Aktuelles, Branche - Dienstag, August 11, 2026 0:59 - noch keine Kommentare
AI incidents are merely symptoms – IT security must focus on identities
In light of the rise in incidents involving rogue AI models, Elmar Eperiesi-Beck recommends modern ‘identity and access management’ to ensure that all identities are always recorded and that, should the worst happen, all access can be completely blocked
[datensicherheit.de, 08|11|2026] Elmar Eperiesi-Beck, CEO of Bare.ID, also addresses threatening incidents involving AI systems in his latest commentary: “From within a test environment, Anthropic’s AI models gained unauthorised access to real data from organisations’ actual systems. The shocking thing about this is that a security analysis revealed that inadequately secured identities had allowed access to production systems, which were subsequently compromised as a result.” He therefore recommends that organisations implement a modern ‘Identity and Access Management’ (IAM) system so that they can comprehensively record all identities, manage their access rights, or completely block access in the case of unknown or compromised identities.

Foto: Bare.ID
Elmar Eperiesi-Beck warns that the benefits of AI seem to be overshadowing the risks posed by new technologies
The expansion of AI and the rise of non-human digital identities are fuelling uncontrolled proliferation
He takes a comparative look back: “Just a few years ago, companies took great care to ensure that machines or devices that were difficult to secure – such as IoT devices – were not connected to the network, let alone the internet.”
Today, however, the expansion of artificial intelligence (AI) and non-human digital identities in particular is leading to a rapid and uncontrolled proliferation of potentially dangerous situations.
“What companies used to regard as a risk for their IoT systems is now of little concern to most, given the growing number of non-human identities. The benefits of AI seem to be overshadowing the risks posed by new technologies.”
Recommendations for the consistent application of existing standards for AI and IoT identity management
However, whether it is traditional IoT or AI with non-human identities, the principle remains the same: “Digital identities of any kind must be carefully checked, granted the most restrictive rights possible, or completely restricted online!” The sheer volume of identities, however, means that organisations can no longer manage them manually. A modern IAM system could provide crucial support at this stage by identifying all identities, managing their access rights, or completely blocking access in the case of unknown or compromised identities.
Eperiesi-Beck raises a key question: “If even companies like Anthropic – which one might assume are fully aware of the potential risks associated with digital identities – make such mistakes, how is a traditional commercial enterprise, whose core business is not AI, supposed to do any better?”
In conclusion, he gives the following answer: “Quite simply: by implementing a tried-and-tested – and ideally even robust – IAM solution that reduces risks arising from unidentified and poorly managed access paths, and by consistently applying existing standards for AI and IoT identity management, which are, after all, already in place.”
Key findings:
- Enthusiasm for the possibilities offered by the new virtual tool, AI, could push precautionary measures into the background.
- Just as in the physical world, tools have a ‘dual-use’ nature – they can be used for good or for harm.
- As IT Security managers must always assume that an incident will occur, they should take appropriate preventive measures.
- Identity management is a fundamentally sound preventative measure in the context of IT security.
- When it comes to the use of AI, too, the principle ‘Hope for the best, but always be prepared for the worst!’ applies.
More information on this topic:
Linkedin
Elmar Eperiesi-Beck – Executive Digital & Security Thought Leader • Entrepreneur • Startup Advisor
tagesschau, 08|06|2026
Nach Anthropic und OpenAI Auch KI von Meta dringt in fremdes System ein
datensicherheit.de, 08|09|2026
Offene Türen für KI-Agenten schließen – das SANS Institute gibt IT-Sicherheitsteams Empfehlungen / Inzwischen häufen sich die Berichte von KI-Anbietern, deren -Agenten aus den Testumgebungen ausbrechen und andere Software-Anbieter hacken
datensicherheit.de, 08|07|2026
Claude-Phishing-Vorfall durch Versagen grundlegender KI-Sicherheitsarchitektur ermöglicht / Laut Medienberichten hatte die KI „Claude“ bei einem Sicherheitstest unerwarteten Zugang zum öffentlichen Internet erlangt
datensicherheit.de, 08|03|2026
„Claude“-Ausbrüche mahnen: KI-Modelle durch „Zero Trust“ einhegen / Sobald ein autonomer KI-Agent eine kontrollierte Umgebung verlassen kann, nimmt er die Grenzen einer Organisation nicht auf die gleiche Art und Weise wahr wie Menschen
datensicherheit.de, 08|03|08.2026
KI-Systeme: Wer testet, haftet für die Folgen / KI-Unternehmen müssen nun die richtigen „Leitplanken“ installieren, damit ihre Produkte nicht zur Gefahr werden
weitere aktuelle Artikel
