TLDR: A new report from Rubrik Zero Labs indicates a significant drop in organizations’ confidence to recover from cyberattacks, coinciding with the widespread adoption of AI agents and the surge in non-human identities. The study highlights that a majority of future cyberattacks are expected to be AI-driven, prompting a critical need for enhanced identity resilience strategies and investments in specialized security personnel.
Palo Alto, California – November 13, 2025 – New research from Rubrik Zero Labs, detailed in their ‘Identity Crisis: Understanding & Building Resilience Against Identity-Driven Threats’ report, reveals a concerning decline in organizations’ ability to withstand and recover from cyber incidents. The study, conducted by Wakefield Research and surveying 1,625 IT Security decision-makers across companies with 500 or more employees, underscores a widening gap between the expanding identity attack surface and enterprises’ confidence in their recovery capabilities.
The report highlights that only 28 percent of respondents in 2025 believe they could fully recover from a cyber incident within 12 hours or less, a notable decrease from 43 percent in 2024. Furthermore, more than half (58 percent) anticipate that it would take at least two days to restore full-service operations following a compromise. This waning confidence signals an urgent need for dedicated resources and a comprehensive strategy to build identity resilience.
The proliferation of AI agents in the workplace is identified as a major contributing factor to this growing vulnerability. The study found that 89 percent of IT decision-makers have already fully or partially integrated AI agents into their identity infrastructure, with an additional 10 percent planning to do so. This rapid adoption is leading to a surge in non-human identities (NHIs), which industry reports suggest now outnumber human users by an alarming 82-1. Securing these NHIs is becoming paramount, given the increasing complexity of managing AI agent operations.
IT leaders are acutely aware of the escalating threat landscape. Over half (58 percent) of IT security decision-makers expect that 50 percent or more of the cyberattacks they face in the next year will be driven by agentic AI. A significant 90 percent of leaders agreed that identity-driven cyberattacks represent a top threat to their organizations.
Andrew Albrech, Chief Information Security Officer at Dominos, emphasized the human element in security, stating, ‘I could have unlimited amounts of technology in place. But if someone socially engineers our support desk to hand over admin passwords, that’s the end of the game. That’s why identity resilience is key.’ This sentiment is echoed by the finding that among organizations that experienced a ransomware attack in 2025, 89 percent resorted to paying a ransom to recover their data or halt the attack.
In response to these escalating threats, organizations are planning significant investments. The report indicates that 89 percent of organizations intend to hire professionals specifically to manage or improve identity management, infrastructure, and security within the next 12 months. Additionally, 87 percent of IT and security leaders are actively planning to change Identity and Access Management (IAM) providers or have already initiated the process, with 58 percent citing security concerns as the primary driver for these changes.
Also Read:
- Cybersecurity Alarms Sound Over AI Agent ‘Query Injection’ Threats
- Salesforce Report Highlights AI Agents as Pivotal for Enhanced Security and Business Growth
Kavitha Mariappan, Chief Transformation Officer at Rubrik, underscored the gravity of the situation: ‘The rise of identity-driven attacks is changing the face of cyber defense… Managing identities in the era of AI has become a complex endeavor, especially with the labyrinth of NHIs. We have an under-the-radar crisis on our hands where a single compromised credential can grant full access to an organization’s most sensitive data. Attackers are no longer breaking in, but logging in, and comprehensive Identity Resilience is absolutely critical to cyber recovery in this new landscape.’ The findings collectively highlight a critical juncture for cybersecurity, demanding a proactive and robust approach to identity resilience in the age of AI.


