Machine identities already outnumber human ones. For organizations without an identity function, the reachable control sits at the network layer.

In access-control terms, an AI assistant that can read a customer database, move files between systems, or call an internal API is a user. It holds credentials, acts on resources, and if it is over-permissioned it becomes one more route into the network that nobody is watching.

Small and midsize companies are wiring these agents into daily operations at speed. Very few have a way to decide what a given bot is allowed to touch.

The scale is no longer arguable. Palo Alto Networks' 2026 Identity Security Landscape, drawn from a survey of more than 2,900 cybersecurity decision-makers, puts machine identities at 109 for every human. The same research found 96% of respondents reporting that human identities operate with access far beyond what their roles require.

109:1 machine identities to human identities, across 2,900+ organizations surveyed Palo Alto Networks, 2026 Identity Security Landscape

That second figure matters more than the ratio. If organizations have not managed to right-size access for identities that belong to named employees, sit in an HR system, and leave on a termination date, the prospect of right-sizing it for autonomous software is remote.

The identity class most SMBs skipped

Zero trust rests on a simple discipline. Trust no connection by default, verify identity and device state on every request, and grant only the access a task requires.

For several years that discipline was aimed almost entirely at people. Enterprises with security teams extended it to service accounts, API keys, and automation. Smaller companies, working without a security operations center, largely did not.

AI adoption is forcing the issue. A copilot that summarizes support tickets needs the ticketing system. An agent reconciling invoices needs financial records. Each integration is a standing credential with a scope someone should be defining, and often nobody is.

These credentials also outlive the work that created them. A departing employee gets offboarded. A bot's access key frequently lingers long after the project that justified it ended, holding permissions no one revisits.

The zero trust principle applies to a bot without modification. It should reach the one system it needs and nothing else, for only as long as it needs it. What has been missing at the smaller end of the market is tooling that enforces this without a specialist to run it, and that is the gap Zero Trust Network Access services from vendors including OpenVPN have moved into.

What agents break that service accounts did not

A static service account has a scope you can write down. That is what makes the inventory-and-attest model work at all.

Agents behave differently. They take sequences of actions, call APIs, spawn sub-agents, and acquire access at runtime that no policy document anticipated. The permission set is a moving target, widening with every integration and every new tool the agent is pointed at.

The credential surface has moved as well. GitGuardian's State of Secrets Sprawl 2026 recorded 28.65 million new hardcoded secrets in public GitHub commits during 2025, a 34% single-year rise and the largest the company has measured. More relevant to agent deployments: the same research found 24,008 unique secrets exposed in MCP configuration files, and roughly 28% of incidents originating outside repositories entirely, in collaboration tools most secrets programs never scan.

Credentials for agents are being created in places nobody is watching, by people who are not on the security team, faster than rotation policy can reach them. GitGuardian also found 64% of valid secrets from 2022 still active.

Compliance and insurance are closing the exit

Smaller organizations cannot simply defer this, because outside parties are removing the option.

The EU's NIS2 directive reaches essential and important entities and their supply chains. DORA covers financial firms and pushes obligations to the technology suppliers serving them. PCI DSS v4.0 applies to any business handling cardholder data, and its future-dated requirements have been mandatory since March 2025. None of these name zero trust. All of them describe its controls: verified identity, least privilege, segmentation, and an auditable record.

A 60-person company selling into a regulated industry usually meets these expectations through a customer's security questionnaire long before a regulator appears.

Insurers apply the same pressure on an annual cycle. Underwriters now want multifactor authentication, least-privilege access, and network segmentation before writing or renewing. For many small businesses the renewal notice is the moment the checklist stops being theoretical.

The tooling was built for someone else

Here the enterprise origins of zero trust become a liability for smaller buyers.

Zscaler, Palo Alto Networks, and Cisco's Duo built platforms sized and priced for large security organizations. The capabilities are real, and so is the assumption that a customer has staff to operate them. A company with one or two IT administrators can end up paying for complexity it cannot run.

At the other end sit connectivity-first tools including Tailscale, Twingate, and NordLayer, built for fast rollout and optimized for getting devices and resources talking to each other quickly. Speed of setup is genuinely useful. Connectivity is a different thing from zero trust. Device posture enforcement, access groups, and least-privilege segmentation are the controls that define the model. They separate a private network from a policy-driven one, and they decide whether a non-human identity is governed or merely connected.

ZTNA Sized for an SMB, Applied to Non-Human Access

CloudConnexa from OpenVPN is one example of the middle position: full Zero Trust Network Access capability, including device posture checks, access groups, and least-privilege segmentation, delivered as a cloud service instead of a stack a small team has to assemble.

Its model extends ZTNA to machine access without a separate product, which matters for a company that will never buy a second platform to govern bots. Application servers, hosts, and IoT devices connect through Connectors, establishing always-on outbound tunnels authenticated by digital certificate instead of a shared secret sitting in a configuration file. A Host Connector exposes only the services running on the machine hosting it. A Network Connector attaches a whole private network and routes on its behalf.

Enforcement then happens per application. CloudConnexa builds a per-app firewall and routes by application domain name, so a connected identity reaches the services its policy permits and has no lateral path elsewhere. Device Identity Verification and Enforcement restricts which devices may connect at all. Access and DNS logs stream to external tooling, which turns an assertion about agent scope into something auditable.

The foundation matters for buyers assessing a smaller vendor. The open-source OpenVPN protocol has been in production for roughly two decades and underpins a large share of the VPN market, which is an unusual position for a product aimed at companies without security engineers.

Pricing tends to reveal who a product is for. OpenVPN publishes plans starting at $7 per month per connection, pricing that scales with headcount instead of arriving as a six-figure platform contract. For a business in the 50-to-200-employee range, that makes the cost of coverage legible in a way enterprise licensing rarely does.

What an SMB Should Evaluate in a Zero Trust Solution

Zero trust makes sense for a small business in 2026 for reasons that have little to do with threat modeling. Compliance frameworks, insurance underwriting, and autonomous software have each made it a condition of operating. The open decision is how to adopt the model without buying a security program to run it.

In practice, check for four things:

  • Access tied to verified identity instead of network location, so sitting inside the tunnel grants nothing by itself
  • Device health confirmed before a connection is allowed
  • Segmentation that limits what any single compromised account, service credential, or agent can reach
  • An operational footprint one or two people can maintain, because a tool needing a security engineer to configure is not right-sized whatever the datasheet says

Zero trust earned its enterprise reputation because large organizations had the budgets and staff to move first. The threats have since spread to everyone, and the AI tools smaller companies adopt for productivity are widening the attack surface as they go.

The machines have logins now. The work for lean IT teams is making sure something is deciding what those logins are allowed to do.

The Hacker News https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgQQyjwPYjJP0wddSEB8Dlpr3dlnQUs52-WmlrZfqJoBPeOvv2Zoqlq-FhEAz_Xeprj_mtrI1MGCW1JS840JUjVEK6VoNe6zCNNTw_7YmyvNmf3E5pprZ3zqP8lszq74Wt97SvbJo5yeuyep0U6-nGs0vdarg4_WUrc5r6L0ML0xE-BsPipJd2-1PMHTvO1/s76-e365/thn.jpg
Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Twitter and LinkedIn to read more exclusive content we post.