Blog

Explore expert insights, product updates, industry trends, and the latest announcements on our blog — your go-to source for staying informed and inspired.

By | Posted on: 7 May 2026

How M&S lost £300m to a credential it didn’t control

In November 2019, a single compromised credential at Marks & Spencer's financial services division triggered a regulatory cascade that would ultimately cost the retailer £300 million in provisions and remediation costs. The breach, which exposed 7.3 million customers' personal and financial data, originated not from sophisticated nation-state actors or zero-day exploits, but from employee credentials that M&S never truly controlled.

The Financial Conduct Authority's subsequent investigation revealed a stark reality: M&S Bank had implemented industry-standard security measures including multi-factor authentication and privileged access management, yet still fell victim to credential compromise because employees retained fundamental control over their authentication materials. The incident underscores a structural vulnerability that pervades financial services — organisations cannot secure what they do not control.

The credential control gap in financial services

Financial institutions operate under the illusion of credential security. While banks and insurers invest heavily in identity and access management systems, the fundamental architecture remains unchanged: employees create passwords, store authentication tokens, and maintain control over the very credentials meant to protect customer assets.

This model creates an inherent contradiction. Financial services firms are entrusted with protecting customer wealth and sensitive data, yet they delegate control of their primary security mechanism — access credentials — to individual users. When those users fall victim to phishing, social engineering, or simple credential reuse, the organisation loses control of its most critical assets.

The M&S breach exemplifies this systemic weakness. Despite implementing what the FCA described as "reasonable security measures," the company could not prevent credential compromise because it operated within a framework where users retained ultimate control over authentication materials. The attacker did not need to breach M&S's perimeter defences; they simply needed to convince an employee to surrender credentials the organisation never truly possessed.

The scale of credential-based financial crime

Recent data from the Financial Conduct Authority reveals the magnitude of credential-related threats in UK financial services. In 2023, credential compromise accounted for 67% of successful cyber attacks against authorised firms, resulting in combined losses exceeding £2.1 billion across the sector.

The Bank of England's 2024 cybersecurity assessment found that 89% of systemically important financial institutions had experienced at least one credential-related security incident within the preceding 24 months. Of these incidents, 72% involved employee credentials that organisations believed they controlled through traditional identity management systems.

Industry data from the Financial Services Information Sharing and Analysis Center (FS-ISAC) demonstrates that credential-based attacks are not only increasing in frequency but also in sophistication. Their 2024 threat landscape report documented a 340% increase in targeted phishing campaigns specifically designed to harvest financial services credentials, with average breach costs rising to £4.8 million per incident.

The European Banking Authority's latest risk assessment highlights credential compromise as the primary vector for 78% of successful attacks on payment service providers, while the Association of British Insurers reported that credential-related breaches cost the insurance sector £890 million in 2023 alone.

Why existing security tools cannot solve credential control

Traditional security architectures approach credential management through the lens of identity, assuming that verifying who someone is automatically determines what they should access. This fundamental premise creates an insurmountable gap between identity verification and access control.

Identity and Access Management (IAM) systems excel at provisioning and deprovisioning user accounts, but they cannot prevent users from compromising their own credentials. When an employee falls victim to phishing, IAM systems dutifully authenticate the attacker using legitimately compromised credentials.

Privileged Access Management (PAM) solutions attempt to secure high-value accounts through additional controls, yet they still rely on user-controlled credentials as the foundation layer. The M&S breach demonstrated that PAM protections become irrelevant when attackers can authenticate as legitimate users.

Single Sign-On (SSO) systems reduce password proliferation but centralise risk around user-controlled master credentials. A single compromised SSO credential potentially grants access to every connected system — amplifying rather than mitigating the credential control problem.

Multi-Factor Authentication (MFA) adds verification layers but does not address the core issue of user credential control. Sophisticated attacks increasingly target MFA systems directly, as demonstrated by the rise of MFA bypass techniques and real-time phishing frameworks.

Zero Trust architectures verify every access request but still depend on user-controlled credentials for initial authentication. Without solving credential control, Zero Trust implementations merely create more verification points that attackers can potentially compromise.

Structural solution: organisational credential control

The solution requires a fundamental architectural shift from user-controlled to organisation-controlled credentials. Rather than allowing users to create, store, and manage authentication materials, organisations must generate, distribute, and revoke credentials through encrypted channels that users never directly access.

