By NHI Mgmt Group Editorial TeamDomain: AnnouncementsSource: ExpelPublished February 25, 2026

TL;DR: Attackers usually choose the cheapest path, according to Expel’s webinar-based analysis of 300 CISOs and CFOs, while identity incidents still dominated 68.6% of events and 52.3% were blocked by basic controls such as MFA and conditional access. The security case for finance is now about measurable risk reduction, business enablement, and the cost of leaving fundamentals unfinished.


At a glance

What this is: This is Expel’s analysis of why foundational controls beat flashy threat chasing, with identity security and operational discipline doing most of the risk-reduction work.

Why it matters: It matters because IAM, PAM, and security architects need to show CFOs that basic identity controls materially reduce exposure, especially where human and non-human access patterns overlap.

By the numbers:

👉 Read Expel's analysis of how boring security controls drive cybersecurity ROI


Context

Fundamental security controls fail most often because they are under-configured, under-prioritised, or measured in ways finance leaders cannot translate into business value. In practice, identity and access management, patching, cloud hygiene, and third-party risk controls stop the attacks that occur most often, while exotic threat narratives absorb attention and budget.

For identity programmes, the key lesson is that access governance is not just an IT control. When MFA, conditional access, onboarding, offboarding, and least privilege are implemented well, they reduce both account takeover risk and the operational friction that usually makes security look like a cost centre rather than a business enabler.


Key questions

Q: What breaks when identity controls are only documented and not executed consistently?

A: When identity controls exist only on paper, the organisation loses the ability to prevent or promptly detect bad access, missed approvals, and offboarding gaps. That creates a control deficiency first, then a broader governance problem if the failures repeat. The practical test is whether the control produces reliable evidence in real operations, not whether it is written into policy.

Q: Why do basic identity controls often outperform advanced threat tooling?

A: Basic identity controls outperform advanced tooling because they interrupt the most common attack paths before compromise spreads. MFA, conditional access, and proper offboarding reduce the opportunities attackers need to turn a stolen credential into a business impact event. The return is higher because these controls block common, repeatable failure modes rather than rare attack techniques.

Q: How can security teams know if cloud identity governance is actually working?

A: The clearest signals are fewer unresolved access findings, shorter evidence-collection cycles, lower counts of stale keys, and reduced reliance on manual review. If teams still spend days reconstructing access state, governance is not operating continuously. Effective programmes can show current MFA coverage, role scope, and credential age on demand.

Q: Who is accountable when identity risk causes measurable business impact?

A: Accountability sits with the teams that own identity governance, privileged access, and security risk decisions, not with the alerting tool alone. Organisations should define who can translate identity findings into financial exposure, who approves remediation, and who is responsible for containment when a privileged identity is compromised.


Technical breakdown

Why basic identity controls stop most attacks

Attackers usually optimise for lowest cost and highest reliability, which is why compromised identities remain a dominant entry path. MFA, conditional access, managed-device requirements, and proper onboarding and offboarding interrupt that path before escalation begins. The important point is not that advanced threats do not exist, but that most successful campaigns still depend on basic control failures such as weak authentication, stale accounts, or poorly enforced access policy. In identity terms, the organisation often loses because it allows persistence in account state after business need has changed.

Practical implication: measure the percentage of accounts protected by phishing-resistant MFA and enforced conditional access, then close the exceptions first.

How configuration determines whether controls work

Many identity incidents succeed not because the control is absent, but because it is inconsistently configured across systems, tenants, or business units. A control like conditional access only reduces risk if policy coverage, device trust, identity proofing, and session enforcement align across the environment. The same applies to offboarding and access reviews: if the workflow exists but stale privileges remain active, the control is present in name only. This is where governance discipline matters more than product count, especially in hybrid estates where human and non-human identities coexist.

Practical implication: audit control effectiveness by environment, not by policy existence, and look for gaps between approved standards and actual enforcement.

Why security ROI is easier to prove with fundamentals

The business case for fundamental controls is stronger because the threats, baseline exposure, and prevention outcomes are easier to quantify. Finance leaders can understand the difference between a credential compromise prevented by MFA and an abstract claim about advanced adversary behaviour. That makes identity governance, patch compliance, and cloud access hygiene easier to tie to cost avoidance, service continuity, and reduced incident response burden. In IAM and PAM programmes, this creates a defensible line from control coverage to operational resilience, which is what CFOs actually fund.

Practical implication: present identity control coverage as avoided-loss economics, using measurable reductions in compromise and remediation effort.


Threat narrative

Attacker objective: The attacker objective is to reach business-relevant systems through the least expensive access path, usually by abusing identity weaknesses rather than deploying novel malware.

  1. Entry occurs when attackers target the cheapest workable path, most often a compromised identity rather than a complex exploit chain.
  2. Escalation follows when basic controls such as MFA, conditional access, or privilege boundaries are misconfigured or inconsistently enforced.
  3. Impact is achieved through account takeover, lateral movement, or abuse of over-privileged access that could have been blocked by fundamentals.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Boring controls are still the dominant risk-reduction lever in identity security. The market often rewards sophisticated narratives, but most real-world compromise still starts with weak authentication, stale access, or policy gaps. For IAM and PAM leaders, that means the highest-value work is usually the least glamorous work, because it reduces the attack paths that adversaries actually use.

