Identity Crisis: Global Firms Face Mounting Risks Amid AI Surge and Lack of Recovery Testing
好的,我现在需要帮用户总结一篇文章的内容,控制在100个字以内,并且不要用“文章内容总结”或“这篇文章”这样的开头。首先,我得仔细阅读用户提供的文章内容。 文章主要讨论了身份威胁检测和响应(ITDR)的采用情况,以及企业在灾难恢复准备方面的不足。根据Quest Software的调查,尽管很多组织采用了ITDR,但超过75%的组织没有按照建议每半年测试一次灾难恢复计划,24%甚至从未演练过。随着企业转向混合云环境,攻击面从网络边界转向了个体身份,尤其是非人类身份(如服务账户和自动化机器人)的数量激增,给安全带来了新的挑战。此外,安全事件与AI的使用相关联的情况增加了57%,显示出攻击者也在利用自动化工具。虽然57%的组织已经建立了正式的ITDR实践,但整体恢复准备仍显不足。专家建议采用NIST网络安全框架来提升整体安全能力。 接下来,我需要将这些关键点浓缩到100字以内。重点包括:ITDR采用率上升、灾难恢复测试不足、非人类身份带来的挑战、AI相关安全事件增加、以及NIST框架的重要性。 最后,确保语言简洁明了,直接描述文章内容。 </think> 文章指出尽管越来越多的组织采用身份威胁检测和响应(ITDR)实践但灾难恢复准备不足仍是重大隐患。调查显示超75%的企业未按建议每半年测试灾难恢复计划24%甚至从未演练。随着企业转向混合云环境攻击面从网络边界转向个体身份尤其是非人类身份(如服务账户和自动化机器人)激增使安全更具挑战性。专家建议采用NIST网络安全框架提升整体安全能力以应对日益复杂的威胁。 2026-3-9 18:23:30 Author: securityboulevard.com(查看原文) 阅读量:5 收藏

Avatar photo

Organizations may be increasingly adopting Identity Threat Detection and Response (ITDR) practices, but a critical gap in disaster recovery readiness is leaving many vulnerable to catastrophic failure.

The annual State of ITDR survey from Quest Software, which gathered insights from 650 IT and security executives worldwide, reveals a startling lack of preparedness around post-attack restoration.

Despite industry recommendations to test disaster recovery plans every six months, more than 75% of organizations fail to do so. More alarming is that 24% of respondents admitted they never practice their recovery plans.

As organizations migrate to hybrid and cloud environments, the attack surface has shifted from the network perimeter to individual identities. This sprawl is compounded by an explosion of non-human identities, such as service accounts and automated bots, which outnumber human users by an estimated ratio of 82-to-1.

Security professionals cited non-human identities as their greatest challenge, with 51% identifying them as the most difficult assets to secure. The complexity arrives at a volatile time; security incidents linked to artificial intelligence (AI) use have surged by 57%, as attackers leverage automated tools for data poisoning and model theft.

There is a notable paradox in how firms perceive their defense versus their recovery. While 79% of respondents expressed confidence that AI tools will improve ITDR effectiveness, Quest executives warn that over-reliance on prevention is a dangerous gamble.

“Identity systems are at the center of most environments,” said Michael Laudon, chief technology officer at Quest Software. “When those systems are compromised, attackers gain immediate access. Most teams are not validating recovery often enough to ensure rapid restoration after an attack.”

There is a silver lining: Adoption is on the rise. Currently, 57% of organizations have formal ITDR practice in place, up from 48% last year. Further, 92% of leaders acknowledge the tangible benefits of these programs.

To bridge the gap between detection and recovery, industry experts point toward the NIST Cybersecurity Framework, which emphasizes a holistic approach across six core pillars: identify, protect, detect, respond, recover, and govern.

As threats become more sophisticated, the report suggests that recovery readiness will be the true differentiator between a minor breach and a business-ending event.

Recent Articles By Author

Avatar photo

Jon Swartz

Jon Swartz is senior content writer at Techstrong Group. Most recently, he was MarketWatch’s senior reporter based in San Francisco covering technology and Silicon Valley. Previously, Swartz was USA Today’s San Francisco bureau chief. He has also written for Forbes, The (London) Independent, London Times, San Francisco Chronicle, and New Orleans Times-Picayune. He has won numerous journalism awards and is a two-time finalist for the Loebs, the Pulitzers of business reporting. Additionally, he frequently appears as a panelist on Fox Business and NBC Bay Area’s Press:Here program. He has been nominated four times for the Pulitzer Prize. Swartz is co-author of “Zero Day Threat: The Shocking Truth of How Banks and Credit Bureaus Help Cyber Crooks Steal Your Money and Identity” and sole author of “Young Wealth.”

jon-swartz has 35 posts and counting.See all posts by jon-swartz


文章来源: https://securityboulevard.com/2026/03/identity-crisis-global-firms-face-mounting-risks-amid-ai-surge-and-lack-of-recovery-testing/
如有侵权请联系:admin#unsafe.sh