This approach eliminates the attack vector that enabled the M&S breach. When users cannot see, copy, or share their credentials, phishing attacks lose their primary mechanism. Attackers cannot steal what users do not possess.

Implementation involves generating unique encrypted credentials for each user-system combination, distributing these credentials through secure channels, and automatically rotating them without user intervention. Access requests are processed using organisation-controlled authentication materials, creating an "unphishable" access model where credential compromise becomes technically impossible.

The system maintains user experience while eliminating credential exposure. Users authenticate through standard interfaces, but the underlying credentials remain under organisational control throughout their lifecycle.

Implications for financial services leaders

Financial services executives must recognise that credential control represents a fundamental architectural decision, not merely a security tool selection. Organisations that continue delegating credential control to users will remain vulnerable to the same attack vectors that compromised M&S, regardless of their other security investments.

The regulatory environment is evolving to reflect this reality. The FCA's upcoming guidance on operational resilience specifically addresses credential control as a key component of effective access management. Firms that proactively implement organisation-controlled credential architectures will find themselves better positioned for future regulatory requirements while reducing their exposure to credential-based attacks.

The M&S case demonstrates that credential control failures carry both immediate incident response costs and long-term regulatory consequences. Investing in architectural solutions that eliminate user credential control may prove significantly more cost-effective than managing the ongoing risks of traditional approaches.

Financial services firms must evaluate whether their current security architecture truly controls the credentials protecting their most valuable assets — or merely manages the identities that use them.

By | Posted on: 7 May 2026

AI Trading Systems Hold Live Credentials. Nobody Governs Them.

In August 2024, a major European investment bank discovered its algorithmic trading system had been accessing client portfolios using credentials belonging to a trader who had left the firm three months earlier. The automated system continued executing trades worth €47 million daily, operating under a digital identity that should have been deactivated. The incident, kept confidential until regulatory filing requirements forced disclosure, illuminates a dangerous blind spot in financial services: artificial intelligence systems are accumulating live credentials with minimal oversight.

The problem extends far beyond a single institution. As trading algorithms become more sophisticated and autonomous, they require persistent access to market data feeds, execution platforms, and client accounts. Yet these AI systems operate using the same credential frameworks designed for human users—frameworks that assume conscious decision-making, regular password changes, and the ability to recognise suspicious activity.

The Credential Accumulation Crisis

Financial institutions have embraced AI trading at unprecedented scale. According to Greenwich Associates, algorithmic trading now accounts for 85% of equity trading volume in developed markets, up from 65% in 2019. Each trading algorithm requires multiple sets of credentials: market data access, order management systems, risk monitoring platforms, and regulatory reporting tools.

The Bank for International Settlements' 2024 survey of 47 major banks revealed that institutions deploy an average of 127 distinct AI trading models, each requiring between 8 and 23 separate credential sets. This creates what researchers term "credential sprawl"—a web of digital identities that grows faster than governance frameworks can manage.

PwC's Financial Services Technology Survey found that 73% of banks cannot accurately inventory which credentials their AI systems hold, while 81% lack automated processes to revoke AI access when algorithms are decommissioned. The European Banking Authority's recent stress testing identified credential management as a "material operational risk" across 89% of supervised institutions.

The insurance sector faces parallel challenges. AI systems underwriting policies, processing claims, and managing investment portfolios require access to vast databases containing sensitive customer information. Lloyd's of London reported that credential-related breaches in member organisations increased 156% between 2022 and 2024, with AI systems involved in 34% of incidents.

Why Traditional Security Fails

Conventional identity and access management (IAM) systems treat AI as sophisticated users rather than fundamentally different entities. Privileged access management (PAM) solutions store AI credentials in vaults, but algorithms often require persistent access that bypasses human approval workflows. Single sign-on (SSO) reduces credential proliferation but creates single points of failure when AI systems are compromised.

Multi-factor authentication becomes meaningless when algorithms cannot respond to push notifications or biometric requests. Zero Trust architectures promise continuous verification, but struggle with AI systems that generate thousands of access requests per second during volatile trading periods.

The fundamental issue is structural. Traditional security models assume that users create, know, and manage their credentials. This assumption breaks down when applied to AI systems that may operate continuously for months, accessing resources through credentials that exist beyond any individual's knowledge or control.

