CIO Influence
CIO Influence News Machine Learning Security

Quest Software Takes Aim at Rogue AI Agents as Identity Security Threats Drive 90% of Cyber Incidents

Quest Software Takes Aim at Rogue AI Agents as Identity Security Threats Drive 90% of Cyber Incidents

Quest logo

Quest gives enterprises NIST-aligned platform to expose identity risk, stop attacks from spreading and recover critical operations faster

Quest Software announced a major expansion of the Quest Security Management Platform, extending identity security across the full NIST Cybersecurity Framework lifecycle so enterprises can stay in control as AI agents gain greater access and autonomy. The unified platform was built over the last 18 months in response to emerging rogue AI agent threats and helps organizations limit the blast radius of attacks and accelerate recovery. AI agents are multiplying the number of identities that require governance, monitoring, and protection.

“The OpenAI and Hugging Face incident was the first of many warnings to companies that any AI agent in your enterprise can cause a serious breach,” said Tim Page, CEO of Quest Software. “AI has created an identity security crisis exposing the limits of legacy systems and making modern resilience an urgent priority. The leaders that prioritize this now are the ones that will lead the agentic era with confidence.”

Microsoft Active Directory and Entra ID remain the identity control plane for most enterprises, governing access across human, non-human and increasingly agentic identities. Legacy endpoint detection and response (EDR), SIEM and enterprise backup were not designed to understand and act within that identity layer. Quest is purpose-built to address identity-specific risks, contain compromised access and recover trusted AD and Entra ID environments while working alongside the broader enterprise security stack.

“Identity has become the front line of security in the AI era, and defending it takes a strong ecosystem of partners building alongside Microsoft,” said Edwin Vargas, Managing Director, Americas โ€“ AI Business Solutions and Security Partnerships, Microsoft.

Also Read:ย CIO Influence Interview with John Elliott, Cybersecurity Author Fellow at Pluralsight

Five new capabilities across the identity-security lifecycle

  • Quest Identity Insights incorporates technology from Quest’s June 2026 acquisition of Anetac to continuously map what human, non-human and agentic identities actually access. It reveals hidden paths to critical systems that periodic scans and configuration-based approaches can miss.
  • Agentic AI Defense autonomously isolates a compromised identity while an attack is underway, helping prevent it from making destructive changes while analysts investigate and respond.
  • Secure Replay, now in private preview, uses AI to distinguish malicious changes from legitimate activity so organizations can recover toward the last known safe state rather than simply restoring an older backup.
  • Quest Guardian Managed Recovery Services addresses the human side of resilience, giving organizations access to Quest or partner expertise to prepare for and execute Active Directory and Entra ID recovery. Quest Guardian Managed Recovery is also available as a fully managed service that partners can white-label and deliver under their own brand, extending Quest’s recovery expertise through the partner ecosystem. Quest’s 2026 State of ITDR study found that more than 75% of organizations lack a tested recovery plan, a significant exposure when compromise of the identity control plane can disrupt access across the enterprise.
  • Quest Secure Migration embeds Identity Defense threat signals directly into the migration workflow, flagging excess privileges, stale accounts and vulnerable devices before cutover, so organizations mitigate legacy exposure during consolidations and M&A, an increasingly targeted moment for attackers.

“Companies need to know in real time who has the keys to their systems, which doors they can open and how to take those keys away before the damage spreads,” said Rakesh Shah, vice president of Product Management and Marketing at Quest Software. “AI agents can hold credentials, reach sensitive systems and act at machine speed. If an agent can be given the keys to the business, security teams must be able to see what it is doing, stop it immediately and recover confidently from whatever it changed.”

Quest supports the bipartisan Stop Rogue AI Act, introduced by Reps. Josh Gottheimer (D-N.J.) and Mike Lawler (R-N.Y.). The legislation would direct NIST to develop standards, guidelines and best practices for securely deploying AI agents, including continuous inventories, verification of agent activity and tamper-resistant records. Those principles closely align with Quest’s approach to identity visibility, control and accountability.

According to its research, Quest identity-security technology can improve recovery time by up to 90% compared with enterprise backup tools. The company has spent more than 25 years protecting Active Directory and Microsoft Entra ID environments. A 10-time Microsoft Partner of the Year and member of the Microsoft Intelligent Security Association, Quest integrates with Microsoft Sentinel and Security Copilot and works alongside Defender for Identity. Quest identity protection and recovery capabilities are also available through a FedRAMP High authorized offeringย for public-sector and other highly regulated environments.

Catch more CIO Insights:ย How Are CIOs Aligning Technology with Workforce Agility?

[To share your insights with us, please write toย psen@itechseries.com ]

Related posts

Hazelcast to Highlight How to Accelerate Measurable Business Outcomes from Investments in Kafka for Streaming Data

GlobeNewswire

Lexar Appoints Compuage Infocom as Its Indian Distributor

CIO Influence News Desk

Nโ€‘able Expands Its Technology Alliance Program with New Integrations, Advancing Incident Response and Hyperautomation

Ancy Nadar