Identity risk tends to drift upward because attacker behavior, user habits, and access patterns change over time. Without ongoing review, organisations lose visibility into trusted accounts, miss emerging anomalies, and fall behind on authentication practices. A steady program of monitoring, education, and control tuning is needed to keep identity security aligned with real-world use.
Why Identity Management Stops Being Reliable When It Becomes a Project
Identity management is only durable when it behaves like a control plane, not a launch initiative. Once teams treat it as “done,” the environment keeps changing underneath it: new accounts appear, privileges accumulate, authentication methods age out, and dormant access quietly becomes normal. The practical result is not just weaker administration, but a widening gap between who should have access and who actually does.
That gap often shows up first in the boring places: stale joiner-mover-leaver records, forgotten service accounts, and review processes that exist on paper but no longer reflect real usage. A control that is not continuously exercised quickly becomes a snapshot, and snapshots age badly in active environments.
For teams building an ongoing programme, the useful mental model is lifecycle management rather than deployment. NHIMG’s IAM and IGA Basics frames this well because provisioning, access review, entitlement governance, and revocation are recurring operations, not one-off deliverables. The same is true of the Identity Security Posture Management (ISPM) Guide, which treats drift, dormant access, and standing privilege as conditions to monitor, not exceptions to close once.
What Breaks First: Visibility, Authentication, and Access Governance
The first failure mode is usually visibility. If identity controls are not continuously refreshed, organisations stop knowing which accounts are active, which credentials are still valid, and which privileges are still justified. That creates blind spots for recertification, incident response, and control ownership, especially where cloud, SaaS, and machine accounts change faster than review cycles.
The second failure mode is authentication staleness. Authentication practices evolve, attackers adapt, and legacy methods become weak links. A programme that was adequate at rollout may lag behind current bypass techniques, especially where MFA fatigue, token theft, and recovery abuse have changed the attacker playbook. NHIMG’s MFA Guide is a useful reminder that authentication strength is not static, and NIST SP 800-63 Digital Identity Guidelines remains the clearest external reference for aligning assurance to current authenticator risk.
The third failure mode is access sprawl. When entitlement review becomes periodic theatre instead of operational discipline, excess access accumulates in human and non-human accounts alike. NHIMG’s Privileged Access Management Guide is especially relevant here because privileged access, JIT, vaulting, and session control only work when they are maintained as living controls. For workload and service access, SPIFFE workload identity specification shows the same principle in a different form: identity must be continuously attested, not assumed forever.
Why the Risk Grows Over Time
When identity management is treated as a project, risk does not merely remain static, it compounds. Old assumptions about who needs access, how they authenticate, and which systems they touch become less accurate each month the programme is left untouched. That is why stale accounts, overprivileged roles, and uncontrolled exceptions become attractive footholds for an attacker who is waiting for the environment to drift.
Top 10 NHI Issues is a useful companion view because it highlights how lifecycle neglect turns into ownership gaps, excessive permissions, reuse, and offboarding failures. The same underlying pattern appears in human identity programmes: if controls are not tuned, reviewed, and measured, the organisation gradually depends on trust that is no longer justified by current state.
Risk also increases because identity is a control dependency for other controls. Logging, segmentation, authorization, and privileged access all assume that identity data is current enough to be trusted. Once that assumption weakens, every downstream control inherits the error.
Risk and Threat Considerations
The main danger is control drift: access reviews, MFA posture, and lifecycle records stop matching reality, so the organisation believes it has tighter governance than it actually does. Attackers look for exactly that gap, because dormant accounts, old tokens, and excessive permissions often provide the easiest path to persistence or lateral movement.
Failure mechanism: Time creates mismatch between the intended access model and the live identity estate, while stale exceptions and unused accounts remain active long after their business need has ended.
Impact: The organisation loses confidence in who can access what, response becomes slower and less precise, and compromise of one account is more likely to spread into broader privilege abuse.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Ongoing identity control depends on credential lifecycle, rotation, and revocation. |
| AC-2 — Account Management | Project-only identity work leaves account inventory, activation, and removal out of date. | |
| IA-2 — Identification and Authentication (Organizational Users) | Identity management fails when authentication assurance is not maintained over time. | |
| Recommendation — Enforce lifecycle management for credentials and rotate or revoke them on change. Continuously review, disable, and remove accounts that no longer have a business need. Reassess user authentication strength and upgrade weak methods as threats change. | ||
| NIST CSF 2.0 | ID.AM-01 — Physical devices and systems within the organization are inventoried | Identity control quality depends on current inventory of accounts and related assets. |
| PR.AA-05 — Identity and access permissions are managed, incorporating the principles of least privilege and separation of duties | The question is fundamentally about access governance that must be maintained, not launched. | |
| Recommendation — Maintain an up-to-date inventory of identity-relevant assets and accounts. Run access governance as a continuous process and remove excess privilege promptly. | ||
| CIS Controls v8 | CIS-5 — Account Management | Continuous account governance is the core safeguard against identity drift and stale access. |
| Recommendation — Operationalize account lifecycle reviews, disablement, and exception tracking as a standing control. | ||
| NIST SP 800-63 | Digital Identity Guidelines | Current identity assurance and authenticator guidance informs ongoing authentication upkeep. |
| Recommendation — Align authenticators and assurance levels to current risk and re-evaluate them regularly. | ||
Practitioner Guidance
What to prioritise: Treat identity as a monitored control with owners, review intervals, and measurable drift rather than as a rollout task. The first things to stabilise are privileged access, dormant accounts, and credential lifecycle, because those areas produce the fastest reduction in exposed attack surface.
What to verify: Verify that recertification evidence, revocation timing, and authentication policy changes are actually happening on schedule, and that exceptions are time-bound. If a team cannot show recent evidence of review or removal, assume the control has degraded even if the tool is still in place.
Practitioner takeaway: The question is not whether identity was implemented, but whether it is still being governed at the speed of real organisational change.
Related resources from NHI Mgmt Group
- What breaks when organisations treat privileged access as a one-time project instead of an ongoing control?
- What breaks when organisations treat remediation as a one-time cleanup instead of an ongoing identity and secrets control process?
- What happens when organisations treat fraud as a one-time training problem instead of an ongoing control issue?
- What happens if organisations treat CCPA compliance as a one-time project instead of an ongoing programme?