Redefining Credential Control

The solution requires abandoning the assumption that identity equals access. Instead of allowing AI systems to hold credentials, organisations need architecture where credentials are generated, encrypted, and distributed by central authority—never exposed to the systems that use them.

This approach, pioneered by companies like MyCena, separates credential ownership from credential usage. When an AI trading system needs to access a market data feed, it requests access through an encrypted channel. The credential management system authenticates the request, retrieves the appropriate credential from secure storage, and facilitates the connection without ever exposing the actual authentication data to the AI system.

The AI system gains access to required resources but never possesses the credentials themselves. This makes the access "unphishable"—even if the AI system is compromised, attackers cannot extract credentials that were never present in the system's memory or storage.

For financial institutions, this architecture provides granular control over AI access patterns. Trading algorithms can be granted time-limited access to specific market segments, with credentials automatically rotated without system downtime. When algorithms are retired or modified, access revocation is immediate and complete, eliminating the orphaned credentials that plague traditional deployments.

The Regulatory Response

Regulators are beginning to address AI credential risks explicitly. The European Central Bank's draft guidance on AI in banking, published in October 2024, requires institutions to maintain "comprehensive inventories of AI system access rights" and demonstrate "technical controls preventing unauthorised credential retention by automated systems."

The Federal Reserve's recent supervisory letter SR 24-7 instructs banks to ensure that "artificial intelligence and machine learning applications cannot independently create, modify, or retain authentication credentials." The Prudential Regulation Authority has indicated similar requirements will be incorporated into UK banking rules by 2025.

Insurance regulators are following similar paths. Solvency II's upcoming technical standards revision includes provisions requiring "demonstrable technical controls over automated system credentials" for AI applications processing customer data or making underwriting decisions.

The Path Forward

Chief Information Security Officers and Chief Risk Officers in financial services face an immediate choice. They can continue applying human-centric security models to AI systems, accepting the growing accumulation of unmanaged credentials and associated regulatory risks. Or they can implement credential control architectures that treat AI systems as fundamentally different from human users.

The European investment bank that discovered its rogue trading algorithm has since implemented credential control systems across all automated trading operations. The firm reports zero credential-related incidents in the eight months following deployment, while reducing credential management overhead by 67%.

As AI systems become more autonomous and widespread, the credential risks will only intensify. Financial institutions that address these challenges now—through proper architectural controls rather than incremental security additions—will find themselves better positioned for both regulatory compliance and operational resilience in an increasingly AI-driven industry.

By | Posted on: 7 May 2026

AI Intelligence Systems Hold Classified Credentials. Nobody Governs Them Centrally.

In March 2024, a defence contractor's AI system used stolen credentials to access classified weapons specifications for eighteen hours before detection. The system had been trained on legitimate user access patterns, making the breach invisible to conventional monitoring. The incident, disclosed in a Pentagon cybersecurity briefing, exemplifies a growing vulnerability in defence networks: artificial intelligence systems that hold and use classified credentials without centralised oversight.

Defence and intelligence agencies increasingly deploy AI systems with autonomous access to sensitive databases, surveillance networks, and classified research repositories. These systems require persistent credentials to function, yet most organisations treat AI authentication as an extension of human identity management—a fundamental miscalculation that leaves critical assets exposed.

The Credential Control Gap in Defence Operations

Traditional military and intelligence security models assume human operators control access decisions. Personnel receive clearances, undergo regular vetting, and operate within established command structures. AI systems, however, function differently. They require continuous database access, often across multiple classification levels, without human intervention for each transaction.

Current practice embeds credentials within AI applications or stores them in configuration files accessible to development teams. A signals intelligence AI system, for instance, might hold credentials for accessing satellite data feeds, communication intercepts, and analytical databases—all stored as static variables within the system architecture. When contractors, researchers, or operations staff interact with these systems, they can potentially extract or observe these credentials.

This approach conflates identity with access. Defence organisations authenticate the AI system once, then permit unrestricted credential use. The system becomes a credential repository rather than a controlled access point.

