From Counties to Campuses, the Next AI Crisis May Begin With a Trusted Identity

By Lou Karu, Area Vice President, U.S. SLED, at Rubrik [ Join Cybersecurity Insiders ]
18

As AI agents gain access to sensitive systems and data, security leaders face a growing challenge: protecting digital identities that can make decisions and act at machine speed.

During Rubrik’s AI + Identity Resilience Summit, cybersecurity leaders from government, higher education, financial services, and technology discussed how organizations can maintain operations when identities are compromised. 

The threats are immediate, and the consequences are severe. Compromised credentials allow attackers to easily impersonate real users, hijack active sessions, and operate without triggering conventional security controls.

Dr. Elizabeth Di Bene, Chief Information Security Officer for Loudoun County, Virginia, warned that quiet dashboards should not automatically provide reassurance. “When dashboards are completely green and quiet, I like to say that’s when you should be most paranoid,” said Dr. Di Bene. “I don’t look for failure alerts. I look for anomalous context, which means behavioral baseline. It also means we assume compromise.” 

Recovery should come before governance

Identity resilience begins with a practical question: Can an organization continue operating after an account or identity system is compromised?

For Dr. Di Bene, recovery provides the foundation for broader identity governance.

“Governance without recovery is an illusion,” said Dr. Di Bene. “If your underlying directory gets corrupted or hit by ransomware, your access roles and vaults have gone away anyway.”

The point challenges a common security narrative. Organizations often focus first on access controls, privileged access management, and identity governance. Those controls remain important, but they cannot restore a trusted identity system after an attack.

Recovery requires more than maintaining backups. After an identity attack, organizations shouldn’t have to choose between restoring a clean state and keeping legitimate changes made since the attack.

The approach should start from a verified clean point, identify what changed afterward, and use identity context to distinguish legitimate changes from malicious ones. The goal is to restore a state that is both clean and current, without bringing attacker persistence back or discarding valid updates.

Recovery should preserve the changes an organization needs while leaving the attacker’s changes behind.

AI agents create a new identity population

Higher education institutions manage vast amounts of data across students, faculty, employees, alumni, and people who hold several roles at once. AI agents add another layer of complexity.

Dana Kilcrease, Chief Information Security Officer at Berkeley College, said organizations should govern an agent’s authority, not just its credentials.

“An AI agent isn’t just another service account,” said Kilcrease. “A traditional service account is going to perform a predictable task, where an agent can then interpret an objective, choose its own tools, and take action. We really have to govern its authority, not only with the credentials.” 

He added that every agent should have a defined human owner, a purpose, limited access, visibility into its activity, and an expiration or review date.

“If nobody can explain why [an AI agent] still exists, it shouldn’t retain access,” said Kilcrease.

The principle offers a clear starting point for organizations that may not yet have mature AI governance programs. Registration, approval, monitoring, and decommissioning protocols can establish accountability before the number of nonhuman identities becomes unmanageable.

Build the recovery safety net before scaling AI 

Identity resilience should become an operational discipline. Organizations that repeatedly test how they will contain compromised identities, quickly restore trusted access, and continue essential services will improve preparedness as new attacks and rogue agents move at AI speed.

AI may accelerate operations, but if not managed properly, it can also magnify technical debt, weak controls, and broken processes. 

To address this challenge, organizations should establish a reliable recovery foundation before expanding AI adoption or overhauling legacy systems.

“Secure your safety net before you touch the highwire,” said Dr. Di Bene. “Establish a recovery baseline on day one so that, as you clean up your legacy systems, you enforce tighter controls, you tackle complex AI identities, and you’re doing so from a position of absolute resilience.”

The views expressed in this article are those of the author and do not necessarily reflect the official policy or position of Rubrik. These views are for informational purposes only and do not constitute business or legal advice. Organizations should consult with legal and compliance professionals to ensure their cybersecurity strategies meet all applicable federal, state, and international requirements.

_______

About Louise Karu 

Louise Karu leads Rubrik’s state, local government and education business across the United States, bringing over 15 years of experience helping public sector organizations transform and safeguard their mission-critical data. With a passion for delivering cyber resilience and data security, Louise has supported state and municipal agencies as they modernize infrastructure and adopt cloud services. 

Join our LinkedIn group Information Security Community!

No posts to display