As the adoption of cloud services and automation accelerates in the UAE, cybersecurity leaders are increasingly urged to focus on securing machine identities. Justin Henkel, CISO at SolarWinds, emphasizes that the rapid expansion of machine actors—such as APIs, AI agents, and automated processes—poses significant security challenges that require immediate attention from technology leaders.
Understanding the Landscape of Machine Identities
The proliferation of machine identities is reshaping enterprise security dynamics. Henkel notes that these identities can range from long-lived service accounts to ephemeral workloads, each with varying levels of authority and access. “The security challenge is not simply that machine identities are multiplying,” he explains. “Software can now obtain and exercise authority at machine speed, often without human approval.” This shift necessitates a comprehensive understanding of what machine identities exist, their purposes, and the controls needed to manage them effectively throughout their lifecycle.
Authority and Risk Management
One of the critical factors in managing machine identities is distinguishing between authentication and authorization. Henkel advises technology leaders to apply the principle of least privilege, limiting access based on specific actions, resources, and timeframes. “Over-privileged machine identities can expand the blast radius of an incident,” he warns, highlighting the potential for a single compromised identity to lead to widespread damage. Continuous monitoring and proactive privilege management are essential to mitigate these risks.
Establishing Ownership and Provenance
With machine identities being created across various platforms and applications, establishing clear ownership is vital. Henkel stresses the importance of integrating ownership into the architecture and deployment workflows. “Visibility is necessary, but discovery alone does not establish that a machine actor is legitimate or safe,” he states. Organizations must ensure that each machine identity is linked to a responsible owner and that its purpose is well-documented to facilitate effective incident response and accountability.
Transitioning to Secure Workload Identity
As machine actors often rely on various credentials for authentication, transitioning to secure workload identities is crucial. Henkel recommends favoring federated identities and short-lived tokens over static secrets, which can be vulnerable to exploitation. “Hardcoded and long-lived credentials remain recurring attack paths,” he cautions, urging organizations to centralize credential management and monitor their usage closely.
Governance at Machine Speed
Finally, Henkel emphasizes that governance frameworks must evolve to accommodate the speed at which machine identities operate. Traditional human-centric governance processes are insufficient for managing machine actors effectively. Instead, organizations should implement automated controls and risk-based human decisions to ensure accountability and security. “The result is governance that operates at machine speed while keeping humans responsible for purpose, authority, risk acceptance, and recovery,” he concludes.
As the UAE continues to embrace cloud technologies and automation, the need for robust machine identity governance becomes increasingly critical. By focusing on these five factors, technology leaders can enhance their security posture and better manage the complexities introduced by machine identities.
For further insights on securing non-human identities, refer to the article on Intelligent CISO.