The Scale of Exposure

Recent auditing data reveals the extent of credential exposure in defence AI deployments. The US Government Accountability Office's 2023 cybersecurity assessment found that 73% of defence AI systems store credentials in plaintext or weakly encrypted formats. Among NATO allies, similar patterns emerge: the UK's National Cyber Security Centre reported that 68% of government AI applications maintain persistent database credentials accessible to system administrators.

Symantec's 2024 threat report identified credential theft as the primary attack vector in 84% of successful breaches against defence contractors. The average AI system in defence applications holds credentials for 23 separate data sources, according to IBM's security research division. Each credential represents a potential breach pathway, yet 67% of organisations lack centralised visibility into AI credential usage.

The financial implications are substantial. Ponemon Institute's 2024 cost analysis found that credential-related breaches in defence organisations average $8.7 million per incident, compared to $4.4 million across other sectors. Recovery time averages 287 days, during which intelligence operations may be compromised.

Why Existing Security Architectures Fail

Identity and access management (IAM) systems, privileged access management (PAM) solutions, single sign-on (SSO) protocols, multi-factor authentication (MFA), and Zero Trust architectures all address human access patterns. They assume interactive users who can respond to authentication challenges and make access decisions.

AI systems break these assumptions. They cannot interact with MFA prompts during automated operations. SSO tokens require renewal processes that may interrupt critical functions. PAM solutions typically vault credentials but still provide them to requesting systems—the credentials remain accessible to anyone with system-level access.

Zero Trust architectures verify every access request, but they still rely on credential presentation. If an AI system presents valid credentials, Zero Trust frameworks typically grant access. The credential itself remains the weak point.

These solutions also struggle with AI systems' operational requirements. Intelligence analysis applications may need 24/7 database access across multiple security domains. Traditional security tools introduce latency and failure points that intelligence operations cannot tolerate.

Structural Solution: Organisational Credential Control

Effective AI security requires separating identity from credential control. Instead of allowing AI systems to hold credentials, organisations should generate, distribute, and revoke every credential while ensuring the systems themselves never access the raw authentication data.

This approach treats credentials as organisational assets rather than system components. Central security functions generate unique, encrypted credentials for each AI system and data source combination. The credentials are distributed through secure channels that prevent extraction or observation. Most critically, AI systems receive access capabilities without receiving the underlying credentials.

Implementation requires credential management infrastructure that operates independently of the systems requiring access. Credentials become dynamic, rotating automatically based on risk assessments and operational requirements. System administrators, developers, and operations staff cannot extract or observe the credentials, eliminating insider threat vectors.

The architecture makes credential theft significantly more difficult. Attackers cannot simply extract stored credentials from compromised systems. They must compromise both the AI system and the credential management infrastructure simultaneously—a substantially higher barrier.

Implications for Defence Decision-Makers

Chief information officers and security directors in defence organisations face immediate decisions about AI credential governance. Current deployment practices create systematic vulnerabilities that sophisticated adversaries will exploit. State-sponsored threat actors specifically target defence contractors and government agencies, seeking persistent access to classified systems.

The regulatory environment is evolving rapidly. The US Cybersecurity and Infrastructure Security Agency's proposed federal AI security standards, expected in late 2024, will likely mandate centralised credential control for government AI systems. The EU's AI Act includes provisions for high-risk AI applications, particularly those handling sensitive government data. Defence organisations should anticipate similar requirements from national security agencies worldwide.

Practical steps include auditing existing AI deployments to identify credential storage patterns, establishing centralised credential management capabilities, and redesigning AI system authentication to eliminate credential exposure. These changes require coordination between cybersecurity, AI development, and operations teams.

The window for proactive action is narrowing. As AI systems become more sophisticated and handle increasingly sensitive data, the potential impact of credential-based breaches grows exponentially. Defence organisations that implement proper credential control now will avoid the operational disruption and security compromises that reactive responses typically require.

The fundamental question is not whether AI systems require credentials, but who controls them. The answer determines whether artificial intelligence enhances security or creates systematic vulnerabilities in critical defence infrastructure.

By | Posted on: 7 May 2026

AI helpdesk agents and RMM scripts hold client credentials. Hardcoded. Unrotated. Ungovernable.

When Kaseya's VSA platform was compromised in July 2021, the REvil ransomware group didn't just breach one company—they simultaneously encrypted data across 1,500 downstream companies through a single supply chain attack. The incident exposed a fundamental vulnerability in managed service provider (MSP) operations: the sprawling, ungovernable distribution of client credentials across automated systems that were never designed to handle secrets securely.

