1Password surveyed 500 American IT and security professionals and 500 developers to learn how organizations are adopting and governing AI for their most technical workers.
Every security team has tried to trace a credential access event back to a specific workload, and received nothing but a "service account." That service account probably had access to an entire vault, and its audit trail doesn’t tell you which repo triggered the request, which specific credential was accessed, or whether the workflow still has access. When an auditor asks, or an incident occurs, that's not a good place to be.
You're staring at a spreadsheet full of screenshots, exported CSVs, and half-finished owner assignments, while the auditor wants one clean answer to a simple question, can you prove the control worked when it mattered? That's the gap compliance automation software is built to close in security programs that can't afford guesswork, especially when logs, cloud settings, identity events, and policy evidence all live in different places.
Most cyber investigations don’t begin at the beginning. Rather, they begin at the end, after systems are locked, data is exposed, and operations have already been disrupted. The outcome is visible, but the cause is not. From there, everything becomes a process of working backward on an incomplete picture. That’s the unique puzzle that keeps Devon Ackerman, Global Services Leader of Digital Forensics and Incident Response (DFIR) firmly planted in the world of chaos every day.
AI didn’t just change how fast you ship. It changed what your AI application security program has to protect. Two years ago, security teams protected code, open source, and containers. Today they also have to protect AI agents, MCP servers, models, prompts, and runtime interactions, configured or deployed faster than any team can manually review. The attack surface didn’t grow. It exploded.
If there’s one thing all of us can agree about modern security, it is that penetration testing is no longer a once-a-year activity. Modern attack surfaces do not stay still. New code ships faster, cloud infrastructure is constantly changing, and APIs are multiplying across product ecosystems. To keep up, engineering teams have moved security earlier in the development lifecycle through shift-left practices.
Like most infrastructure, the Internet's fragility is easy to overlook — as long as it's working. When it fails, its complexity comes into full view. Cloudflare is in a unique position to detect and document the moments when one of the interrelated systems the Internet depends on breaks down and connectivity suffers as a result. Each quarter, we summarize the disruptions we detect and annotate on Cloudflare Radar.
Ask most security leaders how their last significant budget increase came about, and the honest answer is rarely "we made the case and won it." It's usually "something happened." A breach, a near-miss, a competitor's headline, an audit finding that couldn't be ignored or a new regulation with a deadline attached. Security spend still moves in response to events far more often than it moves in response to argument, and that has quietly shaped how the function operates: always slightly behind the risk, always justifying itself against the last incident rather than the next one.