2 Sources
[1]
90% of IT Leaders See Identity Management as Critical for Secure Agentic AI Deployment: Commvault-IDC Study
"AI is fundamentally changing how organizations operate, make decisions, and manage risk," said Vidya Shankaran, Field CTO, Commvault. "But many organizations are discovering that the systems designed to govern people are not prepared to govern a growing population of AI agents, machine identities, and autonomous workflows. Identity is a critical Tier 0 application and has a pivotal role to play in an organization's confidence in a clean recovery." The research also points to a broader resilience challenge. More than half of respondents (57.7%) have not fully defined their minimum viable business -- the critical systems, processes, and functions required to continue serving customers during a disruption. At the same time, many continue to face gaps in recovery orchestration, cleanroom capabilities, and cyber-resilience readiness. To address these challenges, there is a growing need for Resilience Operations (ResOps), an emerging operational discipline that continuously brings together business, security, infrastructure, data protection, and recovery teams around a common objective: maintaining business operations and accelerating recovery in the face of disruption. "IDC predicts that ResOps will mature from an emerging discipline into a mainstream enterprise capability over the next three to five years," said Frank Dickson, Group Vice President for IDC's Security & Trust research practice. "Organizations that build the governance structures, technical capabilities, and testing disciplines now, before the next major incident, will be better positioned to absorb disruption, protect their customers, and sustain competitive operations in an increasingly hostile threat environment."
[2]
Identity Management Emerges as Top Bottleneck for Agentic AI, Executive Survey Finds
Commvault today announced findings from the IDC White Paper, Resilience Operations: The Discipline that Makes Readiness Provable, July 2026, sponsored by Commvault, that reveal a gap between the rapid pace of AI adoption and the identity resilience capabilities needed to support it. In tandem, the company also announced the IDC Cyber Readiness Assessment, sponsored by Commvault, an interactive tool that organizations can use to evaluate resilience preparedness for an AI-driven future. The research was conducted among 539 IT and resilience decision makers in North America, of which approximately 85% have experienced a cyber incident. It found that 90% of respondents believe they need to improve identity-management capabilities to address risks introduced by agentic AI systems. Identity management is a discipline of controlling and governing digital identities, including both human and agent identities, and their access to systems and data across their lifecycle - from creation to decommissioning. As more organizations deploy agents in volume, the rise in non-human identities - many of which have always-on access and can multiply on demand - may rapidly outnumber human identities. Nearly two-thirds of respondents (58.7%) say significant improvements or a complete overhaul of their identity-management approach is required. The research also found that: * Only 26.7% have implemented dynamic role-based identity access controls designed to support AI and analytics. * Only a quarter of respondents (24.7%) have documented and tested their ability to protect, detect compromise of, and recover Active Directory and Entra ID environments. * Nearly all respondents (98.4%) believe collaboration between IT and security teams needs improvement. Half (49.7%) say major improvements are needed. "AI is fundamentally changing how organizations operate, make decisions, and manage risk," said Vidya Shankaran, Field CTO, Commvault. "But many organizations are discovering that the systems designed to govern people are not prepared to govern a growing population of AI agents, machine identities, and autonomous workflows. Identity is a critical Tier 0 application and has a pivotal role to play in an organization's confidence in a clean recovery." Minimum Viability Awareness is Lacking The research also points to a broader resilience challenge. More than half of respondents (57.7%) have not fully defined their minimum viable business -- the critical systems, processes, and functions required to continue serving customers during a disruption. At the same time, many continue to face gaps in recovery orchestration, cleanroom capabilities, and cyber-resilience readiness. To address these challenges, there is a growing need for Resilience Operations (ResOps), an emerging operational discipline that continuously brings together business, security, infrastructure, data protection, and recovery teams around a common objective: maintaining business operations and accelerating recovery in the face of disruption. "IDC predicts that ResOps will mature from an emerging discipline into a mainstream enterprise