Commvault has announced findings from research that identifies a gap between the rapid pace of AI adoption and the identity management capabilities needed to support it.
The findings are published in an IDC White Paper, ‘Resilience Operations: The Discipline That Makes Readiness Provable’, sponsored by Commvault.
IDC surveyed senior IT and C-level respondents representing 539 North American organizations. Of those organizations, 84.5% had experienced a cyber attack within the previous 12 months. The research found that 90.3% of respondents believed their organizations needed to improve identity management practices to address risks introduced by agentic AI systems.
Identity management is defined in the white paper as the discipline of controlling and governing digital identities, including human and agent identities, and their access to systems and data throughout their lifecycle – from creation to decommissioning.
As organizations deploy AI agents at scale, the number of non-human identities may rapidly exceed the number of human identities. Many AI agents have persistent access and can be multiplied on demand. Almost three-fifths of respondents (58.7%) report that their identity management capabilities require significant improvements or a complete overhaul.
The research also found that:
- 26.7% of respondents report that their organizations have dynamic role-based access control (RBAC) supporting AI and analytics.
- 24.7% place their Active Directory and Entra ID protection capabilities at the ‘documented and tested’ stage.
- Almost all respondents (98.4%) expressed the need for better collaboration among teams responsible for IT security. Additionally, 49.7% said major improvements were needed.
“AI is fundamentally changing how organizations operate, make decisions, and manage risk,” said Vidya Shankaran, Field CTO at Commvault. “But many organizations are discovering that the systems designed to govern people are not prepared to govern a growing population of AI agents, machine identities, and autonomous workflows. Identity is a critical Tier 0 application and has a pivotal role to play in an organization’s confidence in a clean recovery.”
Minimum viable business definition remains incomplete
The research also points to a broader resilience challenge. More than half of the organizations surveyed (57.7%) have not fully defined their minimum viable business (MVB). At the same time, many continue to face gaps in recovery orchestration, cleanroom capabilities, and cyber resilience readiness.
The white paper presents resilience operations (ResOps) as an emerging operational discipline that continuously brings together business, security, infrastructure, data protection, and recovery teams around a common objective: maintaining business operations and accelerating recovery following disruption.
“IDC predicts that ResOps will mature from an emerging discipline into a mainstream enterprise capability over the next three to five years,” said Frank Dickson, Group Vice President for IDC’s Security and Trust research practice. “Organizations that build the governance structures, technical capabilities, and testing disciplines now, before the next major incident, will be better positioned to absorb disruption, protect their customers, and sustain competitive operations in an increasingly hostile threat environment.”