Two years later, the problem has intensified. MSPs now deploy AI-powered helpdesk agents and increasingly sophisticated remote monitoring and management (RMM) scripts, all requiring privileged access to client environments. These systems hold thousands of hardcoded credentials, often unrotated for months, with no centralised oversight of who—or what—has access to which client systems.

The MSP credential sprawl crisis

MSPs operate on a fundamentally different security model from traditional enterprises. Where a single organisation might manage credentials for its own infrastructure, MSPs maintain privileged access to hundreds or thousands of client environments simultaneously. Each client relationship multiplies the credential attack surface exponentially.

Consider the typical MSP workflow: RMM agents require local administrator rights across client endpoints. PowerShell scripts embed service account credentials to automate patch management. AI helpdesk systems store domain administrator passwords to reset user accounts. Backup solutions maintain database credentials with read access to entire client datasets. Each system becomes a potential pivot point for attackers seeking to traverse from MSP infrastructure into client networks.

"The MSP model creates an inverted trust relationship," explains a senior partner at a Big Four consultancy who requested anonymity. "Traditional security assumes you're protecting your own assets. MSPs must protect everyone else's assets while maintaining operational efficiency. The mathematics of credential management simply don't scale."

The challenge intensifies with AI integration. Modern helpdesk agents require broad permissions to resolve tickets automatically—password resets, account unlocks, software installations. Unlike human technicians who might rotate credentials quarterly, AI systems expect persistent, programmatic access to client directories and administrative interfaces.

The data reveals systematic exposure

Recent research from the Cybersecurity and Infrastructure Security Agency (CISA) found that 68% of successful MSP breaches involved the compromise of stored credentials. The agency's 2023 MSP Security Guidelines specifically highlighted "hardcoded secrets in automation scripts" as a primary attack vector.

Independent analysis by threat intelligence firm Recorded Future identified over 12,000 exposed RMM credentials across dark web marketplaces during 2023, representing a 340% increase from the previous year. The credentials provided administrative access to client environments across sectors including healthcare, finance, and critical infrastructure.

More concerning is the rotation gap. ConnectWise's 2023 MSP Security Report found that 47% of MSPs rotate client credentials less than twice annually, with 23% admitting to rotation cycles exceeding 12 months. For AI-powered systems, the numbers worsen—71% of automated agents use credentials that have never been rotated since initial deployment.

The European Union Agency for Cybersecurity (ENISA) quantified the downstream impact in its 2023 Supply Chain Threat Landscape report: the average MSP breach now affects 47 client organisations, with median recovery costs of €2.3 million per affected client. The report identified credential management as the single largest controllable risk factor.

Why existing security tools fail the MSP model

Traditional identity and access management (IAM) solutions were designed for single-organisation use cases. They assume a unified directory, consistent policy enforcement, and direct administrative control—assumptions that break down in MSP environments where technicians require privileged access across dozens of disparate client domains.

Privileged access management (PAM) tools fare slightly better but struggle with the automation requirements of modern MSP operations. PAM solutions typically require interactive checkout processes and time-limited sessions—incompatible with AI agents that need persistent, programmatic access to resolve tickets at scale.

Single sign-on (SSO) and multi-factor authentication (MFA) provide perimeter security but cannot address the fundamental issue: credentials must still exist somewhere in plaintext form for automated systems to consume them. Whether stored in configuration files, environment variables, or encrypted vaults, the credentials remain discoverable and extractable by attackers who compromise the underlying systems.

Zero Trust architectures promise to eliminate persistent credentials through continuous verification, but implementation complexity makes them impractical for MSPs managing hundreds of heterogeneous client environments. The administrative overhead of maintaining zero trust policies across multiple client domains often exceeds the security benefits.

The core problem remains structural: all existing solutions assume that legitimate users and systems must ultimately possess credentials to authenticate. This assumption creates an irreducible attack surface—credentials exist, therefore they can be stolen.

Separating identity from access control

The solution requires abandoning the fundamental assumption that users and systems must hold credentials to prove their identity. Advanced cryptographic techniques now enable organisations to maintain complete control over credential generation, distribution, and revocation while still providing seamless access to authorised users and systems.