capability over the next three to five years," said Frank Dickson, Group Vice President for IDC's Security & Trust research practice. "Organizations that build the governance structures, technical capabilities, and testing disciplines now, before the next major incident, will be better positioned to absorb disruption, protect their customers, and sustain competitive operations in an increasingly hostile threat environment." Putting Readiness to the Test To help businesses better understand their current preparedness state, IDC's Cyber Readiness Assessment, sponsored by Commvault, will enable organizations to evaluate their cyber resilience maturity and identify areas where identity, protection, detection, response, and recovery capabilities may require improvement. The assessment is based on the same maturity framework developed through the research and provides participants with a personalized readiness profile.
Share
Copy Link
A Commvault-IDC study reveals that 90% of IT and resilience decision-makers believe identity management capabilities must improve to address risks from agentic AI systems. With non-human identities set to outnumber humans, nearly two-thirds say significant overhauls are required, while only 26.7% have implemented dynamic role-based identity access controls designed for AI.
Identity management has emerged as the critical challenge facing organizations deploying agentic AI systems, according to new research from Commvault and IDC. The Commvault-IDC study surveyed 539 IT and resilience decision-makers across North America and found that 90% believe they need to improve identity management capabilities to address risks introduced by agentic AI
1
2
. Approximately 85% of survey participants have already experienced a cyber incident, underscoring the urgency of this challenge.
Source: DT
The research highlights a fundamental mismatch between systems designed to govern people and the requirements for governing AI agents, machine identities, and autonomous workflows. Nearly two-thirds of respondents—58.7%—indicate that significant improvements or a complete overhaul of their identity management approach is required to support secure agentic AI deployment
2
. As organizations deploy agents in volume, non-human identities with always-on access capabilities that can multiply on demand may rapidly outnumber human identities.The study reveals alarming gaps in infrastructure readiness for governing AI agents. Only 26.7% of organizations have implemented dynamic role-based identity access controls designed to support AI and analytics
2
. Even more concerning, just 24.7% have documented and tested their ability to protect, detect compromise of, and recover Active Directory and Entra ID environments—critical identity infrastructure that serves as a Tier 0 application2
."AI is fundamentally changing how organizations operate, make decisions, and manage risk," said Vidya Shankaran, Field CTO at Commvault. "But many organizations are discovering that the systems designed to govern people are not prepared to govern a growing population of AI agents, machine identities, and autonomous workflows. Identity is a critical Tier 0 application and has a pivotal role to play in an organization's confidence in a clean recovery"
1
.To address these challenges, the research points to the growing need for Resilience Operations (ResOps), an emerging operational discipline that brings together business, security, infrastructure, data protection, and disruption recovery teams around maintaining business continuity during incidents
1
. More than half of respondents—57.7%—have not fully defined their minimum viable business, the critical systems and processes required to continue serving customers during a disruption2
.Frank Dickson, Group Vice President for IDC's Security & Trust research practice, predicts that Resilience Operations (ResOps) will mature from an emerging discipline into a mainstream enterprise capability over the next three to five years. "Organizations that build the governance structures, technical capabilities, and testing disciplines now, before the next major incident, will be better positioned to absorb disruption, protect their customers, and sustain competitive operations in an increasingly hostile threat environment," Dickson stated
1
.Related Stories
The research also uncovered significant collaboration challenges, with nearly all respondents—98.4%—believing that collaboration between IT and security teams needs improvement. Half of those surveyed, 49.7%, say major improvements are needed
2
. To help organizations evaluate their preparedness, IDC has launched a Cyber Readiness Assessment, sponsored by Commvault, enabling businesses to assess their cyber resilience maturity and identify areas where identity, protection, detection, response, and recovery capabilities require improvement2
.Summarized by
Navi
16 Jul 2026•Technology

02 May 2026•Technology

15 Oct 2025•Technology

1
Technology

2
Policy and Regulation

3
Science and Research
