately enforced. 

Across APAC, where small and medium-sized enterprises form the backbone of most national economies, this shift in the threat calculus demands a corresponding shift in how security investment is prioritised. Strong credential management, enforced Multi-Factor Authentication (MFA) and least-privilege access policies are not enterprise luxuries. They are the practical baseline for every organisation connected to a network.

Building for Governance

Safe interaction between AI systems, sensitive data and critical infrastructure requires governance to be designed in from the outset, not retrofitted after deployment. AI agents must operate within clearly defined boundaries, including scoped access, time-limited credentials and continuous monitoring. Vault-based secrets management ensures that AI systems retrieve credentials programmatically rather than storing them statically, eliminating a category of risk that is otherwise difficult to detect and contain. Session-level visibility ensures that when an AI agent's behaviour deviates from its defined task profile, that deviation triggers an automated termination of the session before material damage occurs.

Every AI integration is, at its core, a new privileged identity entering a sensitive environment. It must be governed accordingly.

As for Japan, manufacturing was the most targeted sector in 2025, accounting for 28% of ransomware victims and the structure of Japanese manufacturing compounds the risk. Production networks span hundreds of suppliers, many of them are SMEs with limited security budgets, where one weak link can compromise the entire supply chain. The predominant entry point in almost every case is identity-related, such as a compromised vendor credential, an over-privileged service account or a remote access point without MFA. Japanese manufacturers integrating IT and OT environments cannot treat identity governance as a compliance exercise.

The zero-trust security architecture that Koh and other leaders across the region are calling for is well within reach. What is required is the organisational will to treat identity governance with the same urgency the threat environment demands, and to implement zero trust, least privilege and real-time privileged access monitoring as operational standards, not periodic aspirations.