Non-human identity management is difficult because we are dealing with identities that never sign in in the way humans do. Rather we are dealing with entities that include service accounts, API keys, workload tokens, SaaS app grants, and, of course, AI agents, all of which exist in the chaos of machine-to-machine sprawl. 

These non-human identities outnumber human identities by 25x to 50x in modern enterprises according to the NHI Management Group. They have suddenly come into mainstream focus with the rise of agentic AI. While enterprises want to let workforces run these agents and give them access to systems, how are they to be managed without compromising enterprise security?

Adding to Cisco’s IAM capability

According to Cisco’s VP of Product, Identity, Matt Caulfield, when it comes to agentic AI: 

You need to be in the agent’s path, between the things that it is talking to and the operating system in order to understand its identity. “Of course, it just so happens that Cisco’s core strength is being in the path because it is running the network, and this, for Cisco is where it makes most sense to enforce identity and access for NHI rather than just at endpoints as we typically do for humans.

In order to enforce access rights for non-humans, understanding context becomes critical as it defines operational purpose, maps complex infrastructure dependencies and clarifies risk exposure, which helps enterprises to rapidly develop plans to mitigate any attacks. Cisco has made a number of targeted acquisitions to help it understand agentic identity. Firstly, there is Splunk which provides observability that becomes especially important in tracking the non-deterministic decisions that agents are making. 

In May Cisco snapped up Galileo Technologies which helps to prevent behavioural drift by monitoring for unexpected changes in behaviour. Its capabilities merge into Splunk’s AI Agent Monitoring to track things such as model hallucinations, bias, security risks and cost metrics. Galileo enables the building and running of small language models and then their evals can be turned into one-time guardrails.

Most recently Astrix Security is now in process of being acquired by Cisco and will be added to Cisco Identity Intelligence, Duo and Secure Access. 

Speaking at a recent Cisco analyst briefing Jony Blatt VP Product at Astrix Security, explained that: 

The idea behind the company was to provide a platform that could identify every agent, both those that an organisation onboards and those shadow agents that employees bring in. The platform provides the ability to see inside the agent and understand it, as well as the ability to find the human being with whom each agent is associated.” This enables security-oriented processes to be applied according to the organizational security policy.

Caulfield explains that with this combination of acquisitions Cisco will provide the ability to secure all agents irrespective of their provenance, creating a zero-trust posture for agents.

Pulling the pieces together in Cisco Cloud Control

These IAM capabilities are all being brought together in Cisco Cloud Control and can be integrated across multiple Cisco products to control how agents get to different apps. Using Agent Builder in Cisco Cloud Control Studio, Codex guardrails can be attached to block and allow behaviours, enforcing security policy centrally and controlling agentic actions. Agents onboarded by organizations can be registered with end-users to increase organisational accountability by applying the end-user trust level to agents registered to them. If ownership of the agent is ambiguous then Astrix Security uses agent logic to ask suggested platform provenance or by analysing agent behaviour which can often reveal its likely creator.

While this approach works effectively to manage specialized agents, Caulfield cautions that:

General purpose agents are harder to secure beyond putting guardrails in place because of their breadth of coverage and behavioral span.

The ability to be able to trust agents is particularly important to Cisco because its flagship software product Cisco Cloud Control relies on cross-domain telemetry, purpose-built models and trusted agents. These agents all have to be grounded, governed and action-ready to be reliable and effective.

Anurag Dhingra SVP and GM of Cisco’s Enterprise Connectivity and Collaboration Group told analysts that:

AI is causing a networking supercycle. We had the architecture for the AI-ready secure network last year, but now AgenticOps and understanding how to scale AI safely is getting very real for customers.

When questioned on enterprise deployment of agents, he replied; 

We are very, very early. Every employee is not yet using teams of agents. But a service provider with a network traffic agent generates 450% more total traffic per task when performed by an agent because the agent is very chatty communicating between the cloud (its brain) and the local machine (its hands).

The implication is that the increased network traffic will come, but until theN: 

The security implications are top of mind for customers, they need to be able to secure agents regardless of how network traffic increases.

My take

Cisco is confidently placing two bets by investing in its AI-ready network architecture: the first relies on rising non-human, agentic traffic and that may take a few years to become significant in volume, which brings us to the second bet – the need to secure agents. After all, without security and trust in place, increased agentic AI adoption will not occur to generate the network traffic growth Cisco is anticipating. 

This is why Cisco increasingly talks about network and security in the same breath and also why Brink Sanders has just expanded his role to from Cisco’s SVP, Networking Sales to become Cisco’s SVP Security and Networking Sales. Cisco’s fusion of security and networking is a smart move that will resonate with regulated sectors such as financial services and healthcare, as well as with manufacturing industries still searching for an assurance mechanism to underpin both their IT and OT environments.