ARKION
Field Notes/Field Note No. 12
Field Note · Research

Nobody Has
Counted the
Machines.

A sponsored piece in Cybersecurity Dive argues that identity is the new perimeter and that non-human identities have outrun our ability to see them. It is right. So we followed its numbers to their sources, and then held our own number to the same standard. What we found is not an argument against the thesis. It is the strongest evidence for it.

Published
September 21, 2026
Category
Research
Read Time
9 min
Reference
FN-12-2026

Everyone in this category quotes a ratio. Machine identities outnumber humans by fifty to one, or eighty to one, or ten to one, depending on whose slide you are looking at. We use one of those numbers ourselves. This note is what happened when we stopped repeating the ratio and started clicking the links behind it, including our own.

The Article, Fairly Stated

The piece is “Identity is the new perimeter as rapid NHI proliferation threatens visibility and control”, published in Cybersecurity Dive in May 2026. It is sponsored content, paid for by SHI, a large IT solutions provider and integrator. That is worth saying at the top, because it shapes the conclusion: the piece ends by recommending that you find a partner who can design and operate an identity fabric across your environment. SHI is such a partner.

Disclosing the sponsorship is not the same as dismissing the piece. The argument is sound, the examples are real, and it contains one admission more honest than most unsponsored writing in this category: no vendor yet offers a single, holistic solution that can enforce best practice-based governance across an organization’s entire non-human identity ecosystem. We think that is true. We will come back to it, because we are not claiming to be the exception either.

Brad Bowers, SHI’s global field CISO, is quoted saying that ephemeral identities and those attached to AI agents are directly expanding the attack surface, and that organizations will move to buy tools that show them how these identities are being used, what access they hold, and whether they have been tampered with. That is a fair description of where the market is heading. The rest of this note is about the half of the problem that buying visibility does not solve.

We Followed the Numbers

The article opens on scale, as these pieces do. Three figures carry the argument. We fetched the source behind each one.

Fifty to one

The article states that machine identities may outnumber humans by fifty to one in a large organization, and links to a Silverfort report. The report does say fifty to one. It says it as an estimate: we estimate that NHIs now outnumber human users 50 to 1, carried with no citation and no footnote anywhere in the document. The only figure the report presents as something it actually measured is a range, one human to between thirty and fifty non-human identities, in hybrid environments. The survey underneath it was fielded in mid-2023. The phrase “large organization” is the article’s, not the report’s.

Ten times, by 2020

The article states that by 2020 the average company had ten times more non-human identities than human ones, and links to the Cloud Security Alliance’s State of Non-Human Identity and AI Security report. That report is real and useful, and it does not contain this figure. It states no machine-to-human ratio at all. The ten-to-one number does appear, uncited, in the Silverfort document, as its 2020 baseline.

Forty percent, and thirty-two percent

The article’s most quotable pair: forty percent of organizations had a non-human identity incident in the past year, and thirty-two percent could not tell whether they had. It links to a news write-up, which links to nothing. The research is Keeper Security’s, a vendor, released at the RSA Conference in April 2026. The sample is one hundred and nine people, surveyed on the conference floor. Keeper’s own infographic puts the first number at forty-one percent and does not carry the thirty-two percent figure at all. The source says respondents. The article says organizations.

None of this makes the article dishonest. This is ordinary practice in our category, and we have almost certainly done softer versions of it ourselves. Numbers get picked up from the piece above them in the chain, the hedge falls away at each hop, and an estimate becomes a finding by the third citation.

Our Own Number, Same Standard

It would be cheap to audit someone else’s ratio and not our own. Arkion publishes eighty to one. Here is where it comes from and what it is worth.

The figure is CyberArk’s. Its 2025 Identity Security Landscape reported that machine identities outnumber humans by more than eighty to one. That study surveyed two thousand six hundred cybersecurity decision makers at organizations of five hundred employees and above. Note what that is: a survey of what security leaders believe about their estates. It is a good survey. It is not a census. Nobody walked the environments and counted.

