By NHI Mgmt Group Editorial TeamBased on Veza: “They’re Not Hacking In, They’re Logging In: Ensure Your Insurability in the New Threat Landscape” (October 8, 2025)

TL;DR: Identity security is shifting from authentication to authorization because attackers increasingly log in with valid credentials, not exploits, and insurers are asking for proof of privilege control, NHI accountability, and third-party access limits, according to Veza. The practical test is whether organisations can continuously show who can do what, across users, NHIs, API keys, AI agents, and vendors, before premiums and coverage decisions harden.


At a glance

What this is: This analysis argues that cyber insurability now depends on authorization visibility, not just authentication, because valid credentials, excessive permissions, and hidden access paths are driving the loss profile.

Why it matters: IAM, PAM, NHI, and governance teams need evidence that access can be continuously inventoried and constrained across human, machine, and third-party identities before underwriters treat weak authorization as uninsurable risk.

By the numbers:

  • Ransomware accounted for 58% of large claims, according to Veza.
  • 79% of attacks are now malware-free, according to Veza.

Context

Cyber insurance underwriters are increasingly treating identity authorization as a proof problem, not just a hygiene problem. The article argues that authentication controls alone do not answer the question insurers care about most: what an identity can actually do once it gets in.

That shift matters because the attack path now often starts with valid access, then moves through dormant accounts, over-permissioned roles, and third-party access. The governance gap is not only exposure, but the inability to show complete and current authorization state across human and non-human identities.

For IAM and NHI teams, the practical implication is that visibility, entitlement scope, and lifecycle accountability have become underwriting inputs. The article frames insurability as a function of evidence, not intention.


Key questions

Q: How should security teams prove authorization control to cyber insurers?

A: They should show current entitlement inventories, ownership for each identity, evidence of least privilege, and a repeatable review trail that demonstrates access is measured and reduced over time. Insurers care less about policy statements than proof that excessive privilege, dormant access, and third-party entitlements are being found and removed before loss occurs.

Q: Why do valid credentials still create risk after exploitation?

A: Valid credentials become dangerous when they are harvested through compromise and then reused in channels that look normal to monitoring tools. The risk is not only access, but trust inflation: the system treats stolen identity material as legitimate unless provenance, issuer controls, and behavioural checks are in place.

Q: What do teams get wrong about non-human identity governance?

A: They often manage service accounts, tokens, and API keys with the same lifecycle assumptions used for human users. That breaks down when credentials are created automatically, owned ambiguously, and retired inconsistently. NHI governance needs separate inventory, ownership, rotation, and offboarding discipline because these identities do not follow HR-driven lifecycle patterns.

Q: Should organisations treat third-party access as a privileged identity risk?

A: Yes, because third-party access often bypasses the same scrutiny applied to internal users while still reaching sensitive systems. Organisations should classify external accounts by privilege, require attestation, and remove access when the business need ends. If a supplier or integrator can alter records or administer systems, that access belongs in privileged governance.


Technical breakdown

Why valid credentials beat perimeter controls

The article describes a threat pattern where attackers no longer need to break in if they can log in. That shifts the technical centre of gravity from perimeter defence to authorization control, because authenticated sessions with excessive permissions still allow lateral movement, privilege escalation, and persistence. Authentication confirms identity, but it does not bound what the identity can do after sign-in. In modern environments, the decisive failure is often not login itself but the granted access behind the login. Practical implication: treat authentication as necessary but insufficient, and model post-authentication privilege as the real exposure surface.

Practical implication: inventory the permissions that remain usable after authentication, not just the controls that gate sign-in.

Authorization intelligence across NHIs, API keys, AI agents, and vendors

The article broadens authorization beyond human users to the identities that routinely carry hidden reach: service accounts, API keys, AI agents, and third-party vendors. These identities are operationally different, but they share the same governance need, which is provable access scope and ownership. In NHI terms, the issue is not just secret possession but the entitlement carried by the secret. When an identity lacks clear ownership, lifecycle control, or right-sized permissions, underwriters see uncertainty that can become loss amplification. Practical implication: build one access model that can explain scope, ownership, and revocation for every non-human identity class.

Practical implication: extend entitlement review and ownership evidence to machine identities, not just employee accounts.

Insurability depends on proving least privilege continuously

The article makes least privilege an evidence requirement, not a policy statement. Underwriters want proof of full privilege inventory, dormant permission discovery, separation-of-duties checks, and a trail that shows policy enforcement over time. That is materially different from merely saying a PAM or access review process exists. In governance terms, the organisation must demonstrate that excess privilege is being identified, reduced, and measured across systems, not assumed away by architecture. Practical implication: shift from point-in-time access review to continuous authorization telemetry that can support external assurance.

Practical implication: use continuous entitlement monitoring to produce defensible evidence for access reviews and insurance questionnaires.


