* [![perspectives](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2025/02/prespective-icon.png)](https://origin-www.paloaltonetworks.com.au/perspectives)
* The 82:1 Problem: Securing the Invisible Majority

# The 82:1 Problem: Securing the Invisible Majority

![The 82:1 Problem: Securing the Invisible Majority](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2026/02/82-1-problem-featured.jpg)  
**By [Amy Blackshaw](https://origin-www.paloaltonetworks.com.au/perspectives/author/amy-blackshaw/ "Posts by Amy Blackshaw")** | **5 min read** |  
![share icon](https://paloaltonetworks.com/content/dam/pan/en_US/cxo-perspectives/images/cxo-share.svg)

* LinkedIn button ![linkedin-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-linkedin.svg)
* Twitter share button ![twitter-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-twitter-x-black.svg)
* \[Email share button ![email-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-email.svg)\](mailto:?subject=The 82:1 Problem: Securing the Invisible Majority\&body=Check out this article https%3A%2F%2Forigin-www.paloaltonetworks.com.au%2Fperspectives%2Fthe-821-problem-securing-the-invisible-majority%2F "Share in Email")
* ![copy-icon](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/themes/csp2025/dist/images/icons/icon-share.svg)
  [](https://origin-www.paloaltonetworks.com.au/perspectives/the-821-problem-securing-the-invisible-majority/?pdf=download&lg=en&_wpnonce=83197ae001 "Click here to download") MEET THE AUTHOR  
  ![](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2026/01/Amy-Blackshaw-Head-Shot-24-JPG.jpg)  
  Amy Blackshaw is a seasoned technology and cybersecurity marketing executive with more than 20 years of experience, including over 15 years in cybersecurity. As Senior Vice President of Product Marketing at CyberArk, she leads market-driven strategy and execution to position and launch products and services that address the most critical identity security challenges facing global enterprises. Amy brings deep expertise in building and leading high-performing product and technical marketing organizations across identity security, security operations, anti-fraud, and integrated risk management markets. Prior to CyberArk, she held multiple senior marketing leadership roles at RSA, most recently serving as the marketing leader for the NetWitness business, where she oversaw global marketing strategy and execution. Recognized for her ability to translate complex technologies into clear market leadership, Amy has a proven track record spanning product and marketing strategy, alliance management, business development, and team development. She holds a bachelor's degree from the University of Massachusetts Amherst, an MBA from Simmons University, and is a CISSP....

[Learn more](https://origin-www.paloaltonetworks.com.au/perspectives/author/amy-blackshaw/)

## IN THIS ARTICLE

The new workforce is here. For every human employee, there are now estimated to be [82 machine identities](https://www.cyberark.com/press/machine-identities-outnumber-humans-by-more-than-80-to-1-new-report-exposes-the-exponential-threats-of-fragmented-identity-security/) operating within one enterprise. These identities correspond to service accounts, API keys, bots and autonomous AI agents that run the modern digital infrastructure. They work 24/7, never taking a vacation, getting sick, or logging out. Yet, they always have access to your most sensitive data.

## Outdated Strategy Competing with a Crisis

As it stands today, we are fighting a 2026 challenge with a 2010 strategy. Perhaps it's because we've spent decades perfecting the identity and access management (IAM) industry to secure human users. Yet, we are watching that model break down in real time. Today, access privilege is based on responsibility, not on a neat job title. Powerful access now lives in the hands of executives as well as developers, operators and automated scripts.

The danger is in the double standard. Humans are governed by the rigorous lifecycle controls of HR --- vetting, onboarding and offboarding, but machines do not. We have failed to apply the basic IAM discipline to the machine workforce, despite the fact that they now outnumber us 82 to 1, run without interruption, and operate with pervasive, unmonitored access privilege. We have created both a security gap and an engineering crisis where our most powerful actors are the ones we understand the least.

## Solving the Math

You have to look at the math to understand the scale of the problem. If you have 10,000 employees, for example, you likely have over [820,000 machine identities](https://www.paloaltonetworks.com/perspectives/2026-cyber-predictions). In this equation, your people are a rounding error.

Yet, look where the budget goes. We spend millions of dollars on phishing training, biometric scanners and single sign-on (SSO) for employees. We subject them to background checks, interviews, performance reviews and strict offboarding protocols.

Consider the machine. A developer can spin up a new service account in seconds. Often, to save time, they grant it "admin" privileges --- the digital equivalent of giving the summer intern the master key to the building. Once that project is done, the developer moves on, but the identity remains. It sits there, dormant but active, a sort of zombie account waiting for an attacker to find it.

We have created an environment where the most powerful actors in our networks are also the least supervised.

## The Missing Discipline: Identity Security for Machines

The solution is to fundamentally change our operational philosophy. We need to apply the rigorous discipline of identity security to our machine workforce. We need the same level of visibility and control that our HR discipline enables for humans. And we need to treat both machines and AI agents as high-risk users.

If we managed our digital workforce the way we manage our human one, we would see three immediate shifts.

### 1. Discovery and Onboarding During the Hiring Process

Humans cannot simply walk into an office and start working. They need an offer letter, a role, access privileges, a manager and credentials. In the machine world, however, "silent births" are the norm. Identities appear out of nowhere, created by scripts or automated processes without any oversight. The engineering fix is to move toward Identity-as-Code. In this model, no machine identity should exist without a defined purpose, owner and planned lifecycle. Put simply, if it doesn't have a sponsor, it doesn't get access.

