SEC536: Adversarial AI - Penetration Testing AI Systems


55% of organizations experienced at least one identity-related compromise in the past 12 months, even though 85% report active use of ITDR tools, according to the 2026 SANS State of Identity Threats and Defenses survey.
68% of organizations detect identity attacks within 24 hours, but only 55% contain them in that same window. That gap gives attackers time to escalate privileges before the SOC can intervene.
Only 8% of organizations rotate more than 75% of their non-human identity (NHI) credentials every 90 days, and 59% rotate fewer than half quarterly, leaving most service account keys and API tokens static for months or years.
Credential phishing accounts for 35% of identity attacks, followed by compromised browsers (27%), MFA fatigue (26%), and session token hijacking (23%), according to the survey.
73% of organizations use agentic AI or automations that require credentials, but no single governance control, such as approvals, audit trails, or sandboxing, is used by more than 40% of organizations.