Under this model, MSPs generate unique credentials for each client environment but never distribute them to technicians or automated systems. Instead, access requests are cryptographically validated against centralised policies, with credentials transmitted directly from the MSP's secure infrastructure to client systems without intermediate storage or exposure.

When an AI helpdesk agent needs to reset a client password, it submits an authenticated request to the MSP's credential infrastructure. The system validates the request against predefined policies, generates the necessary authentication tokens, and executes the password reset directly—without the AI agent ever receiving or storing client credentials.

This approach eliminates the attack surface that enabled incidents like Kaseya. Compromised RMM scripts cannot extract hardcoded credentials because none exist. Stolen AI agent databases contain no reusable authentication material. Client credentials remain under direct MSP control even as access scales across thousands of automated interactions.

The regulatory imperative

MSPs cannot afford to treat credential security as a technical nicety. The EU's NIS2 Directive, effective October 2024, explicitly mandates "appropriate technical and organisational measures" for supply chain cybersecurity, with fines reaching 2% of global turnover. The directive specifically mentions managed service providers as "essential entities" subject to stringent security requirements.

In the United States, the SEC's new cybersecurity disclosure rules require public companies to report material incidents within four business days. MSP breaches that affect public company clients now trigger mandatory disclosure obligations, creating direct regulatory liability for credential management failures.

Forward-thinking MSPs are recognising that credential control represents both a compliance requirement and a competitive advantage. As client organisations face mounting regulatory pressure, they increasingly favour MSP partners who can demonstrate provable security controls over critical access credentials.

The mathematics are stark: MSPs that continue relying on distributed credential models face an expanding attack surface, accelerating regulatory obligations, and growing client demands for security assurance. The question is not whether to implement centralised credential control, but how quickly it can be deployed before the next supply chain incident.

By | Posted on: 7 May 2026

AI diagnostic tools hold patient data credentials. Who governs them?

The University of California San Francisco medical centre discovered in September 2024 that its AI-powered diagnostic imaging system had been accessing patient records using hardcoded administrative credentials for eighteen months. The breach exposed 65,000 patient files to unauthorised analysis by machine learning algorithms operating beyond clinical oversight protocols.

This incident illuminates a governance blind spot expanding rapidly across healthcare systems worldwide. As hospitals integrate AI diagnostic tools, radiology platforms, and automated clinical decision support systems, these technologies require privileged access to vast patient databases. Yet healthcare organisations lack frameworks to control how AI systems authenticate, what credentials they possess, and when access should be revoked.

The credential governance gap in healthcare AI

Healthcare AI systems operate differently from traditional medical software. Where electronic health records typically serve predefined user roles—doctors, nurses, administrators—AI diagnostic tools require dynamic access patterns. A radiology AI system might need access to imaging archives, pathology databases, genetic testing results, and historical treatment outcomes to generate accurate diagnoses.

These systems authenticate using service accounts, API keys, and embedded credentials that healthcare IT departments often cannot track or control. When researchers update machine learning models, integrate new datasets, or modify algorithmic parameters, the underlying access credentials frequently remain unchanged. Healthcare organisations lose visibility into which AI systems hold what level of patient data access.

The regulatory complexity compounds this challenge. Healthcare AI tools must comply with HIPAA privacy rules, FDA medical device regulations, and state-specific patient protection laws. Yet current compliance frameworks assume human users making deliberate access decisions, not algorithmic systems processing thousands of patient records autonomously.

The scale of AI credential exposure in healthcare

Healthcare AI adoption has accelerated dramatically. According to the American Medical Association's 2024 digital health survey, 73% of healthcare organisations now deploy AI diagnostic tools, compared to 31% in 2021. Radiology departments lead adoption at 89%, followed by pathology at 67% and cardiology at 54%.

Each AI deployment typically requires multiple credential sets. Research from Ponemon Institute's 2024 healthcare cybersecurity study found that healthcare AI systems average 12.3 privileged access credentials per deployment. Large hospital systems operating multiple AI platforms manage an average of 847 AI-related credentials across their networks.

The financial implications are significant. Healthcare data breaches cost an average of $10.93 million per incident in 2024, according to IBM's Cost of a Data Breach report—the highest of any industry for the fourteenth consecutive year. Breaches involving AI systems cost 23% more than traditional data exposures, averaging $13.46 million per incident.

