TL;DR: Its €2.5 million pre-seed extension, backed by financial-sector investors including Criteria Venture Tech and Bankinter, reflects the growing view that identity is now the primary attacker entry point and that regulated environments need faster detection, response, and compliance alignment, according to 8Layers. Identity governance is shifting from periodic checks to continuous visibility across sessions, service accounts, and cloud identities.
At a glance
What this is: This is a funding update framed as an identity security analysis, with 8Layers arguing that attackers increasingly enter through credentials, sessions, and service accounts rather than perimeter compromise.
Why it matters: It matters because IAM, PAM, NHI, and security teams in regulated environments need continuous identity visibility and response, not audit-time assurance.
Context
8Layers' post is best read as a market signal about identity threat detection and response, not as a simple funding announcement. The company argues that modern attacks increasingly start with stolen credentials, hijacked sessions, or abused service accounts, which pushes identity security from a governance topic into an operational detection problem.
For IAM and security programmes, the more important claim is that compliance, posture, and incident response are converging around the same identity telemetry. That affects how teams design controls for NHI, human access, and emerging AI agent access, because the question becomes how quickly identity abuse can be detected and contained once it begins.
Key questions
Q: How should security teams detect identity attacks when attackers are already inside valid sessions?
A: Security teams should look for deviations in behavior rather than relying only on authentication success. A valid session can still be malicious if the identity starts sending unusual requests, accessing unfamiliar systems, or changing routine actions. Correlating identity activity, SaaS events, and email-origin signals helps expose phishing, token theft, rogue MFA registration, and mailbox rule abuse before attackers persist.
Q: Why do service accounts and administrator accounts need different governance than human logins?
A: Because they are designed for different runtime patterns. Service accounts and administrative identities often operate continuously, integrate with systems, and hold broader permissions, so lifecycle oversight, scope reduction, and revocation need to be more precise than for ordinary user access.
Q: What are the signs that an identity programme is too audit-focused?
A: A programme is too audit-focused when it can explain access after the fact but cannot see abuse forming in real time. Common signs include delayed identity evidence, separate security and compliance datasets, and controls that only produce answers during review cycles. That creates blind spots for fast-moving credential, session, and service-account abuse.
Q: What should organisations do when AI agents start using machine identities to act independently?
A: They should treat the agent as a governed non-human identity with runtime guardrails, not just an automation feature. That means constraining issued credentials, monitoring behaviour, and revoking access quickly when the agent acts outside its intended scope or accesses unfamiliar systems.
Technical breakdown
Why identity threat detection needs structured identity inventory
8Layers' core architectural claim is that identity security works better when the system maintains an inventory of identities, sessions, and resources rather than treating logs as the primary source of truth. A structured inventory lets detections correlate who authenticated, what was used, and which resource was touched without scanning huge event streams after the fact. That matters because identity attacks often unfold across multiple small signals. A log-first model can see the pieces, but a structured model can link them into a coherent attack path. This is especially relevant in regulated environments where speed and auditability both matter.
Practical implication: treat identity inventory as a detection substrate, not just an asset register.
How posture and detection reinforce each other in identity security
The article distinguishes posture from detection and response, and that distinction matters operationally. Posture controls reduce what an attacker can use, while detection and response surface what is already happening. In identity terms, this means reducing standing exposure on accounts, sessions, and cloud identities while simultaneously watching for abuse patterns that indicate compromise or misuse. The two layers are complementary. Without posture, detection sees too much attack surface. Without detection, posture still leaves blind spots where identity misuse can progress unnoticed.
Practical implication: align posture reviews and runtime detection around the same identity objects and trust boundaries.
Why identity evidence maps to compliance more naturally than log evidence
8Layers argues that technical identity state can be validated against security baselines and then reused for compliance reporting. That is a useful model because many identity obligations in frameworks like ENS, NIS2, and ISO 27001 are about whether access is controlled, reviewed, and justified, not whether logs exist in isolation. A live identity control state gives teams a current answer to audit questions instead of forcing reconciliation between separate security and compliance datasets. This does not eliminate the need for governance, but it reduces the gap between control operation and control evidence.
Practical implication: build compliance evidence from live identity state where possible, not from separate reporting exports.
Threat narrative
Attacker objective: The objective is to move through identity trust relationships quietly enough to sustain access, expand control, and complete an intrusion before defenders can correlate the chain.
- Entry begins when attackers obtain stolen credentials, hijack an active session, or abuse an over-permissioned service account to reach identity-controlled resources.
- Escalation follows when the abused identity is used to correlate cloud identities, sessions, and resources in ways that remain invisible to point-in-time controls.
- Impact occurs when the attacker operates long enough to expand dwell time, discover additional paths, and execute a broader campaign before response catches up.
Breaches seen in the wild
- Secrets in VS Code extensions 2025: Wiz found 550+ secrets in VS Code extensions, including publishing tokens able to push malicious updates to about 150,000 installs.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Identity threat detection has become a governance problem, not just a monitoring problem: The article is really describing a shift from static access oversight to runtime identity control. When credentials, sessions, and service accounts are the primary attack surface, periodic review alone cannot keep pace with abuse that unfolds between review cycles. Practitioners should read this as a signal that identity visibility now has to operate continuously, not only during audit windows.
