Cisco Acquires Astrix to Lead Non-Human Identity Security

The News

Cisco has acquired Astrix Security, a specialist in non-human identity (NHI) security and AI agent authorization, and briefed analysts on how the deal fits into its broader agentic AI security strategy. The acquisition brings Astrix’s capabilities for visibility, identity management, and policy enforcement across machine-to-machine connections into Cisco Cloud Control, the company’s unified platform for what it is calling “AgenticOps.” The briefing framed this as a direct response to the expanding attack surface created by AI agents, service accounts, API keys, OAuth tokens, and other non-human identities proliferating across enterprise environments.

Analyst Take

The NHI problem is real, and it’s growing fast

As enterprises deploy AI agents at scale, the identity perimeter has fundamentally shifted. Human users are no longer the dominant access vector. Service accounts, API integrations, CI/CD pipelines, and autonomous AI agents now generate the majority of authentication events in mature cloud environments, yet most identity governance programs were built exclusively for humans. Astrix was one of a small number of vendors focused specifically on discovering, classifying, and governing these non-human identities, making it a credible strategic target.

The security risk here is concrete. ECI Research’s 2026 DevSecOps & AppSec survey found that 45.3% of respondents said AI-assisted development had “increased risk moderately,” with another 17.2% reporting it had “increased risk significantly.” That is nearly two-thirds of surveyed organizations acknowledging that AI tooling has made their security posture worse, not better. AI agents that can autonomously call APIs, write to datastores, and trigger downstream workflows represent the next escalation of that same dynamic. Cisco is betting that identity governance for agents becomes a board-level concern within the next 18 months. That is a reasonable bet.

What Cisco gets from Astrix, technically

Astrix brought three things Cisco did not have in sufficient depth: continuous discovery of non-human identities across SaaS and cloud environments, risk scoring for over-permissioned service accounts and stale OAuth grants, and automated remediation workflows that can revoke or rotate credentials without human intervention. Folding this into Cisco Cloud Control means customers can, in theory, see a unified policy surface across human identities (via Duo), network access (via Cisco’s broader security portfolio), and now machine-to-machine authorization. That architectural convergence matters. Fragmented tooling is a persistent pain point: ECI Research’s 2026 Application Development survey found that 47.4% of respondents identified software supply chain security as a top investment priority for the next 12 months, reflecting the pressure organizations feel to close exactly these kinds of lateral movement risks before an agent-driven incident forces their hand.

The integration question is the one analysts should watch closely. Astrix’s core value was its agentless, API-based discovery model, which let it map NHI relationships without requiring deep instrumentation. Whether Cisco preserves that lightweight approach inside Cloud Control, or gradually assimilates it into a heavier platform dependency, will determine whether the capability retains its appeal for customers who are not already deep in the Cisco stack.

Who wins and who should care

For ITDMs, the acquisition signals that Cisco is serious about owning the AgenticOps security layer, and that organizations delaying NHI governance programs are accumulating technical debt with real breach-risk attached. The Cisco bundle play is attractive for enterprises already standardized on Duo and Splunk, because it reduces the number of vendors in the identity security conversation. The flip side is that best-of-breed buyers who evaluated Astrix as a standalone product now face a different vendor relationship and roadmap.

For developers and platform engineers, the practical implication is that AI agent permissions will increasingly be subject to the same policy-as-code enforcement that governs human access. That means secrets management, OAuth scope reviews, and agent permission audits will need to move left in the development lifecycle, not remain a post-deployment concern.

Looking Ahead

Cisco’s acquisition of Astrix is an early but significant move in what will become a crowded NHI security market. Expect CrowdStrike, Palo Alto Networks, and a wave of identity-focused startups to sharpen their own NHI messaging over the next two to three quarters. The companies that articulate a coherent story connecting human identity, machine identity, and AI agent authorization inside a single control plane will win the largest enterprise deals. Cisco now has the components to tell that story; execution on Cloud Control integration will determine whether it translates into durable revenue.

The longer arc here is about regulatory pressure. As AI agents take on more autonomous decision-making authority inside enterprise systems, governance requirements around who (or what) authorized a given action will intensify. Data sovereignty laws, NIST frameworks, and sector-specific compliance regimes are already influencing release engineering at the majority of organizations surveyed by ECI Research. Non-human identity governance will be folded into those same compliance frameworks within the next 12 to 24 months. Cisco, with Astrix in hand, is positioning itself to be the audit trail for the agentic enterprise. That is a strategically sound place to be.

Authors

  • Paul Nashawaty

    Paul Nashawaty, Practice Leader and Lead Principal Analyst, specializes in application modernization across build, release and operations. With a wealth of expertise in digital transformation initiatives spanning front-end and back-end systems, he also possesses comprehensive knowledge of the underlying infrastructure ecosystem crucial for supporting modernization endeavors. With over 25 years of experience, Paul has a proven track record in implementing effective go-to-market strategies, including the identification of new market channels, the growth and cultivation of partner ecosystems, and the successful execution of strategic plans resulting in positive business outcomes for his clients.

    View all posts
  • With over 15 years of hands-on experience in operations roles across legal, financial, and technology sectors, Sam Weston brings deep expertise in the systems that power modern enterprises such as ERP, CRM, HCM, CX, and beyond. Her career has spanned the full spectrum of enterprise applications, from optimizing business processes and managing platforms to leading digital transformation initiatives.

    Sam has transitioned her expertise into the analyst arena, focusing on enterprise applications and the evolving role they play in business productivity and transformation. She provides independent insights that bridge technology capabilities with business outcomes, helping organizations and vendors alike navigate a changing enterprise software landscape.

    View all posts