Access Management
,
Agentic AI
,
Artificial Intelligence & Machine Learning
CISOs Grapple With AI Blind Spots, Excessive Permissions and Governance Issues
Machine identities continue to multiply as organizations push automation, cloud services and artificial intelligence-driven initiatives deeper into core operations. This rapid growth creates new vulnerabilities, especially when non-human identities carry excessive permissions, lack clear ownership or are completely invisible to security teams.
See Also: Securing Patient Data: Shared Responsibility in Action
“I think it is definitely a challenge with organizations because we are all focused on automation, maybe cloud adoption, AI initiatives, and so when that happens, the number of machine identities is just going to grow exponentially,” said Erin Rogers, senior vice president and director of cyber security risk and compliance at BOK Financial.
Security organizations should invest in adaptive, risk-based identity and access management tools, Rogers said.
“Continuous session evaluation and real-time authentication decisions help limit lateral movement by attackers who rely on stolen credentials, while allowing teams to respond dynamically when behavior or context changes,” she said.
In this video interview with Information Security Media Group, Rogers also discussed:
- Discovering and inventorying machine identities across cloud and on-premises environments;
- Reducing risk through just-in-time access and stronger governance for non-human identities;
- Prioritizing adaptive, risk-based IAM controls to counter credential-based attacks.
Rogers leads the security risk management and IAM programs in information security at BOK Financial, providing strategic direction and guidance to both. She was previously responsible for establishing the information security metrics program, creating an information security risk and control library, coordinating all information security-related interactions with internal and external regulators, and assisting with multiple governance and risk initiatives.