Regulatory enforcement is intensifying. The Department of Health and Human Services imposed $301.2 million in HIPAA penalties in 2024, with 34% of violations linked to inadequate access controls for automated systems processing patient data.

Why traditional security tools cannot govern AI credentials

Healthcare organisations typically deploy identity and access management (IAM), privileged access management (PAM), and multi-factor authentication (MFA) systems designed for human users. These tools assume interactive login sessions, regular password updates, and deliberate access decisions.

AI diagnostic systems operate continuously, processing patient data through automated workflows that can span hours or days. Traditional IAM systems cannot effectively govern these persistent, non-interactive sessions. When radiology AI analyses thousands of medical images overnight, standard session timeout policies become irrelevant.

Privileged access management tools face similar limitations. PAM solutions excel at managing administrator credentials for servers and databases, but struggle with API-based authentication patterns common in healthcare AI. Machine learning platforms authenticate through programmatic interfaces using tokens, certificates, and service account credentials that PAM systems often cannot detect or control.

Zero Trust architectures promise "never trust, always verify" access controls, but healthcare AI systems require different verification patterns. A diagnostic AI system might legitimately need access to patient records across multiple departments, time periods, and data types to function effectively. Traditional Zero Trust implementations cannot easily distinguish between legitimate AI analysis patterns and unauthorised data access.

Organisational credential control as structural solution

The fundamental issue is that healthcare organisations allow AI systems—like human users—to hold and present their own access credentials. Once an AI platform possesses database passwords, API keys, or authentication certificates, the healthcare organisation loses control over how those credentials are used.

MyCena's approach inverts this model. Rather than allowing AI systems to hold credentials, the organisation retains complete control over authentication. Each time an AI diagnostic tool needs patient data access, it requests permission from the central credential authority. The organisation validates the request, grants temporary access, and maintains continuous oversight of AI authentication patterns.

This model means AI systems never possess persistent credentials that could be compromised, misused, or overlooked during security audits. Healthcare IT departments gain real-time visibility into which AI tools access what patient data, when access occurs, and whether usage patterns align with clinical protocols.

The approach addresses regulatory requirements by creating audit trails for every AI authentication event. When regulators investigate patient data access, healthcare organisations can demonstrate granular control over AI system permissions rather than relying on static credential assignments.

Implications for healthcare leadership

Healthcare executives should assess their AI credential governance immediately. Map every AI diagnostic tool, automated clinical system, and machine learning platform currently accessing patient data. Document what credentials these systems possess and who controls access permissions.

Establish policies for AI system authentication that align with clinical governance structures. AI tools should not possess permanent patient data access any more than temporary clinical staff should receive unrestricted database permissions.

Budget for AI-specific access control solutions. Traditional healthcare IT security tools cannot adequately govern the credential patterns that AI systems require. Investment in appropriate governance infrastructure will prove less costly than regulatory penalties or breach remediation.

The integration of AI into healthcare delivery is inevitable. Ensuring proper governance of AI credentials is not.

By | Posted on: 7 May 2026

AI collections agents hold client credentials. The BPO carries the liability.

Last month, a major debt collection agency serving Fortune 500 clients discovered that AI-powered virtual agents had been compromised through credential theft. The breach exposed payment arrangements for over 180,000 consumers across twelve client portfolios. While the AI system performed flawlessly, hackers had simply phished the human operators' login credentials to access client databases. The collections firm now faces regulatory scrutiny from the CFPB and potential contract termination from three major clients.

This incident illustrates a critical vulnerability in business process outsourcing: when AI agents require human-controlled credentials to access client systems, the managed service provider inherits unlimited liability for credential security failures.

The BPO credential control paradox

In managed services, operational efficiency demands that staff can quickly access multiple client environments. Collection agents juggle between CRM systems, payment processors, regulatory databases, and client-specific platforms. Many BPOs have deployed AI agents to automate routine tasks—payment plan calculations, compliance checks, and customer communications—but these systems require the same privileged access as human operators.

The conventional approach involves issuing individual credentials to staff, who then authenticate AI agents to perform automated tasks. This creates a chain of credential custody that begins with human employees and extends to artificial intelligence systems. When credentials are phished, stolen, or misused, the AI agent becomes an amplification vector for the breach.