Threat narrative

Attacker objective: The attacker aims to turn legitimate-looking access into privileged control that enables lateral movement, ransomware, or high-value data theft without triggering traditional perimeter defences.

  1. Entry occurs when an attacker obtains valid credentials through phishing, stolen secrets, or compromised third-party access and logs in without needing an exploit.
  2. Escalation follows when excessive permissions, dormant accounts, or toxic role combinations allow the attacker to move laterally and increase privilege inside the environment.
  3. Impact occurs when the attacker uses that authorised access to exfiltrate data, deploy ransomware, or create losses large enough to affect claims and coverage terms.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Authorization has become the underwriting control plane: The article is right to move the discussion from authentication to authorization, because insurers are no longer satisfied with proof that a user logged in securely. What matters is whether the organisation can prove the scope, ownership, and revocation status of the access that follows login. For identity programmes, that turns entitlement governance into an insurability requirement, not a back-office reporting exercise.

NHI accountability is the missing proof layer: Visibility into service accounts, API keys, and other non-human identities is now central because those credentials often carry durable access that human-centric controls never fully review. A named concept here is authorization evidence debt: the gap between having access controls and being able to prove them under audit or underwriting scrutiny. The implication is that NHI programmes need verifiable ownership and scope data, not just secret inventory.

Dormant privilege is an exposure multiplier: The article’s focus on dormant accounts and over-permissioned roles highlights a failure mode that insurers can price even when no incident has occurred. Idle privilege creates a standing path for misuse, especially when attackers arrive with valid credentials rather than malware. That means identity governance has to measure unused access as a live risk signal, not a clean-up task.

Third-party access now sits inside the insurability perimeter: Vendor and supply-chain identities are not separate from identity risk, they are part of the same access fabric. If access for external identities cannot be described, constrained, and audited, then coverage conversations will increasingly treat that uncertainty as a control weakness. Practitioners should expect insurer scrutiny to follow delegated access, not just employee accounts.

Continuous authorization telemetry is becoming the proof standard: The article points toward a market where static questionnaires will matter less than live evidence of who can access what. That shifts identity security toward continuously measurable controls across users, NHIs, and AI-driven access paths. Practitioners should treat authorization telemetry as an external assurance capability, not only an internal operations metric.

From our research library:

What this signals

Authorization evidence debt: Many organisations can say who authenticated, but far fewer can prove what those identities were allowed to do at the moment of access. That gap becomes material when underwriters want evidence across users, NHIs, vendors, and AI-driven access paths.

Insurance scrutiny will increasingly reward programmes that can explain entitlement scope, dormant privilege, and revocation status in plain terms. The practical shift is from periodic access cleanup to continuously defensible authorization state.

For identity leaders, the consequence is straightforward: least privilege must become measurable across every identity class, not just documented for auditors.


For practitioners

  • Inventory all effective entitlements Build a complete map of who can access what across employees, service accounts, API keys, AI agents, and vendors, then reconcile it against current business need.
  • Prove NHI ownership and accountability Assign a human owner to every non-human identity and document revocation paths, approved use, and lifecycle status for each one.
  • Reduce dormant and over-permissioned access Identify unused privileges, stale accounts, and toxic combinations, then right-size roles to the minimum access needed for current operations.
  • Prepare insurer-ready evidence packs Assemble a repeatable set of entitlement reports, policy enforcement logs, and access review outputs that show authorization control over time.

Key takeaways

  • The article reframes cyber insurability as an authorization problem because attackers are increasingly using valid access rather than exploits.
  • Its evidence points to a claims environment shaped by ransomware and malware-free attacks, which makes entitlement control more commercially relevant.
  • Teams that cannot prove ownership, scope, and least privilege across human and non-human identities will struggle to answer insurer questions with confidence.

Key terms

  • Authorization Intelligence: Authorization intelligence is the ability to see what an identity can actually do, not just whether it authenticated successfully. It combines entitlements, effective access, and usage signals so teams can identify privilege creep, dormant rights, and risky access paths across human, machine, and delegated identities.
  • Dormant Privilege: Dormant privilege is access that remains technically active after the business reason for using it has ended. The account still works, but the relationship, project, or contract that justified it no longer does. In practice, dormant privilege is a lifecycle failure that turns routine collaboration into lingering exposure.
  • Non-Human Identity Accountability: Non-human identity accountability is the practice of assigning clear human ownership, scope, and lifecycle responsibility to service accounts, API keys, tokens, and similar credentials. It is a governance requirement because machine identities do not self-describe intent or business purpose.
  • Insurability Evidence: Insurability evidence is the set of records, controls, and operational proof an insurer can use to assess identity risk. For access governance, that means current entitlements, review history, least-privilege enforcement, and revocation records that show the programme is measurable rather than aspirational.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 25, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org