I'm Cynthia Akiotu, a Cybersecurity Architect and Microsoft MVP in Security, working at the intersection of identity, data security, AI security and governance.
My work is driven by a simple question:
As technology changes how organisations operate, how do we make sure security evolves with it?
For years, that question has centred on people, identities, applications and data. Today, it increasingly includes copilots, AI applications and autonomous agents that can access information, use tools and act on behalf of users and organisations.
That shift is where much of my work, research and writing now sits.

My background is deeply rooted in identity and access management, Zero Trust, data protection and enterprise security.
Identity remains foundational to how I think about security. But the boundaries of identity are changing.
We are moving into an environment where organisations are no longer governing only human identities and traditional applications. They must also understand:
This evolution has naturally expanded my focus into AI security, agent governance and enterprise AI readiness.
For me, AI security is not a separate conversation from cybersecurity. It is the next chapter of it.
My work and research currently span several connected areas.
Looking beyond simply building or adopting AI, to how AI applications, copilots and agents can be observed, governed and secured throughout their lifecycle.
Exploring how authentication, authorisation, privileged access, Zero Trust and identity governance evolve as humans, applications and AI agents increasingly operate alongside one another.
Understanding the new security questions introduced by autonomous and semi-autonomous agents — including agent identity, permissions, tool access, data access, monitoring, lifecycle and accountability.
Where sensitive information lives, who can access it, and how AI changes the way organisational data is discovered, consumed and shared.
The bigger picture: the security, governance, operating model and adoption questions that shape whether AI can scale responsibly.
I don't believe the role of security is simply to say “no.”
But I also don't believe organisations should move fast with AI and hope governance catches up later.
The challenge is finding the balance. Security should create the trust, visibility and guardrails that allow organisations to innovate with confidence.
That means bringing security into the AI conversation early — not after hundreds of copilots or agents have already appeared across the enterprise.
Security and adoption are not competing priorities. Done well, security is what makes sustainable adoption possible.
I speak at conferences, technical communities and industry events about cybersecurity, identity, AI security, governance and the changing enterprise security landscape.
My talks often explore the practical questions behind emerging technology:
I also write and share insights from my research, professional experience and conversations across the security and technology community.
My aim is not simply to explain what new technology can do. It is to explore what it changes — and what organisations need to do differently because of it.

I'm honoured to be recognised as a Microsoft Most Valuable Professional (MVP) in Security.
Being part of the MVP community gives me the opportunity to learn from, contribute to and exchange ideas with security professionals and technology communities around the world.
My Microsoft-focused work includes areas across Entra, Purview, Defender, Copilot, AI security and the broader Microsoft security ecosystem.
At the same time, the principles I write and speak about — identity, trust, governance, data protection and secure AI adoption — extend beyond any single technology platform.
Views, opinions and content shared on this website are my own and do not represent the views, positions or policies of any employer, client or organisation with which I am or have been associated.
Much of my current thinking is focused on what happens as organisations move from AI experimentation to AI at scale — and the questions that raises for security.
If you're organising a conference, building a security or AI initiative, exploring enterprise AI readiness, or simply interested in the future of identity and AI security, I'd love to connect.