Cybersecurity Awareness Month Focus: A Blueprint for Building Resilience in the Agentic AI Era

September 29, 2026

“Securing your business” has been a central theme of Cybersecurity Awareness Month for years. But as organizations embrace AI and, increasingly, autonomous technologies, what it takes to achieve that goal is changing rapidly.

 

The fundamentals recommended by the Cybersecurity & Infrastructure Security Agency (CISA) still matter: avoid and report phishing scams, use strong passwords, implement multifactor authentication (MFA) and a password manager, and keep software up to date. These practices remain essential because attackers continue to exploit the human vulnerabilities and technology gaps they have targeted for years.

 

But they are no longer enough. The rise of generative and agentic AI is introducing new identities, interactions and attack paths that traditional security architectures were never designed to address. As these systems become more deeply embedded in business operations, organizations must rethink not only how they protect technology, but also how they establish trust, govern data and respond to threats.

 

This October, cybersecurity awareness needs to extend beyond the fundamentals. Organizations need the building blocks for cybersecurity resilience in the era of agentic AI.

 

Here are three key elements of a blueprint security leaders can use to evaluate their readiness for the agentic era.

 

1. Identity Security

 

In traditionally human-centric environments, attackers have relied heavily on phishing, credential theft and social engineering to exploit psychological vulnerabilities. To defend against these threats, organizations focused on stronger passwords, MFA, access controls and security awareness training.

 

But the identity landscape is changing. One of the most significant shifts in cybersecurity is the rapid growth of machine-to-machine communication driven by APIs, applications, workloads and automated services. The attack surface is no longer limited to users and infrastructure. It increasingly includes APIs, machine identities, AI agents, autonomous workflows, service accounts and the permissions granted to them.

 

This is why identity—not the network perimeter—is becoming the critical enforcement layer. 

 

Organizations now need to secure the entire identity lifecycle, spanning both human and machine identities. That means moving away from implicit trust and toward continuous verification. Rather than assuming a user, workload or agent is trustworthy because it resides within an approved network or environment, organizations must evaluate whether each request is legitimate based on identity, context, authorization and security posture.

 

In a machine-driven environment, trust is no longer granted; it must be continuously proven.

 

What security leaders can do now

Start by expanding your definition of identity beyond employees, partners and customers. Build an inventory of the human and non-human identities operating across your environment, including service accounts, workloads, APIs, applications and AI agents.

 

Then ensure that every identity—human or machine—has only the access it needs, for only as long as it needs it, and that trust can be withdrawn when conditions change.

 

2. Data Security

 

For decades, enterprise data governance models were built around predictable systems: known datasets, defined users, static permissions and linear workflows. AI fundamentally challenges these assumptions. 

 

AI systems can ingest vast amounts of data, infer relationships, generate new content and take action based on what they learn. Agentic AI takes this a step further, giving systems the ability to access data, interact with applications and make decisions with increasing autonomy. Data can move across applications, cloud environments, APIs and AI agents at machine speed, often in ways traditional governance models were never designed to track.

 

The result is a growing governance gap between how AI operates and how organizations govern their data.

 

Closing that gap requires organizations to establish a strong data security foundation built around three interconnected disciplines:

 

  • Data discovery and inventory management – Effective governance begins with visibility. Organizations must understand what data they collect, create and retain; where it resides across on‑premises, cloud, SaaS and collaboration platforms; how it is accessed, processed, shared and protected; and what regulatory and contractual obligations apply. Without a clear understanding of the data landscape, organizations cannot effectively determine what AI systems should be permitted access.

 

  • Data protection and privacy safeguards – Visibility must be paired with consistent, risk-based controls. This includes classifying and labeling data according to business risk; enforcing least-privilege access and regularly reviewing entitlements; applying encryption and information protection; establishing appropriate retention and defensible deletion policies; and using monitoring, data loss prevention (DLP) and insider-risk controls to detect inappropriate access or movement of sensitive information. 

 

  • AI governance and risk management – Organizations also need governance mechanisms specifically designed for AI. This includes establishing AI governance charters and cross-functional oversight committees; implementing use-case intake and risk tiering; conducting AI impact assessments and algorithm audits; documenting models and tracking their lifecycle; and continuously monitoring for bias, drift, unexpected behavior and misuse. 