### 2. Performance Review Controls

We review human performance yearly, quarterly or sometimes monthly to check whether employees are excelling at their jobs, achieving the desired outcomes, or underperforming. We rarely apply this same scrutiny to service accounts, despite the fact that they operate continuously.

This endurance becomes a fundamental data problem that requires continuous behavioral monitoring. We need to know instantly if an API key, which usually only talks to the billing server, is suddenly trying to access the customer database at 3:00 a.m. That level of performance issue necessitates immediate intervention.

### 3. Termination-Lifecycle Management

When a human leaves the workplace, we use a checklist that includes taking the laptop, cutting access and saying goodbye. But, when a cloud instance is spun down or a microservice is deprecated, the identity often lives on in perpetuity. To solve this, we need to build a kill switch directly into the [CI/CD pipeline](https://www.paloaltonetworks.com/cyberpedia/what-is-the-ci-cd-pipeline-and-ci-cd-security). Automated deprovisioning ensures that, when the code dies, the identity dies with it.

## From Policy to Engineering

For years, we have tried to solve identity through policy. We have written PDFs detailing "Best Practices for Access Management" and hoped developers would read them.

The page has turned and the chapter has closed. You cannot govern over 800,000 entities with a PDF. You must govern them with code.

Conversations must move from the CISO to the VP of engineering, because identity is now an infrastructure problem. It is about how we architect our cloud environments, manage secrets and deploy code.

The "[Unsecured Front Door](https://www.paloaltonetworks.com/perspectives/ais-front-door-why-the-browser-is-your-most-critical-control-point/)" is now the thousands of browsers and API endpoints connecting your enterprise to the world. If your strategy relies on manual reviews and spreadsheets, you have already lost. The attackers are using automation, scanning for these overprivileged, unmonitored accounts at machine speed. We cannot fight them with a decade's old mindset.

## Creating a Safe and Successful Organizational Chart

Ultimately, all of this demands a moment of radical honesty in the C-suite. We need to admit that the organizational chart is nostalgic fiction. It captures the people, but it misses the power.

The 82:1 ratio is a structural reality that isn't going away. We can continue to pretend that the 1% are the only ones who matter, or we can accept the reality of our new workforce.

Governance has evolved beyond security compliance to now be about operational control. If you don't have an automated, code-based system to hire, manage and fire your machine workers, you aren't running a tight ship; you are running a ghost ship.

Curious what else Amy has to say? Check out her other articles on [Perspectives](https://www.paloaltonetworks.com/perspectives/author/amy-blackshaw/).

* [AI](https://origin-www.paloaltonetworks.com.au/perspectives/all-articles/?cat=ai)
* [Identity](https://origin-www.paloaltonetworks.com.au/perspectives/all-articles/?cat=identity)

## Related Content

![](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2026/03/Why-Cybersecurity-KPIs-Are-Changing-featured.jpg) BLOG

### AI

**Why Cybersecurity KPIs Are Changing (And What This Means for Security Leaders)**

True cyber resilience is impossible to achieve without strategic and tactic...

[Helmut Reisinger](https://origin-www.paloaltonetworks.com.au/perspectives/author/helmut-reisinger/ "Posts by Helmut Reisinger")
[](https://origin-www.paloaltonetworks.com.au/perspectives/why-cybersecurity-kpis-are-changing-and-what-this-means-for-security-leaders/)  
![](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2026/03/Weaponized-Intelligence-featured.jpg) BLOG

### AI

**Weaponized Intelligence**

We are building the foundation that makes defense possible....

[Nikesh Arora](https://origin-www.paloaltonetworks.com.au/perspectives/author/nikesh-arora/ "Posts by Nikesh Arora")
[](https://origin-www.paloaltonetworks.com.au/perspectives/weaponized-intelligence/)  
![](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2026/03/RFP-Bottleneck-featured.jpg) BLOG

### AI

**From Weeks to Minutes: How We Applied an AI-First Transformation to the RFP Bottleneck**

Understanding why manual efforts burn hundreds of hours and are bottlenecki...

[Sandeep Uttamchandani](https://origin-www.paloaltonetworks.com.au/perspectives/author/sandeep-uttamchandani/ "Posts by Sandeep Uttamchandani")
[](https://origin-www.paloaltonetworks.com.au/perspectives/from-weeks-to-minutes-how-we-applied-an-ai-first-transformation-to-the-rfp-bottleneck/)  
STAY CONNECTED

## Connect with our team today

Job Level  
Sign me up to receive news, product updates, sales outreach, event information and special offers about Palo Alto Networks and its partners.  
By submitting this form, I understand my personal data will be processed in accordance with Palo Alto Networks [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) and [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown).  
This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.
Reach out  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown)

* [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown)

* [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown)

* [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown)

* [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown)

* [Customers](https://www.paloaltonetworks.com/customers?ts=markdown)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown)

* [Communities](https://www.paloaltonetworks.com/communities?ts=markdown)

* [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown)

* [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown)

* [Documents](https://www.paloaltonetworks.com/legal?ts=markdown)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* AU  
  Select your language
