Security teams should usually favour tactical projects when the organisation needs faster value and lower disruption. The article points to layering strong authentication and adding Single Sign-On as examples of narrower changes that can be deployed in weeks or months. Those projects can improve control and productivity while larger restructuring efforts are postponed.
Why tactical identity work is usually the better recession move
When budgets tighten, the right question is less about whether transformation is desirable and more about which work will reduce risk and friction soonest. Tactical identity projects usually win because they are narrower, easier to phase, and more likely to deliver measurable control improvements without forcing a broad operating-model change.
That does not mean transformation is wrong, only that recession conditions change the decision threshold. If a programme needs new governance, new ownership, major integration work, or broad process redesign before it delivers value, it is harder to justify unless the organisation has a clear risk driver or a time-bound compliance need.
A identity security business case is strongest when it shows near-term reductions in manual effort, outage risk, or access exposure, rather than promising abstract future simplification.
Which identity projects tend to be tactical enough to survive budget pressure?
The best tactical choices are the ones that improve a specific control path and can be delivered with limited dependency chains. Strong authentication uplift, Single Sign-On expansion, targeted access review cleanup, and credential hygiene work usually fit that profile because they improve day-to-day security and user experience without requiring a full redesign of the identity landscape.
Those projects are also easier to stage. Security teams can often start with a single application family, a high-risk user population, or a narrow set of privileged access paths, then expand once the initial pattern is proven. That approach preserves momentum and avoids the common failure mode of large programmes that stall while waiting for enterprise-wide agreement.
For broader sequencing, the Identity Security Programme Guide shows how to organise smaller wins into a roadmap without pretending every improvement requires a multi-year rebuild.
For teams dealing with service accounts, APIs, or workload credentials, the Cloud Workload Identity Guide is a useful reminder that some tactical moves, such as replacing static keys with temporary credentials, can materially reduce exposure fast.
When should a team still back a multi-year transformation?
Longer transformation work is justified when tactical fixes would leave the organisation with fragmented controls, repeated rework, or an unmanaged risk concentration. If the current identity model is so inconsistent that every new app integration creates a one-off exception, short projects may relieve pain but they will not fix the underlying operating burden.
The same is true when the organisation has a structural problem such as duplicated directories, fragmented access governance, poor lifecycle ownership, or weak visibility over privileged and non-human accounts. In those cases, tactical projects should still happen, but they need to be framed as stabilisation steps on the way to a better target state.
The practical distinction is whether the programme can be decomposed into independently useful increments. If each phase produces value on its own, the work can usually be funded tactically. If value only appears after a complete redesign, it is a transformation programme and should be treated as a strategic investment, not a short-term savings initiative.
Identity Security Maturity Model helps teams judge whether they are improving capability in steps or merely delaying a larger architecture decision.
Risk and Threat Considerations
Recession decisions can create false economy if teams cut the work that protects the highest-risk access paths. The main risk is not that tactical projects are too small, but that organisations use them to postpone urgent fixes around authentication strength, privilege sprawl, or credential lifecycle control.
Failure mechanism: Teams keep legacy access patterns in place because the transformation is deferred, while the exposed controls remain easy to abuse through stolen credentials, weak session handling, or excessive privileges. That leaves the organisation with short-term savings and persistent attack surface.
Impact: The result can be continued account takeover exposure, harder incident containment, and a longer tail of operational drag from manual workarounds. Even when no compromise occurs, the organisation may end up paying more later because deferred cleanup compounds technical and governance debt.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Tactical identity work often starts with stronger user authentication. |
| IA-9 — Identification and Authentication (Service and Application Accounts) | Workload and service credentials are a common tactical cleanup target. | |
| IA-5 — Authenticator Management | Credential lifecycle work directly supports short tactical identity projects. | |
| Recommendation — Harden organizational login paths before broader transformation. Replace static service credentials with stronger machine authentication. Enforce rotation, revocation, and secure storage for authenticators. | ||
| NIST CSF 2.0 | PR.AA-05 — Identity Management, Authentication, and Access Control | The question is about prioritising practical identity controls during constrained budgets. |
| Recommendation — Prioritise access controls that deliver immediate risk reduction. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Tactical identity changes often focus on access cleanup and least privilege. |
| Recommendation — Tighten account and access management where risk is concentrated. | ||
Practitioner Guidance
What to prioritise: Start with the identity changes that reduce exposure fastest, especially strong authentication, SSO, privileged access cleanup, and removal of long-lived or shared credentials. These usually give the best blend of risk reduction and visible operational benefit.
Decision rule: If the project can be delivered in one domain, one population, or one application cluster and leaves behind a lasting control improvement, it is a good tactical candidate. If it needs enterprise-wide redesign before any benefit appears, treat it as transformation and defend it on strategic grounds.
What to verify: Make sure each tactical project has a clear owner, a measurable outcome, and a known rollback or exception path. Recession periods punish vague roadmaps, so the team should be able to show what changed, what risk was reduced, and what remains outstanding.
Practitioner takeaway: In a downturn, the best identity strategy is usually to buy time with narrow, high-value control improvements while reserving multi-year transformation for the problems that cannot be solved safely in slices.
Related resources from NHI Mgmt Group
- How should security teams choose an identity platform for hybrid and multi-cloud environments?
- How should security teams use identity data lakes to reduce over-privileged access in multi-cloud environments?
- How should security teams prioritise NHI remediation in cloud environments?
- How should security teams govern non-human identities at scale?