78% of APAC Organizations Hit by Machine Identity Breaches
- By CDOTrends editors
- April 14, 2025

Machine identity security failures have reached critical levels across the Asia Pacific region, with more than three-quarters of organizations experiencing breaches linked to compromised non-human credentials within the past year, according to new research from CyberArk.
The identity security leader’s “2025 State of Machine Identity Security Report” reveals a perfect storm brewing: exponentially multiplying machine identities, increasingly frequent certificate-related outages, and widespread security incidents — all while AI adoption accelerates the risks.
Mounting machine identity crisis
The findings paint a concerning picture for CISOs already battling expanded attack surfaces. Among the 1,200+ security leaders surveyed across multiple countries:
- 78% of APAC organizations reported security incidents or breaches stemming directly from compromised machine identities
- An identical 78% experienced at least one certificate-related outage last year
- 74% now face these outages monthly, while 77% report weekly incidents
- 85% expect machine identities in their environments to surge by as much as 150% over the next 12 months
These compromises go beyond just technical inconveniences. They’re creating substantial business impacts, including application launch delays (51%), unauthorized access to sensitive data or networks (51%), and customer-impacting outages (37%).
AI amplifies the threat landscape
As organizations race to adopt AI capabilities, new machine identity security challenges emerge. The research underscores this concern, with 82% of APAC security leaders stating that machine identity security will be vital for securing AI’s future.
An equal percentage (82%) emphasized that protecting AI models from manipulation and theft requires greater focus on machine identity authentication and authorization protocols. This suggests that traditional IAM frameworks designed primarily for human users are insufficient for the emerging AI-driven landscape.
Program maturity gaps persist
Despite mounting evidence of the risks, machine identity security programs remain immature across most organizations. The report reveals:
- 94% claim some form of machine identity security program, but many lack maturity
- 46% cite the absence of a cohesive strategy as their top concern
- 42% struggle to adapt to shorter machine identity lifecycles
- 38% fear adversaries exploiting stolen machine identities
Organizational silos compound these challenges, with responsibility for preventing machine identity compromises fractured across security teams (51%), development teams (29%), and platform teams (14%).
Kurt Sand, general manager of machine identity security at CyberArk, warns: “Cybercriminals are increasingly targeting machine identities — from API keys to code signing certificates — to exploit vulnerabilities, compromise systems and disrupt critical infrastructure, leaving even the most advanced businesses dangerously exposed.”
Bottom line
For CISOs, this research should serve as a clear call to action to establish centralized machine identity governance. The trend of machine identities exponentially outpacing human identities requires a strategic shift from traditional identity approaches to comprehensive machine identity lifecycle management.
Consider implementing an end-to-end machine identity security strategy that includes automated certificate management, secret rotation, zero-trust access controls for machine-to-machine communications, and robust monitoring for anomalous machine identity behavior.
With quantum computing threats on the horizon and AI agents proliferating throughout enterprise environments, closing machine identity security gaps must become a tier-one priority.
Image credit: iStockphoto/tadamichi