Two corrections came out of writing this note. The first is ours. Our internal documentation attributed eighty to one to “Cloudflare / CyberArk, 2026”. Cloudflare publishes ratios about bot traffic, not about machine identities per employee, and the figure is from 2025, not 2026. We had carried a joint attribution that the second name does not support. We corrected our canonical source table while writing this paragraph.

The second correction is the number itself, or rather what has happened to it. The successor to that study, published in 2026 under Palo Alto Networks, which now owns CyberArk, reports the ratio at one hundred and nine to one, from two thousand nine hundred and thirty cybersecurity leaders. One research series, one year apart, eighty to one hundred and nine. We continue to publish eighty to one, because that is the figure in our locked source table and we do not move a number without reason. But a reader deserves to know that the most recent reading from the same series is a third higher.

What We Changed While Writing This
Our source table now reads CyberArk Identity Security Landscape, 2025, not Cloudflare / CyberArk 2026, with a note that the 2026 successor reports one hundred and nine to one. If you have an Arkion deck or page that credits Cloudflare for this figure, it predates this note and it is wrong. We would rather correct it in public than quietly.

The Disagreement Is the Finding

Lay the numbers next to each other. Ten to one. Thirty to fifty. Fifty to one. More than eighty to one. One hundred and nine to one. These are not competing measurements of the same object. They are estimates, produced by asking people, of a population that no organization maintains a register for.

Compare that with the human side of the same building. Nobody publishes duelling estimates of how many employees a company has, because headcount is knowable. Every person is hired through one process, issued an identity by one system, owned by one manager, and removed through one workflow. The number is not an estimate because the population is governed.

The ratio is not a fact about machines. It is a fact about counting. Every published figure is an estimate of a population nobody owns.

Which is why the visibility argument, correct as far as it goes, stops short. Discovery tools will tell you what exists in an environment on the day they run. They will not tell you who asked for it, who is accountable for it, what it was created to do, or what should happen to it when the person behind it leaves. An inventory is a photograph. It is not a register.

Thirty-Two Percent Is Not a Detection Problem

Set aside how small that sample was, because the shape of the finding survives the methodology. Some meaningful share of security leaders cannot say whether they have had an incident involving a machine credential. That is worth sitting with, because it is not a failure of monitoring. It is a failure of attribution.

To answer “no, we were not breached through a machine identity”, every machine identity has to resolve to something you can audit: an owner, a purpose, a scope, a lifetime. When a credential has none of those, the honest answer is not no. It is that you cannot tell. Absence of evidence is the only answer the architecture can produce.

The article’s own examples make the point. In Cloudflare’s Thanksgiving 2023 incident, the intruder entered with one service token and three service accounts, credentials taken in an earlier compromise elsewhere and never rotated. Not a vulnerability. Credentials that belonged to nothing in particular and were therefore missed in a rotation that reached everything else.

Six Systems, Still No Owner

The article’s remedy is honest about its own difficulty: you will need to integrate secrets management, identity governance and administration, privileged access management, identity and access management, and cloud infrastructure entitlement management, then augment all of it with specialized non-human identity discovery. That is an accurate description of what is currently on the market.

It is worth asking what each of those systems actually holds. Identity governance holds people and their entitlements. Privileged access management vaults and brokers privilege. Entitlement management right-sizes cloud permissions. A secrets manager stores and rotates the material. Discovery enumerates what exists. Every one of them is organized around a credential or a permission.

None of them holds the fact that makes offboarding, attribution and cost allocation possible: that this agent belongs to this named human, and here is the unbroken chain from a sub-agent four levels down back to that person. You can buy all six and still fail the four-question test we set out in FN-10, because the chain is not any of their jobs.

Where That Leaves Us

We agree with the admission at the centre of the article. No vendor offers a single holistic solution for governing every non-human identity in an enterprise, and we are not claiming to be one. We have said before that we work in a deliberately narrow room. This is what that room contains: the ownership chain, issued at machine speed, anchored to a named human in the directory you already run, surviving every sub-agent an agent spawns, and revocable in one action.

