Ignition on AI: Understanding Agentic AI and Staying in Control

August 11, 2026

The Unseen Workforce: Why Identity Governance Must Keep Pace with AI 

Posted by Ignition Technology

August 20, 2026

The Unseen Workforce: Why Identity Governance Must Keep Pace with AI 

During Infosec Europe 2026, Ignition Technology joined cybersecurity leaders from across the industry for an exclusive executive lunch hosted by our vendor partner, Sendmarc. Moderated by Sendmarc Chief Operations Officer Kieran Frost, the discussion centred on one of the biggest cybersecurity questions facing organisations today: What happens to email security when bad actors get access to the latest AI models? 

While the debate focused on email security, phishing and business email compromise, a broader theme quickly emerged. AI isn’t creating entirely new threats, it’s accelerating existing ones. At the same time, organisations are managing a growing number of human identities, machine identities and AI agents, creating new governance challenges and expanding the attack surface. 

Representing Ignition Technology on the panel was our CSO, Sean Remnant, who joined fellow industry leaders including Mike Britton, Chief Information Officer at our vendor partner Abnormal AI; Andy Bates, Co-Founder of StonesThroDoug Pecarski, Chief Executive Officer at Simply Discover; and Mark Overton, Chief Information Security Officer at Softcat. 

The panel of experts examined how AI is transforming the threat landscape, enabling attackers to launch more sophisticated phishing, impersonation and business email compromise campaigns at greater scale. It also explored the limitations of legacy security stacks and the growing risks facing organisations that have yet to modernise their defences. 

The attacks haven’t changed as much as you think 

One of the most striking themes from the discussion was that the shape of cyber-attacks remains surprisingly familiar. 

Business Email Compromise (BEC), phishing, supply chain attacks and credential abuse are still dominating the threat landscape. The difference is that AI has dramatically reduced the effort required to execute them at greater speed, scale and sophistication. As several panellists observed, attackers no longer need specialist skills, significant budgets, or large teams to create convincing, highly personalised campaigns. 

As Mike Britton, CIO at Abnormal AI, noted: “Now the financially motivated criminals are operating at nation-state levels, now the script kiddies are operating at the financial crime syndicate level.” 

Instead of sending one generic phishing email to thousands of employees, attackers can now generate thousands of personalised messages targeting thousands of individuals simultaneously. The attack techniques are familiar; the scale and speed are not. For organisations, this raises a critical question: where should security teams focus their efforts to stay ahead? 

Identity has become the security perimeter 

If AI is increasing the scale and speed of attacks, the obvious question is where should organisations focus their defences? Throughout the session, Sean returned to a simple but important principle: organisations must focus on reducing their attack surface and getting the basics right before adding further complexity. 

(Sean Remant, Ignition Technology) 

He shared a poignant point around this, “The first thing is understanding their attack surface and their assets. There’s so many organisations that have no idea of what they’ve got.” In an era of cloud adoption, sprawling identities and growing numbers of AI agents, organisations cannot secure what they cannot see. 

Identity is increasingly at the centre of this challenge. Organisations are no longer managing access for employees alone; they are also governing access for applications, service accounts, cloud workloads and AI agents. Each new identity creates another potential pathway to critical systems and data, making visibility, access control and governance more important than ever. 

While AI implementation is dominating boardroom discussions, many organisations are still lacking fundamental security disciplines. Visibility gaps, poorly managed identities, legacy access controls and sprawling cloud estates continue to create vulnerabilities that can be exploited by attackers. 

The answer is not simply to deploy more security tools, but to strengthen the fundamentals. With attackers leveraging AI to discover and exploit security gaps faster than ever, organisations need greater visibility of their assets, stronger identity governance and the ability to respond at speed and scale. As AI models become more powerful, cyber resilience starts with knowing who, and what has access to your environment. 

Why identity governance must keep pace 

Perhaps the most important takeaway from the event is that we are no longer preparing for an AI-driven future. We are already operating in one. 

AI assistants, autonomous agents and machine identities are becoming embedded across every successful enterprise. As these digital workers take on more responsibility, organisations must move faster to understand their assets, reduce their attack surface and strengthen identity governance. 

With both defenders and attackers having access to the same powerful technologies, competitive advantage won’t come from deploying more tools or agents, but from establishing permissions and privilege and accountability at scale. As AI reshapes the workforce, identity is no longer just a security consideration, it has become the defining security challenge of our time. 

Related posts