A recent report from Axonius, in partnership with the Ponemon Institute, revealed a significant security gap: 12.7% of enterprise devices within a median inventory of 298,000 are missing their expected security agents. This absence poses serious risks, especially as SOC and XDR vendors advance autonomous security capabilities that rely on data integrity to operate effectively. The report highlights that while autonomous agents can act quickly, they may be acting on incomplete data, which is concerning as organizations increasingly face confirmed or suspected AI-related security incidents. As the landscape evolves, ensuring comprehensive data governance, as underscored by the CSA’s Agentic Trust Framework, is essential before deploying these autonomous solutions.
Ivanti: Ivanti develops IT and security management solutions focused on endpoint protection, vulnerability response, and device orchestration. Field CISO Mike Riemer has commented on the rapid exploitation timelines for known vulnerabilities in cloud environments, underscoring the need for comprehensive visibility in traditional security controls.
Axonius: Axonius provides a cybersecurity platform for asset discovery, inventory management, and security control integration across enterprise environments. The company collaborated with the Ponemon Institute on its 2026 Actionability Report, which examined gaps in security agent coverage and their implications for automated systems. CEO Joe Diamond highlighted how incomplete visibility creates structural blind spots that autonomous agents will act upon without human oversight.
Joe Diamond: Joe Diamond is the CEO of Axonius, a cybersecurity asset management company. He has discussed the limitations of self-reported security data and the heightened risks posed by autonomous agents operating on incomplete asset inventories in production environments.
Mike Riemer: Mike Riemer serves as Field CISO at Ivanti, an IT and security solutions provider. He has addressed the speed at which known vulnerabilities are targeted in real-world networks and the continued relevance of established security measures when properly scoped.
Data Governance: The CSA’s Agentic Trust Framework requires verified data governance before agents can act on security findings.
AI Integration Risk: Organizations are encountering confirmed or suspected AI-related security incidents as they deploy agents with varying levels of approval and oversight.
Autonomous Deployment: SOC and XDR vendors are increasingly pushing autonomous investigation and remediation capabilities into production environments.
