Skip to main content

Aug 7, 2026

The Blast Radius Problem

Mike Britton

The blast radius problem makes this urgent. Harrison describes what a compromised, over-permissioned agent actually means: "If you have autonomous agents broadly connected in your environment — agents that can perform tasks, take calls broadly from your workforce — that's the first place I'm going as an attacker. I'm going there to stage persistence, deliver payloads, figure out what actions I can perform, provision access." The blast radius isn't a corner of the environment. It's the whole thing.

Britton lands the same problem from the governance architecture side: agents don't come with org charts. "I know Ryan's role, I know his job responsibilities, I know what systems he has access to. When it comes to agents — who owns that agent, what part of the org does that agent work for, what systems should they have access to? It just becomes a lot murkier and more convoluted." The credential is real. The permissions are real. But there's no person, no role definition, no accountability structure — and so there's no baseline against which anomalous behavior is detectable until it's already too late.

Who owns that agent, what part of the org does that agent work for, what systems should they have access to? It just becomes a lot murkier and more convoluted.

— Mike Britton · CIO

 

The operational reason for that hygiene failure is more specific than it sounds. Jesus Garcia, Abnormal AI's Solutions Architect, describes what happens when a security team tries to rotate a service account that's been in production for five or six years: "Sometimes the current owner wasn't the person that implemented it. There's no documentation. They don't know all the locations where that username and password has been hard-coded in."

"There's hesitation — almost a confrontation between IT and security teams — when trying to perform just basic password hygiene tasks. And while IT and security is discussing all this, the malicious actors are there to take full advantage."

— Jesus Garcia, Solutions Architect, Abnormal AI

The access review process that worked for human identities—periodic audits, entitlement reports, the occasional regulator finding—has no equivalent for machine identities in most environments. You can't review what you can't see, and you can't see what you never thought to track.

Protect Against Evolving Email Threats

See how behavioral AI detects attacks that legacy defenses miss.