Identity inventory is the named control concept that changes the detection model: A structured inventory of identities and sessions is more than a technical preference. It changes what can be correlated, retained, and validated across time, which is why it becomes the foundation for identity threat detection and response. The practitioner conclusion is that unstructured logs should no longer be treated as the core identity evidence layer.
Compliance and detection are converging on the same identity state: The post implies that technical baselines can serve both security operations and framework alignment when the identity record is continuously current. That is significant because it reduces the gap between what defenders see and what auditors ask for. For regulated programmes, the practical conclusion is that identity governance should produce live evidence, not retrospective reconstruction.
Service account abuse remains the most under-governed part of the identity estate: The article places service accounts alongside human credentials and sessions as active attack paths, which is the correct framing. Too many programmes still separate human IAM from NHI governance, even though attackers do not respect that separation. The practitioner conclusion is that service account control must sit inside the same operational identity model as human access.
AI agents widen the identity problem because they add another class of access that cannot be handled as a simple extension of human IAM: 8Layers' mention of AI agents is important because it points to an emerging governance gap, not just a new workload type. If the programme still assumes identities are either human users or static machine accounts, it will miss runtime behaviour that changes faster than traditional review and certification models can absorb. The practitioner conclusion is to treat AI-agent access as its own governance design problem.
What this signals
Identity inventory is becoming the control plane for detection and governance: When identity state is structured, teams can connect access, session activity, and resource use without relying on slow log reconstruction. That shifts identity security from evidence gathering after the event to correlation during the event, which is where response value is won.
NHI and human identity programmes are converging operationally: The article is a reminder that service accounts, sessions, and human credentials now sit in the same attack graph. Identity teams that keep machine access in a separate lane will miss the correlations that matter most during active abuse.
AI-agent access will pressure existing governance cadences: If an identity can act, adapt, and chain actions faster than review cycles, the control model has to move closer to issuance and runtime behaviour. That is the direction identity governance is heading, whether programmes have formalised it yet or not.
For practitioners
- Map identity telemetry to real attack paths Correlate credentials, sessions, service accounts, and cloud resources as one chain so that abuse can be seen in context rather than as isolated alerts.
- Separate posture controls from detection controls Use posture to reduce standing exposure and use runtime detection to catch identity abuse that still gets through, especially in regulated environments.
- Build compliance evidence from live identity state Align technical identity baselines with audit requirements so the same control data can support security operations and framework alignment.
- Fold service accounts into the main identity programme Treat service accounts as first-class governed identities, with the same visibility and control expectations as human access.
- Define AI-agent access as a distinct governance case Do not extend human certification models unchanged to AI agents; evaluate whether their access changes too quickly for periodic review to be meaningful.
Key takeaways
- 8Layers frames identity as the primary attack surface, with credentials, sessions, and service accounts driving the shift toward runtime detection.
- The article argues that structured identity inventory improves correlation across identity events and makes response faster than log-first approaches.
- For practitioners, the main implication is that identity governance, detection, and compliance evidence need to converge on the same live identity state.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack surface, NIST CSF 2.0 sets the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | Service accounts and other machine identities are described as common abuse paths. |
| NHI-01 — Improper Offboarding | The post stresses continuous identity state, which is essential when accounts and sessions outlive intent. | |
| Recommendation — Reduce standing access on service accounts and other NHI credentials to shrink attacker reach. Revoke stale identity access promptly when a human or machine account is no longer needed. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | The article centres on stolen credentials, hijacked sessions, and abuse across identity-bound resources. |
| Recommendation — Map identity detections to credential access and lateral movement techniques to spot chained abuse. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is about governing and monitoring identity permissions as an operational control. |
| Recommendation — Continuously validate identity entitlements against expected access and investigate drift quickly. | ||
| ISO/IEC 27001:2022 | A.8.2 — Privileged Access Rights | The post discusses privileged identity exposure and control state in regulated environments. |
| Recommendation — Review privileged access rights on a live basis and remove excessive permissions before they are abused. | ||
Key terms
- Identity Threat Detection and Response: Identity threat detection and response is the practice of finding misuse of credentials, unusual access patterns, and compromised identities across human and machine actors. For NHIs, it relies on telemetry from code, vaults, cloud services, and pipelines to detect abuse early enough to contain it.
- Identity Inventory: Identity inventory is the process of discovering and recording every identity that can access systems or data. For NHIs, it includes owner, purpose, privilege scope, lifecycle status, and where the credential is used. Without inventory, governance, audit evidence, and incident response all become partial and unreliable.
- Service Account: A special-purpose account used by applications, automated tools, or services rather than a human user to interact with systems, APIs, and infrastructure. Service accounts are a primary category of NHI and one of the most frequently exploited attack vectors.
- Compliance Evidence: Compliance evidence is the artefact trail that proves a control operated as intended. In identity programmes, that usually includes approvals, review outcomes, revocation records, and exception handling. Strong evidence is time-bound, attributable, and reusable across audits instead of being rebuilt manually for each framework.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org