October 1, 2026
Identity security signals: What to watch this Cybersecurity Awareness Month
Breaking down recent security and technology trends and what they reveal about the future of identity, access, and risk.
This October, Cybersecurity Awareness Month arrives during a milestone year: America’s 250th anniversary. CISA’s Cybersecurity Awareness Month campaign brings government and industry together to help people and organizations take practical steps to stay safer online.
As America marks 250 years, the technologies and threats shaping what comes next are changing quickly. AI is already making it easier to impersonate trusted users, create convincing attacks, and compromise credentials at scale. Meanwhile, agentic AI systems are becoming digital identities themselves as they access data, make decisions, and take action inside workflows.
For Imprivata, this makes the message for Cybersecurity Awareness Month simple: make security the easy choice. Organizations need to protect every identity — people, devices, third parties, and AI — without slowing down the work that matters.
Against this backdrop, recent headlines reveal new signals about identity security.
Signal 1: Strong authentication doesn’t have to mean more friction
AI is raising the stakes for authentication by making it easier for attackers to find weaknesses and turn compromised access into broader exposure. Researchers recently used Anthropic’s Claude to identify and exploit vulnerabilities that provided access to an OpenAI employee’s ChatGPT account and internal software repository. The incident shows why protecting authentication and credentials becomes even more important as AI accelerates what attackers can do once they find an opening.
But the answer cannot simply be more passwords, prompts, and authentication steps. When security creates too much friction, people look for faster ways around it—potentially creating new gaps in the process. Organizations need authentication that is both stronger and easier to use, making secure access the natural path for legitimate users while making credential-based attacks harder to execute.
Signal 2: Security must work for the people deploying and using it
The challenge of making security work for frontline workers is especially clear across critical infrastructure. States are now expanding cybersecurity support for locally operated water systems, hospitals, utilities, and other essential services. But while research shows that 88% of state CIOs consider attacks on critical infrastructure a major concern, only 31% of state CIO budgets include funding to support local governments and special districts.
New initiatives are trying to close that resource gap. The Center for Internet Security and OpenAI recently launched an AI Cyber Defense Pilot to explore how AI can help resource-strained state and local governments and critical infrastructure organizations strengthen threat detection and response.
These developments underscore the need for security that fits naturally into existing workflows and makes it easier for frontline workers to operate securely while keeping essential services moving.
Signal 3: When risk rises, security should get smarter, not harder
AI is also changing security spending priorities. About seven in 10 CISOs surveyed by IANS and Artico Search identified AI as their top priority for new cybersecurity spending, including investments in security automation and identity and access management (IAM).
That investment reflects a broader need to keep pace with a faster and more dynamic threat landscape. Cybersecurity experts examining recent AI incidents have pointed to established practices such as monitoring activity, constraining permissions, and detecting anomalous behavior as ways organizations can manage new risks.
Organizations can apply the same principle to access, using context and risk to determine when stronger controls are necessary rather than treating every access attempt the same.
Signal 4: Healthcare resilience depends on sustainable security practices
Healthcare shows how quickly new technology can outpace the resources and governance needed to secure it. Research from Imprivata and Vanson Bourne found that 83% of surveyed organizations have deployed AI across select departments or multiple use cases, while 72% say AI tools are deployed without IT approval at least occasionally. That gap creates new questions around visibility, access, and accountability at a time when healthcare organizations are already managing significant cybersecurity demands.
Those pressures are drawing greater attention. Newly reintroduced federal legislation would establish stronger cybersecurity requirements for hospitals while providing $1.3 billion in implementation assistance. At the same time, an OpenAI research agent gained unauthorized access to a Services Australia health-statistics portal, another example of what can happen when an autonomous system moves beyond its intended boundaries.
Together, these developments underscore the need to build AI governance into healthcare security, with clear visibility into which systems are operating, what they can access, and how their access is controlled.
Signal 5: AI agents need identity, limits, and proof
Additional research shows that organizations are moving quickly to adopt agentic AI while governance struggles to keep pace. Research from EY found that many companies’ AI strategies do not yet account for agentic tools, even as agents gain greater autonomy and access to connected environments.
Recent developments show the scale of the issue. OpenAI has said its agents interacted with publicly available U.S. government resources, while OpenAI, Anthropic, and researchers are reportedly examining tens of thousands of security incidents involving frontier AI models.
The industry is increasingly recognizing the need for stronger identity and access controls around AI agents. Recent moves from Nvidia to introduce safeguards for autonomous agents and Okta to form a coalition focused on agentic AI security reflect a broader shift toward establishing clear identities, access boundaries, monitoring, and accountability for AI agents.
What do these signals mean for cybersecurity as a whole?
Cybersecurity Awareness Month is about turning awareness into action. Now more than ever, organizations need identity security that makes access easy for people, adapts as risk changes, and extends visibility and accountability to AI agents.
As America marks 250 years and cybersecurity enters its next era, resilience will depend on protecting every identity while keeping critical work moving and, ultimately, making security the easy choice.
Questions about the intersection of AI, identity, and cybersecurity?