- KI-Vorfälle nur Symptome – IT-Sicherheit muss auf Identitäten fokussieren
- Nach 8 Monaten NIS-2 deutet eco-Stimmungsbild auf Umsetzungshürden hin
- Führungskräfte ins Visier: Ransomware-Akteure zielen auf Inhaber privilegierter Rechte
- Bedrohlicher Trend: Meta-KI-Hack aktuelles Beispiel für potenziell verhängnisvolle Entwicklung
- 6 Strategies for Maintaining Cyber Resilience During Peak Vacation Periods
- 6 Ratschläge zur Sicherung der Resilienz auch in Zeiten erhöhter urlaubsbedingter Abwesenheit
- Existenzielle IT-Sicherheit treibt Deutschlands Krankenhäuser zur digitalen Aufrüstung
- Zutrittskontrolle als Governance- und Cybersecurity-Priorität
- KI als Produktivitätstreiber: Beschäftigte gewinnen bis zu acht Stunden pro Woche
- Anstieg der Hardware-Preise in Folge KI-getriebener Halbleiter-Nachfrage
- Claude-Phishing-Vorfall durch Versagen grundlegender KI-Sicherheitsarchitektur ermöglicht
- NIS-2 Compliance: Proven When It Matters Most
- Reges Interesse am 4. KI-Tag der Wirtschaft des Landes Brandenburg
Aktuelles, Experten, Studien - Aug. 11, 2026 0:54 - noch keine Kommentare
Nach 8 Monaten NIS-2 deutet eco-Stimmungsbild auf Umsetzungshürden hin
Der eco hat eine Kurzabfrage unter Unternehmen mit Bezug zu IT-Sicherheit, digitaler Infrastruktur und NIS-2 durchgeführt und die Ergebnisse publiziert
[datensicherheit.de, 11.08.2026] Der eco – Verband der Internetwirtschaft e.V. hat genau acht Monate nach Inkrafttreten von NIS-2 die „etwas schleppende Entwicklung der diese Woche neu veröffentlichten BSI-Registrierungszahlen“ kommentiert – diese könnte demnach darauf hindeuten, dass die Umsetzung für Unternehmen weiterhin herausfordernd ist. Ein aktuelles Stimmungsbild unter Unternehmen aus dem eco-Umfeld bestätige diesen Eindruck: „Es gibt weiterhin deutliche Umsetzungshürden, vor allem bei Dokumentation, Meldeprozessen und Risikomanagement.“ Dieses basiere auf einer eco-Kurzabfrage unter Unternehmen mit Bezug zu IT-Sicherheit, digitaler Infrastruktur und NIS-2 – es gebe einen Eindruck aus der Praxis wieder, ohne einen weiterlesen…
weitere Beiträge in Experten
- Bedrohlicher Trend: Meta-KI-Hack aktuelles Beispiel für potenziell verhängnisvolle Entwicklung
- Anstieg der Hardware-Preise in Folge KI-getriebener Halbleiter-Nachfrage
- Claude-Phishing-Vorfall durch Versagen grundlegender KI-Sicherheitsarchitektur ermöglicht
- Reges Interesse am 4. KI-Tag der Wirtschaft des Landes Brandenburg
- Digitalisierung der Schiene: TÜV-Verband fordert Modernisierung sicherheitsrelevanter Verfahren
Aktuelles, Branche - Aug. 11, 2026 0:59 - noch keine Kommentare
AI incidents are merely symptoms – IT security must focus on identities
In light of the rise in incidents involving rogue AI models, Elmar Eperiesi-Beck recommends modern ‘identity and access management’ to ensure that all identities are always recorded and that, should the worst happen, all access can be completely blocked
[datensicherheit.de, 08|11|2026] Elmar Eperiesi-Beck, CEO of Bare.ID, also addresses threatening incidents involving AI systems in his latest commentary: “From within a test environment, Anthropic’s AI models gained unauthorised access to real data from organisations’ actual systems. The shocking thing about this is that a security analysis revealed that inadequately secured identities had allowed access to production systems, which were subsequently compromised as a result.” He therefore recommends that organisations implement a modern ‘Identity and Access Management’ (IAM) system so that they can comprehensively record all identities, manage their access rights, or completely block access in the case of unknown or compromised identities.

Foto: Bare.ID
Elmar Eperiesi-Beck warns that the benefits of AI seem to be overshadowing the risks posed by new technologies
The expansion of AI and the rise of non-human digital identities are fuelling uncontrolled proliferation
He takes a comparative look back: “Just a few years ago, companies took great care to ensure that machines or devices that were difficult to secure – such as IoT devices – were not connected to the network, let alone the internet.”
Today, however, the expansion of artificial intelligence (AI) and non-human digital identities in particular is leading to a rapid and uncontrolled proliferation of potentially dangerous situations.
“What companies used to regard as a risk for their IoT systems is now of little concern to most, given the growing number of non-human identities. The benefits of AI seem to be overshadowing the risks posed by new technologies.”
Recommendations for the consistent application of existing standards for AI and IoT identity management
However, whether it is traditional IoT or AI with non-human identities, the principle remains the same: “Digital identities of any kind must be carefully checked, granted the most restrictive rights possible, or completely restricted online!” The sheer volume of identities, however, means that organisations can no longer manage them manually. A modern IAM system could provide crucial support at this stage by identifying all identities, managing their access rights, or completely blocking access in the case of unknown or compromised identities.