 

In the agentic era, protecting data is no longer simply about preventing unauthorized access. It is about ensuring that the right data reaches the right system, for the right purpose, under the right controls as well as empowering organizations to see and respond when those boundaries change.

 

What security leaders can do now

Begin by identifying where your most sensitive data is and where AI can reach it. From there, map which AI applications and agents can access that data, identify gaps in permissions and monitoring, and prioritize controls around the highest risk use cases. Establish clear ownership for those controls and review them regularly as AI systems, data flows and agent capabilities evolve.

 

The goal is not simply to lock data down. It is to create enough visibility and control to enable responsible AI adoption without allowing access to sensitive information to outpace governance.

 

3. Security Operations Center (SOC) Modernization 

 

Cybersecurity is no longer simply about stopping bad actors at the perimeter. In an increasingly automated environment, organizations also need to prevent trusted users, applications, workloads and AI agents from executing compromised or unauthorized instructions.

 

The challenge is scale and speed. Machines can generate activity, interact with systems and propagate changes far faster than human analysts can manually investigate. Human expertise remains essential, but the role of the security practitioner is evolving from manually processing every alert to providing oversight, judgment and strategic direction while automation handles repetitive tasks at machine speed.

 

Organizations need to evolve traditional managed detection and response (MDR) into a modern, AI-powered security operations model that can continuously evaluate, prioritize, investigate and respond to risk before it becomes an incident.

 

Rather than simply monitoring alerts, a modern SOC can leverage agentic AI and automation to investigate security events, enrich alerts with contextual intelligence, correlate activity across disparate environments, conduct follow-on analysis and recommend or initiate response actions. This enables security teams to move beyond reactive alert monitoring to achieve a connected, continuously improving security operations program that accelerates response while keeping experienced security practitioners in control.

 

In the agentic era, SOC modernization ultimately means creating a security operation that can detect, investigate and respond to threats faster and more effectively to proactively reduce cyber risk and continuously strengthen security posture.

 

What security leaders can do now

You don’t need to transform your entire SOC overnight. Start by identifying where automation and AI can eliminate the most manual work without compromising human oversight.

 

The objective is a human-led, AI-augmented security operation that can respond at machine speed without surrendering human judgment.

 

 

Use Cybersecurity Awareness Month as a Launch Pad

Cybersecurity Awareness Month provides a natural opportunity to step back from day-to-day security operations and assess whether your organization is prepared for what comes next.

 

Start with the fundamentals but build beyond them.

 

Secure identity so you know who—and what—is accessing your environment.

 

Secure data so AI systems can use information responsibly without exceeding established boundaries.

 

Modernize security operations so your SOC can detect, investigate and respond at the speed of an increasingly automated environment.

 

Together, these capabilities create a foundation for cybersecurity resilience in the agentic AI era.

 

Optiv helps organizations assess, design and modernize their security programs through an Advise, Deploy, Operate model grounded in real-world experience, cross-industry expertise and best-in-class technology. Whether you're beginning to explore agentic AI or already deploying autonomous systems across your environment, Optiv can help you build a security strategy designed for what comes next.

 

Contact Optiv to start building your blueprint for cybersecurity resilience.

VP, Chief Information Security Officer
Rob Gregory — VP, Chief Information Security Officer

Rob Gregory has nearly 20 years of experience across numerous areas of cybersecurity, with a strong emphasis on cyber strategy, organizational resilience and executive communication around cyber’s impact on business objectives. Prior to Optiv, Gregory held leadership positions in multiple sectors in the financial industry and was most recently CISO of an insurance company.

Gregory began his cybersecurity career in the U.S. Army, where he rose to the rank of chief warrant officer and led multinational teams in global joint operations. He enforced compliance with DoD, NIST and ISO standards across an organization of more than 4,000 users.

About Optiv Security: Secure greatness.® 
Optiv is the world’s largest pure-play cybersecurity company. With unmatched technology partnerships and deep technical expertise, Optiv securely enables the AI era for more than 6,000 clients. From financial services and health care, to government, energy and retail, organizations trust Optiv to advise, deploy and operate cybersecurity programs that reduce risk and deliver real results. Learn why Optiv is the most trusted brand in cyber at optiv.com.