Identity governance has become a finance conversation, not just a technical one. When controls are measurable, the security team can explain avoided loss, business enablement, and operational continuity in the language CFOs understand. That shifts IAM from a compliance activity to a budgetable risk function, which is where mature programmes win executive support.

Configuration quality is the real control surface in modern identity programmes. The issue is rarely whether MFA or conditional access exists. The issue is whether those controls are enforced consistently across applications, devices, and exceptions, especially where service accounts and third-party access extend the blast radius. Practitioners should treat inconsistent enforcement as the primary governance defect.

Identity security now spans human, non-human, and delegated access patterns in one operating model. Expel’s findings reinforce a broader pattern: the same discipline that protects employee access also constrains service accounts, tokens, and third-party integrations. That intersection matters because the enterprise cannot justify separate governance logic for each identity class forever, so unified policy and monitoring become the practical endpoint.

From our research:

What this signals

Excess privilege remains the hidden tax on identity programmes. When access is easier to grant than to remove, security teams end up preserving risk by default. The practical signal for readers is to treat entitlement cleanup, delegation review, and access drift as recurring operational work, not audit-only tasks.

Identity control coverage should now be measured against business enablement, not just compliance status. If security cannot show where MFA, conditional access, and offboarding are supporting revenue, onboarding, or third-party collaboration, funding will stay fragile. This is where the Ultimate Guide to NHIs , Why NHI Security Matters Now is useful for framing the broader governance case.


For practitioners

  • Baseline identity control coverage first Inventory MFA, conditional access, managed-device enforcement, onboarding, and offboarding coverage across all business units. Prioritise the identities and applications where exceptions still allow login from unmanaged devices or untrusted locations.
  • Translate control performance into avoided-loss metrics Report identity security as blocked compromise attempts, reduced exception counts, and faster offboarding rather than abstract maturity scores. Tie each metric to a business process or financial exposure so finance can see the risk reduction.
  • Audit configuration drift across access policies Compare approved identity policy baselines with actual enforcement in production, including tenant-specific overrides and legacy exceptions. Treat policy drift as a governance failure because it creates invisible access paths.
  • Extend governance to delegated and third-party access Review vendor connections, service accounts, and API-based integrations with the same discipline used for employee access. Validate that standing privileges, shared accounts, and unused integrations are removed or constrained before they become the easiest path in.

Key takeaways

  • Most attackers still succeed by exploiting basic identity and access failures, not by using extraordinary techniques.
  • The strongest cybersecurity ROI story comes from measurable control coverage, especially where identity controls block common compromise paths.
  • IAM teams should treat configuration quality, exception management, and delegated access governance as the real levers of risk reduction.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05The article centers on access governance and excessive privilege across identity types.
NIST CSF 2.0PR.AC-4Conditional access and managed identity enforcement align directly to access control governance.
NIST SP 800-53 Rev 5IA-2Authentication controls are central to blocking the attacks discussed in the article.
CIS Controls v8CIS-6 , Access Control ManagementThe post focuses on access policies, identity hygiene, and control enforcement.
MITRE ATT&CKTA0006 , Credential Access; TA0004 , Privilege EscalationThe article describes common identity abuse paths that map to credential theft and privilege gain.

Map identity control gaps to TA0006 and TA0004, then prioritise the access paths most likely to be abused.


Key terms

  • Conditional Access: Conditional access is a policy model that decides whether an action should proceed based on context such as posture, resource sensitivity, timing, and scope. For AI agents, it must be evaluated at request time so a valid credential does not automatically equal permitted behaviour.
  • Identity Governance: Identity governance is the set of controls that defines who approves access, who owns it, how it is reviewed, and when it is removed. In practice, it turns identity management from a deployment task into a durable control system that can withstand audits, organisational change, and operational growth.
  • Off-boarding: Off-boarding is the process of removing a departing user’s access, credentials, and related entitlements from the environment. In mature IAM programmes, it also includes reviewing sessions, shared secrets, delegated roles, and linked non-human identities so that exit events do not leave behind hidden access paths.
  • Over-Privilege: Over-privilege is the state where an identity holds more access than the work requires. In IAM and NHI programs, it usually emerges from role drift, delayed offboarding, emergency exceptions, and copied permissions that are never removed.

What's in the full article

Expel's full article covers the operational detail this post intentionally leaves for the source:

  • How the webinar participants framed security ROI for CFO audiences, including the language that made budget discussions land.
  • The full breakdown of identity, endpoint, cloud, and third-party control examples that illustrate where fundamentals most often fail.
  • The survey context from 300 CISOs and CFOs, including how the research was used to support the business-case argument.
  • The broader CISO-CFO communication model that Expel and SMBC used to connect security controls to business enablement.

👉 Expel's full post includes the CFO framing, webinar insights, and control examples behind the argument.

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, identity lifecycle, and secrets management. It gives security and identity practitioners a practical framework for reducing access risk across human and non-human estates.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 19, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org