Eperiesi-Beck raises a key question: “If even companies like Anthropic – which one might assume are fully aware of the potential risks associated with digital identities – make such mistakes, how is a traditional commercial enterprise, whose core business is not AI, supposed to do any better?”
In conclusion, he gives the following answer: “Quite simply: by implementing a tried-and-tested – and ideally even robust – IAM solution that reduces risks arising from unidentified and poorly managed access paths, and by consistently applying existing standards for AI and IoT identity management, which are, after all, already in place.”
Key findings:
- Enthusiasm for the possibilities offered by the new virtual tool, AI, could push precautionary measures into the background.
- Just as in the physical world, tools have a ‘dual-use’ nature – they can be used for good or for harm.
- As IT Security managers must always assume that an incident will occur, they should take appropriate preventive measures.
- Identity management is a fundamentally sound preventative measure in the context of IT security.
- When it comes to the use of AI, too, the principle ‘Hope for the best, but always be prepared for the worst!’ applies.
More information on this topic:
Linkedin
Elmar Eperiesi-Beck – Executive Digital & Security Thought Leader • Entrepreneur • Startup Advisor
tagesschau, 08|06|2026
Nach Anthropic und OpenAI Auch KI von Meta dringt in fremdes System ein
datensicherheit.de, 08|09|2026
Offene Türen für KI-Agenten schließen – das SANS Institute gibt IT-Sicherheitsteams Empfehlungen / Inzwischen häufen sich die Berichte von KI-Anbietern, deren -Agenten aus den Testumgebungen ausbrechen und andere Software-Anbieter hacken
datensicherheit.de, 08|07|2026
Claude-Phishing-Vorfall durch Versagen grundlegender KI-Sicherheitsarchitektur ermöglicht / Laut Medienberichten hatte die KI „Claude“ bei einem Sicherheitstest unerwarteten Zugang zum öffentlichen Internet erlangt
datensicherheit.de, 08|03|2026
„Claude“-Ausbrüche mahnen: KI-Modelle durch „Zero Trust“ einhegen / Sobald ein autonomer KI-Agent eine kontrollierte Umgebung verlassen kann, nimmt er die Grenzen einer Organisation nicht auf die gleiche Art und Weise wahr wie Menschen
datensicherheit.de, 08|03|08.2026
KI-Systeme: Wer testet, haftet für die Folgen / KI-Unternehmen müssen nun die richtigen „Leitplanken“ installieren, damit ihre Produkte nicht zur Gefahr werden
Weitere Beiträge Branche
- KI-Vorfälle nur Symptome – IT-Sicherheit muss auf Identitäten fokussieren
- Führungskräfte ins Visier: Ransomware-Akteure zielen auf Inhaber privilegierter Rechte
- 6 Strategies for Maintaining Cyber Resilience During Peak Vacation Periods
- 6 Ratschläge zur Sicherung der Resilienz auch in Zeiten erhöhter urlaubsbedingter Abwesenheit
- Existenzielle IT-Sicherheit treibt Deutschlands Krankenhäuser zur digitalen Aufrüstung
Aktuelles, A, Experten, Service, Wichtige Adressen - Jan. 13, 2026 1:08 - noch keine Kommentare
Registrierung bei ELEFAND: Krisen- und Katastrophenvorsorge bei Auslandsaufenthalten
„ELEFAND“ dient der Elektronischen Erfassung von Deutschen im Ausland
[datensicherheit.de, 13.01.2026] Die Fides Reisen Lufthansa City Center Global Incoming Network GmbH & Co. KG nimmt aktuelle geopolitische Ereignisse zum Anlass, insbesondere Geschäftsreisenden eine Registrierung beim Auswärtigen Amt (AA) zu empfehlen: Ereignisse – wie etwa Anfang Januar 2026 in Venezuela – zeigten, wie schnell sich die Lage in einem Land ändern kann. Deutsche Staatsbürger sollten sich daher in der AA-Krisenvorsorgeliste „ELEFAND“ registrieren und ihre Daten dort auch stets aktuell halten. Die Notfall-Benachrichtigung per SMS sollte aktiviert sein – und nach Verlassen des jeweiligen Landes sollte ein entsprechender Vermerk vorgenommen werden. weiterlesen…
Weitere Beiträge Service
- DigiCert-Umfrage: Manuelle Zertifikatsprozesse führen zu Ausfällen, Compliance-Fehlern und hohen Verlusten im Unternehmen
- Threat Hunting: Bedeutung und Wertschätzung steigt
- Umfrage: 71 Prozent der IT-Entscheidungsträger besorgt über Mehrfachnutzung von Passwörtern
- Fast die Hälfte der Unternehmen ohne geeignete Sicherheitsrichtlinien für Remote-Arbeit
- Umfrage: Bedeutung der Konsolidierung von IT-Sicherheitslösungen