That is not a replacement for discovery. Run the scan, buy the visibility, integrate the six systems if that is what your estate needs. Our only amendment to the article’s advice is this: make sure something in what you assemble carries the chain back to a person. If nothing does, you will have bought a very clear photograph of an estate you still cannot govern, and the next time someone asks whether a machine identity was involved, you will still be in the thirty-two percent.

The Test We Would Apply
Before you accept any ratio, including ours, ask the source three questions. Was it counted or estimated? Who paid for the research? Does the linked page actually contain the number? The last one fails more often than it should.
Arkion Research Desk
Field Note FN-12-2026 · Distributed under arkion.ai/field-notes
For questions or to discuss findings: research@arkion.ai
Sources & Notes
  • Cybersecurity Dive, “Identity is the new perimeter as rapid NHI proliferation threatens visibility and control” (published May 11, 2026). Labelled sponsored content, paid for by SHI. The subject of this note. Quotations from Brad Bowers, field CISO (global) at SHI, and the “no vendor yet offers a single, holistic solution” line are taken from it directly.
  • Silverfort, “Insecurity in the shadows: new data on the hidden risks of non-human identities” (PDF, posted November 2025). Source of the fifty-to-one figure. The document presents it as an estimate (“we estimate”, “it is now estimated”) with no citation. Its measured figure is a range of one to thirty through one to fifty in hybrid environments. Vendor marketing material; the underlying Osterman Research survey was fielded in May and June 2023.
  • Cloud Security Alliance, “The State of Non-Human Identity and AI Security” (released January 26, 2026, sponsored by Oasis Security). The page the article links for its ten-times-by-2020 claim. Fetched and searched in full: it states no machine-to-human ratio. It does report that fewer than a quarter of organizations have documented policies for creating or removing AI identities, and that twelve percent are highly confident they can prevent attacks via non-human identities.
  • Keeper Security, research released at RSA Conference 2026 (April 7, 2026), press release. Source of the forty percent and thirty-two percent figures, which the article reached via a secondary write-up that links to neither. First-party vendor research, sample of one hundred and nine, gathered on the conference floor. Keeper’s own infographic reports forty-one percent and omits the thirty-two percent figure. We cite the shape of the finding, not the percentages, and say so in the text.
  • CyberArk, “Machine identities outnumber humans by more than 80 to 1”, 2025 Identity Security Landscape (April 23, 2025). Conducted by Vanson Bourne among 2,600 cybersecurity decision makers at organizations of 500 employees and above. This is the source of the eighty-to-one figure Arkion publishes. Self-reported survey, not a measurement of live estates.
  • Palo Alto Networks, 2026 Identity Security Landscape. The successor to the CyberArk series following the acquisition. States “machine identities outnumber humans 109:1” from 2,930 global cybersecurity leaders surveyed.
  • Cloudflare, “Thanksgiving 2023 security incident”. Cloudflare’s own disclosure. Initial access used one service token and three service accounts, credentials taken in an earlier compromise and not rotated. Cited as a non-human identity failure, in Cloudflare’s own words.
  • Palo Alto Networks investor relations, agreement to acquire CyberArk (July 30, 2025). The release states an equity value of approximately twenty-five billion dollars, a point-in-time figure based on the ten-day average share prices as of July 25, 2025, not a fixed price.
  • Gartner press release, June 25, 2025. Source of the prediction that at least fifteen percent of day-to-day work decisions will be made autonomously through agentic AI by 2028. Worth noting that the same release predicts that over forty percent of agentic AI projects will be cancelled by the end of 2027. Both are predictions, not measurements.
  • Method: every source above was fetched and read directly in September 2026, rather than cited from the article that referenced it. Where a figure did not appear on the page cited, we say so. Arkion’s own locked source table was corrected during the writing of this note.
Next Step

Stop estimating.
Count yours.

Published ratios are estimates of somebody else’s estate. The only number that matters is the one in your environment, and how many of those identities resolve to a person. A read-only Discovery Scan produces both.