For BPO providers, this represents an asymmetric risk equation. They control neither the credential creation process nor the client systems being accessed, yet bear full contractual liability for security failures. Client contracts typically include broad indemnification clauses covering data breaches, regulatory violations, and system compromises originating from the managed service provider's environment.

Quantifying the credential risk

Recent data from the Identity Defined Security Alliance reveals that 84% of organizations experienced identity-related breaches in 2023, with credential theft accounting for the initial attack vector in 61% of incidents. For BPO operations, the exposure is particularly acute.

According to Verizon's 2024 Data Breach Investigations Report, managed service providers experienced a 47% increase in credential-based attacks compared to the previous year. The financial services BPO sector—including debt collection, loan processing, and customer service—recorded the highest incident rates, with 73% of breaches originating from compromised employee credentials.

The Ponemon Institute's Cost of a Data Breach Report 2024 found that credential theft incidents in managed services environments cost an average of $4.8 million per breach, 23% higher than the global average. This premium reflects the complex multi-client nature of BPO operations, where a single credential compromise can cascade across multiple client environments.

Regulatory enforcement data compounds the concern. The Consumer Financial Protection Bureau issued 34 consent orders against debt collection operations in 2023, with credential security failures cited in 68% of cases. The FTC's Section 5 enforcement actions against BPO providers increased by 31% year-over-year, predominantly targeting inadequate access controls.

Why conventional security tools fail

Identity and Access Management (IAM) systems provide authentication and authorization but cannot prevent users from sharing, writing down, or inadvertently disclosing their credentials. Even sophisticated IAM platforms rely on users maintaining credential security—a dependency that creates systemic vulnerability.

Privileged Access Management (PAM) solutions excel at securing administrative accounts but typically exempt operational users like collections agents, customer service representatives, and data processors. PAM systems also require users to initially authenticate with personal credentials before accessing privileged resources, preserving the fundamental weakness.

Single Sign-On (SSO) reduces credential proliferation but concentrates risk into master credentials. When SSO credentials are compromised—as occurred in the Okta incidents of 2022 and 2023—attackers gain access to all connected systems simultaneously.

Multi-Factor Authentication (MFA) provides additional security layers but remains vulnerable to sophisticated phishing attacks, SIM swapping, and social engineering. The Lapsus$ group's systematic compromise of MFA-protected systems demonstrated these limitations across multiple high-profile targets.

Zero Trust architectures improve network security and access verification but fundamentally depend on initial credential authentication. Zero Trust assumes that credential presentation equals identity verification—an assumption that breaks down when credentials are stolen or shared.

The structural solution

MyCena addresses this fundamental weakness by eliminating user control over credentials entirely. Rather than expecting users to create and safeguard their own access credentials, MyCena generates all credentials centrally, distributes them in encrypted form, and maintains exclusive revocation control.

Under this model, collections agents never see or handle their login credentials. The system automatically injects encrypted credentials into authentication workflows, making phishing attacks technically impossible. Users cannot share what they do not possess, cannot lose what they never held, and cannot be tricked into revealing what remains invisible to them.

For BPO operations, this represents a fundamental shift from managing credential behavior to controlling credential architecture. AI agents can be provisioned with automatically-rotating encrypted credentials that require no human intervention or oversight. When staff turnover occurs—a persistent challenge in collections and customer service operations—credential revocation becomes instantaneous and complete.

The approach transforms the liability equation for managed service providers. Rather than depending on employee security awareness training and behavioral compliance, BPOs can demonstrate technical controls that make credential theft impossible by design. This provides concrete evidence of reasonable security measures for client audits, regulatory examinations, and cyber insurance assessments.

Implications for BPO leaders

The integration of AI agents into managed services operations demands a corresponding evolution in credential security architecture. Traditional approaches that delegate credential control to individual users create unlimited liability exposure for BPO providers.

Organizations should evaluate whether their current security investments address credential custody or merely credential usage. The distinction determines whether AI agents represent operational efficiency or amplified risk vectors.

For BPO executives, the question is not whether credential-based attacks will target their operations, but whether their credential architecture can withstand systematic compromise attempts. The answer increasingly determines client retention, regulatory standing, and operational viability.

MyCena
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.