Back Morningstar Netwrix 2026 Data and Identity Security Report: AI Adoption Outpacing AI Readiness ...
Only 11% of organizations report full AI security readiness, while 17% remain entirely unprepared and 45% are still developing governance programs.
FRISCO, Texas , June 10, 2026 /PRNewswire/ -- Netwrix, a recognized leader in identity and data security, today released its 2026 Data and Identity Security Report, drawing on responses from 2,317 IT and security professionals across 1,889 organizations in more than 60 industries worldwide.
Among organizations where AI significantly expanded the number of identities requiring access, breach rates reached 43% over the past twelve months, compared with 11% where AI had not materially changed access patterns. The gap persisted even among organizations that were ahead on core security practices, including data visibility and non-human identity governance.
"Organizations where AI expanded access saw four times the breach rate of those where it didn't, 43% versus 11%," said Grady Summers, CEO of Netwrix. "The root cause here is speed. AI adds identities and accesses data faster than human-paced reviews can track them, and attackers can create an impact in seconds. Governance has to run at that speed or it's just theater."
2026 Data and Identity Security Report Highlights
76% of organizations do not fully govern or monitor non-human identities. 75% of sensitive data exposures begin with compromised identities or misconfigured permissions, and 76% of organizations can't immediately revoke standing access when it is no longer needed.
74% of organizations lack a unified view of sensitive data and the identities that can access it. 70% have no unified strategy connecting identity and data visibility, making it difficult to know what AI is touching or who can reach it.
Only 11% have operationalized AI governance through continuous enforcement and monitoring. Only 19% fully govern non-human identities, and only 20% fully monitor employee use of shadow AI.
Only 23.5% of organizations can respond at the speed attackers move. Nearly 63% require between one and three days to remediate identified risks.
Organizations with 500 to 999 employees reported a 40.3% breach rate, the highest of any size segment. Technology, healthcare, and construction reported the highest breach rates by industry. In North America, 24% of breached organizations reported losses of at least $100,000 in the past year; 12% reported losses above $250,000.
Data, Identity & AI Security Assessment
Netwrix today also launched the Data, Identity & AI Security Assessment, a free benchmarking tool that evaluates organizations across 12 security dimensions and five maturity tiers for AI readiness. Participants receive a personalized assessment of their current posture, key areas of exposure, and recommended steps.
Additional Resources:
The Netwrix 2026 Data and Identity Security Report was produced by Netwrix Research Lab. Netwrix surveyed 2,317 security professionals globally in early 2026, benchmarking 1,889 organizations across more than 60 industries, five maturity tiers, and 12 security dimensions. Respondents by region: Americas 68%, EMEA 23%, APAC 9%.
Netwrix's vision is to create a world where every organization has secured its data and identities. The 1Secure™ SaaS platform unifies identity and data security to provide complete visibility into where data lives, who can access it, and how it's governed. With Netwrix, security teams strengthen data protection, safeguard identities, and stay ahead of evolving threats. Today, more than 13,000 customers, including nearly 25% of the Fortune 500, rely on Netwrix solutions across hybrid and AI-driven environments. With a 95% customer satisfaction rating, Netwrix offers flexible delivery models that are quick to deploy, easy to use, and built to scale for organizations of all sizes. For more information visit .
Natalie Reina Director of Public Relations, Netwrix [email protected]
Dzmitry Varennikau Senior PR Manager (US & EMEA), Netwrix [email protected]
View original content to download multimedia:
The articles, information, and content displayed on this webpage may include materials prepared and provided by third parties. Such third-party content is offered for informational purposes only and is not endorsed, reviewed, or verified by Morningstar.
Morningstar makes no representations or warranties regarding the accuracy, completeness, timeliness, or reliability of any third-party content displayed on this site. The views and opinions expressed in third-party content are those of the respective authors and do not necessarily reflect the views of Morningstar, its affiliates, or employees.
Morningstar is not responsible for any errors, omissions, or delays in this content, nor for any actions taken in reliance thereon. Users are advised to exercise their own judgment and seek independent financial advice before making any decisions based on such content. The third-party providers of this content are not affiliated with Morningstar, and their inclusion on this site does not imply any form of partnership, agency, or endorsement.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
